Legal information
Privacy and cookie policy
Version 24 July 2026
Who is responsible?
The organizer of NA Sweden’s 40th Anniversary Convention 2027 is responsible for the personal data processed in the registration system. Questions about personal data can be sent to registration@na40.se.
Data we process
We process the information you provide during registration, including name, email address, telephone number, country, language, order contents and discount information. We also store payment status and payment references from Stripe, email and SMS delivery logs, check-in status and necessary technical security logs.
Why we process the data
The data is used to administer registrations, payments, confirmations, changes, refunds, QR tickets, check-in and support. It is also used to prevent misuse and to meet accounting or other legal obligations.
Who may receive the data?
Data is only shared when needed to operate the registration. This can include our web hosting and database provider, Stripe for payments, the email provider for confirmations and 46elks when SMS is sent. Payment card details are handled by Stripe and are not stored in this system.
Retention
Personal data is kept only for as long as needed to administer the convention, handle claims and meet legal obligations. Accounting records and payment documentation may need to be kept for a longer period under applicable law. Data that is no longer needed will be deleted or anonymised.
Your rights
You may request information about your personal data and ask for incorrect data to be corrected. Depending on the circumstances, you may also request deletion, restriction or object to processing. Contact us at registration@na40.se. You may also lodge a complaint with the Swedish Authority for Privacy Protection.
Necessary cookie
NA40.se uses the first-party session cookie __Host-NA40SESSID only when a function needs temporary server-side state, for example registration, a protected form, check-in or administrator login. Ordinary public information pages do not create the cookie merely because they are read.
The cookie contains a random session identifier and is used for language within an active session, shopping-cart state, form security and authenticated administration. It is protected with Secure, HttpOnly, SameSite=Lax and Path=/, has no Domain attribute and is deleted when the browser session ends. It is not used for analytics, advertising, profiling or cross-site tracking.
Because this cookie is necessary for the function explicitly requested by the visitor, it is used without a consent banner. NA40.se currently does not set optional analytics or marketing cookies.
Messages
Contact details are used for information connected to your registration and the convention. They are not used for unrelated marketing without a separate basis or consent.