01Who is responsible for your data
EventControl ID is operated by Dispatch Communication AB ("Dispatch", "we", "us"), a company registered in Sweden. For the personal data described here, Dispatch acts as the data controller under the EU General Data Protection Regulation (GDPR).
To confirmCompany registration number and registered address. Also whether Dispatch is controller or processor for sign-in data where your access is arranged by your employer — that distinction changes some wording below and needs legal review.
02What this statement covers
This statement covers EventControl ID only — the service that signs you in and hands you on to the EventControl products you are entitled to use: Flow, Screens and vNext.
It does not cover what you then do inside those products. The content you create in them — events, plans, work orders and so on — is handled under the agreement between Dispatch and the organisation that gave you access.
03What we ask your Microsoft account for
If you sign in with Microsoft, the consent screen asks you — or your IT administrator, on your organisation's behalf — to approve these permissions:
| Permission | What it is for |
|---|---|
openid | Signs you in and identifies the account you signed in with. |
profile | Basic profile information, from which we take your display name. |
email | Your email address. |
User.Read | Reads the basic profile of the signed-in user — that is, your own. |
offline_access | Keeps your session going without asking you to sign in again each time. |
Of everything these permissions make available, EventControl ID uses two things: your display name and your email address.
It does not read your mail, your files, your calendar or your organisation's directory, and it requests no permission that would let it do so.
You or your administrator can withdraw this consent at any time in Microsoft Entra ID or your Microsoft account settings. Doing so stops you signing in to EventControl products with Microsoft; it does not by itself delete what has already been stored — for that, see your rights.
04What EventControl ID stores about you
| What | Why |
|---|---|
| Your account Email address, display name, and whether the email address has been verified. |
To identify you, show your name in the EventControl products, and know whether the address can be trusted for account notices and recovery. |
| Linked sign-in methods One record per method you use to sign in — for example your Microsoft account. |
So the right account is found when you come back through the same sign-in method, and so you can use more than one. |
| Active sessions For each session currently open: the IP address and the browser user-agent it was created from. |
To keep you signed in, and so a session that you do not recognise can be spotted and ended. |
| Sign-in event log For each sign-in event: the time, the email address, the type of event, which EventControl application it was for, whether it succeeded or failed, the IP address, the browser user-agent, and an approximate city and country. |
To detect and investigate misuse — repeated failed attempts, sign-ins from unexpected places — and to answer the question "who signed in, when, and to what". |
That is the whole of it. EventControl ID stores no other category of personal data about you.
05Approximate location in the sign-in log
To make the sign-in log useful, the IP address of a sign-in event is sent to ipapi.co, an external service, which returns an approximate city and country. The sign-in log then stores the IP address together with that city and country.
This is a coarse, IP-derived estimate — it is not GPS, and it is not read from your device. ipapi.co is a sub-processor for this purpose and receives nothing from us but the IP address.
To confirmipapi.co's operating entity, where it processes the data, the data processing agreement in place, and the transfer safeguards if processing happens outside the EU/EEA.
07What we never do with it
08Legal basis for processing
| Data | Basis under GDPR Article 6 |
|---|---|
| Account data, linked sign-in methods, active sessions | Necessary to provide the sign-in service you or your organisation asked for — performance of a contract, Art. 6(1)(b); or, where the contract is with your organisation rather than with you, our legitimate interest in delivering it, Art. 6(1)(f). |
| Sign-in event log, including IP address, user-agent and approximate location | Our legitimate interest in keeping accounts secure, detecting and investigating misuse, and maintaining an account of access — Art. 6(1)(f). |
To confirmLegal review of the bases above, including the legitimate-interests balancing for the sign-in log, and which basis is correct where a customer organisation is involved.
09How long we keep it
Account data is kept while your account exists. Sessions end when you sign out or when they expire.
To confirmThe actual retention periods — for account data after an account is closed, for expired sessions, and for entries in the sign-in log. No period is stated here because none has been verified.
10Your rights
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct anything inaccurate (rectification);
- delete it (erasure), where we have no overriding reason to keep it;
- restrict what we do with it while a question about it is resolved;
- hand it over to you or another provider in a machine-readable form (portability);
- stop processing that relies on our legitimate interests — including the sign-in log — where your situation gives you grounds to object.
How to exercise them
Write to info@dispatch.se. We may need to verify who you are before we act. The GDPR gives us one month to respond, extendable where a request is complex.
If your access was arranged by your employer or another organisation, contact their IT administrator as well — some requests have to be handled by them, and closing your access is usually theirs to do.
If you are not satisfied
You can complain to the Swedish data protection authority, Integritetsskyddsmyndigheten (IMY), at imy.se, or to the supervisory authority in the EU or EEA country where you live or work.
To confirmWhether a dedicated privacy contact address should replace info@dispatch.se here, and whether a data protection officer is appointed and needs naming.
11Security
EventControl ID is served over HTTPS, sign-in is delegated to your existing identity provider where you use one, and the sign-in log exists so that unusual access can be spotted.
To confirmA verified description of the technical and organisational measures in place, and the breach notification process. Nothing further is claimed here, and no certification or compliance standard is asserted, because none has been verified.
12Changes to this statement
We may update this statement. The current version is always the one published at this address, and the date below reflects when it last changed.
To confirmEffective date, and how material changes are announced to users and to customer organisations.
13Contact
Dispatch Communication AB
Email: info@dispatch.se
Web: dispatch.se
See also the Terms of Service for EventControl ID.
To confirmPostal address and company registration number.
Last updated: To confirmdate
