Privacy Policy

Last updated: July 16, 2026

1. Data Controller

sête Technology AB (org. nr 559584-2658), a company registered in Sweden, is the data controller responsible for the processing of your personal data. You can contact us at support@withsete.com for any privacy-related inquiries.

2. Introduction

sête ("we", "us", "our", or "Company") operates the sête platform (the "Service"). This privacy policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Swedish data protection law.

3. Legal Basis for Processing

We process personal data under the following legal bases as defined in GDPR Article 6:

  • Contract (Article 6(1)(b)): Processing necessary to provide the Service (account management, event planning features)
  • Consent (Article 6(1)(a)): Guest data submitted through RSVP forms, where explicit consent is obtained at the time of submission
  • Legitimate Interest (Article 6(1)(f)): Service improvement, security monitoring, and fraud prevention
  • Legal Obligation (Article 6(1)(c)): Retention of consent records, tax and billing records

4. Types of Data Collected

Account Data

  • Email address and name (required for account creation)
  • Profile picture (optional)
  • Payment information (processed securely through Stripe — we do not store card details)

Guest Data (collected on behalf of event planners)

  • Via Excel/CSV import: Names, email addresses, phone numbers, addresses, dietary restrictions, and any custom fields provided by the event planner
  • Via RSVP form: Names, email addresses, phone numbers, dietary restrictions, attendance preferences, and custom field responses
  • Via share links: Client names and optional email addresses for collaboration access

Usage Data

We collect information about how the Service is accessed and used, including browser type, pages visited, time spent on pages, and other diagnostic data.

5. Data Retention

  • Account data: Retained while your account is active. Upon account deletion, data is permanently removed after a 30-day grace period.
  • Guest data: Subject to configurable retention (default: 365 days after an event date). Event planners can adjust retention periods per event.
  • Consent records: Retained independently of account data as required by GDPR Article 7(1) to demonstrate that valid consent was obtained.
  • Billing records: Retained for the period required by Swedish tax law.

6. Your Rights Under GDPR

As a data subject, you have the following rights under GDPR:

  • Right of Access (Article 15): You can request a copy of all personal data we hold about you
  • Right to Rectification (Article 16): You can update your personal data through your account settings
  • Right to Erasure (Article 17): You can request deletion of your account and all associated data from your account settings
  • Right to Restriction (Article 18): You can request restriction of processing in certain circumstances
  • Right to Data Portability (Article 20): You can download all your data in a structured, machine-readable JSON format from your account settings
  • Right to Object (Article 21): You can object to processing based on legitimate interest
  • Right to Withdraw Consent: Where processing is based on consent, you can withdraw consent at any time by contacting the event organizer or us directly

7. How to Exercise Your Rights

You can exercise your rights in the following ways:

  • Data Export: Go to Settings → Account → Export My Data
  • Account Deletion: Go to Settings → Account → Delete My Account
  • Guest Data Requests: If you are a guest whose data was submitted via an RSVP form, contact the event organizer or email us at support@withsete.com
  • Other requests: Contact us at support@withsete.com. We will respond within 30 days.

8. Use of Data

sête uses the collected data for the following purposes:

  • To provide and maintain our Service
  • To notify you about changes to our Service
  • To allow you to participate in interactive features of our Service when you choose to do so
  • To provide customer support and handle your requests
  • To gather analysis or valuable information so that we can improve our Service
  • To monitor the usage of our Service
  • To detect, prevent and address technical issues and fraud

9. Third-Party Data Processors

We use the following third-party services that may process your data:

  • Stripe (payment processing) — processes payment information under their own privacy policy. Data may be transferred to the US under Standard Contractual Clauses.
  • Amazon Web Services (AWS) (hosting, file storage, email delivery via SES) — data is stored in EU regions. AWS complies with GDPR through a Data Processing Addendum.
  • AWS AppSync (real-time collaboration) — processes real-time updates for collaborative seating chart editing (guest additions, seat assignments, chart modifications).
  • Vercel (application hosting) — serves the application and may process request metadata (IP addresses, headers). Data processing governed by Vercel's DPA.

10. International Data Transfers

Some of our third-party processors may transfer data outside the European Economic Area (EEA). In such cases, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data Processing Agreements with all processors
  • Assessment of the legal framework in the recipient country

11. Security of Data

We implement appropriate technical and organizational measures to protect your personal data, including encryption at rest and in transit, access controls, regular security reviews, and row-level security policies for data isolation between users. While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet is 100% secure.

12. Supervisory Authority

If you believe that our processing of your personal data violates data protection laws, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY):

  • Website: www.imy.se
  • Email: imy@imy.se

13. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us at:

  • Email: support@withsete.com
  • Data Controller: sête Technology AB (org. nr 559584-2658)