How Alteron AB collects, uses and protects personal data across our website and the Node service.
This policy explains how Alteron AB collects, uses and protects personal data across our website and the Node meeting-room service — the data we hold, why we hold it, who we share it with, and the rights you have under the GDPR.
Alteron AB (org. no. 0006148472), Råkritegatan 78, Malmö, Sweden, is the data controller for the personal data described in this policy, except where we act as a data processor on behalf of our business customers (see section 2). This policy applies to our website alteron.se and to the Alteron Node meeting-room booking system.
For any privacy question, or to exercise your rights, contact us at privacy@alteron.se. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act.
For our website, marketing and sales relationships, Alteron is the controller and decides why and how data is processed. For data that our business customers put into Node — such as employee accounts, room bookings and calendar events — the customer is the controller and Alteron acts as their processor. In that case, processing is governed by a Data Processing Agreement (DPA) between Alteron and the customer, and this policy is provided for transparency.
When you contact us for support or sales, we keep the correspondence and any details needed to answer you and maintain our business relationship.
When your organisation connects Node to Microsoft 365 or Google Workspace, we synchronise room calendars in both directions so bookings stay consistent. All calendar traffic runs through our secure backend — the panels and browser never talk to Microsoft or Google directly. We process only the calendar data needed to mirror bookings (room, time, title and event identifiers) and do not use it for any other purpose.
Node data is hosted within the European Union (Supabase, Frankfurt / eu-central-1). Where a provider such as Microsoft or Google may process data outside the EU/EEA, such transfers are protected by adequacy decisions or the European Commission's Standard Contractual Clauses together with appropriate safeguards.
We keep personal data only as long as needed for the purposes above. Account and booking data are retained for the life of the customer relationship and deleted or anonymised after the service ends, subject to any longer period required by law (for example, accounting records kept for seven years under Swedish law). Contact-form messages are kept for as long as needed to handle your enquiry.
We protect data with encryption in transit, row-level access controls that scope every record to its organisation, per-device credentials that can be revoked individually, and least-privilege access for our team. No system is perfectly secure, but we work continuously to keep your data safe and will notify you and the relevant authority of any personal-data breach as required by law.
Under the GDPR you have the right to access your personal data and to request rectification, erasure, restriction, portability, and to object to processing based on our legitimate interests. Where processing relies on consent, you may withdraw it at any time. To exercise any right, email privacy@alteron.se. If Alteron acts as a processor for your employer, we will refer your request to the customer who controls the data.
If you believe we process your data unlawfully, we would like the chance to help — please contact us first. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy@imy.se, www.imy.se.
Node is a workplace product intended for use by organisations and their staff. It is not directed at children, and we do not knowingly collect personal data from children.
We may update this policy as our service or the law evolves. We will post the new version here with an updated date and, for material changes, notify customers directly.