Skip to content

SDLCAI

Privacy Policy

Toska Osuuskunta is committed to protecting your privacy. This policy describes how personal data is handled for SDLCAI.

Please take time to review our practices. If there are any practice matters that do not suit your consent, we recommend not using this site.

Party Responsible for Processing Data

Toni Ristola
TOSKA Osuuskunta
c/o Toska Osuuskunta
Suonotkontie 1 B 22
00630 HELSINKI

info <at> futurefrontend.com

The responsible party is the natural or legal person who jointly with others decides on the purposes and means of processing personal data, such as names and email addresses.

Collecting Information

We collect information from you when you register, purchase a ticket, submit a poster proposal, or fill out another form on this site. The fields collected depend on the service you use. Please do not submit personal information that you do not want us to process.

Poster Proposals

When you submit a poster proposal, we collect the designated presenter's name and email address, organization or affiliation, poster title and abstract, the submission time, review status, and the acknowledgements and privacy consent submitted with the form.

We use this information to review proposals as they arrive, contact presenters about questions and rolling acceptance decisions, and coordinate poster-session logistics. If a proposal is accepted, we also use the designated presenter's contact details to arrange the one event ticket included with that poster.

For an accepted proposal, the poster title and abstract may be published in the event program under the acknowledgement given on the proposal form. Acceptance does not guarantee that these details will be published. The designated presenter's name and contact details and private review information are not included in the public program. Earlier proposal records may also include separately listed author or presenter names, a supporting URL, and setup or accessibility notes. That legacy information is not published and remains subject to the retention review described below.

We retain poster proposal records through the event follow-up and will conduct a manual retention review by 31 January 2027. At that review, personal data for proposals that were not accepted will be deleted from the proposal database and its backups. For accepted proposals, contact details and operational notes are kept only as long as needed for event administration or legal obligations. If title or abstract details have been published in the event program, they may remain as part of that event record.

Speaker Workspace and Contact

For confirmed speakers, the organizer assigns an email address used for private workspace access and operational event announcements. The address is encrypted at rest and linked to the speaker’s stable internal identifier. A speaker can request a short-lived, single-use sign-in link from the public speaker login page. The page does not reveal whether an address is assigned. We store only keyed hashes of sign-in and session secrets.

To prevent sign-in email abuse, we use Cloudflare Turnstile and short-lived keyed fingerprints of the normalized email address and connecting IP address for rate limiting. We do not store the raw IP address in the speaker login-request table. Login request records are automatically removed after 24 hours.

The workspace lets a speaker propose changes to their public name, professional role, biography, website and social links, and the title and description of talks already assigned to them. Drafts and submitted revisions remain private until an organizer reviews them. Approved information may be published in the event programme, slides, and promotion graphics and may remain as part of the public event record. A proposed portrait is decoded, cropped, stripped of metadata, and re-encoded as a private 400x400 WebP for review; the original upload is not retained.

Operational email is limited to the speaker relationship, including access, programme review, deadlines, logistics, promotion material, and optional topic-video coordination. Optional promotional communication preferences are stored separately. Delivery records identify the speaker and outcome but do not contain the plaintext address. Replies sent to info@sdlcai.org are received in the organizer’s Google Workspace mailbox.

Speakers also record whether they will provide presentation material in advance or use their own laptop. For advance material, we collect the selected format—PowerPoint, PDF, or web presentation—and the HTTPS address of a web presentation. These private venue-logistics responses are encrypted at rest, available only to authorized organizers, and are not published.

A speaker may optionally upload a one-to-two-minute topic video directly to Cloudflare Stream. We record the assigned talk, Stream identifier, processing and review state, duration, and the speaker’s explicit choices about captioning, cropping, excerpting, editing, and publication. The upload requires signed playback and remains private while it is processed and reviewed. Stream source videos are scheduled for deletion after 31 January 2027; permission evidence is retained as needed to document any approved promotional use.

A sign-in link expires after 15 minutes and works once. Speaker access and sessions expire after 31 October 2026. We will review and delete private speaker contact details and presentation setup responses by 30 November 2026 unless they are still required for event follow-up or a legal obligation. A speaker can ask us to correct their address or presentation setup, suppress further email, or delete private details earlier by emailing info@sdlcai.org.

Speaker Travel Receipts

If the organizer enables travel receipt uploads, you can submit receipt files, expense descriptions, dates, original amounts and currencies, and optional notes in your private speaker workspace. We associate each receipt with your speaker name and use it to review and process agreed travel expenses after the event. Please include only the information needed for the expense and do not enter bank or payment-card details in the form.

Receipt files and details are encrypted in storage. They are accessible to you and authorized organizers and are not published. Processing notes are visible to you. You can remove an unprocessed receipt while you have workspace access; contact info@sdlcai.org for corrections afterwards.

Receipts remain available to organizers after speaker workspace access expires and are not included in the automatic cleanup of dinner or presentation responses. Organizers retain them for reimbursement follow-up and remove them from this workspace when no longer needed, after saving any required accounting records separately. Deleting a receipt here does not remove copies already downloaded for accounting.

Speaker Dinner Responses

Speakers use their authenticated workspace to tell us whether they will attend the dinner on 12 October 2026. If someone attends, we collect a meal preference, food requirements, and whether cross-contamination is a concern. We process this information with the respondent’s express consent to plan the dinner safely. Older personal and shared unlisted forms remain temporarily available for responses created before the workspace flow; the shared form also collects the respondent’s name.

Responses are encrypted at rest. Access is limited to authorized event organizers. We share only the food information needed by the dinner caterer and do not include these records in our long-lived event backups. A speaker may update their response until the stated deadline or withdraw consent by contacting us.

Dinner invitation and response records are scheduled for deletion after 26 October 2026. Organizers can also delete all dinner data earlier from the protected admin area once it is no longer needed.

Using Your Information

We will use your personal information for the following purposes:

  • Personalizing our website. We would like to create the best experience for you. By using your personal information, we are able to cater our site towards your needs.
  • Improving our website. Through the information and feedback given, we are able to improve our site thanks to your insights.
  • Improving customer service. Your information will allow us to create a more effective customer service experience by utilizing the data provided.

Information, Blocking, Deletion

As permitted by law, you have the right to be provided at any time with information free of charge about any of your personal data that is stored as well as its origin, the recipient and the purpose for which it has been processed. You also have the right to have this data corrected, blocked or deleted. You can contact us at any time using the address given in our legal notice if you have further questions on the topic of personal data.

Third Party Services

Depending on what features and services you use we store different data.

Cloudflare

The website is hosted via the service Cloudflare. By visiting the website Cloudflare stores access logs including the IP addresses, stored for less than 30 days. Cloudflare also provides the encrypted database, private file storage, edge rendering, and transactional Email Sending used by the speaker workspace. Learn more in the Cloudflare Privacy Policy.

Google Workspace

Messages and replies sent to info@sdlcai.org are received in an organizer-controlled Google Workspace mailbox. Google processes message content and sender details to provide that mailbox. See the Google Privacy Policy.

Tito

We use Tito to manage and process tickets of the conference. An up to date compilation of the personal data they collect and how long they retain it can be found in their Tito Privacy Policy.

Stripe

If you purchase a ticket the payment is handled by Stripe. They store the cardholder name, email address, unique customer identifier, order ID, bank account details, payment card details, card expiration date, CVC code, date, time, amount of transaction, merchant name, ID and location. For further details please see the Stripe Privacy Statement.

Mailjet

If you would like to receive our newsletter, we require a valid email address as well as information that allows us to verify that you own the specified email address and agree to receive the newsletter. No additional data is collected or is only collected on a voluntary basis.

We only use this data to send the requested information and do not pass it on to third parties. You can revoke consent to the storage of your data and email address as well as their use for sending the newsletter at any time, for example through the unsubscribe link in the newsletter.

For further details please see the Mailjet Privacy Statement.

Google Drive

Google Drive is used to store and edit our internal documents. Some of these documents contain names, email addresses, payment information, company information and profile pictures collected when a ticket is purchased. Learn more in the Google Privacy Policy.

Amazon Web Services

Amazon Web Services are used to manage domains, DNS and emails. Some emails contain private information including email addresses and names. Learn more from the Amazon Privacy Notice and Amazon Privacy FAQ.

Questions and Feedback

We try to keep our privacy policy transparent and easy to understand. In case you have questions or do not understand parts of it, please let us know if we can improve it further: info <at> futurefrontend.com.

Changes

We reserve the right to update or modify this Privacy Policy from time to time without prior notice. Please review this document especially before you provide any information. Your continued use of the services after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised Privacy Policy.

The last update to our Privacy Statement was posted on 25 August 2026.