Privacy Policy for Nawa Studio
- Last updated:
- 30 July 2026
- Version:
- 1.1
This is a translation of the Swedish original. In the event of any difference in meaning, the Swedish version prevails.
1. Data controller
Nawa Studio is a brand operated by:
Creatio Haerent Studio AB is the data controller for the processing of personal data described in this privacy policy.
In this policy, the terms Nawa Studio, the Studio, we and us refer to Creatio Haerent Studio AB.
2. Who does the policy apply to?
This privacy policy applies to you if you:
- visit nawastudio.se
- contact Nawa Studio
- create a user account
- book or apply for an event
- are named as a participant in someone else's booking
- take part in an event or are on a waiting list
- create or use a recurring booking profile
- make a payment, refund or donation
- subscribe to the newsletter or other mailings
- apply to become a volunteer
- are or have been a volunteer
- work at or administer an event
- are an event administrator or main administrator
- represent a supplier, partner or other organisation
- appear in a safety, injury or incident report
3. What personal data do we process?
The personal data we process depends on the contact you have with Nawa Studio.
3.1. Identity and contact details
We may process:
- name
- Diversia Nick or another chosen display name
- email address
- telephone number where needed
- user ID
- preferred language
- account status
- user role and permissions
A legal name may be needed for payments, insurance matters, contact with authorities, accounting or secure identification, for example.
A Diversia Nick can be used as a display name in the system. A legal name should only be available to people who need it.
3.2. Bookings and participation
We may process:
- which events you have booked or applied for
- booking number and event number
- booking status
- participant status
- waiting list status
- dates and times
- participant roles
- answers to the event's questions
- cancellations and changes
- past and upcoming bookings
- practical information ahead of the event
- information about the main booker
- information about other people included in the booking
3.3. Booking profiles
When you create a booking profile we may process:
- verified email address
- name or Diversia Nick
- telephone number
- language
- profile settings
- active and previous bookings
- pre-filled basic details for future bookings
Event-specific answers, health information and other privacy-sensitive data must not be reused automatically in new bookings.
3.4. Payments, refunds and donations
We may process:
- booking number
- event number
- the main booker responsible for payment
- participant fee
- donation to Ropefund
- amount paid
- payment status
- payment date
- payment method
- payment reference
- Swish transaction identifier
- refund details
- information about who administratively registered or changed a payment
We do not store complete BankID information, card details or login credentials for your bank.
3.5. Volunteers and staff
We may process:
- volunteer application
- name or Diversia Nick
- contact details
- previous experience
- stated skills
- motivation for the volunteer application
- dates of application and approval
- volunteer status
- requests sent
- accepted and declined shifts
- shifts, functions and times
- availability
- introductions and safety briefings
- calendar invitations
- responses to calendar invitations
- administrative notes
- withdrawals and changes
3.6. Event administrators and main administrators
We may process:
- account details
- user role
- event ownership
- editing permissions
- requests for access to events
- administrative actions
- audit history
- login history
- security logs
3.7. Communication
We may process content and metadata from:
- contact forms
- booking messages
- support cases
- newsletters
- event messages
- volunteer requests
- communication about payments and refunds
- communication about cancellations
- communication about safety and incidents
3.8. Technical data
When you use the website or the event platform we may process:
- IP address
- date and time
- browser
- operating system
- device type
- language and display settings
- login events
- security logs
- error reports
- information about the use of personal links
- necessary cookies and local storage
3.9. Photographs, film and audio
Where photography, filming or audio recording takes place we may process:
- photographs
- video recordings
- audio recordings
- a name or Diversia Nick linked to the material
- information about consent given or withdrawn
Booking, attending or working at an event does not automatically mean that you consent to being photographed or published.
3.10. Safety and incident data
In the case of an accident, conflict, personal injury, safety incident or other serious event we may process:
- date, time and place
- a description of the event
- people involved
- witness statements
- measures taken
- photographs or other documentation from the event
- contact with insurance companies
- contact with legal advisers
- contact with authorities, emergency services or healthcare
4. Where do we get the personal data from?
The personal data mainly comes:
- directly from you
- from a main booker
- from another person who includes you in a booking
- from event administrators
- from main administrators
- from volunteer and staff administration
- from payment providers
- from calendar providers
- from the technical logs of the website and the system
- from other people in connection with a documented incident
- from insurance companies or authorities where relevant
When someone else provides your email address or other personal data in a booking, you should receive information about the booking and the processing of your personal data where this is possible and appropriate.
5. Why do we process personal data?
5.1. Answering questions and enquiries
We process personal data in order to:
- answer questions
- handle contact enquiries
- handle venue and event enquiries
- provide requested information
- follow up a case
Legal basis: legitimate interest, or steps taken at your request prior to a possible contract.
5.2. Administering user accounts
We process personal data in order to:
- create and verify accounts
- enable login
- administer roles and permissions
- reset passwords
- protect accounts against unauthorised use
- show the user's own bookings, assignments and settings
Legal basis: performance of the user agreement and legitimate interest in secure account administration.
5.3. Administering bookings and events
We process personal data in order to:
- receive bookings and applications
- administer participants
- carry out event selection
- administer waiting lists
- send confirmations
- communicate booking status
- send practical information
- handle changes and cancellations
- run the event
Legal basis: performance of a contract, steps prior to a contract and legitimate interest.
5.4. Administering booking profiles
We process personal data in order to:
- create and verify the booking profile
- pre-fill future bookings
- show your own bookings
- manage profile settings
- protect the profile against unauthorised access
Legal basis: performance of the user agreement and legitimate interest.
Creating a booking profile is voluntary.
5.5. Handling payments and donations
We process personal data in order to:
- calculate participant fees
- receive and register payments
- process Swish payments
- register manual payments
- send payment confirmations
- carry out refunds
- administer donations to Ropefund
- meet bookkeeping and accounting requirements
Legal basis: performance of a contract and legal obligation.
5.6. Managing volunteers and staff
We process personal data in order to:
- receive and assess volunteer applications
- approve or decline applications
- administer the volunteer register
- send voluntary requests about shifts
- plan staffing
- register responses and withdrawals
- send calendar invitations
- organise safety information
- administer staff functions
Legal basis: steps at the person's request, performance of the volunteer agreement and legitimate interest.
5.7. Administering volunteer prioritisation
Event administrators can decide the order in which volunteers receive requests for a particular event.
The prioritisation may be based on, for example:
- relevant experience
- skills for the task
- previous experience of the event type
- familiarity with the venue
- the need for continuity
- availability
- a suitable distribution of experience within the team
Declining a request must not automatically lower a volunteer's priority or affect the chance of receiving future requests.
Legal basis: legitimate interest in organising suitable and safe staffing.
5.8. Administering permissions
We process personal data in order to:
- create administrator accounts
- give access to the right events and functions
- process requests for editing permissions
- log administrative actions
- prevent unauthorised access
Legal basis: legitimate interest in protecting the systems and organising the business.
5.9. Safety and incident management
We process personal data in order to:
- prevent accidents
- protect participants, volunteers and staff
- investigate safety incidents
- handle insurance matters
- establish, exercise or defend legal claims
- provide information to authorities where required
- protect a person's life or health in an emergency
Legal basis: legitimate interest, legal obligation or protection of vital interests.
5.10. Newsletter and marketing
We process personal data in order to:
- send newsletters
- provide information about upcoming events
- manage subscriptions
- manage unsubscriptions
- document when and how consent was given
Legal basis: consent or another applicable legal basis for existing customer relationships.
You can unsubscribe from marketing mailings at any time.
5.11. Photographs and publication
Identifiable photographs and films from privacy-sensitive events are normally published only after clear and separate consent.
Consent to photography or publication must:
- be voluntary
- be separate from the booking terms
- not be pre-ticked
- be possible to withdraw
- be possible to refuse without affecting the ability to take part or to volunteer
Legal basis: normally consent.
5.12. Technical logs and system security
We process technical data in order to:
- enable login
- protect user accounts
- protect personal response links
- detect intrusion and misuse
- troubleshoot the system
- carry out backups
- document administrative changes
Legal basis: legitimate interest in maintaining a secure and functioning system.
6. Data about other participants
A main booker can book or apply on behalf of several people.
The main booker is responsible for ensuring that:
- the details provided are correct
- other participants know that their details are being provided
- only necessary details are provided
- other participants have access to this privacy policy
The main booker may not:
- consent to newsletters on behalf of another adult
- consent to photography or publication on behalf of another adult
- create a personal booking profile for someone else
- provide unnecessary sensitive personal data about someone else
When another participant's email address is provided, that person may receive their own message about the booking.
7. Sensitive and particularly protected personal data
Taking part in certain events or answering certain questions may mean that personal data reveals or suggests information about, for example:
- health
- sex life
- sexual orientation
- religious or philosophical beliefs
- other private circumstances
We therefore undertake to:
- collect only data that is genuinely needed
- avoid unnecessary free-text fields
- state clearly when sensitive data should not be provided
- limit access to people with an actual need
- not include sensitive data in ordinary email messages
- not transfer unnecessary data to payment providers
- not publish participant lists
- use shorter retention periods where possible
Processing sensitive personal data requires both a legal basis under Article 6 GDPR and an applicable exemption under Article 9 GDPR.
8. Automated functions and decisions
The system can automatically:
- check whether an event has places available
- place bookings in different statuses
- administer waiting lists
- send messages and reminders
- check payment status
- send volunteer requests according to an administrative priority order
- stop requests when a shift is fully staffed
The following decisions must not be made solely automatically without meaningful human assessment:
- which participants are selected for an event
- whether a volunteer application is approved
- whether a volunteer status is ended
- whether a person is granted administrative permissions
- decisions with significant legal or similar consequences for the person
9. Cookies and local storage
Nawa Studio may use necessary cookies or equivalent technology for:
- login
- authentication
- security
- session handling
- language selection
- light or dark display mode
- the booking flow
- saving cookie settings
Necessary cookies are used to make the website and the system work.
Analytics, statistics and marketing cookies must only be activated after an active choice where consent is required.
Visitors must be able to change or withdraw their choices.
More detailed information may be provided in a separate cookie policy or in the website's cookie settings.
10. Who has access to the personal data?
Only people who need the data for their tasks should have access to it.
10.1. Main administrators
Main administrators may have access to the personal data needed to administer the business and the system.
10.2. Event administrators
Event administrators only have access to data needed for events they own or have approved editing permissions for.
Access to an event must not automatically give access to all participant data, payment data, volunteer history or internal notes.
10.3. Volunteers and staff
Volunteers and staff only have access to information needed for their specific tasks.
They should normally not have access to:
- complete participant lists
- detailed application answers
- payment details
- sensitive personal data
- internal administrative notes
10.4. Suppliers and processors
We may use suppliers for, for example:
- website and system development
- database and storage
- authentication
- email delivery
- calendar functions
- payments
- accounting
- backups
- IT support
- information security
- web statistics
Suppliers who process personal data on our behalf must process the data in accordance with our instructions and are covered by applicable data processing agreements.
10.5. Other recipients
Personal data may be disclosed to:
- banks and payment providers
- accounting consultants
- insurance companies
- legal advisers
- emergency services and healthcare
- authorities
- courts
This only happens where necessary or required by law.
We do not sell personal data.
11. Transfers outside the EU and EEA
Some technical suppliers may process personal data outside the EU or EEA.
Such a transfer must only take place where there is a valid legal ground, for example:
- an adequacy decision
- the European Commission's standard contractual clauses
- another permitted transfer mechanism
- supplementary technical and organisational safeguards
Information about current suppliers and safeguards can be requested by contacting hello@nawastudio.se.
12. How long is personal data kept?
Personal data is not kept for longer than is needed for each purpose.
12.1. Contact enquiries
Ordinary contact cases are normally deleted within 12 months after the case is closed.
12.2. Event applications that do not lead to participation
The data is normally deleted or anonymised within 6–12 months after the event, unless it needs to be kept for a complaint, an incident or a legal claim.
12.3. Bookings and participation history
Ordinary booking and participant data is normally kept for a maximum of 24 months after the event.
Detailed event answers and sensitive data must be deleted earlier when they are no longer needed.
12.4. Booking profiles
A booking profile is kept for as long as it is active.
After closure or long-term inactivity the data is normally deleted or anonymised within 24 months, unless it needs to be kept for an active booking or a legal obligation.
12.5. Payment and accounting data
Data that constitutes accounting information is kept for as long as accounting legislation requires.
12.6. Volunteer applications
Declined or withdrawn volunteer applications are normally deleted within six months.
12.7. Active and former volunteers
Data about volunteers is kept for as long as the person is active or paused, and normally for a maximum of 24 months after the most recent volunteer shift or after the volunteer status ended.
12.8. Newsletter
The email address is used for the newsletter until the person unsubscribes or withdraws consent.
A limited suppression record may then be kept to prevent the person from receiving new mailings against their wishes.
12.9. Photographs and films
Material is kept for as long as it is used for the stated purpose, or until a withdrawn consent can be acted upon.
Material already printed or publication already carried out cannot always be recalled, but future use must be stopped where possible.
12.10. Incidents and insurance matters
Data is kept until the event has been investigated and any insurance matters or legal claims have been finally resolved.
12.11. Technical logs
Ordinary security and access logs are usually kept for a maximum of 12 months.
Logs may be kept longer where they are needed to investigate a specific security incident.
12.12. Backups
Deleted data may remain for a limited time in backups before it is overwritten in line with our backup routines.
13. How do we protect personal data?
We use appropriate technical and organisational security measures, for example:
- role-based access
- access restrictions at database level
- strong authentication
- multi-factor authentication for administrators where possible
- personal and time-limited response links
- encrypted communication
- protection of API keys and other system secrets
- logging of administrative actions
- regular review of permissions
- backup and restore routines
- data minimisation
- limited access to sensitive data
- routines for personal data breaches
Email messages must not contain sensitive personal data or more information than the recipient needs.
14. Do you have to provide personal data?
It is voluntary to:
- visit the website
- contact us
- apply for or book an event
- create a booking profile
- apply to become a volunteer
- subscribe to the newsletter
Some data is nevertheless necessary for us to handle a booking, payment, application or volunteer engagement.
If necessary data is not provided, we may be unable to deliver the requested service.
15. Your rights
Depending on the circumstances, you have the right to:
- receive information about how we process your personal data
- request a copy of your data
- have inaccurate data corrected
- request erasure of personal data
- request restriction of processing
- object to processing based on legitimate interest
- receive certain data through data portability
- withdraw a consent
- object to direct marketing
- lodge a complaint with the Swedish Authority for Privacy Protection
The rights are not absolute. For example, we may need to keep data required by law or needed to handle a legal claim.
To exercise your rights, contact:
We may need to verify your identity before a request is handled.
16. Withdrawing consent
Where processing is based on consent, the consent can be withdrawn at any time.
Withdrawal does not affect the lawfulness of processing already carried out before the consent was withdrawn.
Newsletter consent must be possible to withdraw through an unsubscribe link or by contacting hello@nawastudio.se.
Consent to photography and publication must be possible to handle separately from the booking and other terms.
17. Complaints
Please contact Nawa Studio first if you have questions or views about the processing of your personal data.
You also have the right to lodge a complaint with:
Information about how to submit a complaint is available on IMY's website.
18. Contact and changes
Questions about personal data can be sent to:
We may update the privacy policy when the business, the systems or applicable rules change.
In the event of material changes we will provide information through the website, the event platform or email.
The current version is always available at nawastudio.se.
19. The picture portal: photos, consent and publication
This section describes how the Nawa Studio picture portal works. The portal is used when photographers upload pictures from the studio's events and when the people shown in those pictures decide for themselves whether, and where, the pictures may be published. This section adds to the rest of the policy and applies in addition to it.
Last updated This section was added on 30 July 2026 and forms part of version 1.1 of the privacy policy. Earlier versions of the policy and of the consent texts shown in the portal are preserved unchanged in our audit history, so it is always possible to see exactly which wording a person read when consent was given.
Controller The controller for the processing in the picture portal is Creatio Haerent Studio AB, company registration number 559594-6632, which operates the business Nawa Studio. Questions about pictures, consent or erasure can be sent to hello@nawastudio.se.
19.1. What data is processed in the picture portal?
- the pictures themselves and related technical metadata, such as file format, size and time of upload
- your name or the nickname you choose to be shown with
- your email address, used to send the personal consent request and any later reminders or confirmations
- information about the photographer: name or alias, contact details, which pictures were uploaded and which terms and assurances the photographer accepted
- your consent choice for each individual picture and for each individual publication channel, including the time and the exact text and picture version the choice applies to
- how you wish to be credited, that is by name, by nickname or not at all
- technical security and audit information showing when a picture was uploaded, reviewed, approved, downloaded, published, withdrawn or deleted
Pictures of people can be sensitive data. They are therefore processed in the portal only with your explicit consent, and they are kept in a closed state until you have made your choice.
No facial recognition We do not use facial recognition, biometric identification or any other automated technology to recognise people in pictures. The link between a picture and a person is always made manually by the photographer or by an authorised picture administrator, and it can always be corrected.
19.2. Why is the data processed?
- to receive pictures from photographers and check the files for safety before anyone else can see them
- to obtain individual and freely given consent from every identifiable person
- to administer which publication channels are approved for each picture
- to document where a picture has actually been published
- to handle withdrawal of consent and to request removal of a picture that has already been published
The pictures are not used to train AI models, to profile you, to build a general marketing database or for any other purpose. If a new purpose ever becomes relevant, it requires a new explicit choice from you.
19.3. Legal basis
Publication of pictures in which you are identifiable takes place solely on the basis of your explicit and freely given consent, provided separately for each channel.
A limited security, contractual and audit history may be retained on the basis of our legitimate interest in being able to show what has happened to a picture, or where the law requires it. That history is never used to publish anything.
Saying no, not answering at all or changing your mind later has no negative consequences for you, whether in booking, participation or volunteering.
19.4. Pictures with several people
In a picture with several identifiable people, each person decides for themselves. No one can answer on behalf of anyone else.
A picture may only be published in the channels where every identified person has an active yes at that moment. If someone has not answered, has answered no, or later withdraws their consent, that channel falls away immediately for the whole picture.
19.5. Who can see the pictures?
- authorised picture administrators and publishers at Nawa Studio, who need the access in order to review and publish
- the publication channels and platforms you have explicitly chosen
- necessary operational suppliers, for example for hosting, storage and email delivery, who process the data as processors on our instructions
We never sell pictures or information about you, and we do not share them with any other recipient.
19.6. How are the pictures protected?
- original files are held in private storage that is not reachable through open links
- access is governed by roles, and the administrator roles require two-factor sign-in
- uploaded files are checked and processed before they become visible; if the checks are not yet complete the file stays blocked and cannot be shown, approved or downloaded
- metadata in the files, such as location information, is handled during processing so that such information does not travel with a published picture
- every consent is bound to an exact picture version and an exact version of the channel's terms; a new version of the picture requires new consent and old answers do not count
- originals are downloaded through short-lived single-use links tied to a named channel, a stated purpose and one individual administrator; the link cannot be reused or shared
- all significant events are written to an audit log that cannot be altered afterwards
19.7. How long are the pictures kept?
Material that no one has answered for, that has been declined or that has been withdrawn, together with the related original files, is deleted according to the retention documented in the picture portal. Until deletion the material is blocked and cannot be published.
Approved material is kept only for as long as the purpose requires and the consent is active. We review the material regularly and remove what is no longer needed.
A separate minimum history for security and audit is kept apart from the pictures and is erased on the basis of what is legally justified. We deliberately state no exact time limits here that the portal does not yet apply automatically.
19.8. Your rights and how to change your mind
You have the right of access, rectification, erasure and restriction, and where relevant also data portability. You may at any time lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
You can withdraw your consent at any time, for a single channel or for everything, without giving a reason. The withdrawal applies going forward and does not affect the lawfulness of publication before you changed your mind. The channel immediately stops being approved, and if the picture has already been published a case is opened to have it removed where that is possible.
If you recognise yourself in a picture you should not be linked to, you can flag this in the portal. The link is then removed and the picture is blocked for the channels concerned.
19.9. How to reach the portal
The picture portal's start page is at nawastudio.se/en/pictures, and in Swedish at nawastudio.se/sv/pictures.
When a picture in which you are identifiable has been uploaded, you receive an email with a personal link to the page for managing your consent. The link contains a unique, time-limited code that only you receive, that is never shown in this policy and that should never be forwarded. Through the same link you can later see your choices and change or withdraw them. If the link has stopped working we will send a new one after contact at hello@nawastudio.se.
19.10. The photographer's responsibility, rights and licence
The photographer is responsible for uploading pictures only from the event the assignment concerns, for naming every person who is identifiable in the picture and for following the studio's terms and the order that applies during the event.
The photographer retains copyright in their pictures and grants Nawa Studio a limited right to use them in the approved channels. The photographer may limit their own licence.
The photographer's acceptance of the terms covers only the photographer's own undertakings and rights. The photographer can never give consent on behalf of any of the people shown in the picture; every depicted person always consents for themselves.