Skip to main content

1. Who We are and how to contact us

This privacy policy applies to the website sddisrupted.com and all data processing activities carried out by the association Service Design Disrupted, headquartered in Schlieren, Canton Zurich, Switzerland.

Service Design Disrupted is the data controller responsible for the personal data collected and processed through this website and its associated activities, including the organisation of events and the management of newsletter communications.

For any questions, requests, or concerns relating to the use of your personal data, you may contact us at: privacy@sddisrupted.com.

We are committed to handling your personal data with care, transparency, and in full compliance with the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the General Data Protection Regulation of the European Union (GDPR).

2. What Data We Collect and Why

We collect and process personal data only for specific, legitimate purposes and only to the extent necessary to fulfil those purposes. The following describes the categories of data we collect and the reason for each.

2.1 Association Members

For individuals who are members of the association, we collect and process the following data:

  • Full name
  • Email address
  • Telephone number
  • Country of residence
  • Interests regarding service design

Name, email address, telephone number, and country of residence are collected for the purpose of managing the membership relationship, enabling communication among members, and allowing members to exercise their membership rights. The legal basis for this processing is the contractual relationship established by membership of the association.

Information regarding members’ interests in service design is collected in the form of free text and is used solely for the purpose of tailoring event content and informing the design of future events and services offered by the association. The legal basis for this processing is your explicit consent, given at the time of providing this information. You may update or request the deletion of this information at any time by contacting us at privacy@sddisrupted.com.

2.2 Event Registrants

For individuals who register for events organised by Service Design Disrupted, we collect and process the following data through our event registration platform, Luma:

  • Full name
  • Email address
  • Organisation
  • Job title
  • Country
  • Event and date of attendance

This data is collected for the purpose of managing event registrations, communicating relevant information about the event to attendees, and understanding the professional profile of our audience in order to improve future events. The legal basis for this processing is the contractual relationship established by registering for an event.

2.3 Newsletter Subscribers

For individuals who voluntarily sign up to receive our newsletter, we collect and process the following data through our email marketing platform, MailerLite:

  • Email address

This data is collected solely for the purpose of sending communications about upcoming events and activities organised by Service Design Disrupted. The legal basis for this processing is your explicit consent, given at the time of subscription. You may withdraw your consent and unsubscribe at any time. Please refer to section 3 for more details on the newsletter and how to unsubscribe.

2.4 Data We Do Not Collect

We do not collect payment card data. Payments for event tickets are processed directly and exclusively by Stripe through the Luma platform. Service Design Disrupted never receives, stores, or processes card details of any kind.

We do not collect any special categories of sensitive personal data, such as health information, political opinions, religious beliefs, or biometric data.

2.5 Event Speakers

For individuals who participate as speakers at events organised by Service Design Disrupted, we collect and process the following data:

  • Full name
  • Email address
  • Organisation and job title
  • Professional biography
  • Photo
  • Bank account details (IBAN and BIC) where the speaker is to be paid a fee or reimbursed for expenses

Professional and contact data — including name, email address, organisation, job title, biography, and photo — is collected for the purpose of managing the speaker relationship, communicating logistical and organisational information, and promoting the event programme through the association’s website, event pages, and other communications materials. The legal basis for the processing of contact and professional data is the contractual relationship established by the speaker agreement. The legal basis for the publication of biographical information and photos is your explicit consent, which will be requested separately and in writing prior to any publication.

Banking details — specifically IBAN and BIC — are collected solely for the purpose of processing payment of speaker fees or reimbursement of expenses. This data is handled exclusively by the association’s treasurer, stored securely in an access-controlled environment, and is never shared with third parties beyond what is strictly necessary to execute the bank transfer. Banking details will be permanently deleted within 30 days of confirmation that the payment or reimbursement has been successfully processed.

Please note that while banking details are deleted after payment, the association is required under Swiss accounting law to retain financial records — including invoices and payment amounts — for a period of up to 10 years. These records document the transaction itself but do not include banking details.

2.6 Sponsor Representatives

Sponsors of events organised by Service Design Disrupted are typically organisations rather than natural persons. However, we collect and process personal data relating to the individual representative acting on behalf of the sponsoring organisation. This data includes:

  • Full name
  • Job title
  • Email address
  • Telephone number

This data is collected for the purpose of managing the sponsorship relationship, coordinating the practical aspects of the sponsor’s participation in the event, and maintaining communication throughout the event cycle. The legal basis for this processing is the contractual relationship established by the sponsorship agreement, and the legitimate interest of the association in maintaining effective communication with its sponsors.

Personal data of sponsor representatives will not be used for any purpose beyond the management of the sponsorship relationship, and will not be shared with third parties except where strictly necessary for the organisation of the event.

3. Newsletter Communications

3.1 Purpose and Nature of the Newsletter

Service Design Disrupted operates a newsletter to keep interested individuals informed about upcoming events, conferences, workshops, and other activities organised by the association. The newsletter is strictly tied to the association’s activities and will only be active when events or services are being promoted. It is not used for general marketing purposes unrelated to the association’s work.

3.2 Subscription and Consent

Subscription to the newsletter is entirely voluntary. By subscribing, you give your explicit consent to receive email communications from Service Design Disrupted via our email marketing platform, MailerLite.

To confirm your subscription and protect you from unauthorised sign-ups, we use a double opt-in process. This means that after submitting your email address, you will receive a confirmation email asking you to actively confirm your wish to subscribe. Your email address will not be added to our mailing list until this confirmation is completed.

3.3 Data Collected and Processed

For newsletter subscribers, we collect and process only your email address. No additional personal data is required to subscribe to the newsletter.

When you interact with our newsletter — for example by opening an email or clicking a link — MailerLite may automatically collect certain technical data, such as whether the email was opened and which links were clicked. This data is used solely to understand the effectiveness of our communications and improve future newsletters. It is processed by MailerLite on our behalf under a data processing agreement that ensures an equivalent level of data protection to that required by Swiss and European law.

3.4 Retention Period

We will retain your email address on our mailing list for as long as you remain subscribed. If you have not interacted with our newsletter — for example by opening an email or attending an event — for a period of three years, we will permanently delete your email address from our mailing list, unless you have actively reconfirmed your wish to remain subscribed within that period.

3.5 Unsubscribing

You may withdraw your consent and unsubscribe from the newsletter at any time, without giving any reason and without any consequence. Every newsletter we send includes an unsubscribe link at the bottom of the email. You may also request to be removed from our mailing list by contacting us directly at privacy@sddisrupted.com. Upon unsubscribing, your email address will be permanently deleted from our mailing list within a reasonable period and will not be used for any further communications.

4. How Long We Keep Your Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and in accordance with applicable Swiss and European data protection legislation. The following retention periods apply to each category of data we process.

4.1 Association Members

Personal data collected in the context of membership of the association is retained for the duration of the membership relationship. Upon termination of membership, whether by resignation, exclusion, or any other cause, personal data will be deleted within a reasonable period, except where retention is required to fulfil a legal obligation or to resolve any outstanding dispute arising from the membership relationship.

Information provided by members regarding their interests in service design will be retained for the same period as other membership data, unless the member requests its deletion earlier, in which case it will be deleted promptly upon request.

4.2 Event Registrants

Personal data collected in the context of event registration is retained for a period of three years from the date of the event. This retention period allows us to manage any follow-up communications related to the event, resolve any disputes, and use aggregated, anonymised data to inform the design of future events. After this period, personal data will be permanently deleted.

4.3 Event Speakers

Contact and professional data collected in the context of speaker participation — including name, email address, organisation, job title, biography, and photo — will be retained for a period of three years from the date of the event, after which it will be permanently deleted. Where a speaker’s biography and photo have been published on the association’s website or other communications materials, these will remain published for as long as the speaker has given their explicit consent to such publication. Published biographical information and photos will be removed promptly upon withdrawal of consent or upon the speaker’s request.

Banking details collected for the purpose of processing speaker payments or expense reimbursements will be permanently deleted within 30 days of confirmation of successful payment, as described in section 2.5. Financial transaction records required for accounting purposes will be retained for up to 10 years in accordance with Swiss accounting law.

4.4 Sponsor Representatives

Personal data collected in the context of the sponsorship relationship will be retained for a period of three years from the conclusion of the relevant event or the termination of the sponsorship relationship, whichever is later. After this period, personal data will be permanently deleted. Financial records relating to sponsorship agreements will be retained for up to 10 years in accordance with Swiss accounting law.

4.5 Newsletter Subscribers

As described in section 3.4, newsletter subscriber data is retained for as long as the subscription remains active. Email addresses of subscribers who have not interacted with our communications or attended an event for a period of three years will be permanently deleted unless the subscriber has actively reconfirmed their wish to remain on the mailing list.

4.6 Legal and Administrative Records

Where personal data forms part of the association’s legal or administrative records — for example in the minutes of general meetings — it will be retained for as long as required by applicable Swiss law or for the duration of the association’s existence, whichever is longer.

5. How We Protect Your Data

Service Design Disrupted implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure. These measures are reviewed and updated as necessary to reflect the current state of technology and the nature of the data we process.

Access to personal data is limited to those members of the association who need it to fulfil their specific responsibilities. Where personal data is processed by third party service providers, we require that those providers maintain equivalent standards of data security, as described in section 6.

In the event of a personal data breach that poses a risk to the rights and freedoms of the individuals concerned, we will notify the competent supervisory authority — the Federal Data Protection and Information Commissioner (FDPIC) — in accordance with the obligations set out in the Swiss Federal Act on Data Protection. Where the breach is likely to result in a high risk to the individuals concerned, we will also notify those individuals directly without undue delay.

6. Who We Share Your Data With

We do not sell, rent, or otherwise share your personal data with third parties for commercial purposes. Personal data is shared with third parties only to the extent strictly necessary to fulfil the purposes described in this privacy policy, and always under conditions that ensure an equivalent level of data protection.

The following third parties may process personal data on behalf of Service Design Disrupted:

6.1 MailerLite

We use MailerLite to manage our newsletter mailing list and send email communications to subscribers. MailerLite processes email addresses and email interaction data — such as open rates and link clicks — on our behalf. MailerLite is certified to ISO/IEC 27001:2022 and complies with the EU-US and Swiss-US Data Privacy Frameworks, ensuring that data transfers between Switzerland and the United States are conducted on a legally sound basis. MailerLite’s data storage infrastructure is located in the European Union. For more information, please refer to MailerLite’s privacy policy and data processing addendum, available at mailerlite.com.

6.2 Luma

We use Luma as our event registration platform. When you register for an event organised by Service Design Disrupted, Luma collects and processes your registration data on our behalf and shares it with us as the event host. Luma is GDPR compliant and processes personal data in accordance with its data processing addendum. For more information, please refer to Luma’s privacy policy, available at luma.com.

6.3 Stripe

Payment for event tickets is processed exclusively by Stripe through the Luma platform. Service Design Disrupted does not receive, store, or process any payment card data. Stripe handles all card data directly and maintains PCI DSS Level 1 certification, the highest level of payment security certification available. For more information, please refer to Stripe’s privacy policy, available at stripe.com.

6.4 Banking Institutions

Where speaker fees or expense reimbursements are processed by bank transfer, the association’s banking institution will necessarily process the relevant banking details — specifically IBAN and BIC — as part of the transfer. This processing is strictly limited to the execution of the payment and is governed by the terms and applicable regulations of the banking institution concerned.

6.5 Legal and Regulatory Authorities

We may be required to disclose personal data to competent legal or regulatory authorities where this is required by Swiss law or ordered by a court or public authority. In such cases, disclosure will be limited to what is strictly required by the applicable legal obligation.

6.6 A Note on International Data Transfers

Some of the third party service providers listed above — in particular MailerLite and Luma — may process personal data outside of Switzerland or the European Union. Where such transfers occur, they are conducted on the basis of appropriate legal safeguards, including adherence to the Swiss-US Data Privacy Framework, standard contractual clauses, or other mechanisms recognised under Swiss and European data protection law.

7. Your Rights as a Data Subject

Under the Swiss Federal Act on Data Protection (nFADP) and, where applicable, the General Data Protection Regulation of the European Union (GDPR), you have a number of rights regarding the personal data we hold about you. These rights are described below, along with information on how to exercise them.

7.1 Right of Access

You have the right to request confirmation of whether we hold personal data about you, and if so, to receive a copy of that data along with information about how it is being processed. This includes the purposes of processing, the categories of data held, and the parties with whom it has been shared.

7.2 Right to Rectification

You have the right to request the correction of any inaccurate or incomplete personal data we hold about you. We will action such requests promptly and without undue delay.

7.3 Right to Erasure

You have the right to request the deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn your consent and no other legal basis for processing exists, or where the data has been processed unlawfully. Please note that this right may be limited where retention is required to comply with a legal obligation — for example the retention of financial records under Swiss accounting law, as described in section 4.

7.4 Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances — for example while the accuracy of the data is being verified, or while an objection to processing is being considered.

7.5 Right to Data Portability

Where processing is based on your consent or on a contractual relationship, and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to request that it be transmitted to another controller where technically feasible.

7.6 Right to Object

You have the right to object at any time to the processing of your personal data where that processing is based on the legitimate interests of the association. Where you object, we will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for the establishment, exercise, or defence of legal claims.

7.7 Right to Withdraw Consent

Where processing is based on your consent — for example your subscription to our newsletter or your provision of information regarding your service design interests — you have the right to withdraw that consent at any time without giving any reason and without any negative consequence. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

7.8 Right to Lodge a Complaint

If you believe that the processing of your personal data by Service Design Disrupted is in breach of applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), whose contact details are available at fdpic.ch. If you are based in a European Union member state, you may also lodge a complaint with the data protection authority of your country of residence.

7.9 How to Exercise Your Rights

To exercise any of the rights described above, please contact us in writing at: privacy@sddisrupted.com.

We will respond to your request within 30 days of receipt. Where a request is complex or involves a large volume of data, we may extend this period by a further 30 days, in which case we will notify you of the extension and the reasons for it. We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.

8. Cookies and Website Analytics

The website sddisrupted.com may use cookies — small text files stored on your device — to ensure the proper functioning of the website. At present, we do not use website analytics tools or tracking technologies that process personal data beyond what is strictly necessary for the website to operate.

Should we introduce analytics tools or other technologies that collect or process personal data in the future, this privacy policy will be updated accordingly, and where required by applicable law, your consent will be requested before any such tools are activated. We will notify you of any such changes in accordance with section 9 of this policy.

9. Changes to This Privacy Policy

Service Design Disrupted reserves the right to update or amend this privacy policy at any time in order to reflect changes in our data processing activities, the tools and platforms we use, or the applicable legal and regulatory framework.

Any changes to this privacy policy will be published on this page at sddisrupted.com. Where changes are material — meaning they significantly affect the way we process your personal data or the rights available to you — we will notify you directly by email where we hold your email address, and we will clearly indicate the nature of the changes made.

The date of the most recent update to this privacy policy is indicated at the top of this page. We encourage you to review this policy periodically to stay informed about how we are protecting your data.

Your continued use of our website or services following the publication of any changes constitutes your acknowledgement of the updated policy. Where a change requires your renewed consent — for example if we introduce a new purpose for processing your personal data — we will request that consent explicitly before proceeding with the new processing activity.

Service Design Disrupted 26

 

DHub Barcelona
Plaça de les Glòries Catalanes, 38
08018 Barcelona, Spain

Stay Tuned

Join our mailing list to receive updates on speakers, schedules, and upcoming announcements for our conference.

    © 2026, Service Design Disrupted

    Privacy Preference Center