This Privacy Policy explains how WM Event & Design (SWEDEN) AB (company no. 559444-6527) (“Cascora”, “we”, “us”) collects, uses, and protects personal information when you use the Cascoraplatform, websites, and related services (the “Service”).
1. Information we collect
We collect the following categories of information:
- Account information: name, email address, company details, and role, provided when you register or are invited to the Service.
- Customer content: projects, budgets, scopes of work, invoices, files, and contact records (which may include personal data about your clients, suppliers, and team members) that you or your collaborators add to the Service.
- Usage and device data: log data, IP address, browser type, and interactions with the Service, used for security and to improve the product.
- Communications: messages you send us, such as support requests and feedback.
2. How we use information
We use personal information to:
- provide, operate, and secure the Service;
- create and manage accounts, including invitations between organisations;
- send service emails such as invitations, notifications, and account messages;
- respond to support requests and communicate about the Service;
- monitor performance, debug issues, and improve features;
- comply with legal obligations.
Where the law requires a legal basis for processing, we rely on the performance of our contract with you, our legitimate interests in running and improving the Service, your consent where applicable, and compliance with legal obligations.
3. Sharing within the platform
Cascora is a collaboration platform. Information you add may be visible to other members of your organisation, and, where you use sharing features, to the clients and suppliers you invite, according to the permission and visibility settings applied. We do not decide what you share; the organisation controlling each project does.
4. Service providers (subprocessors)
We use a small number of trusted infrastructure providers to operate the Service. These currently include:
- Supabase: database, authentication, and file storage;
- Vercel: application hosting and content delivery;
- Resend: transactional email delivery.
These providers process data on our behalf under contractual protections. We do not sell personal information, and we do not share it with third parties for their own advertising purposes.
5. International transfers
Our service providers may store or process information in countries other than your own. Where personal information is transferred internationally, we take steps designed to ensure it receives an adequate level of protection, such as relying on appropriate contractual safeguards offered by our providers.
6. Data retention
We retain personal information for as long as your account is active or as needed to provide the Service, resolve disputes, and meet legal obligations. When an account is closed, Customer Data is deleted or anonymised within 90 days, except where we are required to keep it longer (for example, billing records).
7. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls, row-level security on customer records, and audit logging of key actions. No system is completely secure, so we encourage you to use a strong, unique password and to keep your credentials confidential.
8. Your rights
Depending on where you live, you may have rights over your personal information, which can include the right to:
- access a copy of the personal information we hold about you;
- correct inaccurate information;
- request deletion of your information;
- object to or restrict certain processing;
- receive your information in a portable format;
- withdraw consent where processing is based on consent;
- complain to your local data protection authority.
To exercise any of these rights, contact us using the details below. If your data was added to the Service by one of our customers (for example, as a contact of an event agency), we may direct your request to that customer, who controls that data.
9. Cookies
We use cookies and similar technologies that are necessary to operate the Service, for example keeping you signed in and remembering preferences. We do not currently use third-party advertising cookies. If this changes, we will update this policy and seek consent where required.
10. Children
The Service is intended for business use by adults. It is not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, please contact us so we can delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. If a change is material we will give reasonable notice (for example by email or in-app notice). The “Last updated” date at the top shows when this policy was most recently revised.
12. Contact
Privacy questions and requests can be sent to william@wmeventdesign.com or by post to WM Event & Design (SWEDEN) AB, Stockholm, Sweden.