You are the controller
The event is yours and so is the data. We are your processor, acting on your instructions, and a data processing agreement is available as part of contracting.
Security & data
Names, contact details, medical incidents, safeguarding concerns, and sometimes children. This page explains how that data is held, who can reach it, and what happens to it afterwards.
Where it lives
Multi-tenant systems usually mean everyone's rows sitting in the same tables behind a filter. This isn't that.
Who can see it
A policy that says "only look at what you need" is worth very little unless the system enforces it.
Access is granted per module and per action. A gate steward's account can be scoped to the site access log and nothing else — not incidents, not the registry, not reports. They don't get a restricted view of the safeguarding case; they get no view of it.
Sensitive incidents can be restricted so only senior roles see they exist. They can also be locked, so opening one requires typing a written justification first. That justification is stored permanently against your name.
Available on every account and enforceable across your whole tenant using a standard authenticator app.
Every view, edit, export, login and permission change is recorded with who, what and when. It is exportable for your own records, and it cannot be edited or deleted by anyone — including us.
This is what turns "we think the right people saw it" into an answer you can actually give a regulator, an insurer or a parent.
We can reach your tenant for support and provisioning. When we do, it is logged in the same audit trail you can read. You can verify that yourself rather than take our word for it.
Compliance
We will not claim a certification we do not hold. This is what is actually in place.
The event is yours and so is the data. We are your processor, acting on your instructions, and a data processing agreement is available as part of contracting.
Keep records only as long as your own policies require. When you're done, your data is deleted on request — properly, including from backups on the retention cycle.
If someone asks what you hold about them, the registry and audit trail let you answer accurately instead of guessing. We'll help if you need it.
Resilience
Questions
Yes, as part of contracting. If your organisation has its own DPA or supplier security questionnaire, we will work to your documentation rather than insist on ours.
It stays available for as long as you need it for debriefs, insurance and reporting. After that it's deleted on your instruction. For annual events most clients keep the registry so the following year starts with it — that's your call, not ours.
No. We don't mine it, we don't aggregate it into benchmarks, and we don't train anything on it. It's your event's data and it's used to run your event.
You'd be told without delay, with what we know and what we're doing, so you can meet your own 72-hour notification duty. We will tell you early with an incomplete picture rather than late with a complete one.
Yes — supervisors and event managers can view and export it directly. It isn't something you have to ask us for.
Send it to us. Answering it properly up front is faster than letting it delay your event.