Security & data

Control rooms handle exactly the data the law cares about.

Names, contact details, medical incidents, safeguarding concerns, and sometimes children. This page explains how that data is held, who can reach it, and what happens to it afterwards.

Where it lives

One client, one database.

Multi-tenant systems usually mean everyone's rows sitting in the same tables behind a filter. This isn't that.

Isolated tenant
Every client gets their own separate database. Your incidents and your registry are not in a shared table with another event's, and there is no query that could accidentally return someone else's data because it isn't there to return.
UK hosted
Servers are in the UK. Your event data is not replicated to other jurisdictions.
In transit
Everything is served over HTTPS. The application is not reachable over plain HTTP at all.
Backups
Your tenant is backed up continuously throughout the event, and copies are held off-site encrypted. Restores are tested by actually restoring them, not by assuming the file is fine.
Attachments
Photos and documents attached to incidents are backed up alongside the database, so a restore doesn't hand you a log full of references to missing evidence.

Who can see it

Need-to-know, enforced by the system.

A policy that says "only look at what you need" is worth very little unless the system enforces it.

Roles and modules

Access is granted per module and per action. A gate steward's account can be scoped to the site access log and nothing else — not incidents, not the registry, not reports. They don't get a restricted view of the safeguarding case; they get no view of it.

Restricted and locked incidents

Sensitive incidents can be restricted so only senior roles see they exist. They can also be locked, so opening one requires typing a written justification first. That justification is stored permanently against your name.

Multi-factor authentication

Available on every account and enforceable across your whole tenant using a standard authenticator app.

The audit trail

Every view, edit, export, login and permission change is recorded with who, what and when. It is exportable for your own records, and it cannot be edited or deleted by anyone — including us.

This is what turns "we think the right people saw it" into an answer you can actually give a regulator, an insurer or a parent.

Our own access

We can reach your tenant for support and provisioning. When we do, it is logged in the same audit trail you can read. You can verify that yourself rather than take our word for it.

Compliance

Designed for UK GDPR and the DPA from the ground up.

We will not claim a certification we do not hold. This is what is actually in place.

You are the controller

The event is yours and so is the data. We are your processor, acting on your instructions, and a data processing agreement is available as part of contracting.

Retention you set

Keep records only as long as your own policies require. When you're done, your data is deleted on request — properly, including from backups on the retention cycle.

Subject access

If someone asks what you hold about them, the registry and audit trail let you answer accurately instead of guessing. We'll help if you need it.

Third parties in the loop. Some features rely on external providers: SMS delivery, transactional email, what3words location lookup, and our network and DNS provider. These are listed with their roles in the data processing agreement, and features you don't enable don't send anyone anything.

Resilience

Available when it matters, which is all of it.

Connectivity
A live monitor on every operator's screen. The dangerous failure isn't losing connection — it's not knowing you have.
Hot standby
An optional on-site mirror that takes over if the site loses internet entirely.
Resilient links
Satellite and multi-network cellular available as an on-site service where the venue's own connectivity can't be trusted.
Recovery
Documented recovery procedures, rehearsed rather than filed. Backups are restored as a test, not just written.

Questions

What procurement usually asks.

Can we have a data processing agreement?

Yes, as part of contracting. If your organisation has its own DPA or supplier security questionnaire, we will work to your documentation rather than insist on ours.

What happens to our data after the event?

It stays available for as long as you need it for debriefs, insurance and reporting. After that it's deleted on your instruction. For annual events most clients keep the registry so the following year starts with it — that's your call, not ours.

Do you use our data for anything else?

No. We don't mine it, we don't aggregate it into benchmarks, and we don't train anything on it. It's your event's data and it's used to run your event.

What if there's a breach?

You'd be told without delay, with what we know and what we're doing, so you can meet your own 72-hour notification duty. We will tell you early with an incomplete picture rather than late with a complete one.

Can we see the audit trail ourselves?

Yes — supervisors and event managers can view and export it directly. It isn't something you have to ask us for.

Security questionnaires.

Send it to us. Answering it properly up front is faster than letting it delay your event.