Data & Privacy

Data Control & GDPR

This page explains who controls data on the Ocupio platform, what data is collected, how it is used, how long it is retained, and what rights both event organisers and attendees hold under UK GDPR and the Data Protection Act 2018.

Last updated: June 2026

Overview & Roles

Ocupio operates as a data processor. Each event organiser (the company or professional body running an event) is the data controller for the personal data of their attendees. This distinction is fundamental under UK GDPR and the Data Protection Act 2018.

Event Organiser — Data Controller

  • • Determines the purpose and means of processing
  • • Responsible for lawful basis of processing
  • • Responsible for responding to data subject requests
  • • Controls data retention and deletion
  • • Issues their own privacy notice to attendees

Ocupio — Data Processor

  • • Processes data only on the controller's instruction
  • • Provides infrastructure for data collection and storage
  • • Maintains security and access controls
  • • Provides tools for organisers to fulfil GDPR obligations
  • • Signs Data Processing Agreements on request

Ocupio does not access, sell, share or use attendee data for any purpose other than delivering the platform service. No attendee data is used for advertising, profiling, AI training or any commercial purpose beyond the event management service contracted by the organiser.

What Data is Collected

Data is collected at the point of registration, during the event, and post-event. The exact fields collected depend on the configuration set by the event organiser.

Registration Data

Examples

Full name, email address, phone number, employer/firm name, job title

Legal Basis

Legitimate interest (event delivery) or explicit consent

Retention

Set by the organiser — 6 months to 2 years after the event, or manually

Dietary & Accessibility

Examples

Dietary requirements, accessibility or mobility needs

Legal Basis

Explicit consent (special category data)

Retention

Deleted immediately after event delivery; not retained

Custom Questions

Examples

Up to 5 custom questions set by the event organiser (e.g. session preferences, firm type)

Legal Basis

Legitimate interest or consent, depending on question content

Retention

Same as registration data

Attendance Records

Examples

QR check-in timestamp, check-in method, session attendance

Legal Basis

Legitimate interest (CPD compliance, event reporting)

Retention

Anonymised after the organiser's retention period expires

Post-Event Survey

Examples

NPS score, star ratings, speaker ratings, open-text feedback

Legal Basis

Consent (voluntary survey participation)

Retention

Set by the organiser; linked to attendee record

Marketing Consent

Examples

Opt-in to future communications from the organiser; networking opt-in

Legal Basis

Explicit consent

Retention

Until withdrawn by the data subject

How Data is Used

Personal data collected through Ocupio is used exclusively for the following purposes on behalf of the event organiser:

  1. Event registration management — confirming places, managing waitlists, venue capacity tracking
  2. Attendee communications — registration confirmations, event reminders, day-of logistics, post-event follow-up
  3. On-the-day operations — QR code check-in, seating plans, dietary requirement management
  4. CPD certificate generation — where applicable, personalised PDF certificates bearing the attendee's name and CPD hours
  5. Post-event reporting — anonymised aggregate analytics for the organiser; named feedback where the attendee has consented
  6. Data subject request management — facilitating the organiser in responding to erasure, access and portability requests

Ocupio does not use attendee data for: advertising or retargeting, profiling or scoring, AI model training, or sharing with any third party for commercial purposes.

Event Organiser Data Control

Event organisers on Ocupio have comprehensive control over all data associated with their events. The following capabilities are available directly from the Ocupio dashboard:

Full Data Export

Export a complete CSV of all attendee data, registrations, check-in records and survey responses for any event at any time.

Selective Deletion

Delete registration records, survey responses, or all personal data for a specific event independently. Anonymised stats are always preserved.

Automated Retention

Set a data retention policy of 6 months, 1 year or 2 years. Personal data is automatically purged once the period expires post-event.

Consent Records

Full audit trail of every attendee consent, including timestamp, IP address and consent type. Exportable for regulatory audit.

Data Subject Requests

Log and manage individual right-to-erasure and right-of-access requests. Ocupio provides the tooling; the organiser is responsible for responding.

Compliance Report

Generate a plain-text GDPR compliance summary for your organisation at any time, suitable for internal audits or DPA submissions.

All of these controls are available in the Data & Privacy Centre within the Ocupio dashboard, accessible to all admin and owner roles within an organisation.

Attendee Data Subject Rights

Every individual whose data is processed through Ocupio holds the following rights under UK GDPR. These rights are exercised through the event organiser as data controller, not through Ocupio directly.

Right of Access (Article 15)

You can request a copy of all personal data held about you by the event organiser.

Right to Erasure (Article 17)

You can request that your personal data be permanently deleted. This is the 'right to be forgotten'.

Right to Rectification (Article 16)

You can request correction of any inaccurate or incomplete data held about you.

Right to Restriction (Article 18)

You can request that processing of your data is restricted while a dispute or request is resolved.

Right to Data Portability (Article 20)

You can request your data in a structured, machine-readable format.

Right to Object (Article 21)

You can object to processing based on legitimate interest, including direct marketing.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time.

Right to Complain

You may lodge a complaint with the ICO (ico.org.uk) if you believe your data has been mishandled.

How to exercise your rights

Contact the event organiser directly — their contact details will be in the registration confirmation email you received. If you cannot reach the organiser or need to escalate, contact privacy@okupio.com and we will assist.

Data Retention

Each event organiser sets their own data retention policy within Ocupio. The available options are 6 months, 1 year, or 2 years after the event ends — or manual deletion. The organiser can change this setting at any time from their Data & Privacy Centre.

Once the retention period expires, personal identifiers (name, email, phone, dietary requirements) are automatically removed. Anonymised aggregate data — such as total attendance figures, NPS averages and CPD hours issued — is retained permanently so that the organiser's reports remain accurate.

Dietary requirements and accessibility information are treated as special category data under Article 9 GDPR. This data is used solely for operational event delivery and is not retained after the event date.

Ocupio's own data retention for platform operation data (billing, account records, audit logs) is governed by our separate Privacy Policy.

Security & Storage

Ocupio implements the following technical and organisational measures to protect personal data:

  • All data is encrypted in transit using TLS 1.2 or higher
  • All data is encrypted at rest using AES-256
  • Data is stored within EU/EEA data centres compliant with UK GDPR adequacy requirements
  • Access to production data is restricted to authorised Ocupio personnel on a least-privilege basis
  • Role-based access controls ensure that each organisation's data is logically isolated from all other organisations
  • All access to personal data is logged in a tamper-evident audit trail
  • Subprocessors are assessed for compliance and bound by Data Processing Agreements
  • Regular security reviews and penetration testing are conducted
  • Data breach procedures are in place in accordance with Article 33/34 GDPR notification requirements

Sub-processors

Ocupio uses a small number of carefully selected sub-processors to deliver the platform service. All sub-processors are bound by Data Processing Agreements and are assessed for GDPR compliance.

ProcessorPurposeLocation
Base44 (Platform Infrastructure)Application hosting, database, authenticationEU/EEA
ResendTransactional email deliveryEU/EEA
StripePayment processing (where ticketed events are used)EU/EEA

Ocupio does not transfer personal data outside the UK/EEA without appropriate safeguards in place (standard contractual clauses, adequacy decisions or other approved mechanisms).

Cookies

Ocupio uses a minimal number of cookies necessary to deliver the service. No third-party advertising or tracking cookies are used.

CookiePurposeDuration
auth_tokenMaintains your authenticated sessionSession / 30 days if 'remember me'
org_sessionStores your active organisation contextSession
_ga (optional)Anonymous usage analytics (Google Analytics, if enabled)2 years

Contact & Data Requests

For any data protection queries, subject access requests, erasure requests, or to request a Data Processing Agreement, contact:

Ocupio Data Protection Contact

Email: privacy@okupio.com

Response time: Within 72 hours for acknowledgement; full response within 30 days in line with ICO requirements

ICO Registration: Ocupio is registered with the Information Commissioner's Office (ICO)

Complaints: You have the right to lodge a complaint with the ICO (ico.org.uk) at any time

This page constitutes Ocupio's public data processing notice. It supplements but does not replace the full Privacy Policy and the Data Processing Agreement available to enterprise customers. For event organisers, your responsibilities as data controller are set out in the Ocupio Terms of Service.