Overview & Roles
Ocupio operates as a data processor. Each event organiser (the company or professional body running an event) is the data controller for the personal data of their attendees. This distinction is fundamental under UK GDPR and the Data Protection Act 2018.
Event Organiser — Data Controller
- • Determines the purpose and means of processing
- • Responsible for lawful basis of processing
- • Responsible for responding to data subject requests
- • Controls data retention and deletion
- • Issues their own privacy notice to attendees
Ocupio — Data Processor
- • Processes data only on the controller's instruction
- • Provides infrastructure for data collection and storage
- • Maintains security and access controls
- • Provides tools for organisers to fulfil GDPR obligations
- • Signs Data Processing Agreements on request
Ocupio does not access, sell, share or use attendee data for any purpose other than delivering the platform service. No attendee data is used for advertising, profiling, AI training or any commercial purpose beyond the event management service contracted by the organiser.
What Data is Collected
Data is collected at the point of registration, during the event, and post-event. The exact fields collected depend on the configuration set by the event organiser.
Registration Data
Examples
Full name, email address, phone number, employer/firm name, job title
Legal Basis
Legitimate interest (event delivery) or explicit consent
Retention
Set by the organiser — 6 months to 2 years after the event, or manually
Dietary & Accessibility
Examples
Dietary requirements, accessibility or mobility needs
Legal Basis
Explicit consent (special category data)
Retention
Deleted immediately after event delivery; not retained
Custom Questions
Examples
Up to 5 custom questions set by the event organiser (e.g. session preferences, firm type)
Legal Basis
Legitimate interest or consent, depending on question content
Retention
Same as registration data
Attendance Records
Examples
QR check-in timestamp, check-in method, session attendance
Legal Basis
Legitimate interest (CPD compliance, event reporting)
Retention
Anonymised after the organiser's retention period expires
Post-Event Survey
Examples
NPS score, star ratings, speaker ratings, open-text feedback
Legal Basis
Consent (voluntary survey participation)
Retention
Set by the organiser; linked to attendee record
Marketing Consent
Examples
Opt-in to future communications from the organiser; networking opt-in
Legal Basis
Explicit consent
Retention
Until withdrawn by the data subject
How Data is Used
Personal data collected through Ocupio is used exclusively for the following purposes on behalf of the event organiser:
- Event registration management — confirming places, managing waitlists, venue capacity tracking
- Attendee communications — registration confirmations, event reminders, day-of logistics, post-event follow-up
- On-the-day operations — QR code check-in, seating plans, dietary requirement management
- CPD certificate generation — where applicable, personalised PDF certificates bearing the attendee's name and CPD hours
- Post-event reporting — anonymised aggregate analytics for the organiser; named feedback where the attendee has consented
- Data subject request management — facilitating the organiser in responding to erasure, access and portability requests
Ocupio does not use attendee data for: advertising or retargeting, profiling or scoring, AI model training, or sharing with any third party for commercial purposes.
Event Organiser Data Control
Event organisers on Ocupio have comprehensive control over all data associated with their events. The following capabilities are available directly from the Ocupio dashboard:
Full Data Export
Export a complete CSV of all attendee data, registrations, check-in records and survey responses for any event at any time.
Selective Deletion
Delete registration records, survey responses, or all personal data for a specific event independently. Anonymised stats are always preserved.
Automated Retention
Set a data retention policy of 6 months, 1 year or 2 years. Personal data is automatically purged once the period expires post-event.
Consent Records
Full audit trail of every attendee consent, including timestamp, IP address and consent type. Exportable for regulatory audit.
Data Subject Requests
Log and manage individual right-to-erasure and right-of-access requests. Ocupio provides the tooling; the organiser is responsible for responding.
Compliance Report
Generate a plain-text GDPR compliance summary for your organisation at any time, suitable for internal audits or DPA submissions.
All of these controls are available in the Data & Privacy Centre within the Ocupio dashboard, accessible to all admin and owner roles within an organisation.
Attendee Data Subject Rights
Every individual whose data is processed through Ocupio holds the following rights under UK GDPR. These rights are exercised through the event organiser as data controller, not through Ocupio directly.
Right of Access (Article 15)
You can request a copy of all personal data held about you by the event organiser.
Right to Erasure (Article 17)
You can request that your personal data be permanently deleted. This is the 'right to be forgotten'.
Right to Rectification (Article 16)
You can request correction of any inaccurate or incomplete data held about you.
Right to Restriction (Article 18)
You can request that processing of your data is restricted while a dispute or request is resolved.
Right to Data Portability (Article 20)
You can request your data in a structured, machine-readable format.
Right to Object (Article 21)
You can object to processing based on legitimate interest, including direct marketing.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
Right to Complain
You may lodge a complaint with the ICO (ico.org.uk) if you believe your data has been mishandled.
How to exercise your rights
Contact the event organiser directly — their contact details will be in the registration confirmation email you received. If you cannot reach the organiser or need to escalate, contact privacy@okupio.com and we will assist.
Data Retention
Each event organiser sets their own data retention policy within Ocupio. The available options are 6 months, 1 year, or 2 years after the event ends — or manual deletion. The organiser can change this setting at any time from their Data & Privacy Centre.
Once the retention period expires, personal identifiers (name, email, phone, dietary requirements) are automatically removed. Anonymised aggregate data — such as total attendance figures, NPS averages and CPD hours issued — is retained permanently so that the organiser's reports remain accurate.
Dietary requirements and accessibility information are treated as special category data under Article 9 GDPR. This data is used solely for operational event delivery and is not retained after the event date.
Ocupio's own data retention for platform operation data (billing, account records, audit logs) is governed by our separate Privacy Policy.
Security & Storage
Ocupio implements the following technical and organisational measures to protect personal data:
- All data is encrypted in transit using TLS 1.2 or higher
- All data is encrypted at rest using AES-256
- Data is stored within EU/EEA data centres compliant with UK GDPR adequacy requirements
- Access to production data is restricted to authorised Ocupio personnel on a least-privilege basis
- Role-based access controls ensure that each organisation's data is logically isolated from all other organisations
- All access to personal data is logged in a tamper-evident audit trail
- Subprocessors are assessed for compliance and bound by Data Processing Agreements
- Regular security reviews and penetration testing are conducted
- Data breach procedures are in place in accordance with Article 33/34 GDPR notification requirements
Sub-processors
Ocupio uses a small number of carefully selected sub-processors to deliver the platform service. All sub-processors are bound by Data Processing Agreements and are assessed for GDPR compliance.
| Processor | Purpose | Location |
|---|---|---|
| Base44 (Platform Infrastructure) | Application hosting, database, authentication | EU/EEA |
| Resend | Transactional email delivery | EU/EEA |
| Stripe | Payment processing (where ticketed events are used) | EU/EEA |
Ocupio does not transfer personal data outside the UK/EEA without appropriate safeguards in place (standard contractual clauses, adequacy decisions or other approved mechanisms).
Contact & Data Requests
For any data protection queries, subject access requests, erasure requests, or to request a Data Processing Agreement, contact:
Ocupio Data Protection Contact
Email: privacy@okupio.com
Response time: Within 72 hours for acknowledgement; full response within 30 days in line with ICO requirements
ICO Registration: Ocupio is registered with the Information Commissioner's Office (ICO)
Complaints: You have the right to lodge a complaint with the ICO (ico.org.uk) at any time
This page constitutes Ocupio's public data processing notice. It supplements but does not replace the full Privacy Policy and the Data Processing Agreement available to enterprise customers. For event organisers, your responsibilities as data controller are set out in the Ocupio Terms of Service.