Aventa · Information

Data protection

Last reviewed: 9 October 2026

Draft for review. Operator details, data arrangements and final terms are being confirmed. This draft is not an accepted organiser agreement.

Clear responsibilities

Organisers decide which participant information is needed to deliver their events. Aventa supplies the software, maintains platform accounts and processes relevant event records. Controller and processor responsibilities must be agreed for each activity; using a platform does not transfer every data-protection obligation to it.

Before taking entries

  • Provide a privacy notice explaining purposes, lawful bases, recipients and retention.
  • Collect only event information you need. Health data requires an additional special-category condition and appropriate restrictions.
  • Keep operational event messages separate from optional promotional marketing.
  • Limit team access and protect exports, printed start lists and emergency-contact reports.
  • Agree how rights requests, incidents and data deletion will be handled.

The processing agreement

A signed processing agreement must identify the service, duration, purposes, data types and affected people, and cover instructions, confidentiality, security, subprocessors, assistance with rights and incidents, audits, and return or deletion. The provider list, hosting locations, transfer safeguards and backup periods still require deployment-specific confirmation.

These requirements follow the ICO’s controller–processor contract guidance. This overview is not a signed processing agreement or certification of compliance.

Requests and incidents

Use Contact for privacy requests or suspected exposure of information. Describe the issue without sending passwords, full payment details or unnecessary medical records. Urgent event safety matters should go to the organiser or emergency services as appropriate.