Security, privacy and accessibility
The system holds attendee data for public bodies and training providers, so it is built to standards they can evidence: ISO 27001 practices, UK GDPR obligations and WCAG 2.2 AA.
ISO 27001 aligned information security
- Access is granted by role, reviewed regularly and removed when people change roles.
- Significant administrative actions are written to an audit log that cannot be edited.
- Data is encrypted in transit and at rest, and backups are taken on a fixed schedule.
- Changes follow a documented review process before they reach the live system.
- Security incidents follow a defined response and notification procedure.
UK GDPR and data protection
- Personal data is collected for a stated purpose and kept only as long as it is needed.
- Marketing consent is recorded separately from booking consent and can be withdrawn at any time.
- Subject access, correction and erasure requests are handled through the system and tracked to completion.
- Attendee data is stored in the United Kingdom and the European Economic Area.
- Delegate lists are shared only where the attendee has chosen to appear on them.
WCAG 2.2 AA accessibility
- Every page can be operated by keyboard alone, with a visible focus indicator throughout.
- Colour contrast meets AA thresholds in both light and dark appearance.
- Forms use real labels, describe their errors in plain words and group related fields.
- Content reflows to a single column on small screens without losing any functionality.
- Motion is reduced automatically when a visitor asks their device for that.
Availability and resilience
- The public booking journey is the most protected part of the service.
- Capacity is planned around peak enrolment periods, not quiet weeks.
- Restores from backup are tested, not assumed.
- Planned maintenance is scheduled away from event days wherever possible.
Need our documentation?
We can share our information security summary, data processing terms and accessibility statement for procurement reviews.