GDPR-friendly event registration: how DelegateFlow protects guest data

Guest lists hold names, employers and sometimes health information. Here’s how DelegateFlow is designed so the right people see the right things — and how it helps you meet your obligations under UK GDPR.

The delegate list, with requirements kept separately

You stay in control of your guests’ data

For your events, your organisation decides what is collected and why. DelegateFlow processes guest data on your instructions, under a data processing agreement, and you can link your own privacy notice from every reply form.

Each organisation walled off

Every organisation’s events, delegates and requirements are separated by rules in the database itself, not just hidden on screen — so a mistake in one screen can’t show one organisation’s guests to another. These rules are checked by automated tests.

Dietary and access details treated as sensitive

Allergies and access needs can be health information, which UK GDPR treats as special category data. You can require guests’ explicit consent before these details are stored; without it, nothing they enter is kept. The details are stored separately, stay hidden until someone opens them, and each time your team does, it’s recorded.

Your caterer can be given a list focused on catering — names, dietary needs and allergies — without delegates’ accessibility, mobility or hearing details.

  • Optional explicit consent
  • Hidden until needed, with every viewing recorded
  • A caterer list with only what the caterer needs

Only the access each person needs

Organisers, their colleagues and our team sign in with a password and an authenticator app. Colleagues with a reports view only see the guest list and individual requirements if you allow it. Door staff see names, organisations and arrival status only, for the events they’re working on, around the day of the event.

Secure links and tickets

Each guest’s reply link and QR ticket is long and random, so it can’t be guessed. The database only holds a fingerprint of each one, so a copy of the database wouldn’t give anyone working links. A forwarded link can be replaced at any time.

A full record of who did what

Sign-ins, exports, viewing of requirements and changes to guest records are written to an audit log that can’t be edited. Each event has its own setting for how long personal data should be kept after it ends.

Common questions

Is dietary information special category data?

Allergies and many dietary or access needs can reveal health information, which is special category data under UK GDPR. DelegateFlow lets you ask for explicit consent and keeps these details separate and restricted. This isn’t legal advice — your data protection lead should decide what’s right for your events.

Who is the data controller?

Normally your organisation, for your events. DelegateFlow acts as your processor and only uses guest data to run your events, on your instructions.

Which suppliers process the data?

Supabase (database and sign-in), Vercel (website hosting) and Resend (email). They only process data on our instructions.

Do search engines see guest information?

No. Reply links, tickets and signed-in areas are excluded from search engines, and guest details are never shown on public pages.

See it with your next event.

We’ll walk you through an event from invitation to arrival, and show you how it would work for yours.

We’ll only use these details to reply to you. See our privacy notice.