You stay in control of your guests’ data
For your events, your organisation decides what is collected and why. DelegateFlow processes guest data on your instructions, under a data processing agreement, and you can link your own privacy notice from every reply form.
Each organisation walled off
Every organisation’s events, delegates and requirements are separated by rules in the database itself, not just hidden on screen — so a mistake in one screen can’t show one organisation’s guests to another. These rules are checked by automated tests.
Dietary and access details treated as sensitive
Allergies and access needs can be health information, which UK GDPR treats as special category data. You can require guests’ explicit consent before these details are stored; without it, nothing they enter is kept. The details are stored separately, stay hidden until someone opens them, and each time your team does, it’s recorded.
Your caterer can be given a list focused on catering — names, dietary needs and allergies — without delegates’ accessibility, mobility or hearing details.
- Optional explicit consent
- Hidden until needed, with every viewing recorded
- A caterer list with only what the caterer needs
Only the access each person needs
Organisers, their colleagues and our team sign in with a password and an authenticator app. Colleagues with a reports view only see the guest list and individual requirements if you allow it. Door staff see names, organisations and arrival status only, for the events they’re working on, around the day of the event.
Secure links and tickets
Each guest’s reply link and QR ticket is long and random, so it can’t be guessed. The database only holds a fingerprint of each one, so a copy of the database wouldn’t give anyone working links. A forwarded link can be replaced at any time.
A full record of who did what
Sign-ins, exports, viewing of requirements and changes to guest records are written to an audit log that can’t be edited. Each event has its own setting for how long personal data should be kept after it ends.
Common questions
Is dietary information special category data?
Allergies and many dietary or access needs can reveal health information, which is special category data under UK GDPR. DelegateFlow lets you ask for explicit consent and keeps these details separate and restricted. This isn’t legal advice — your data protection lead should decide what’s right for your events.
Who is the data controller?
Normally your organisation, for your events. DelegateFlow acts as your processor and only uses guest data to run your events, on your instructions.
Which suppliers process the data?
Supabase (database and sign-in), Vercel (website hosting) and Resend (email). They only process data on our instructions.
Do search engines see guest information?
No. Reply links, tickets and signed-in areas are excluded from search engines, and guest details are never shown on public pages.
More of what DelegateFlow does
See it with your next event.
We’ll walk you through an event from invitation to arrival, and show you how it would work for yours.
