Privacy Policy for Controlled Events


The event organiser, Controlled Events, has the legal responsibility to tell ticket buyers and event attendees how their personal information will be collected and used. You can find their Privacy Policy below or contact them to request it.


1. Introduction

Thank you for choosing to be part of our community at Controlled Events Limited ("Controlled Events", "we", "us", "our").

This Privacy Notice explains how Controlled Events collects, uses, stores and shares personal information about you in accordance with applicable data protection legislation, including the UK General Data Protection Regulation, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.

This notice applies to current and former employees, workers, apprentices, volunteers, placement students, self-employed contractors and consultants.

This notice does not form part of any contract of employment or contract for services. Controlled Events may update it at any time.

2. Scope

Controlled Events Limited brand describes itself as follows, “…A range of businesses, public sector organisations and large Consultancy firms choose Controlled Events Limited to provide business continuity and crisis management consultancy, event control and communications, training and readiness activity. We set ourselves apart from larger firms and sole traders by offering tailored services with the benefit of knowledge development over ten years in the resilience business, experience in supporting some of the UK’s largest resilience projects and development of a small network of Subject Matter Experts who provide us with the strength in depth for particular areas of your project. Since 2011 we have worked with Clients in the UK, Europe, USA and Middle East and we are able to quickly and seamlessly integrate into your plan for a resilience project, exercise or training programme to design, produce, deliver to the standards and good practice relating to your sector.”

This notice explains how we use personal data about you in connection with your employment, work or engagement with Controlled Events.

3. Data Controller Details

Controlled Events is a data controller. This means that we determine the purposes and means of processing your personal data.

Our contact details are:

support@controlledevents.com

The person responsible for data protection compliance is:

Rob Walley, Managing Director, support@controlledevents.com

4. Data Protection Principles

In relation to your personal data, we will:

  • process it fairly, lawfully and transparently
  • collect it only for proper reasons connected with your employment, work or engagement
  • use it only for the purposes explained in this notice or for compatible purposes
  • ensure it is accurate and kept up to date where necessary
  • keep it only for as long as we need it
  • protect it against unauthorised access, accidental loss, destruction or damage.

5. Types of Personal Data We Process

We may collect, store and use the following categories of personal data about you:

  • name, address, date of birth, personal email address and telephone number
  • emergency contact and next of kin details
  • gender, marital status and dependants
  • recruitment information, including CVs, application forms, interview notes, references, education history and employment history
  • right to work documentation
  • driving licence details where relevant
  • bank details, tax information and National Insurance number
  • job title, job description, department, reporting line, pay, benefits, working hours and other terms and conditions
  • payroll, pension and benefits information
  • annual leave, family leave and sickness absence records
  • performance records, appraisals, objectives, training records and development information
  • conduct, disciplinary, grievance, capability and investigation records
  • correspondence with or about you
  • health and medical information where relevant
  • information used for equal opportunities monitoring
  • CCTV footage, building access records or visitor records where applicable
  • information about your use of Controlled Events IT systems, devices, applications, email, internet, communications systems and security logs
  • meeting recordings, transcripts or notes where meetings are recorded
  • any other personal data necessary for managing your employment, work or engagement.

6. Special Category Personal Data

We may process special category personal data, including information relating to:

  • health, sickness absence and medical conditions
  • disability and reasonable adjustments
  • race, ethnic origin, religion or belief, sexual orientation or other information used for equal opportunities monitoring
  • trade union membership where relevant
  • biometric data, only where applicable and legally permitted.

We will only process special category data where we have a lawful basis and an additional condition for processing. This may include where processing is necessary for employment law obligations, health and safety, sickness absence management, reasonable adjustments, occupational health, equality monitoring, legal claims or where you have given explicit consent.

7. Criminal Offence Data

We will only collect and use criminal offence data where it is appropriate given the nature of your role or engagement and where the law allows us to do so.

This may include employment background checks, security clearance, safeguarding requirements, insurance requirements or client contractual requirements where relevant.

8. How We Collect Your Data

We will usually collect personal information directly from you during recruitment and throughout your employment, work or engagement.

We may also collect personal data from third parties, including:

  • recruitment agencies
  • former employers
  • referees
  • occupational health providers
  • medical professionals
  • payroll, pension or benefits providers
  • clients or project contacts where relevant
  • external advisers
  • background check providers
  • IT systems, security systems, meeting platforms and communication tools.

Where meetings are recorded, the recording may be collected directly from the meeting platform or device used to host or record the meeting.

9. Why We Use Your Data

We process your personal data for reasons connected with your employment, work or engagement. These include:

  • making recruitment and appointment decisions
  • checking your right to work in the UK
  • carrying out the contract we have entered into with you
  • paying you and administering tax, National Insurance, pensions and benefits
  • managing your role, work, performance, development and training
  • managing sickness absence, health and safety, occupational health and reasonable adjustments
  • managing annual leave, family leave and other absence
  • dealing with disciplinary, grievance, capability, performance or investigation processes
  • maintaining accurate personnel records
  • communicating with you
  • managing business planning, restructuring or organisational change
  • preventing fraud
  • ensuring our administrative and IT systems are secure
  • complying with legal obligations
  • dealing with legal claims or potential legal claims
  • meeting client, contractual, regulatory or audit requirements where relevant.

10. Lawful Bases for Processing

We will only use your personal data where the law allows us to. Most commonly, we will use it where:

  • processing is necessary for the performance of a contract with you
  • processing is necessary to comply with a legal obligation
  • processing is necessary for our legitimate interests or the legitimate interests of a third party
  • processing is necessary to protect your vital interests or someone else’s interests
  • processing is needed in the public interest, where applicable.

In limited circumstances, we may ask for your consent. Where we ask for consent, you have the right to withdraw that consent at any time.

11. If You Do Not Provide Personal Data

Some personal data is necessary so that we can enter into or manage our relationship with you. If you do not provide information that we need, we may be unable to employ you, engage you, pay you, provide benefits, comply with our legal obligations or continue our working relationship with you.

12. Sharing Your Data

We may share your personal data with colleagues within Controlled Events where this is necessary for them to carry out their duties.

We may also share your personal data with third parties where this is necessary and lawful, including:

  • payroll providers
  • pension providers
  • benefit providers
  • insurers
  • occupational health providers
  • IT providers
  • external HR, legal or professional advisers
  • clients, where relevant to your work or engagement
  • regulatory bodies, public authorities or law enforcement agencies where required
  • third parties involved in a business sale, restructure or transfer.

Where third parties process your personal data on our behalf, we will take reasonable steps to ensure that they handle it securely and in line with data protection requirements.

13. International Transfers

We will not transfer your personal data outside the UK unless appropriate safeguards are in place and the transfer is lawful under applicable data protection legislation.

Further information about any international transfers and safeguards can be obtained from [insert job title/contact details].

14. Protecting Your Data

We have implemented procedures and safeguards to protect your personal data against accidental loss, unauthorised access, unlawful disclosure, destruction or misuse.

Where we share your data with third parties, we will provide appropriate instructions and expect them to keep your data secure.

You are also required to comply with Controlled Events Data Protection Policy, Cyber Security and Acceptable Use Policy and any other relevant procedures.

15. IT Monitoring, Communications and System Logs

We may monitor Controlled Events IT and communications systems, including email and messaging systems, internet usage, device activity, login records, system usage logs, network traffic, use of corporate applications and security alerts.

We carry out monitoring for legitimate business purposes, including:

  • maintaining IT and cyber security
  • protecting Controlled Events systems, data, clients and users
  • detecting and investigating suspected misuse, misconduct or security incidents
  • ensuring compliance with organisation policies and legal obligations
  • supporting internal investigations where appropriate.

Monitoring will be proportionate and limited to what is reasonably necessary for the relevant purpose.

16. Meeting Recordings and Transcription Tools

From time to time, we may record meetings, including virtual meetings or in-person meetings captured through audio or video recording tools. Meeting recordings and transcripts may contain personal data.

Recordings may be used for purposes such as:

  • accurate record-keeping of decisions or actions
  • training and development
  • supporting investigations, grievances, disciplinaries, sickness absence or performance-related processes
  • audit, compliance or regulatory requirements
  • evidence in relation to disputes or legal claims.

Where a meeting is recorded, we will normally notify participants in advance or at the start of the recording.

Access to recordings will be restricted to those who require it for the relevant purpose. Recordings will be retained only for as long as necessary and then securely deleted.

17. AI-Assisted Tools and Automated Decision-Making

Controlled Events may use AI-assisted tools or automated systems to support business activities, including administration, drafting, research, transcription, workflow support, recruitment administration, security monitoring or data analysis.

We will not make decisions about you based solely on automated processing where the decision has a legal or similarly significant effect on you unless this is permitted by law and appropriate safeguards are in place.

Where AI-assisted tools are used to support decision-making, human review and judgement will remain part of the process.

18. How Long We Keep Your Data

We will only keep your personal data for as long as necessary for the purpose for which it was collected, including for the purpose of satisfying legal, accounting, reporting, contractual or regulatory requirements.

Retention periods may vary depending on the type of data and the reason for holding it.

Further information about retention periods can be obtained from [insert job title/contact details].

19. Your Rights

Under data protection law, you have rights in relation to your personal data. These include:

  • the right to be informed about how we use your data
  • the right of access to your personal data
  • the right to ask us to correct inaccurate or incomplete data
  • the right to ask us to delete personal data in certain circumstances
  • the right to ask us to restrict processing in certain circumstances
  • the right to object to processing in certain circumstances
  • the right to request transfer of your personal data in certain circumstances
  • rights relating to automated decision-making and profiling.

If you wish to exercise any of these rights, please contact [insert job title/contact details].

20. Data Protection Complaints

If you have a concern or complaint about how we handle your personal data, please contact [insert job title/contact details].

We will acknowledge data protection complaints within 30 days of receipt. We will take appropriate steps to investigate the complaint without undue delay, keep you informed where appropriate and tell you the outcome.

You also have the right to complain to the Information Commissioner’s Office.

21. Updates to This Notice

We may update this Privacy Notice from time to time. You will be notified of significant changes where appropriate.