Legal · last updated February 2026

Data processing agreement

This page sets out the processing terms that apply when Vantra handles personal data on a customer's behalf. It is app-owner content, not an independent audit or certification. A signable copy is available before you commit — email privacy@vantra-uk.com and we will send it.

Roles

The customer is the controller. Vantra is the processor and acts only on the customer's documented instructions, which include using the product as intended and anything agreed in writing.

Subject matter and duration

Processing lasts for the term of the customer's subscription plus the export window, and covers the operation of event control, staffing and ejections record-keeping.

Categories of data subject

  • The customer's own staff and controllers.
  • Subcontracted and supplied staff recorded against an event.
  • Members of the public named in an incident, ejection, welfare or lost property record.
  • Client and venue contacts.

Types of personal data

  • Identity and contact details, job role, call sign, shift times and sign-in records.
  • SIA licence numbers, expiry dates, qualifications and screening status.
  • Free-text incident narrative, descriptions and, where the customer enables it, photographs and signatures.
  • Welfare assessment answers and safeguarding flags, which are special category or otherwise sensitive data and are treated as such.

Security measures

  • Data encrypted in transit and at rest.
  • Row-level access control enforced in the database so one customer cannot reach another's records, and role-based access down to individual fields.
  • Append-only log entries enforced by database triggers, with corrections held as signed amendments.
  • A hash-chained audit trail written by the database rather than by application code, so tampering is detectable rather than merely prohibited.
  • Second factor required for account owners.
  • No standing Vantra access to customer records; support access is requested with a reason, approved by the customer, time-limited, banner-visible and fully audited.
  • Backups taken daily and restore tested.

Sub-processors

We use cloud hosting and managed database services, transactional email delivery and error monitoring. The current named list, with the country each operates in, is in the signable copy. We give customers notice before adding a sub-processor that touches their data, and a customer may object on reasonable data protection grounds.

International transfers

Customer data is stored in the United Kingdom or the European Economic Area. Where a transfer outside the UK is necessary, it relies on an adequacy decision or the UK International Data Transfer Addendum to the Standard Contractual Clauses.

Assistance

  • We help the customer respond to data subject requests, including access, correction and erasure, using the export and deletion tools in the product.
  • We notify the customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting their data, with what we know at the time.
  • We assist with data protection impact assessments and with prior consultation where required.
  • We make available the information needed to demonstrate compliance with these terms, and allow audits on reasonable notice.

Confidentiality and personnel

Everyone with access to customer data is bound by confidentiality obligations and has access only to what their work requires.

Return and deletion

On termination the customer may export everything for 30 days. After that we delete the data and instruct sub-processors to do the same, unless we are required by law to retain it.