Legal · last updated February 2026

Privacy policy

This page is maintained by Vantra and explains what personal data we hold, why we hold it and what you can ask us to do with it. It covers this website and the Vantra product. It is written to be read, not to be survived.

Two different roles

For our own website and account records, Vantra is the data controller. For the event records our customers create inside the product — log entries, staff details, incident and ejection records — the customer is the controller and Vantra is the processor acting on their instructions. If you are a member of the public who appears in an event record, the organisation running that event is the controller, and a request about that record should go to them. We will help them answer it.

What we collect from this website

  • Early access and demo forms: your name where given, email address, company name and anything you type into the note field. Used to reply to you and to tell you when a module is ready.
  • Sign-up and account data: name, work email, company, and the role you are given inside your company's account.
  • Security and operational logs: sign-in events, IP address and browser user agent, kept so an account compromise can be investigated.
  • We do not run advertising trackers, and we do not sell or share personal data with anyone for marketing.

What customers process inside the product

Vantra is used to keep operational records for events. Those records can include staff names, SIA licence numbers and expiry dates, screening information, shift times, and details of incidents, ejections and welfare assessments — some of which is sensitive. The customer decides what is entered and how long it is kept. Vantra provides retention settings, role-based access, an append-only log and an audit trail, so the customer can meet their own obligations.

Lawful bases

  • Contract — running an account for a customer and providing the product.
  • Legitimate interests — replying to an enquiry you sent us, keeping the service secure, and preventing misuse. Balanced against your interests, and you can object.
  • Consent — for optional product emails. Withdraw it at any time using the unsubscribe link or by emailing us.
  • Legal obligation — where we have to keep or disclose something by law.

Who we use to run the service

We keep the list of sub-processors short and it is set out in full in the data processing agreement. In summary: cloud hosting and database services with data stored in the United Kingdom or the European Economic Area, transactional email delivery, and error monitoring. We tell customers before we add a new sub-processor that touches their data.

Where data is held

Customer data is stored in the United Kingdom or the European Economic Area. Where a supporting service involves a transfer outside the UK, it is covered by the UK International Data Transfer Addendum or an adequacy decision.

Support access

No one at Vantra has standing access to a customer's event log. If support needs to look at a record, access is requested with a stated reason, approved by someone with owner permission in that account, expires on a timer, is shown as a banner inside the interface while it is active, and everything opened is written to the customer's audit trail.

How long we keep things

  • Website enquiries: 24 months from your last contact with us, then deleted.
  • Account records: for the life of the account and 12 months afterwards, so a returning customer's history is intact and billing questions can be answered.
  • Event records inside the product: for the period the customer sets. Deletion runs automatically when it elapses and the customer receives a report of what was removed.
  • Security logs: 12 months.

Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing based on legitimate interests, or ask for it in a portable format. Email privacy@vantra-uk.com. We will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner's Office at ico.org.uk.

Cookies

This site sets only the cookies needed to keep you signed in and to keep the sign-in form secure. There are no analytics or advertising cookies, which is why you are not being asked to accept anything.

Changes

If this policy changes in a way that affects you, we will say so by email to account owners rather than quietly updating the date at the top.