SSympozium

Privacy Policy

Version 2.0. Effective 4 October 2026. This version replaces version 1.0.

1. Who we are

1.1 Sympozium is a trading name of AJB Medical Services Ltd, a company registered in England and Wales (company number 12797861). Registered office: Oakmoore Court, Kingswood Road, Hampton Lovett, Droitwich, Worcestershire, WR9 0QH. We're registered with the Information Commissioner's Office (ICO), registration reference ZA130690.

1.2 For the processing described in this policy, we are the controller of your personal data. Contact us about anything in this policy at admin@sympozium.co.uk.

1.3 This policy explains:

  • what personal data we collect and why;

  • who can see it;

  • how long we keep it; and

  • your rights.

2. Organisers are responsible for their own use of your data

2.1 Events on Sympozium are run by organisers (for example an NHS department, a society or a course). When you book a place, the organiser's event team can see some of your details so they can run the event (section 6).

2.2 The organiser is a separate controller of the data it uses or takes off Sympozium, for example if it exports its registrant list or contacts you. The organiser's use of your data is its responsibility and is covered by its own privacy information. Our Organiser Terms require organisers to use attendee data only for purposes connected with their events, and in line with data protection law.

3. What we collect

3.1 If you create an account:

  • your title, first name, last name and email address;

  • your password, which we never see (it's handled by our sign-in service);

  • optionally, your preferred name, post-nominals, phone number, job title, place of work, a short biography and a photo;

  • which version of our Terms of Use you accepted, and when;

  • whether you'd like occasional product updates from us (the tick on the sign-up page and in My account).

3.2 If you book a place at an event:

  • the details on the registration form: phone number, place of work and job title (saved with the booking as you entered them);

  • accessibility needs, if you choose to tell us (section 5);

  • dietary requirements, if the event is catered and you choose to tell us (section 5);

  • your answers to the organiser's own questions;

  • the booking itself: event, ticket type, ticket reference, amount paid, status, any refund (including part refunds, and the reason the event team recorded, which isn't shown to you), and payment references from Stripe, or from the organiser's own Stripe account for events paid directly to the organiser. We never see or store your full card number.

  • whether and when you were checked in, and how (at the desk, by scanning a code at the venue, or by opening an online event's join link);

  • any waitlist you join, and invitations to invitation-only tickets;

  • your feedback (section 7) and your certificates, including your name and any CPD points shown on them.

3.3 If you're a speaker, faculty member or member of an event team:

  • your role at each event or organisation;

  • invitations sent to you (the name and email address the organiser typed);

  • files you upload;

  • faculty certificates showing your name, your role at the event and any sessions you led, with their dates, times and rooms and your time leading sessions (each certificate also names the event's directors);

  • a record of when a name label was printed for you;

  • what you do in the event team's tools (for example, who checked someone in and when, who refunded a ticket, who downloaded an attendee list).

3.4 If you act for an organisation:

  • the organisation's details;

  • the names of its directors and team;

  • its bank details (name on the account, sort code and account number), which only its organisation directors and our administrators can see;

  • a record of which director accepted our commercial terms and the Organiser Terms, which version, and when;

  • if the organisation connects its own Stripe account: the account's ID, whether it can take payments and receive payouts, who connected it and when, and, where we complete the connection on someone's behalf, a note of their written approval.

Organisers on Pay as you go don't give us card details. Organisers who take the organisation subscription pay through Stripe, which processes their card details. We never see or store full card numbers.

If an organisation connects its own Stripe account, Stripe collects identity and business details from the organisation's representative directly, under Stripe's own terms and privacy policy, as a separate controller. We don't see those details.

3.5 When you use the site:

  • technical information our hosting and sign-in providers record for security and to keep the service running, such as your IP address, browser type and the time of requests;

  • records of emails we send you, including whether each was delivered or bounced.

3.6 When you contact us: your messages and our replies.

4. How we use your data, and our lawful bases

What we do Lawful basis (UK GDPR)
Run your account, and let you sign in, book, cancel and get refunds Contract
Take payments (or, for events paid directly to the organiser, create the payment on the organiser's Stripe account), record them, and pay organisers where we hold the money Contract
Share your booking details with the event team (section 6) Contract; legitimate interests (letting organisers run their events)
Check you in, issue certificates, and send feedback requests and reminders the organiser has set up Contract; legitimate interests
Show speakers and the event team the names and job titles of people expected at a session Legitimate interests (preparing sessions)
Show faculty and speakers' names on event pages Legitimate interests (telling attendees who is teaching)
Print name labels for an event (name, post-nominals, job title and role) Legitimate interests (running the event)
Share anonymous feedback with organisers and speakers, and produce speaker reports Legitimate interests (improving education)
Send emails the organiser writes to attendees or its team through Sympozium Legitimate interests (event communications)
Keep financial records Legal obligation
Keep security logs and records of who did what (including downloads of attendee lists), prevent fraud, handle payment disputes Legitimate interests; establishing or defending legal claims
Tell you about changes to our terms or this policy Legitimate interests
Send occasional product updates, if you've ticked the box Consent
Accessibility needs and dietary requirements Your explicit consent (section 5)

Where we rely on legitimate interests, we've balanced our interests against yours. You can ask us for details, and you can object (section 11).

We don't make decisions about you that have legal or similarly significant effects solely by automated means. Certificates are issued automatically when the conditions the organiser set are met. If you think one should have been issued, ask the organiser, who can release it.

5. Accessibility needs and dietary requirements

5.1 These are optional. They may reveal information about your health or beliefs, which the law treats as special category data.

5.2 We collect them only with your explicit consent, which you give on the registration form.

5.3 They're shared only with the event team for that event, so they can support you and arrange catering. You can withdraw your consent at any time by emailing us, and we'll remove them.

5.4 We delete them 30 days after the event's last day.

6. Who can see your data

6.1 The public can see published event pages, including the organiser's details and the names of faculty and speakers. Attendee lists are never public.

6.2 Other signed-in users can't see your profile. Where they need to, for example on an event team you're both part of, they see your name only. Faculty and speakers' details on public event pages are covered by 6.1.

6.3 An event's team, for events you've booked or have a role at:

Role What it can see
Event support staff (for example at the check-in desk) Your name, email address, ticket type, reference, check-in status, amount paid, the phone number you gave when booking, and your accessibility and dietary notes
Event admins and directors, and the organisation's directors and admins As above, plus your registration answers, groups and refund details. They can export the registrant list (names, email addresses, phone numbers, ticket and payment details, check-in status).
Event directors (and event admins, if the organisation allows it), and organisation directors Also the event's payment and refund totals

6.4 Event teams can also download or print attendee lists, the programme and presentation files, so that the event can run if the internet is unavailable. We keep a record of each download and export: who made it and when.

6.5 Speakers see the names and job titles of people expected at their sessions (no contact details), and feedback on their sessions without names.

6.6 Name labels. Event admins and directors can print name labels showing your name, post-nominals, job title and your role at the event. We record who was printed and when; the labels themselves aren't stored.

6.7 Events paid directly to the organiser. When you pay the organiser through its own Stripe account, the organiser receives your name, email address and payment details (but not your full card number) in that account, as a separate controller.

6.8 Our administrators (currently the founder) can see what's needed to run and support the platform, handle payments and payouts, and investigate problems.

6.9 Our service providers (section 9).

6.10 Others where the law requires, for example HMRC, the police with proper authority, or a court. Also a buyer of our business, who would be bound by this policy.

6.11 We never sell your data.

7. Feedback

7.1 Feedback is anonymous to organisers and speakers. They see ratings and comments without your name or when you submitted them. Inside Sympozium, your feedback stays linked to your account so we can tell when your certificate is due and let you edit it.

7.2 In a small group, a speaker or organiser may still be able to guess who wrote a comment.

7.3 If you tick "I'm happy for the organisers to contact me about my feedback", the organisers will see your name and email alongside all your feedback for that event. Speakers never see who you are.

7.4 Speaker feedback reports contain figures and comments, but no information about who gave them.

8. Emails

8.1 About your bookings and roles: confirmations, changes, cancellations, refunds, waitlist offers, invitations, reminders, feedback requests and certificates. These are part of the service.

8.2 From organisers: messages the event team writes to attendees or faculty through Sympozium. Replies go to the organiser.

8.3 Product updates: we send these only if you've ticked "Send me occasional product updates". We don't send any at the moment. You can untick it in My account at any time.

8.4 Tracking: we record whether each email was delivered or bounced. We don't track whether you open our emails or click their links.

9. Our service providers and where your data is held

9.1 We use these providers to run Sympozium. They process data for us under contracts that protect it.

Provider What it does Where
Supabase Database, sign-in and file storage UK (London)
Vercel Hosts and runs the website EU (Dublin, Ireland)
Stripe Card payments and refunds US and Ireland
Resend Sends our emails EU (Ireland)
Google (Places) Address search when organisers enter a venue or organisation address (receives what they type) US
postcodes.io Turns venue and organisation postcodes into map coordinates UK

9.2 Stripe is also a separate controller for some purposes, such as preventing fraud and meeting its own legal obligations, and for the identity details it collects from organisations that connect their own Stripe account (3.4). See Stripe's privacy policy.

9.3 International transfers. Data held in the EU (Ireland) is covered by the UK's adequacy regulations for the EU. For transfers to the US (Stripe and Google), we rely on the UK Extension to the EU-US Data Privacy Framework, under which both are certified.

9.4 We'll update this list before adding a provider that handles your personal data.

10. How long we keep your data

Data How long
Your account and profile Until you ask us to delete your account (section 11)
Bookings, payments, refunds and payouts At least 6 years after the end of the financial year they relate to, as the law requires. If your account is erased, they're kept without your name.
Check-ins, and whether a certificate was issued With the booking record, as above
Certificate files Until your account is erased
Accessibility and dietary notes 30 days after the event's last day
Registration answers Until your account is erased
Waitlist entries and invitations Until your account is erased
Feedback Comments until your account is erased; star ratings are kept without your identity for the event's statistics
Speakers' files Until the speaker or organiser removes them
Records of emails sent While your account exists; if it's erased, your address is removed
Security logs and records of who did what As long as needed to keep the platform secure and resolve disputes. They contain no free text about you.
Your messages to us Up to 2 years after the matter is closed
Records of name labels printed With the event's records

Copies an organiser has taken off Sympozium are the organiser's responsibility (section 2).

11. Your rights, and deleting your account

11.1 You have the right to:

  • access: get a copy of your personal data;

  • rectification: correct it (you can change most details yourself under My account);

  • erasure: have it deleted;

  • restriction: limit how we use it;

  • objection: object to our using it on the basis of legitimate interests;

  • portability: receive data you gave us in a reusable format;

  • withdraw consent: where we rely on consent, at any time.

11.2 Email admin@sympozium.co.uk from the address on your account. We'll reply within one month. If we need more time, we'll tell you why. We may need to confirm your identity.

11.3 Deleting your account. Self-service deletion isn't available yet, so email us (11.2) and we'll do it for you.

  • We remove what identifies you: name, email, phone, job, workplace, photo, the details on your bookings, your registration answers and your feedback comments.

  • We delete your certificate files, so download any you want to keep first.

  • We keep the financial record of each purchase and whether you attended, without your name, because the law requires it. Star ratings are also kept without your identity.

  • You can't delete your account while you hold a place at an event that hasn't finished, while a refund or payment dispute is open, or while you're the only director of an organisation. We'll tell you what needs to be sorted out first.

  • Stripe keeps its own payment records under its own policy.

  • Copies an organiser has already taken off Sympozium are the organiser's responsibility.

12. Complaints

12.1 If you're unhappy with how we've handled your personal data, email admin@sympozium.co.uk with "Data protection complaint" in the subject line. We'll acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay.

12.2 You can also complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113.

13. Cookies

13.1 We use only what's strictly necessary, so we don't ask for cookie consent:

  • a sign-in cookie that keeps you signed in (it lasts up to 400 days unless you sign out) and a short-lived cookie used when you confirm your email or reset your password; and

  • on the check-in desk only, temporary storage in your browser that's cleared when you close the tab.

We don't use advertising or analytics cookies or any third-party tracking. Our fonts are served from our own site.

13.2 When you pay, you're taken to Stripe's secure payment page, which uses its own cookies under Stripe's policy.

13.3 If we add any other cookies, we'll update this section first and ask for your consent where the law requires it.

14. Security

14.1 We protect your data by:

  • limiting what each person can see to what their role needs, enforced in the database itself;

  • keeping files private and opening them only through links that expire after a few minutes;

  • encrypting data in transit;

  • recording who does what; and

  • requiring our administrators to use two-factor authentication.

14.2 No system is perfectly secure. If a breach puts your rights at risk, we'll tell you and the ICO as the law requires.

15. Children

15.1 Sympozium is for adults. You must be 18 or over to create an account.

16. Changes to this policy

16.1 We'll update this policy when our processing changes, and show the version and date at the top. We'll email account holders about significant changes before they take effect.