GDPR & DATA PROCESSING
OUR COMMITMENT
Accolade is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We act as a data processor on behalf of our clients (data controllers) when handling attendee, nominee, and guest data within the platform. Where we process data about our own customers — account holders, billing contacts — we are the controller, and our Privacy Policy covers that.
DATA PROCESSING AGREEMENT
All Accolade customers on paid plans are covered by our standard Data Processing Agreement (DPA). The DPA sets out the terms under which we process personal data on your behalf, including the types of data processed, the purposes of processing, security measures, sub-processor obligations, and data subject rights.
To request a signed copy of our DPA, email privacy@accolade.live with your organisation name and account email.
DATA WE PROCESS
| Category | Examples | Lawful basis |
|---|---|---|
| Attendee data | Name, email, dietary requirements, accessibility needs | Contractual necessity |
| Nominee data | Name, biography, category, supporting materials | Contractual necessity |
| Judge data | Name, email, scoring records, conflict declarations | Contractual necessity |
| Sponsor data | Company name, contact details, contract terms | Legitimate interest |
SUB-PROCESSORS
| Provider | Purpose | Processing location |
|---|---|---|
| Render | Application hosting | European Union — Frankfurt region, per our service configuration |
| Aiven | Managed MySQL database and storage | European Economic Area — exact region being confirmed with the provider |
| Stripe | Payment processing | United States, under the UK Addendum to the EU Standard Contractual Clauses |
| Our SMTP email provider | Transactional email delivery | Being confirmed |
We will give notice of any new sub-processor before it begins processing customer personal data, so that you have the opportunity to object.
SECURITY MEASURES
AES-256 encryption at rest. TLS 1.2 or higher for all data in transit. Role-based access controls. Passwords hashed with bcrypt. The application runs on Render, in Render’s Frankfurt region. The database is Aiven managed MySQL, reached over TLS. Both are within the European Economic Area.
Our Security & Compliance page lists the controls in full, including our certification status and the controls we do not yet have.
DATA SUBJECT RIGHTS
Data subjects (attendees, nominees, guests) have the right to access, rectify, erase, restrict, and port their data. Client administrators can action these requests directly within the Accolade platform. For requests that cannot be resolved through the platform, contact our Data Protection Lead at privacy@accolade.live.
DATA RETENTION
Customer data is retained for the duration of the service agreement plus 90 days. Upon account termination, all personal data is permanently deleted from primary databases within 90 days.
Backups are encrypted and taken daily. They expire automatically on a rolling window set by our database provider, which means a record deleted from the live platform remains inside unexpired backups until the last backup containing it rolls off. Backups are never used to restore deleted customer records to the live platform. We are confirming the exact retention window with the provider and will publish it here once it is confirmed.
BREACH NOTIFICATION
In the event of a personal data breach, Accolade will notify the affected data controller without undue delay and in any event within 72 hours of becoming aware, in accordance with Article 33 of UK GDPR.
CONTACT
For GDPR queries, DPA requests, or data protection concerns, contact our Data Protection Lead at privacy@accolade.live. This is the single contact point for data protection across all six of our published documents.