PRIVACY POLICY
1. WHO WE ARE
Accolade is the trading name under which the platform at accolade.live is operated. Our registered address is available on request by emailing hello@accolade.live.
We are the data controller for personal data collected through our website and platform. Our Data Protection Lead can be contacted at privacy@accolade.live. That is the single contact point for every data protection question, request or complaint.
2. WHAT DATA WE COLLECT
Account Data
When you create an account or request a demo, we collect your name, email address, organisation name, and any other information you provide during signup.
Usage Data
We automatically collect information about how you use the platform, including pages visited, features used, session duration, browser type, device type, and IP address.
Event Data
Data you enter into the platform about your events, including nominee information, guest lists, judge details, sponsor details, and ceremony schedules. This data is controlled by your organisation and we process it on your behalf.
Payment Data
Payment processing is handled by Stripe. We do not store credit card numbers. We retain your billing email, plan type, and transaction history.
3. HOW WE USE YOUR DATA
We use your data to:
- Provide and maintain the Accolade platform
- Process your account registration and demo requests
- Send you service-related communications (account alerts, security notices, system updates)
- Respond to your support requests
- Improve the platform based on usage patterns
- Comply with legal obligations
We will not sell your data to third parties. We do not use your event data for advertising.
4. LAWFUL BASIS FOR PROCESSING
We process personal data under the following lawful bases under UK GDPR:
- Contract: Processing necessary to provide the platform services you signed up for
- Legitimate interest: Fraud prevention and platform security
- Consent: Marketing communications (you can withdraw consent at any time)
- Legal obligation: Tax records, regulatory compliance
5. DATA SHARING
We share data only with:
- Stripe: Payment processing
- Our hosting and database providers: Server infrastructure and managed database. See the sub-processor table on our GDPR page for who they are and where they process.
- Our email provider: Transactional emails
All third-party processors are bound by data processing agreements. Hosting and the database are within the European Economic Area. Not every sub-processor is: payments are processed by Stripe in the United States under the UK Addendum to the EU Standard Contractual Clauses. The sub-processor table on our GDPR page lists every third party that touches your data and where each one processes it, and it is the authoritative list.
6. DATA RETENTION
Active account data is retained for the duration of your subscription. After cancellation, your data is retained for 90 days to allow export, then permanently deleted from primary databases. Financial records are retained for 7 years as required by UK law.
Backups are encrypted and taken daily. They expire automatically on a rolling window set by our database provider, which means a record deleted from the live platform remains inside unexpired backups until the last backup containing it rolls off. Backups are never used to restore deleted customer records to the live platform. We are confirming the exact retention window with the provider and will publish it here once it is confirmed.
7. YOUR RIGHTS
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate data
- Erase your data (right to be forgotten)
- Restrict or object to processing
- Data portability (receive your data in a structured format)
- Withdraw consent at any time
- Lodge a complaint with the ICO (Information Commissioner's Office)
To exercise any of these rights, email privacy@accolade.live. We will respond within one month, as required by UK GDPR Art.12(3).
8. COOKIES
We use essential cookies to keep you logged in and maintain your session. We do not currently set any analytics or advertising cookies on our public pages. See our Cookie Policy for the full list and for what will change if we switch analytics on.
9. SECURITY
We protect your data with encryption at rest and in transit (TLS 1.2 or higher), secure session management, access controls, and regular security reviews. The application runs on Render, in Render’s Frankfurt region. The database is Aiven managed MySQL, reached over TLS. Both are within the European Economic Area. Our Security page sets out the controls in full, including what we do not yet have.
10. CHILDREN
Accolade is not intended for use by anyone under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
11. CHANGES TO THIS POLICY
We may update this policy from time to time. Material changes will be communicated via email. The "last updated" date at the top always reflects the current version.
12. CONTACT
For any privacy-related question, request or complaint, contact our Data Protection Lead at privacy@accolade.live. You also have the right to complain directly to the ICO at ico.org.uk.