Data protection policy

Our approach to protecting personal data under the UK GDPR and the Data Protection Act 2018.

Last updated 2 October 2026

Our commitment

Pixel Takeaway Limited aims to handle personal data lawfully, fairly and transparently under the UK GDPR and Data Protection Act 2018. This policy describes our approach. Our privacy notice explains what happens to your information in more detail; a published policy is not a certification of compliance.

Scope and responsibility

This policy covers personal data we handle through LearnersBench, our website and related communications. Event organisers usually decide the purposes of processing their delegates' data, and we provide the service on their behalf. We make our own decisions about data used to operate and secure our service. Responsibilities for each event depend on the arrangement with its organiser.

We limit staff access by role and organisation. Management is responsible for reviewing privacy risks, access and incidents. Staff and contractors with access to personal data should receive appropriate instructions and training.

Lawful bases

Where we act as controller, our purposes and lawful bases include providing requested services under a contract, meeting financial or other legal obligations, and pursuing legitimate interests in service operation and security. Organisers determine and explain their own bases for administering events. We do not assume that a contract with an organiser is automatically the lawful basis for processing every delegate's data.

For health, disability, religious or other special category information, an additional UK GDPR Article 9 condition is required, as well as an Article 6 lawful basis. The event organiser must establish the relevant condition and explain it to delegates. Marketing choices and non-essential measurement tools require the relevant consent; withdrawal does not affect essential booking messages.

Data minimisation

We ask for the details needed to provide the service. Organisers can add registration questions and must consider whether each question is necessary, particularly where answers could reveal sensitive information. Delegate networking is optional and limited to eligible participants who have chosen to share.

Dietary and accessibility details are used for event arrangements and available to those making them. They are not automatically deleted when an event ends; they may remain with event records until an approved erasure request or an administrator applies the retention process described in our privacy notice.

Retention

Retention depends on the event, legal requirements and the type of record. Administrators can anonymise delegate records for events older than a selected six-month to ten-year period; this does not happen automatically. Non-identifying totals and necessary financial records can remain. The privacy notice explains other records without a fixed automatic deletion date. We should review retention arrangements with organisers and securely remove data when it is no longer needed.

Withdrawing marketing consent stops future marketing use; a minimal record of the choice may be kept to avoid contacting the person again.

Sub-processors and transfers

We use hosting, identity, email, payment and other providers, as well as optional organiser-connected services. The privacy notice names the services that may receive information. We do not promise that all data is stored or accessed only in the UK or EEA.

Where we act as processor, arrangements with organisers and any relevant sub-processors should meet UK GDPR Article 28 requirements. For restricted international transfers, an applicable adequacy regulation or valid safeguards such as the UK International Data Transfer Agreement or UK Addendum and any required risk assessment should be in place. Ask us about the safeguards relevant to your event.

Individual rights

Depending on the circumstances, individuals may ask to access, correct, erase, restrict or transfer their data, object to certain processing or withdraw consent. We may verify identity and work with the event organiser where it controls the data. Rights have legal conditions and exceptions; we normally respond within one calendar month and explain any permitted extension within that time.

Write to team@learnersbench.com or contact the organiser. You may complain to the Information Commissioner's Office at ico.org.uk or 0303 123 1113.

Security

The service uses encrypted connections, role-based access, organisation separation, staff two-step sign-in checks and activity records for significant actions. These technical measures support information security, but do not amount to ISO 27001 certification or a complete information security management system on their own.

Suspected personal data breaches should be investigated and documented. Where we are the controller and a breach is likely to result in a risk to people's rights and freedoms, we must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. If the risk is high, we must also notify affected people without undue delay. Where we act as processor, we must tell the organiser without undue delay so it can fulfil its obligations.

Data protection by design

New or changed uses of personal data should be reviewed for necessity, access and privacy risks before release. A data protection impact assessment is required where processing is likely to result in a high risk to people's rights and freedoms. This policy does not replace an assessment or the organisational records and agreements required by law.

Company details

Pixel Takeaway Limited, registered company number 08705786, registered address 1 Canada Sq 37th Floor, Canary Wharf, London, E14 5AA, UK. Contact team@learnersbench.com with any question about this policy.