Last updated: 29 September 2026
This policy sets out how Eventay Ltd, trading as London Conference Venue, complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025 and the Privacy and Electronic Communications Regulations (PECR). It applies to all personal information we handle about clients, event guests, venue contacts, suppliers and website visitors, and to everyone who works for us or on our behalf.
For what we collect about you and your rights, please read our Privacy Policy.
We handle personal information so that it is:
We are accountable for following these principles and keep records to show that we do.
Our Data Protection Lead oversees compliance with this policy, keeps our records of processing up to date and is the point of contact for individuals and the Information Commissioner’s Office (ICO). Contact: data.protection@eventay.co.uk, Eventay Ltd, 344-354 Grays Inn Road, London WC1X 8BP.
Everyone who handles personal information for us receives data protection training and is bound by confidentiality.
We share clients’ event requirements with venues and hotels only as needed to check availability, quote and deliver the event. Suppliers that process personal information on our behalf, such as hosting, email, CRM and booking-platform providers, do so under written contracts that meet UK GDPR Article 28. We check that they keep information secure.
We send marketing emails only with consent, or to existing business customers under the PECR “soft opt-in”, always with a simple way to unsubscribe. Before calling businesses for marketing, we screen numbers against the Corporate Telephone Preference Service (CTPS) and we honour any request not to be contacted.
We respond to requests to access, correct, delete, restrict, object to or port personal information within one month, extendable by two months for complex requests. We carry out reasonable and proportionate searches, verify identity where needed and keep a record of each request.
We use access controls, encrypted connections, secure passwords and multi-factor authentication where available, and we limit access to those who need it. Any suspected breach must be reported to the Data Protection Lead at once. We assess it and, where it is likely to result in a risk to people’s rights, report it to the ICO within 72 hours of becoming aware of it. We tell the people affected without undue delay where the risk is high. We record all breaches, whether or not they are reported.
Before starting new processing that is likely to be high risk, we carry out a Data Protection Impact Assessment. We only transfer personal information outside the UK with an appropriate safeguard, such as UK adequacy regulations, the International Data Transfer Agreement or the UK Addendum.
We have a complaints procedure for data protection concerns. We acknowledge complaints within 30 days, investigate them without undue delay and tell the person the outcome. Anyone can also complain to the ICO at ico.org.uk/make-a-complaint or on 0303 123 1113.
We review this policy at least once a year and whenever the law or our services change.
See also our Privacy Policy and Cookie Policy.