Privacy Policy
This policy explains how we collect, use, and protect your personal data when you use Build My Event, and your rights under UK data protection law.
Last updated: 26 August 2026 · Version 2026-08-26
1. Data controller
Build My Event is operated by Division 1 Systems Ltd (registered in England and Wales, company number 17300786), which is the data controller for the personal data described in this policy. Our registered office is 128 City Road, London, EC1V 2NX.
For any privacy question or to exercise your rights, contact us at support@buildmyevent.co.uk.
2. Personal data we collect
- Account details: name and email address. Sign-in is handled by WorkOS, so any password you set is held by WorkOS and never by us.
- Where you created your account from a page that showed our sign-up notice, a record of that acceptance — the date and time, and the versions of our terms and Acceptable Use Policy that were current.
- Business information: for suppliers, company name, company registration number, service details, pricing, availability, and profile content.
- Event information: details you enter about events, proposals, contracts, and messages.
- Payment and payout data: the information needed to process payments through Stripe, including the payout details you give directly to Stripe. We do not store full card numbers or your bank account details.
- Identity and business verification data: documents you submit to Stripe for identity verification, the outcome of company checks against the Companies House register, and any qualification, licence, or insurance documents you upload to us.
- Financial account records: payments, refunds, fees, and — where a refund leaves a supplier owing money back — the outstanding amount and the steps taken to recover it.
- Communications: messages and enquiries sent through the platform, and the emails we send you, including whether delivery succeeded or failed.
- Usage data: how you interact with the service, device and log information, and IP address.
- Referral link clicks: if you arrive through a Growth Partner invite link we record the click, with your IP address and browser details stored only as a one-way scrambled value we use to spot duplicate and abusive clicks, not to identify you.
3. Legal basis for processing
We rely on the following legal bases under UK GDPR:
- Contract: to provide the service, manage your account, and process bookings and payments.
- Legitimate interests: to secure and improve the platform, verify that suppliers are who they say they are, prevent fraud, recover money owed to us, and communicate about your account, balanced against your rights.
- Legal obligation: to keep financial records and comply with tax and accounting requirements. Our payment provider also carries out identity and anti-money-laundering checks required of it by law.
- Consent: for any optional communications or non-essential cookies, which you can withdraw at any time.
4. People who contact suppliers without an account
You can contact a supplier through Build My Event without creating an account, and suppliers can add contact details for people who have enquired with them directly. This section explains how we handle that data.
Enquiry contacts. When you use a supplier's public enquiry form, we collect your name, email address, and the message you write, along with any optional event details you choose to add (such as event type, location, date, and guest numbers).
Supplier-imported leads. A supplier may import contact details for people who have enquired with them outside the platform. This can include a name, email address, and phone number.
Lawful basis. We rely on the legitimate interests of the supplier and of the platform to receive, route, and respond to your enquiry, and to summarise it automatically so the supplier can reply quickly. We balance this against your rights and only use the data for that purpose.
How long we keep it. We do not delete these on a fixed timetable. An enquiry you send is deleted when the supplier who received it closes their account, and a lead a supplier imported is anonymised when that supplier closes their account. Until then it is kept as part of that supplier's business record.
Your rights if you do not have an account. Because you have no account or self-serve settings to manage this data, you can ask us to give you access to it or to erase it by emailing support@buildmyevent.co.uk. We will verify your request and respond within the timescales set out below.
5. AI assistance and free text
Free text you enter — for example an enquiry message or event details — may be processed by our AI assistant (AWS Bedrock, in a UK/EU region) to summarise it or to help draft a response. Please do not include sensitive or special-category details that you do not need to share.
These features are optional and are not always switched on: they depend on the feature being enabled on the platform and on the supplier's plan. Where they are off, nothing you write is sent to the AI assistant at all.
6. Payments, identity, and business verification
Stripe and Stripe Connect. Payments are processed by Stripe. To receive money, a supplier onboards to Stripe Connect and gives Stripe the details it needs to open a connected account — typically name, date of birth, address, company details, and bank account details. Stripe runs its own identity, anti-money-laundering, and sanctions checks on that information as it is required to do by law, and acts as an independent controller for those checks. We receive the account identifier and the outcome (verified, or what is still outstanding); we do not receive or store the underlying documents or the bank details.
Identity verification. Where an individual identity check is needed, we start a Stripe Identity session. The identity document and any selfie are submitted directly to Stripe. We store the result of the check and when it was carried out, not the document itself.
Documents you upload to us. Suppliers can upload evidence of qualifications, licences, and insurance to be shown as verified on their profile. Those files are stored by us on our own infrastructure and reviewed before a verification is approved. We rely on our legitimate interest in marketplace trust and safety, and on the supplier agreement with us.
Companies House. Where a supplier gives a company registration number, we look that number up in the public Companies House register to check the company exists, is active, and that its registered name matches the business name on the profile. We send the company number to the Companies House Public Data API and store what comes back — the registered company name, status, and whether the name matched. Where the check passes, a factual note to that effect can appear on contracts the supplier issues. Companies House maintains that register as a public body and is the controller of it. We rely on our legitimate interest in preventing fraud and giving organisers accurate information about who they are contracting with.
7. Automated decisions
Some steps on the platform happen automatically, without a person reviewing them first:
- Cancellation refunds are calculated by a fixed rule from the date of cancellation, the event date, and who cancelled. The rule that applies to a booking is written onto the contract when it is issued and is set out in our Terms of Service.
- Recovery steps after a refund. Where a refund leaves a supplier owing money back to us, our system automatically pauses bank payouts once the balance has been outstanding for a short period, and later removes the supplier's public profile from the marketplace and stops new enquiries and proposals. The triggers are how long the balance has been outstanding and how many times it has happened in the last 90 days. These steps affect a supplier's ability to win new work. They reverse automatically as soon as the balance is cleared.
- Business verification against Companies House. Where a supplier gives a company registration number, we check it against the public register automatically. If the company is on the register, is active, and its registered name matches the name on the profile exactly, we grant the business verification automatically and adopt the register's version of the company name and number onto the profile. A close but inexact name match is not granted automatically — it is held for a person to confirm. If the company is not found, is not active, or the name does not match, no verification is granted; the supplier's other routes to verification are unaffected.
- Withdrawing a Companies House verification. We re-check verified companies against the register on a schedule. Where a company is no longer on the register, or is no longer active, the verification is withdrawn automatically: the badge stops showing, the record is put into our review queue for a person to look at, and we tell the supplier once — in their account, and by email unless they have turned verification emails off. No automatic payment, payout, or booking action follows from this check. Where a company is still active but has been renamed on the register, we update the name and number we hold to match it.
- Identity verification through Stripe. Where a supplier verifies their identity using Stripe Identity, Stripe runs the checks and we record the outcome automatically, without a person reviewing it: a verified result approves the supplier's identity verification, and a result that Stripe returns as needing further input is recorded as not approved. The outcome replaces whatever identity verification we previously held for that supplier, and we tell them the result in their account, and by email unless they have turned verification emails off.
- Enquiry triage. Enquiries may be summarised and labelled automatically to help a supplier prioritise. A person — the supplier — decides how to respond.
If an automated step has been applied to you and you think it is wrong, email support@buildmyevent.co.uk. A person will look at it, and you can give us your side of it. This is handled by email rather than through a form in the product.
8. Third-party processors and other recipients
We share data with service providers who process it on our behalf:
- Amazon Web Services (AWS): cloud hosting, database, and file storage for the platform. Our primary infrastructure is hosted in the UK (London region). AI assistance runs on AWS Bedrock, which we call in the London region, but the model profile we use may serve the request from another AWS region in the UK or EU. The AI features are supplier-facing: summarising an enquiry, and helping a supplier draft a proposal, a listing, or a reply.
- WorkOS: authentication and sign-in (name, email address, and login credentials).
- Stripe: payment processing, Stripe Connect onboarding, payouts, and identity verification (payment, payout, and verification data). For the checks Stripe is legally required to run, it acts as an independent controller — see section 6.
- Resend: delivery of transactional email (name and email address, and delivery outcome).
- Mapbox: geocoding and distance calculation for supplier matching (location and postcode data).
- Postcodes.io: looking up UK postcodes and coordinates to work out travel distance and whether a booking is feasible (postcode and location data only).
- Sentry: error monitoring and diagnostics (technical log data, which may include limited identifiers such as an IP address).
Each processor is bound by a data processing agreement and may only use the data to provide their service to us.
Other recipients. We send a supplier's company registration number to Companies House to check it against the public register (see section 6). Companies House is a public body and is not acting as our processor. We may also share data with our professional advisers, or with a regulator, law-enforcement body, or court where we are required or permitted to do so by law.
We do not use third-party advertising networks, ad trackers, or third-party analytics products on the platform, and we do not sell personal data.
For the current list of sub-processors, their purpose, and where they process data, see our Sub-processors page.
9. International transfers
Our core platform data is hosted in the UK. Some processors (such as AWS, Stripe, Resend, WorkOS, Mapbox, and Sentry) are based outside the UK and may process data internationally — AI assistance runs on Amazon Bedrock through a cross-region inference profile, so a request may be served from another AWS region in the UK or EU. Where they do, we rely on appropriate safeguards such as UK adequacy regulations or standard contractual clauses incorporated into the provider's data processing agreement.
10. How long we keep data
- Active accounts: for as long as your account remains open.
- Closed accounts: when you ask us to delete your account we anonymise your personal data straight away, as part of processing the request — not on a later timetable.
- Financial records, including payments, refunds, fees, and any amount owed to us after a refund: kept for at least 7 years to meet HMRC requirements. These survive account closure, with personal details removed from them where we can.
- Your record at Stripe, our payment provider: Stripe keeps its own record of payments you made or received, which we cannot delete without breaking the financial records above. When you close your account we clear your name and address from that record. If you still owe money on a booking, we keep the email address needed to send you that invoice until it is settled, and clear it afterwards.
- Verification records: kept so we can show why a supplier was marked as verified at the time. The documents you uploaded to support a verification are deleted 30 days after we have reviewed them; only the decision and its date are kept.
- Security and administrative logs: deleted after 2 years.
- The record that you accepted our terms, and which version: kept for as long as your account exists and afterwards for as long as we may need it to establish, exercise, or defend a legal claim.
11. Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, subject to our legal retention duties;
- receive your data in a portable, machine-readable format;
- object to or restrict certain processing;
- ask for a person to review an automated step, as described in section 7.
You can exercise two of these yourself, straight away and without asking us. Your account and data settings will download a copy of everything we hold about you, or close your account and erase it. The same two controls sit in the Security tab of your account settings.
For any other right — or if you would rather we did it — email support@buildmyevent.co.uk. We aim to respond within 30 days.
12. Cookies
We use essential cookies to keep you signed in and to keep the service secure, and one functional cookie to credit a Growth Partner referral if you arrive through an invite link. For details, see our Cookie Policy.
13. Complaints
If you have a concern about how we handle your data, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO) at https://ico.org.uk.