Skip to data-processing terms
CoverDockStart with CoverDock

Venue data

Data-processing terms

Last updated 5 September 2026

Roles and scope

These terms supplement the CoverDock service terms where WebConnect Media processes personal data for a customer using CoverDock. The customer is the controller and WebConnect is the processor for venue-controlled guest and operational data. Processing lasts while the service is provided and for the limited period needed for secure backup, return, deletion and legal obligations.

Processing instructions

WebConnect will process customer personal data only to provide, secure, support and maintain CoverDock, on the customer’s documented instructions, or where law requires otherwise. The service configuration, authorised support requests and service terms form part of those instructions.

People and data

Data subjects may include guests, event attendees, prospective guests, venue employees, contractors and customer contacts. Data may include identity and contact details, booking and event information, preferences and notes, communications, attendance, transaction status, device and audit information, and any special-category details a guest voluntarily includes in free text. Customers should avoid requesting or recording unnecessary sensitive information.

Security and confidentiality

WebConnect will use appropriate technical and organisational measures for the risk, including tenant access controls, signed authentication, encryption of stored provider credentials, audit attribution, database constraints, backups, controlled support access and secure development checks. Personnel with access are bound by confidentiality obligations.

Subprocessors and transfers

WebConnect may use subprocessors for infrastructure, email, payment connectivity, monitoring and support. WebConnect remains responsible for imposing appropriate data-protection obligations on those subprocessors. Customers will be informed of a material new subprocessor and may raise a reasonable data-protection objection. Required safeguards will be used for restricted international transfers.

Assistance and incidents

Taking account of the service and information available, WebConnect will reasonably assist with data-subject requests, security assessments, breach obligations and regulator enquiries. WebConnect will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for the customer’s response.

Return, deletion and audit

CoverDock provides eligible exports and guest anonymisation controls. At the end of the service, WebConnect will delete or return customer personal data as agreed, except where retention is legally required or temporarily unavoidable in protected backups. WebConnect will provide information reasonably necessary to demonstrate compliance and support proportionate audits subject to confidentiality, security and cost arrangements.

Customer obligations

The customer is responsible for a lawful basis, accurate instructions, transparent guest notices, appropriate staff access and its own response to guest rights. The customer must configure retention and free-text collection proportionately and tell WebConnect promptly about any instruction that creates a security or compliance concern.

Contact

Data-protection questions and requests relating to these terms can be sent to info@webconnect.media.

CoverDock homePrivacy noticeService termsCookie noticeContact WebConnect