Legal

Data Processing

Who processes your data, on whose instructions, and the subprocessors we rely on to run the network.

Last updated 22 July 2026

1. Controller and processor

EE Conf Limited is the data controller for personal data collected through FOCUS: it decides why and how that data is processed. The FOCUS platform and its supporting infrastructure act as a processor, handling personal data only on EE Conf Limited's documented instructions and under a data processing agreement. This page summarises how that works; the underlying agreement governs where there is any conflict.

2. What is processed and why

Personal data is processed only to deliver the FOCUS network: running collectives, handling registrations and applications, understanding the network through firmographic segmentation, keeping the platform secure, and communicating with participants. The categories of data and the lawful bases are set out in our Privacy Policy.

3. Subprocessors

We use a small set of trusted providers ("subprocessors") to run the platform. Each processes personal data only as needed to provide its service, under contractual data-protection obligations. The current subprocessors are:

  • Hosting (compute): a private server located in the United States, which runs the application and stores data.
  • Database: a LibSQL database holding member, registration, and firmographic records.
  • Email delivery: a transactional email provider used to send service and (where opted in) network messages.
  • Analytics: first-party, privacy-preserving analytics used to understand and improve the site.

Object storage sits outside that list, deliberately. Profile media and files are stored on servers in the European Union, in a cloud account held by EE Conf Limited itself. Because EE Conf Limited contracts with that provider directly, the provider is its own processor rather than a subprocessor engaged on its behalf. The content-delivery and DNS services in front of the site sit in the same account, on the same footing.

Anti-bot protection on public forms is built into the platform and uses no third-party service. We name categories of provider rather than companies here; the specific providers are identified in the underlying data processing agreement and our records of processing.

4. International transfers

Because our hosting is currently in the United States, personal data is transferred outside the UK. These transfers are protected using appropriate safeguards under UK GDPR: the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. See the Privacy Policy for detail.

5. Security measures

Both controller and processor maintain appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, anti-bot protection on public intake, and breach response. These are described in our Security page.

6. Data subject rights and deletion

The processor supports the controller in responding to your rights requests, including erasure. When you ask us to delete your account and data, deletion is completed within a 30-day window, subject to records we are legally required to keep.

7. Changes to subprocessors

If we add or change a subprocessor, we will update this page and the "last updated" date above. Questions can be sent to [email protected].