MARTYN'S LAW COMMENCES SPRING 2027 ·

Bloop

ZONE: THE DILIGENCE

The answers, published rather than promised.

Most vendors say 'ask us for the security overview'. This is it, in public. If your procurement process needs it as a PDF with your company name on the request, there is a form at the bottom.

Who is the controller, and who is the processor?

For this website, Templar Works Ltd is the controller. Inside the product, the event organiser is the controller for the people on their events (crew, suppliers, artists, guests) and Templar Works Ltd is their processor, acting on their instructions under a data processing agreement available on request.

Where does the data live?

The application and database are hosted in the UK/EU region configured for the deployment [ASH: confirm the production region]. Object storage for documents and photographs defaults to eu-west-2 (London). Analytics is PostHog EU. The full sub-processor list, with what each one receives, is on the privacy page.

How is access controlled?

Every record is scoped to an organisation, and every endpoint checks membership and role before returning anything: deny by default rather than filter afterwards. Portals for suppliers and individuals are separate session types bound to a single allocation or person, so a supplier login cannot reach the event team's data.

What is logged?

Every create, update and delete of significant data writes an audit entry: who did it, what changed, before and after, and when. The actor is typed (staff user, supplier, individual, system) so the trail is forensic rather than approximate. Secrets are redacted from audit payloads.

How are credentials and tokens handled?

Session cookies are httpOnly, sameSite lax, and secure behind the proxy. Scanner device API keys are stored only as hashes and are rotatable. Third-party OAuth tokens (Xero) are stored encrypted, never in plain text.

What about special category data?

Some events require health and safety induction records, dietary requirements or DBS status. These are held because the organiser needs them to run the event safely, are scoped like everything else, and are covered by the retention schedule the organiser sets.

What happens to data after an event?

The organiser's retention schedule decides. Bloop ships with GDPR-sensible defaults which the organiser can adjust, and deletion actually deletes rather than hiding a row.

Do you send marketing to people on our events?

No. People accredited through Bloop receive transactional messages about the event they are working on and nothing else. Any SMS can be stopped by replying STOP, which suppresses that number permanently and globally.

Full detail, including the sub-processor table and your rights, is on the privacy page. A DPA and our record of processing activities are available on request.

Need it as a document?

Tell us where to send it and we will reply with the security overview and DPA as attachments, from a human, usually the same day.

WE'LL EMAIL YOU THE ASSET AND NOTHING ELSE UNLESS YOU ASK