Controller and processor roles
Activity providers are typically the data controller for parent and child data they collect through bookings, registers and communications. Activora acts as a data processorwhen handling that data on the provider's instructions to deliver the platform.
Activora is the controller for its own account, billing, marketing and platform analytics data. See our Privacy Policy for details.
Data ownership
Providers retain ownership of their customer lists, booking records, session data and communications content. Activora does not sell provider or parent data to third parties. Export tools are available so providers can retrieve their data at any time.
Processing instructions
We process personal data only to provide, secure and improve the Activora platform — including bookings, payments, registers, messaging, reporting and support. We do not use provider customer data for unrelated marketing without consent.
Deletion and portability
Providers may export data via dashboard tools. On account closure, we delete or anonymise personal data within 90 days unless retention is required by law, ongoing disputes, or legitimate business records (such as invoicing). Parents may exercise rights directly with their provider or contact Activora for assistance.
Retention
Retention periods vary by data type. Booking and payment records may be kept for up to seven years for accounting and tax purposes. Safeguarding and attendance registers may be retained according to provider policy and legal requirements. Full details are in our Privacy Policy.
Security measures
We implement encryption in transit and at rest, role-based access controls, audit logging, regular backups and infrastructure monitoring. See Data Storage & Security for a full overview.
Sub-processors
We use trusted sub-processors to deliver the platform, including:
- Cloud hosting and database (EU/UK regions where available)
- Stripe — card payment processing
- GoCardless — Direct Debit collections
- Email and notification delivery providers
We maintain agreements requiring sub-processors to meet GDPR-equivalent standards. Material changes to sub-processors will be notified to providers.
Request a signed DPA
Enterprise and franchisor customers may request a countersigned DPA. Contact us with your organisation details and we will arrange this.
