Security Annex — BookYourWebinar.com
Date: 28th March 2026
This Security Annex describes the technical and organisational measures implemented by BookYourWebinar.com and its sub-processors (including 123 Reg) to protect Personal Data processed through the platform. It is provided for transparency and to support GDPR/UK GDPR compliance.
- Data Encryption
- In transit: All Personal Data transmitted between users and BookYourWebinar.com is encrypted using industry-standard TLS/HTTPS.
- At rest: Personal Data stored on our servers is not encrypted at rest. Access is restricted via authentication and role-based access controls.
- Access Control and Authentication
- Access to Personal Data is restricted to authorised personnel on a need-to-know basis.
- Accounts are protected with secure authentication measures, including strong passwords and optional multi-factor authentication for administrative accounts.
- Access rights are regularly reviewed and revoked when no longer needed.
- Backups and Disaster Recovery
- Regular backups of Personal Data are performed to ensure data availability and continuity.
- Disaster recovery procedures exist to restore service in the event of system failure or outage.
- Backup data is stored securely and retained in accordance with legal and operational requirements.
- Monitoring, Logging, and Incident Response
- Logs are maintained to track access, changes, and system events relevant to Personal Data.
- Monitoring systems and intrusion detection tools are used to identify security threats.
- Security incidents affecting Personal Data are managed according to established procedures. Incidents are detected, investigated, contained, and remediated, and affected parties are notified when required under applicable law.
- Sub-Processor — 123 Reg
- Service Provided: Hosting and storage of platform and customer data.
- Location: United Kingdom
- Security Measures: 123 Reg maintains security policies, technical safeguards, monitoring, and incident response procedures aligned with industry best practices.
- Reference / Privacy Info:
- 123 Reg Privacy Policy
- 123 Reg Data Processing Addendum
- 123 Reg Hosting Security Features
- International Data Transfers
- Certain sub-processors, including Stripe, PayPal, Vimeo, and YouTube, may transfer Personal Data to the United States.
- All transfers are conducted under GDPR/UK GDPR-compliant safeguards, such as Standard Contractual Clauses (SCCs), to ensure an adequate level of protection.
- Copies of relevant agreements are available to Controllers upon request.
- Data Return or Deletion
- Upon termination of Services, or upon request from the Controller, Personal Data will be either:
- Securely returned to the Controller, or
- Permanently deleted, except where retention is required by law (e.g., tax, accounting, or legal obligations).
- Procedures are in place to ensure these actions are performed securely and can be demonstrated to Controllers upon request.
- General Security Practices
- Security policies and procedures are reviewed and updated regularly.
- Personnel are trained in data protection and security best practices.
- All measures are designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
- Role-Based Access Control (RBAC)
Access to Personal Data is managed through role-based access controls (RBAC), ensuring that users can only access information necessary for their role. This includes different access levels for administrators, instructors, and users, with permissions aligned to business needs and regularly reviewed.
- Vulnerability Management and Testing
Regular vulnerability assessments and security testing are performed to identify and mitigate potential risks. Findings are addressed according to risk level, and testing is repeated periodically to ensure ongoing protection of Personal Data.
- System log
System logs are maintained to monitor access and changes to Personal Data, supporting detection of anomalies and investigation of potential security incidents.
- Data Minimization & Retention
We only collect Personal Data necessary for specified purposes and retain it only for as long as needed. Data is deleted automatically or securely at the end of the retention period, unless legal obligations require longer storage.
- Data Subject Rights (DSARs) Access requests
We respect data subject rights under GDPR/UK GDPR. Requests for access, correction, or deletion of personal data will be responded to promptly, typically within 30 days.
- Right to erasure (“right to be forgotten”)
Users have the right to request erasure of their personal data. Requests will be honored promptly unless legal obligations require retention of certain data.
- Rectification and restriction of processing
Users have the right to request correction of inaccurate data (rectification) or to restrict the processing of their personal data. Requests will be handled promptly in accordance with GDPR/UK GDPR.
- Data Portability
Users have the right to receive their personal data in a structured, commonly used, and machine-readable format. Upon request, we will provide the data securely to the user or, where technically feasible, directly to another data controller.
- Data Breach Notification
In the event of a personal data breach, BookYourWebinar.com has a documented process to detect, investigate, and remediate incidents. Where required by law, authorities and affected individuals will be notified promptly, typically within 72 hours of becoming aware of the breach.
- Privacy by Design & Default
Privacy considerations are incorporated into the design and operation of BookYourWebinar.com. Measures such as minimizing data collection, applying defensive defaults, and embedding security controls help ensure Personal Data is protected throughout its lifecycle.
- Training & Accountability
All personnel with access to Personal Data receive regular training on data protection, security, and GDPR/UK GDPR requirements. Responsibilities for data protection are clearly defined, and compliance is monitored through internal reviews and audits.
This Security Annex is part of the BookYourWebinar.com Data Processing Agreement and Terms & Conditions.