Before launch: this page describes how Lanyard behaves, in plain English. The binding terms of service, privacy notice and data processing agreement are being drafted with a solicitor and will replace it. Nothing here is legal advice or a contract.

The contact licence, and who can see what.

What an exhibitor agrees to

Before their first scan, every exhibitor at an event accepts that event organiser’s contact licence. The organiser writes it. Ours is the default and is deliberately strict:

  • One introduction email
  • One follow-up
  • One phone call
  • Never added to a mailing list, and never passed on to anyone else

Access to the leads ends on a date the organiser sets — thirty days after the event by default. After that the exhibitor cannot open the list at all.

The licence binds the exhibitor. The permission comes from the visitor, at registration. An organiser who allows more contact here than they asked for on their registration form has not made it lawful — only made it look sanctioned — so the two need to say the same thing.

Who can see a visitor’s details

The event organiser, and the exhibitors who scanned that particular visitor. Nobody else. Exhibitors cannot see each other’s leads, and no other organiser using Lanyard can see anything belonging to your event. That is enforced by the database, not by the interface.

That includes us. Our own administrative tools report account and usage figures — how many events, how many scans, what plan — and have no route to a visitor’s name, school or email address. Supporting a data problem therefore needs the organiser’s cooperation, which we think is the correct trade.

Badge codes contain no personal data at all. A badge that is photographed, posted online or left on a table exposes nothing, because there is nothing in it to expose.

Roles and where data lives

Under UK GDPR the event organiser is the data controller for their visitors. Lanyard is their processor. Exhibitors become controllers in their own right for the contacts they receive, which is why the licence exists.

Data is held in the United Kingdom. Every scan, export and change of access is written to an audit log the organiser can read. A visitor who wants their details removed should contact the event organiser, who can delete them.

Questions about any of this before you start? Ask us — it is the sort of thing we would rather get straight up front.