We use cookies to enhance your experience and analyze site traffic. By accepting, you consent to our use of analytics cookies. Learn more about our cookie policy

    Skip to main content

    Privacy Policy

    Last updated: 28 February 2026

    1. Data Controller

    TRM Flex Ltd ("we", "us", "our") is the data controller responsible for your personal data.

    • Business Name: TRM Flex Ltd
    • Contact Email: hello@trmflex.com
    • Jurisdiction: United Kingdom

    2. About TRM FLEX

    TRM FLEX is an integrated event operations platform. The platform provides event management tools, a workforce marketplace, supplier coordination, ticketing, email communications, financial controls, and AI-assisted workflows. Within the workforce marketplace, TRM FLEX does not employ workers, does not process payroll, does not collect National Insurance numbers, and does not deduct tax. Workers using our marketplace are responsible for their own tax affairs.

    3. Information We Collect

    Worker Data

    • Full name and contact details (email, phone number)
    • Profile photograph (for identity verification)
    • Date of birth (partial display only for verification purposes)
    • Right-to-work documentation
    • Bank details (for payment purposes only, encrypted at rest)
    • Attendance timestamps and location data during shifts
    • Availability and work preferences
    • CVs and certifications submitted for AI-assisted parsing

    Client Data

    • Company name and business details
    • Contact name and email address
    • Phone number
    • Billing information and address
    • Shift booking history
    • Event details (names, dates, locations, attendee information)
    • Email campaign content and recipient lists
    • Documents submitted for AI-assisted processing

    Supplier Data

    • Company name and contact details
    • Service categories and capability descriptions
    • Compliance documentation (insurance, health & safety policies)
    • Booking and payment history

    Guest & Ticketing Data

    • Guest names and contact details (collected on behalf of event clients)
    • Ticket purchase and check-in records
    • Feedback responses

    4. Lawful Basis for Processing

    We process your personal data under the following lawful bases:

    • Contract: Processing necessary to perform our services and fulfil our contractual obligations to you
    • Legitimate Interest: Processing necessary for our legitimate business interests, such as improving our services, fraud prevention, and platform security
    • Legal Obligation: Processing necessary to comply with legal requirements, including right-to-work verification
    • Consent: Where you have given specific consent, such as for analytics cookies or marketing communications

    5. How We Use Your Data

    • Facilitating connections between workers and clients
    • Verifying identity and right-to-work status
    • Processing payments to workers and from clients
    • Managing event operations and workflows
    • Processing supplier bookings and payments
    • Facilitating ticket sales and guest management
    • Sending transactional communications (shift confirmations, reminders)
    • AI-assisted document classification, brief parsing, and workflow automation
    • Maintaining platform security and preventing fraud
    • Improving our services and user experience
    • Complying with legal and regulatory requirements

    6. AI Data Processing

    Certain platform features use artificial intelligence to process data you provide, including:

    • Document triage (classifying uploaded identification and compliance documents)
    • CV parsing (extracting skills, experience, and availability)
    • Brief parsing (converting natural-language event briefs into structured data)
    • Proposal generation (creating draft proposals from lead information)

    AI processing is performed using third-party AI model providers. Data sent for AI processing is used solely for the requested task and is not used to train AI models. AI outputs are advisory and subject to human review. For full details of how AI is governed, including UK legal references, automated decision-making safeguards, and your data subject rights, please refer to our AI Policy.

    7. Third-Party Services

    We share data with the following categories of third-party service providers:

    • Payment processing: PCI-DSS compliant payment provider for secure transactions
    • Email delivery: Transactional and marketing email infrastructure
    • Cloud infrastructure: Database, authentication, and hosting services
    • AI model providers: For AI-assisted document and workflow processing

    These providers process data on our behalf and are contractually bound to protect your information.

    8. Data Retention

    • Active accounts: Data retained while your account remains active
    • Subscription cancellation: Data retained until the end of your paid billing period; account reverts to limited state thereafter
    • Lapsed payment: Data preserved for 28 days after payment failure; permanently deleted if payment is not restored (see Client Terms, Section 21)
    • Account deletion request: 30-day recovery window during which data is retained but not processed; permanent deletion after 30 days (see Client Terms, Section 22)
    • Closed accounts: Core records retained for 6 years for legal and accounting purposes
    • Right-to-work documents: Retained for 2 years after the end of engagement
    • Financial records: Invoices, transaction logs, and tax records retained for 6 years as required by HMRC, in anonymised form where the account has been deleted
    • AI processing logs: Retained for 12 months for audit and improvement purposes

    9. Data Security

    We implement appropriate technical and organisational measures to protect your personal data, including encryption of sensitive data at rest and in transit, access controls, and regular security reviews.

    10. Your Rights

    Under UK GDPR, you have the following rights:

    • Access: Request a copy of your personal data
    • Rectification: Request correction of inaccurate data
    • Erasure: Request deletion of your data (subject to legal retention requirements)
    • Portability: Request transfer of your data in a machine-readable format
    • Objection: Object to processing based on legitimate interests
    • Restriction: Request limitation of processing in certain circumstances

    Submit a Data Subject Request

    To exercise any of the above rights, email us with your request. We will respond within 30 days.

    Email Data Request

    11. Complaints

    If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

    12. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through the platform.