Privacy Policy

Purpose

Corvia Limited, trading as Ticketer, respects your privacy and is committed to protecting your personal data.

This privacy notice explains how we collect, use, store, share and protect personal data in connection with our website, business operations, customer and supplier relationships, and the products and services we provide.

It also explains your rights under applicable data protection laws, including the Data Protection Act 2018, the UK GDPR, the EU GDPR where applicable, and those laws as amended or supplemented from time to time, including by the Data (Use and Access) Act 2025.

References to “Ticketer”, “we”, “us” or “our” mean Corvia Limited trading as Ticketer.

Data Protection Principles

Ticketer processes personal data in accordance with the data protection principles. 

This means personal data must be: 

  • processed lawfully, fairly and transparently 
  • collected for specified, explicit and legitimate purposes 
  • adequate, relevant and limited to what is necessary 
  • accurate and kept up to date where required 
  • kept for no longer than necessary 
  • protected using appropriate technical and organisational measures 
  • handled in a way that supports accountability and good governance 

We are responsible for being able to demonstrate our compliance with these principles. 

Controller for personal data

A controller is an organisation that decides why and how personal data is processed. 

Ticketer acts as controller where we process personal data for our own business purposes. This includes personal data processed in connection with: 

  • our website 
  • enquiries and communications 
  • customer and supplier relationship management 
  • sales, marketing and events 
  • contract management 
  • finance and administration 
  • recruitment 
  • legal, regulatory, audit and compliance activities 
  • information security and service protection 
  • business improvement and reporting 

Unless we tell you otherwise, Ticketer is the controller for personal data we collect through this website and through our direct business interactions with you. 

Processor For Personal Data

Ticketer also acts as processor for some personal data we process on behalf of our customers. 

Where we act as processor, the customer is usually the controller. In those circumstances, we process personal data in accordance with the customer’s documented instructions, the relevant contract, applicable data processing terms, and data protection laws. 

Where you are an employee, contractor, passenger, driver, operational user or other individual connected to one of our customers, the relevant customer’s privacy notice may provide further information about how your personal data is used. 

Nothing in this privacy notice transfers ownership of personal data to Ticketer. Personal data is handled in accordance with data protection law, the relevant controller and processor roles, and the applicable contractual arrangements. 

Scope

This privacy notice applies to personal data processed by Ticketer in connection with: 

  • visitors to our website 
  • customers and prospective customers 
  • suppliers and service providers 
  • business contacts 
  • users of Ticketer systems, portals, platforms or services 
  • individuals who contact us or correspond with us 
  • individuals who attend Ticketer events or subscribe to Ticketer updates 
  • individuals whose personal data is processed as part of our business operations, support services, compliance activities or service delivery 

Where we process personal data on behalf of a customer, the customer is responsible for ensuring that appropriate privacy information is provided to individuals where required. 

Types of Personal Data

Personal data means any information relating to an identified or identifiable individual. It does not include information where the identity has been removed and the individual can no longer be identified. 

We may collect, use, store and transfer different types of personal data, including: 

Identity Data
This may include first name, last name, title, job title, username or similar identifier. 

Contact Data
This may include business address, billing address, delivery address, email address and telephone number. 

Account and User Data
This may include login credentials, user roles, access permissions, account settings, profile information and system identifiers. 

Financial Data
This may include bank account details, payment details, invoicing information and billing records. 

Transaction Data
This may include details of products or services purchased, payments made, services provided, customer records and related commercial information. 

Technical Data
This may include internet protocol address, browser type and version, time zone setting, location information, device information, operating system, platform, log data and other technology information. 

Usage Data
This may include information about how you use our website, products, services, portals or systems. 

Support and Service Data
This may include support tickets, service requests, diagnostic information, issue records, correspondence, incident records and service management information. 

Marketing and Communications Data
This may include your preferences in receiving marketing from us, event information, communication preferences and records of our communications with you. 

Security and Compliance Data
This may include audit logs, access logs, monitoring alerts, investigation records, compliance records, vulnerability management information and information needed to protect our systems, services and data. 

We may also process customer, platform and service data where this is necessary to provide, operate, secure, monitor, support and improve our products and services. 

Customer data and service data 

In providing our products and services, Ticketer may receive, generate or process customer data, platform data, service data, support data, diagnostic data, usage data and technical data. 

Where this information includes personal data, Ticketer will process it in accordance with applicable data protection laws, the relevant controller and processor roles, and the applicable contractual arrangements. 

Ticketer may use customer, platform, service, support, diagnostic, usage and technical data where necessary to provide, operate, support, secure, monitor, maintain and improve its products and services. 

Where Ticketer uses aggregated or anonymised information for analytics, reporting, service improvement, product development or business purposes, we do so in a way that does not identify individuals. 

Nothing in this privacy notice transfers ownership of customer data or personal data to Ticketer. 

How We Collect Personal Data

We may collect personal data directly from you when you: 

  • complete a form on our website 
  • contact us by email, phone, post or through another communication channel 
  • request information from us 
  • subscribe to updates or publications 
  • attend an event 
  • provide feedback 
  • correspond with us about products or services 
  • use our website, portals, systems or services 
  • raise a support request 
  • apply for a role with us 

We may also collect personal data indirectly from: 

  • customers 
  • suppliers 
  • business partners 
  • service providers 
  • public sources 
  • professional advisers 
  • regulators or public authorities 
  • systems, logs, cookies and similar technologies 

Where we receive personal data from a customer in connection with the services we provide, the customer is responsible for ensuring that it has the right to share that personal data with us.

Providing Personal Data

Where we need to collect personal data by law, under a contract, or to provide products or services, and you do not provide that information when requested, we may not be able to perform the contract or provide the relevant service. 

Where this applies, we will tell you at the time where possible. 

How We Use Your Personal Data

Ticketer will only use personal data where the law allows us to. 

We may use personal data where: 

  • it is necessary to perform a contract with you or with the organisation you represent 
  • it is necessary to comply with a legal obligation 
  • it is necessary for our legitimate interests or those of a third party, provided those interests are not overridden by individual rights and freedoms 
  • consent has been given, where consent is required 
  • another lawful basis applies under data protection laws 

We do not generally rely on consent as the main lawful basis for processing personal data, except where consent is required, such as for certain marketing activities or non-essential cookies and similar technologies. 

Where we rely on consent, you have the right to withdraw consent at any time.

Purposes For Which We Will Use Your Personal Data

We have set out below the main purposes for which we use personal data and the lawful bases we rely on.

 

Purpose or activity 

Type of data

Lawful basis for processing 

To respond to enquiries and communicate with you Identity Data, Contact Data, Marketing and Communications Data Performance of a contract or steps before entering into a contract. Necessary for our legitimate interests in responding to enquiries and managing business relationships. 
To manage our relationship with customers, suppliers and business contacts Identity Data, Contact Data, Transaction Data, Marketing and Communications Data Performance of a contract. Necessary for our legitimate interests in managing business relationships, keeping records updated and administering our business. 
To provide products and services Identity Data, Contact Data, Account and User Data, Transaction Data, Technical Data, Usage Data, Support and Service Data Performance of a contract. Necessary for our legitimate interests in providing, operating and supporting our products and services. Where we act as processor, processing is carried out in accordance with customer instructions. 
To manage payments, fees, charges and invoicing Identity Data, Contact Data, Financial Data, Transaction Data Performance of a contract. Necessary to comply with legal obligations. Necessary for our legitimate interests in recovering money owed to us and managing our financial records. 
To provide support, investigate issues and manage service requests Identity Data, Contact Data, Account and User Data, Technical Data, Usage Data, Support and Service Data Performance of a contract. Necessary for our legitimate interests in providing support, resolving issues and maintaining reliable services. 
To administer and protect our business, website, systems and services Identity Data, Contact Data, Account and User Data, Technical Data, Usage Data, Security and Compliance Data Necessary for our legitimate interests in running our business, providing administration and IT services, maintaining network and information security, preventing fraud and protecting our services. Necessary to comply with legal obligations where applicable. 
To monitor, secure and improve our products and servicesTechnical Data, Usage Data, Support and Service Data, Security and Compliance Data Necessary for our legitimate interests in maintaining secure, reliable and effective products and services. Consent where required for non-essential cookies or similar technologies.
To use analytics to improve our website, services, customer relationships and user experience Technical Data, Usage Data, Marketing and Communications Data Necessary for our legitimate interests in keeping our website and services updated, relevant and effective. Consent where required for non-essential cookies or similar technologies. 
To send marketing communications and business updates Identity Data, Contact Data, Marketing and Communications Data Necessary for our legitimate interests in promoting our products and services to business contacts. Consent where required by law. 
To comply with legal, regulatory, audit and compliance obligations Relevant personal data depending on the matter Necessary to comply with legal obligations. Necessary for our legitimate interests in managing compliance, risk, disputes, claims and audit activities. 
To manage business change, restructuring or corporate activity Identity Data, Contact Data, Transaction Data, Financial Data, relevant business records Necessary for our legitimate interests in managing business operations, restructuring, transactions or corporate change. 

 

Where more than one lawful basis may apply, the relevant lawful basis will depend on the specific processing activity and context. 

Legitimate Interests

Where we rely on legitimate interests, we consider and balance our interests against the rights, freedoms and interests of individuals. 

Our legitimate interests may include: 

  • managing and developing our business 
  • providing and improving products and services 
  • supporting customers 
  • maintaining accurate business records 
  • protecting our systems, data and services 
  • preventing fraud and misuse 
  • maintaining information security 
  • managing business risk 
  • communicating with business contacts 
  • understanding how our website and services are used 
  • managing legal claims, disputes and regulatory matters 

Where required, we carry out appropriate assessments to support our reliance on legitimate interests. 

Recognised Legitimate Interests

Data protection law now includes a lawful basis known as recognised legitimate interests for certain specific public interest purposes. 

Ticketer will only rely on recognised legitimate interests where the processing falls within one of the purposes recognised by law and where the conditions for relying on that lawful basis are met. 

Where recognised legitimate interests do not apply, Ticketer will rely on another appropriate lawful basis, such as ordinary legitimate interests, contract, legal obligation or consent. 

Marketing Communications

Ticketer may send you marketing communications about our products, services, updates, events and resources where permitted by law. 

You have the right to object to processing of your personal data for direct marketing purposes. 

You can unsubscribe from marketing communications at any time by using the unsubscribe method included in our communications or by contacting us. 

Where you opt out of marketing communications, this will not affect service, contractual, security, support or administrative communications that we may need to send. 

Cookies and Similar Technologies

We use cookies and similar technologies on our website and, where applicable, in connection with our products, portals or services. 

Some cookies and similar technologies are necessary for the website or service to work. 

Other cookies or similar technologies may help us understand how the website or service is used, improve performance, remember preferences, support functionality, or provide relevant content. 

Where required by law, we will ask for consent before using non-essential cookies or similar technologies. 

Data protection and electronic communications laws now allow some limited types of cookies and similar technologies to be used without consent, such as certain statistical or functionality cookies, where the legal conditions are met. 

Where consent is required, you can manage your preferences through the cookie tools made available on our website. 

More information is available in our Cookie Policy. 

How We Share Personal Data

We may share personal data with the parties set out below where necessary and lawful: 

  • Internally – our employees, workers, contractors and authorised personnel who need access to personal data for legitimate business purposes. 
  • Customers – where relevant to the services we provide or where we process personal data on behalf of a customer. 
  • Suppliers and service providers – this may include IT, hosting, software, security, communications, analytics, support, payment, professional and outsourced service providers. 
  • Professional advisers – this may include lawyers, auditors, accountants, insurers, bankers and other professional advisers. 
  • Regulators, law enforcement bodies and public authorities – where required by law, regulation, legal process or good governance. 
  • Advertising networks, analytics providers and website service providers – where relevant to our website, marketing, analytics or communications activities and where permitted by law. 
  • Third parties involved in business change – where relevant to an acquisition, transfer, restructuring, merger, investment, sale or reorganisation of any part of our business. 

We do not sell personal data. 

Suppliers and Sub-processors

We use trusted suppliers and service providers to help us provide, host, support, secure, monitor, maintain and improve our website, products and services.

Where these suppliers process personal data on our behalf, we require them to handle personal data securely, only process it for authorised purposes and comply with applicable data protection requirements.

Where Ticketer acts as processor for a customer, the use of sub-processors will be governed by the relevant customer contract, data processing agreement or applicable data processing terms.

Where required, we will obtain appropriate customer authorisation for sub-processors and ensure that suitable contractual protections are in place.

International Transfers

We may transfer or process personal data outside the United Kingdom or European Economic Area where this is necessary for our business operations, products or services. 

Where we transfer personal data internationally, we will use appropriate safeguards required by data protection law. 

This may include: 

  • adequacy regulations or adequacy decisions 
  • the UK International Data Transfer Agreement 
  • the UK Addendum to the EU Standard Contractual Clauses 
  • EU Standard Contractual Clauses 
  • another lawful transfer mechanism available under applicable data protection laws 

Where required, we will assess whether the transfer provides appropriate protection for personal data. To find out more about the transfer mechanism used, please contact us. 

Data Security

We have put in place appropriate security measures designed to prevent personal data from being accidentally lost, used, accessed, altered or disclosed in an unauthorised or unlawful way. 

Ticketer maintains an ISO/IEC 27001 certified information security management system, which supports the governance, risk management and control environment for information security and personal data protection. 

These measures may include access controls, authentication controls, encryption where appropriate, logging, monitoring, vulnerability management, supplier assurance, staff training, incident response processes and audit activity. 

We limit access to personal data to employees, workers, contractors, suppliers and other authorised parties who have a business need to know. 

Those parties are required to process personal data appropriately and are subject to confidentiality obligations. 

The transmission of information over the internet is not completely secure. Although we take reasonable measures to protect personal data, we cannot guarantee the security of information transmitted to us over the internet. 

Data Retention

Ticketer will only retain personal data for as long as reasonably necessary to fulfil the purposes for which it was collected. 

This includes retaining personal data where necessary for: 

  • service delivery 
  • customer and supplier relationship management 
  • contract administration 
  • support 
  • security 
  • legal and regulatory compliance 
  • tax and accounting 
  • audit and reporting 
  • dispute resolution 
  • complaints handling 
  • legal claims 

To determine the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the purposes for which it is processed, the risk of harm from unauthorised use or disclosure, legal and regulatory requirements, and whether the purpose can be achieved through other means. Where Ticketer acts as processor for customer data, retention may be determined by the customer, the relevant contract, product configuration or applicable data processing terms. We may anonymise personal data so that it can no longer be associated with an individual. Where information has been anonymised, we may use it for research, statistical, reporting, analytics, service improvement or business purposes without further notice. 

Children’s Data

This website is not intended for children and we do not knowingly collect personal data from children through this website. 

Automated Decision-Making

Automated decision-making means making a decision about an individual by automated means without meaningful human involvement. 

Ticketer does not use personal data collected through this website to make decisions about individuals based solely on automated processing which produce legal or similarly significant effects. 

If this changes, we will provide appropriate information about the processing, the logic involved, the significance and likely consequences of the processing, and any applicable safeguards. 

Data Subject Rights

Under certain circumstances, you have rights under data protection laws. 

You may have the right to: 

  • Request access to your personal data: This is known as a data subject access request and enables you to receive a copy of the personal data we hold about you. 
  • Request correction of your personal data: This enables you to ask us to correct incomplete or inaccurate personal data. 
  • Request erasure of your personal data: This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. 
  • Object to processing: This enables you to object where we process personal data based on legitimate interests or for direct marketing purposes. 
  • Request restriction of processing: This enables you to ask us to suspend the processing of personal data in certain circumstances. 
  • Request transfer of your personal data: This enables you to ask us to provide certain personal data in a structured, commonly used and machine-readable format. 
  • Withdraw consent: Where we rely on consent, you can withdraw that consent at any time. This will not affect the lawfulness of processing carried out before consent was withdrawn. 
  • Challenge certain automated decision-making: Where applicable, you may have rights in relation to certain automated decisions. 

These rights are not absolute and may not apply in every case. 

Where Ticketer acts as controller, you can contact us to exercise your rights. 

Where Ticketer acts as processor on behalf of a customer, we may need to refer your request to the relevant customer as controller. 

Keeping Personal Information Accurate and Current

It is important that the personal data we hold is accurate and current. 

Please keep us informed if your personal data changes during your relationship with us. 

Carrying Out Your Data Subject Rights

You will not usually have to pay a fee to exercise your data subject rights. 

However, we may charge a reasonable fee or refuse to act on a request where the request is manifestly unfounded or excessive. 

We may need to request specific information from you to help us confirm your identity and ensure that personal data is not disclosed to someone who is not entitled to receive it. 

We may also contact you to ask for further information in relation to your request. 

We try to respond to legitimate requests within one month. Occasionally it may take longer if your request is complex or you have made a number of requests. In that case, we will notify you and keep you updated. 

If you wish to exercise any of your rights, please contact us using the details in the Contact Us section. 

Concerns and Data Protection Complaints

We would appreciate the opportunity to deal with any concern or complaint in the first instance. 

If you are unhappy with how we have handled your personal data, or you believe that we have not complied with data protection law, you can raise a data protection complaint with us. 

You can contact us using the details in the Contact Us section. 

We will acknowledge your complaint within 30 days of receiving it. 

We will take appropriate steps to investigate the complaint and will respond without undue delay. 

If we need further information from you, or if the matter is complex, we will let you know. 

If you remain unhappy, you have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection matters. 

If you live or work outside the UK, or your complaint relates to processing outside the UK, you may also have the right to complain to another supervisory authority. 

Changes to this Privacy Notice

This privacy notice may be changed from time to time in response to legal, technical, operational or business developments. 

We will take appropriate measures to inform you when we update this privacy notice. 

Where required by applicable data protection laws, we will obtain consent to material changes. 

Contact us

If you would like more information about how we handle personal data, or if you would like to exercise your data protection rights or raise a data protection complaint, please contact our Data Protection Officer function at: 

Email: DPO@ticketer.co.uk 

Address: Ticketer, Marlborough House, Charnham Lane, Hungerford, Berkshire, RG17 0EY 

Telephone: (+44) 020 3195 8800 

This version was last updated in June 2026.