The small print, in plain words
Data processing agreement
Last updated 4 October 2026
This agreement forms part of the organiser terms. It sets out how Ticket Folk processes personal data on your behalf, as Article 28 of the UK GDPR requires. "You" means the organiser, as controller; "we" means Ticket Folk, as processor.
1. What we process, and why
| Subject matter | Providing the Ticket Folk platform to you under the organiser terms. |
|---|---|
| Duration | For as long as you use Ticket Folk, then until the data is deleted or anonymised as set out in section 8. |
| Nature and purpose | Selling and delivering tickets, checking people in, taking and returning deposits, receiving and reviewing applications, and sending the emails and texts that go with them. |
| People | Your ticket buyers and ticket holders, applicants (volunteers, traders, course runners, performers), and your team. |
| Personal data | Names, email addresses, phone numbers, postcodes, vehicle registrations, order and payment records, check-in records, application answers and documents, and review notes. |
| Special category data | None is required. If you ask applicants for it, such as health or access needs, you’re responsible for having a lawful condition to process it. |
2. Your instructions
We process the data only on your documented instructions: the organiser terms, this agreement, and how you set up and use Ticket Folk. If the law requires us to process it otherwise, we’ll tell you first unless the law forbids that. We’ll tell you if we think an instruction breaks data protection law.
3. Confidentiality
Everyone who can access the data on our side is bound by a duty of confidentiality and only accesses it when they need to.
4. Security
We protect the data with appropriate technical and organisational measures, including:
- encryption in transit for every connection to the platform;
- sign-in by single-use, short-lived email links, and an authenticator-app code before refunds;
- role-based access, so each member of your team sees only what their role allows;
- card details handled only by Stripe, never stored by us;
- personal details removed from records after the retention period.
5. Sub-processors
You authorise us to use the sub-processors on our sub-processors page. We’ll give you at least 30 days' notice by email before adding or replacing one, so you can object. If we can’t resolve a reasonable objection, you can end the organiser terms. We put data protection terms in place with each sub-processor that are at least as protective as this agreement, and we remain responsible for their work.
6. Transfers outside the UK
Where a sub-processor handles data outside the UK, we make sure the transfer is covered by UK adequacy regulations or by the International Data Transfer Agreement or Addendum.
7. Helping you
- We’ll help you answer requests from people exercising their rights, and pass on any request we receive about your event.
- We’ll tell you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
- We’ll help with data protection impact assessments and consultations with the ICO, where they relate to our processing.
8. When processing ends
When you stop using Ticket Folk, you can ask us for a copy of your data first. We then delete or anonymise it, except where the law requires us to keep records. Order and payment records are kept for six years after the event and then stripped of personal details.
9. Showing we comply
We’ll give you the information you reasonably need to show we meet this agreement, and answer reasonable questions and questionnaires. Audits or inspections are by agreement, with reasonable notice, and no more than once a year unless a breach or regulator requires it.
10. Contact
Email [email protected].