UK GDPR & Data Protection Policy
1. Purpose & Scope Ooser Fest C.I.C. ("we", "our", "us") is committed to protecting personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy applies to all personal data collected through our website, communications platforms, and operational activities.
2. Data We Collect
Public Subscribers: Email addresses and communication preferences provided via opt-in forms for digital newsletters and schedule updates.
Collaborators & Stakeholders: Names, phone numbers, email addresses, and professional roles for artists, venue operators, suppliers, contractors, and volunteers processed under legitimate interest for festival coordination.
3. Data Storage & Third-Party Processors
We utilise secure third-party platforms to store and manage data:
Mailchimp: Manages opt-in mailing lists, digital schedule downloads, and public newsletters.
Google Workspace: Manages operational contact lists and administrative correspondence. Both providers maintain UK GDPR compliance and robust security infrastructure. We do not sell, rent, or trade personal data to third parties.
4. Individual Rights Individuals have the right to request access to their personal data, request corrections, or request complete deletion of their records at any time. Marketing emails include an automated "Unsubscribe" link. Data requests can be submitted to ooserfest@gmail.com.