Privacy Policy
Trademark
Seaty is a registered trademark and trading name of Seaty Ltd. Information Commissioner's Office Reference ZA543843.
What kinds of personal information about you do we process?
When you use or interact with Seaty Services, we may collect your personal data. This could be on behalf of us or at other times on behalf of an organiser using Seaty to run their event.
Personal information that we collect and process in connection with all of our products and services, if relevant, includes:
- Full name
- Email address
- Records of your contact with us, such as message and email history when you get in touch with us
- Demographic information such as preferences
- Other information relevant to customer surveys and/or offers
What we collect from all users
Information you voluntarily provide to Seaty Services such as when you sign up for an account to use our Services, get in touch with us with questions, or browse sections of our website.
Personal data we may collect from you includes without limitation your name, email address and other information that enables users to be personally identified.
Information we collect automatically would be data that is sent to us from the device and browser you are using to connect to the website.
This information may include without limitation, your IP address, characteristics about your access device or browser, information on the status of your activities on Seaty or similar technologies.
When you sign up for the use of Seaty Services or submit any personal data to us, we may therefore link other non-personal data with your personal data.
At such a time, we will likely treat any such combined data as your personal data until it can no longer be associated with you or used to identify you.
What we collect from event organisers
When you are an event organiser we will collect additional personal data from you.
When you use our payment processing services we will need to collect financial information from you (for example your bank account information or an address to verify your personal information) to facilitate payments and information required for taxation purposes.
We may collect information from other third party sources such as websites, your bank, our payment processing partners (Stripe) and credit checking organisations.
Gift Aid Information Collection
For UK registered charities using Seaty, we may collect additional personal information when attendees opt to make Gift Aid declarations on their ticket purchases.
Gift Aid personal data we collect includes:
- Full name
- Street address
- Town/city
- Postcode
- UK taxpayer declaration
Legal basis for Gift Aid processing:
We process Gift Aid information under Article 6(1)(a) (consent) and Article 6(1)(c) (compliance with legal obligations) of UK GDPR, as Gift Aid declarations are required by HMRC for UK tax reclaim purposes.
Gift Aid data retention:
Gift Aid declarations and related personal data are retained for 6 years as required by HMRC regulations. This data is stored securely and is only used for Gift Aid claim purposes and HMRC compliance.
Gift Aid data sharing:
Gift Aid information is shared only with the relevant charity organisation for HMRC submission purposes. Seaty acts as a data processor for Gift Aid information on behalf of the charity organisation who remains the data controller.
Your Gift Aid rights:
You can withdraw your Gift Aid declaration by contacting the charity organisation directly. Please note that once a Gift Aid claim has been submitted to HMRC, we may still need to retain the data for compliance purposes even if you withdraw consent.
Waiting List Information Collection
When you join a waiting list for an event, we collect personal information to allow the event organiser to contact you when tickets become available.
Waiting list personal data we collect includes:
- Full name
- Email address
- Phone number (optional)
- Number of tickets requested
- Preferred dates (optional)
- Accessibility requirements (optional)
- Additional notes (optional)
Legal basis for waiting list processing:
We process waiting list information under Article 6(1)(a) (consent) of UK GDPR. By joining a waiting list, you consent to the event organiser contacting you about ticket availability.
Waiting list data retention:
Waiting list entries are retained until actioned by the event organiser. When an entry is marked as completed (you received tickets), your personal data (name, email, phone) is automatically deleted from the waiting list, retaining only the non-personal record of tickets requested and the linked order. Pending and contacted entries retain personal data until the organiser marks them as completed or the event is deleted.
Waiting list data sharing:
Waiting list information is shared with the event organiser who manages the waiting list for their event. Seaty acts as a data processor for waiting list information on behalf of the event organiser who remains the data controller.
Your waiting list rights:
You can request removal from a waiting list by contacting the event organiser directly. Event organisers can mark your entry as refused, which removes you from the active waiting list while retaining a record for audit purposes.
Survey, Questionnaire and Form Information Collection
Event organisers can build surveys, questionnaires, and forms on Seaty and collect responses from attendees, members, and the public. If you respond to one, the organiser decides what is asked and why: the organiser is the data controller for your response, and Seaty processes it on their behalf.
Survey personal data we collect includes:
- Full name and email address (except for anonymous surveys, which collect neither)
- Your answers to the organiser's questions
- For document questions (where an organiser asks you to read something, for example their own terms or policies): whether you agreed or acknowledged the document, and the time you opened it
- For anonymous surveys only: a one-way hash of your IP address, used to discourage duplicate submissions. It cannot be turned back into your address
- Where your response is linked to a booking: references to the related order, event date, and ticket type, used to prevent duplicate responses and to group results
Anonymity modes:
Every survey uses one of three anonymity modes, and the survey page tells you which one applies before you answer:
- Identified: your name, email address, and answers are stored together, and the organiser can see who said what.
- Confidential: your name and email are stored with your response so duplicates can be prevented and results can be grouped (for example by event date or ticket type), but the organiser only ever sees grouped results, never who gave an individual answer. Groups of fewer than five responses are hidden from the organiser.
- Anonymous: no name or email address is collected.
Survey invitations by email:
If a survey reaches you by email, you were included either because you opted in to surveys from that organiser or because you have an operational relationship with them (for example you are a member or administrator of the organisation). The link in the email contains an encrypted token that identifies the invitation: it carries your email address and, where relevant, a reference to your booking, so that your response can be attributed correctly and you are not sent duplicate invitations. No personal information appears in the link in readable form. We also keep a record of which email addresses each survey was sent to, for the lifetime of that survey, so organisers do not contact you twice.
Sensitive answers and other people's details:
Some organiser forms ask for information that is special category data under UK GDPR, for example medical, allergy, or dietary details on a membership form, or ask for the details of another person, for example an emergency contact. The organiser collecting this information is the data controller for it and is responsible for having a valid lawful basis, normally your explicit consent given by choosing to answer the question. If you provide someone else's details, please make sure they know you have done so.
Legal basis for survey processing:
Responding is always voluntary. For feedback surveys the lawful basis is your consent (Article 6(1)(a)), given by choosing to submit a response. For membership and operational forms the organiser will normally rely on its contract or legitimate interests for the details it needs from you (Articles 6(1)(b) and 6(1)(f)), and on your explicit consent for any special category data (Article 9(2)(a)). Survey invitation emails are sent only to people who opted in to surveys from the organiser or who have an operational relationship with them.
AI summaries of written survey answers:
Where a survey or questionnaire asks you to write an answer in your own words, the organiser may choose to have those written answers grouped into common themes so they can read the sense of what people said without reading every response. This is not automatic and does not happen to every survey. It runs only when someone at the organiser with survey permission expressly asks for it on a particular question, and it is never available on a form. The organiser is the data controller and makes that decision; Seaty carries it out on their instruction, and records who asked for it and when.
When it runs, the text of the written answers to that one question is sent to OpenAI to be summarised. Your name, email address and every other identifier stay in Seaty and are never sent, and no more than 500 answers and 500 characters of each answer are included. On anonymous and confidential surveys the summary must be written in the AI's own words, and Seaty checks the result and removes anything that reproduces an answer word for word, because a distinctive comment can identify someone even where no name was recorded.
Seaty does not use your answers to train AI models, and does not use them for any purpose of its own: they are processed only to provide this service to the organiser who collected them.
The summary is stored so that reading it again costs nothing. If your responses are deleted, whether by the organiser or at your request, the stored summary for that survey is deleted at the same time so your words do not survive inside it. Text that has already been sent may persist in OpenAI's own abuse-monitoring records for up to 30 days and cannot be recalled within that window; nothing identifying you accompanied it.
Survey data retention:
Survey responses are retained while the organiser keeps the survey, including archived surveys. Organisers can permanently delete an individual's responses at any time using the built-in data request tool, and you can ask the organiser to do this for you. Anonymous responses cannot be matched to you and therefore cannot be individually deleted; that is a consequence of their anonymity. Any AI summary generated from written answers is stored with the survey and is deleted whenever a response is deleted or a respondent is erased.
Your survey rights:
Contact the event organiser to access, correct, or delete your survey responses; they are the data controller, and Seaty provides them with a tool to permanently delete an individual's responses. If you need help reaching an organiser, email Support@Seaty.co.uk.
What we do with the information we gather
We require this information to understand your needs and provide you with a better service, and in particular for the following reasons:
- Internal record keeping - We maintain records of your account and transactions
- Service improvement - We may use the information to improve our products and services
- Market research - From time to time, we may also use your information to contact you for market research purposes. We may contact you by email, phone or mail
- Website customisation - We may use the information to customise the website according to your interests
- Promotional communications - We may periodically send promotional emails about new products, special offers or other information which we think you may find interesting using the email address which you have provided
- Facilitating event updates - We may use your email address (and share it with the relevant event organiser) so they can provide you with necessary updates or additional information about the event you're attending. In some cases, Seaty may also send or facilitate these communications on the organiser's behalf. These messages are typically non-marketing in nature (e.g., changes to date, venue, schedule) unless you have explicitly opted in to receive marketing content from that organiser
Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures to safeguard and secure the information we collect online.
Card payment data:
Card payments are processed by Stripe, an external payment provider certified to PCI DSS Level 1. Card numbers, expiry dates, and security codes are entered directly into Stripe-hosted fields and never reach Seaty's servers. We store only a Stripe payment reference for each transaction, which is meaningless without Stripe's own systems.
Passwords:
Passwords are salted and hashed before storage. Plaintext passwords are never written to disk and never appear in logs. We cannot recover a forgotten password, only reset it.
Two-factor authentication:
Every email-and-password sign-in is followed by a one-time six-character code emailed to the account. The code is valid for twenty minutes, single-use, and required on every login. Knowing the password is not enough on its own. An attacker would also need access to the email inbox. Sign-in through Apple, Google, or Microsoft single sign-on relies on the identity provider to handle the second factor.
Encryption at rest:
The Seaty database runs on Microsoft Azure SQL with platform-level encryption at rest (Transparent Data Encryption) enabled. Email values embedded in unsubscribe and preference URLs are additionally encrypted at the application layer so that those URLs cannot be reverse-engineered from server logs or browser history.
Where your data is hosted:
Seaty runs on Microsoft Azure in the UK South region. Application servers, the primary SQL database, and the Azure Blob Storage containers that hold cached public pages and uploaded images all sit in UK South. Personal data does not leave the United Kingdom for routine processing. Where a sub-processor below operates internationally (for example Stripe for card processing, or Apple, Google, and Microsoft for single sign-on), any cross-border transfer takes place under that provider's own documented UK GDPR transfer mechanism.
Mailshot click tracking:
When a recipient opens or clicks a Seaty mailshot, we record the event for campaign reporting. For recipients who are not signed in, the visitor IP address is hashed with SHA-256 and a per-environment salt before storage. We never store raw IP addresses for marketing analytics.
Separation of public and admin systems:
Public event listings and organisation pages are served from a read-only static cache. Visitors browsing or buying tickets do not touch the live database that holds order, member, or financial data. The admin systems that do touch that database require an authenticated sign-in.
Error monitoring:
When the platform encounters an unexpected error, a fingerprint based on the error type, a normalised version of the error message, and the request path is recorded so we can identify and fix issues. Identifying customer data is not part of the fingerprint.
Data breach notification:
In the unlikely event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by UK GDPR.
If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, providing information about the nature of the breach and the measures we are taking to address it.
Sub-processors
Seaty uses a small number of third-party providers to deliver the service. Each acts as a sub-processor of personal data on our behalf. The list below is the current set. If it changes we will update this page.
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Application hosting, SQL database, blob storage | UK South |
| Stripe | Card payment processing, SCA, refunds, payouts | UK / EU / US (under Stripe's UK GDPR transfer mechanism) |
| Postmark | Transactional and mailshot email delivery | US (under Postmark's UK GDPR transfer mechanism) |
| Apple, Google, Microsoft | Optional single sign-on for organiser accounts | Globally distributed; the identity provider handles the second factor |
| Dropbox | Optional file storage integration for event organisers who choose to enable it | US (under Dropbox's UK GDPR transfer mechanism) |
| OpenAI | AI-assisted drafting for event organisers (survey and marketing content generation). Only organisation and event details (names, descriptions, dates, ticket category names) are sent; attendee, respondent, order, and financial data is never sent. Separately, and only where an organiser expressly chooses to run it on a particular question, the free-text answers to a single survey or questionnaire question are sent to be grouped into themes: the answer text only, never a name, email address or any other identifier, and never from a form. See AI summaries of written survey answers | US (under OpenAI's UK GDPR transfer mechanism) |
| Google (Analytics & Ads) | Optional, consent-gated website analytics and advertising conversion measurement, enabled per organisation | US (under Google's UK GDPR transfer mechanism) |
| Meta (Pixel) | Optional, consent-gated advertising conversion measurement, enabled per event | US (under Meta's UK GDPR transfer mechanism) |
Where a sub-processor operates outside the UK, the transfer relies on that provider's own UK adequacy or Standard Contractual Clauses position. If you need the underlying documentation for a procurement or data-protection-impact-assessment exercise, contact Support@Seaty.co.uk and we will point you to it.
The Google and Meta entries are only active when (a) the relevant event organiser has configured Google Analytics, Google Ads, or the Meta Pixel for their events, and (b) you have given the matching cookie consent. Analytics tools require your "Google Analytics" consent; advertising tools (Google Ads conversion tracking and the Meta Pixel) require your "Advertising" consent. For advertising, Google and Meta act as independent controllers of the data they receive under their own privacy policies. If you decline the relevant consent, no data is sent to these providers. You can change your choices at any time via Seaty's cookie preferences.
Google Ads conversion tracking sends only the fact that a purchase happened plus its value and currency. Seaty does not send any customer personal data (such as your email address, name, or postal address) to Google or Meta for advertising measurement.
Data Processing Agreement (UK GDPR Article 28)
If you are an event organiser using Seaty, Seaty acts as your processor in respect of attendee personal data your event collects. The processor obligations set out in Article 28 of the UK GDPR are set out in full in our standalone Data Processing Agreement, which forms part of the Terms of Service. If you need a copy executed under your organisation's name for your procurement records, email Support@Seaty.co.uk.
Your data rights: how to exercise them
The UK GDPR gives you specific rights over your personal data. To exercise any of the rights below, email Support@Seaty.co.uk. We will respond within one month, as required by Article 12(3), and longer only where the law permits.
- Right of access (Article 15): request a copy of the personal data we hold about you
- Right to rectification (Article 16): correct inaccurate personal data
- Right to erasure (Article 17): ask us to delete your account and personal data, subject to legal retention obligations (for example HMRC tax records, Gift Aid declarations, charity audit requirements)
- Right to data portability (Article 20): receive your data in a structured, commonly used, machine-readable format
- Right to restrict processing (Article 18): ask us to limit how we use your data
- Right to object (Article 21): object to processing carried out under our legitimate interests
- Right to withdraw consent: for any processing based on consent, you can withdraw it at any time
If you are an attendee whose data is held because you bought tickets through an organiser, the organiser is the data controller for those records. We will help you contact them.
How we use cookies
A cookie is a small file which asks permission to be placed on your computer's hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site.
Cookies allow web applications to respond to you as an individual. The web application can tailor its operations to your needs, likes and dislikes by gathering and remembering information about your preferences.
You can find more information on how we use cookies by reading our Cookies Policy.
Links to other websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website.
Therefore, we cannot be responsible for the protection and privacy of any information which you provide whilst visiting such sites and such sites are not governed by this privacy statement.
You should exercise caution and look at the privacy statement applicable to the website in question.
Controlling your personal information
You may choose to restrict the collection or use of your personal information in the following ways:
Marketing preferences:
Whenever you are asked to fill in a form on the website, look for the box that you can click to indicate that you do not want the information to be used by anybody for direct marketing purposes.
If you have previously agreed to us using your personal information for direct marketing purposes, you may change your mind at any time by writing to or emailing us at Support@Seaty.co.uk
Data protection:
We will not sell, distribute or lease your personal information to third parties. We may use your personal information to send you promotional information which we think you may find interesting if you tell us that you wish this to happen.
Correcting your information:
If you believe that any information we are holding on you is incorrect or incomplete, please write to or email us as soon as possible, at the above address. We will promptly correct any information found to be incorrect.
The UK General Data Protection Regulation (UK GDPR)
The UK General Data Protection Regulation (UK GDPR) is the privacy law that governs how we handle personal data. This regulation requires that Seaty, and event organisers using the service, provide users and attendees with comprehensive information about how their personal data is processed.
Are you an event organiser using Seaty? For plain-English UK GDPR guidance covering your responsibilities as a data controller (lawful basis, data minimisation, retention, sharing attendee data with venues), see our GDPR for UK event organisers guide.
Information on what you need to know
The legal grounds for the processing of your personal data:
We are required to tell you about the legal ground we rely on to process all personal data about you. In relation to this we will process your personal data only because:
- You provided your consent
- The processing is in our legitimate interest as an event organising and ticketing platform
- It is necessary for our agreed contractual relationship
- The processing is necessary for us to comply with our legal or regulatory obligations
Retention of personal data:
Personal data may be required for as long as is needed to provide you with your services, or in the event of complying with our legal obligations, resolving disputes that may arise, and enforcing agreements.
We retain different types of data for different periods:
- Active account data - Retained while your account remains active
- Inactive account data - Retained for 10 years after your last account activity, after which it will be deleted
- Transaction records - Retained for 7 years for accounting and tax purposes
- Gift Aid declarations - Retained for 6 years as required by HMRC regulations
- Marketing preferences - Retained until you withdraw consent or your account is deleted
- Support communications - Retained for 3 years to assist with ongoing support queries
- Waiting list entries - Personal data deleted when entry is completed; non-personal records retained with linked order
- Survey and form responses - Retained while the organiser keeps the survey, including archived surveys; organisers can permanently delete an individual's responses at any time and should do so on request
- Survey send records - The record of which email addresses a survey was sent to is kept for the lifetime of that survey to prevent duplicate sends
- AI summaries of written survey answers - Generated only on an organiser's express request, stored with the survey so it need not be regenerated, and deleted whenever a response is deleted or a respondent is erased
Know your rights:
Data protection laws provide you with rights in relation to personal data that we hold about you here at Seaty, including a right to request a copy of the personal data, request that we rectify, restrict or remove your personal data and unsubscribe from marketing communications.
You can exercise these rights by contacting us or changing the "cookie settings" in your browser (see our Cookies Policy for more information).
Note that all requests to exercise data protection rights will be assessed by us on a case by case basis. There may be times where we are not legally required to comply with your request because of the laws in your jurisdiction or because of exemptions provided for in data protection legislation.
Making complaints:
If you have a complaint about how we handle your personal data, please get in touch with us to explain the situation.
If you are not happy with how we have attempted to resolve your complaint, you may contact the Information Commissioner's Office (ICO), the UK's data protection authority, at https://ico.org.uk or by calling 0303 123 1113.
Seaty as a data controller and a data processor:
UK data protection laws make a distinction between organisations that process personal data for their own purposes (known as "data controllers") and organisations that process it on behalf of other organisations (known as "data processors").
Seaty may act as either a data controller or a data processor in respect of your personal data, depending on the circumstances.
When Seaty is a data controller:
If you create an account with us to organise your events, Seaty will be a data controller in respect of the personal data that you provide as part of your account.
We will also be a data controller of the personal data that we have obtained about the use of the applications or Seaty properties, which could relate to organisers or consumers. We use this to conduct research and analysis to help better understand and serve users of the services as well as to improve our platform and provide you with more targeted recommendations about events we think may be of interest to you.
If you have a question or complaint about how your personal data is handled, these should always be directed to the relevant data controller since they are the ones with primary responsibility for your personal data.
When Seaty is a data processor:
If you register for an event as a consumer, we will process your personal data to help administer that event on behalf of the event organiser and to help the organiser target, and understand the success of, their event and event planning.
In these circumstances, Seaty provides the "tools" for organisers, including optional survey and form templates that organisers may adapt; the organiser decides what personal data to request on registration forms, surveys, and event pages, and Seaty is not responsible for the continued accuracy of any personal data provided.
Any questions that you may have relating to your personal data and your rights under data protection law should therefore be directed to the organiser as the data controller, not to Seaty.
Related Information
- Terms of Service - Our terms and conditions
- Cookies Policy - How we use cookies and tracking technologies
Contact Us
For privacy-related questions or to exercise your data protection rights, please contact us at:
Email: Support@Seaty.co.uk
Information Commissioner's Office Registration: ZA543843