Privacy Notice

This is STAR's Privacy Notice from 20 July 2022. A copy of our previous notice can be found here.

Who we are

We are The Society of Ticket Agents and Retailers, a company limited by guarantee and registered in England and Wales under registration number 03453544 and our registered office is at Blake House, 18 Blake Street, York YO1 8QG.

We are the data controller of the personal data we collect and process, as further described in this Privacy Notice. We take our responsibilities under data protection and privacy laws seriously and are also registered as a data controller with the Information Commissioner’s Office (“ICO”) under registration number ZA894374.

When this notice applies

This notice applies whenever we collect and process personal data relating to individuals (“you”, “your”) in the following circumstances:

  • when you use our website (“website”, “site”) or services;
  • when you contact us via our website or through other means, or when you interact with us by participating in one of our events or promotions, by registering to receive updates, newsletters or job alerts from us, or by expressing an interest in STAR membership on behalf of your organisation and progressing such enquiries, for example through submitting a membership application;
  • when you make a complaint through STAR regarding a STAR member; or
  • when you interact with us in your capacity as a representative of a STAR member.

This notice does not apply to the processing of personal data relating to job applicants, staff, former staff, Council Members or former Council Members. That processing is described in a separate privacy notice.

This notice sets out the basis on which we collect and process your personal data in the circumstances described above, as well as your rights in connection with it. Please read this notice carefully to ensure that you understand how we process the personal data that you provide or that we otherwise collect about you. Please note that this website and our services are not intended for use by children and we do not knowingly collect or process personal data relating to children.

The information we collect about you

Depending on the nature of your relationship and interaction with us, we may collect, use, store and transfer different kinds of personal data about you. We have outlined the ways we do this in greater detail below.

Website Users

When using our website and communicating with us via the site (including through the use of any contact forms that are made available) or through other channels, then we may process the following types of your personal data:

  • Identity Data including first name and last name.
  • Contact Data including addresses, email addresses and telephone numbers.
  • Communications and Marketing Data including the time, nature and content of your communications with us, as well as any communications preferences specified.
  • Technical Data including internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device model and other technology on the devices you use to access this website or our software.
  • Usage Data including information about how you use our website and services.

Complainants

If you make a complaint to STAR about a STAR member, then we may process the following types of your personal data

  • Identity Data including first name and last name.
  • Contact Data including billing address, delivery address, email address and telephone numbers.
  • Complaints Data including the details of relevant bookings and of the circumstances surrounding the complaint.
  • Financial Data including payment card details in some circumstances, such as when we are processing a complaint on your behalf and it may then be helpful for us to have some details about the method of payment you used when purchasing from a STAR member. However, for debit and credit cards, we will only process the name of the card scheme, card provider and/or bank and the last four digits of the payment card. We do not need or collect anything further in this respect.
  • Transaction Data including details about payments to and from other STAR members.
  • Health Data including any information regarding health conditions, such as disability status, dietary or allergen information, Covid status or other illnesses, to the extent that such information is provided as part of an active complaint you have made through STAR.

Members

If you are a representative of an existing STAR member, then we may process the following types of your personal data:

  • Identity Data including first name and last name.
  • Contact Data including billing address, delivery address, email address and telephone numbers.
  • Communications and Marketing Data including the time, nature and content of your communications with us, as well as any communications preferences specified and event attendance details.
  • Financial Data including in some circumstances payment card details, such as when we are processing payments for membership fees or other services provided by STAR.
  • Transaction Data including in some circumstances details about payments to and from STAR.
  • Health Data including details of dietary or allergen information and disability status, where such information is provided in connection with your attendance at one of our events.

Non-Members

If you are not a representative of an existing STAR member but have attended one of our events, expressed an interest in STAR membership or otherwise engaged with us through available channels on behalf of your organisation then we may process the following types of your personal data:

  • Identity Data including first name and last name.
  • Contact Data including billing address, delivery address, email address and telephone numbers.
  • Communications and Marketing Data including the time, nature and content of your communications with us as well as any communications preferences specified and event attendance details.
  • Financial Data including payment card details in some circumstances, such as when we are processing a complaint on your behalf and it may then be helpful for us to have some details about the method of payment you used when purchasing from a STAR member. However, for debit and credit cards, we will only process the name of the card scheme, card provider and/or bank and the last four digits of the payment card. We do not need or collect anything further in this respect.
  • Transaction Data including in some circumstances details about payments to and from STAR.
  • Health Data including details of dietary or allergen information and disability status, where such information is provided in connection with your attendance at one of our events.

Sensitive personal data

We do not intend on collecting or otherwise processing any special categories of personal data about you involving details of your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health, disability, or genetic or biometric data. We also do not process data related to criminal offences or convictions.

In rare cases and as outlined further in this notice we may process limited amounts of sensitive data. However, to assist us in this regard, we ask that you do not share such data with us unless it is strictly necessary. Should you provide such sensitive data, we will seek your consent to use it where necessary (for example where it forms part of a complaint or where it is necessary to manage attendance at one of our events).

Anonymous data

Please note that in certain circumstances we may anonymise data meaning that it can no longer be used to identify you. For example, we may do this for statistical purposes in circumstances where the results cannot be used to identify or relate to you. In such cases, the anonymous data no longer constitutes your personal data.

How we collect your information

Where we collect your personal data, this will often be provided directly to us by you. However, there may also be cases where we collect your personal data from other sources, as further described below.

Website Users

  • Information you give us: when you make an enquiry or raise a dispute with us via email or the contact forms on our website, then we may store personal data you give us such as your name, email address, postal address, telephone number as well as details of your enquiry or dispute.
  • Information about your interactions with us: we will store any correspondence we have with you against the details of your dispute or enquiry. If you supply information on paper then we will scan it and store it electronically with those other details. If we send you emails, we may keep a record of ones you have opened and any links in those emails that you may click on.
  • Automated technologies and interactions: we will automatically collect Technical Data and Usage Data about your equipment, browsing actions and patterns when you visit and navigate the website, through the use of cookies, server logs and other similar technologies.

Complainants

  • Information you give us: when you make an enquiry or raise a dispute with us via email or the contact forms on our website, then we will store personal information you give us such as your name, email address, postal address, telephone number as well as details of your enquiry or dispute.
  • Information about your interactions with us: we will store any correspondence we have with you against the details of your dispute or enquiry. If you supply information on paper then we will scan it and store it electronically with those other details. If we send you emails, we may keep a record of ones you have opened and any links in those emails that you may click on.
  • Information from third parties: when investigating a dispute with one of our members, then we may need to obtain details of the complaint and its surrounding circumstances from the relevant member, to enable us to be able to resolve the dispute with our member.

Members

  • Information you give us: when you make an enquiry, or raise a dispute with us via email or the contact forms on our website. We will store personal information you give us such as your name, email address, postal address, telephone number as well as details of your enquiry or dispute.
  • Information about your interactions with us: we will store any correspondence we have with you against the details of your dispute or enquiry. If you supply information on paper then we will scan it and store it electronically with those other details. If we send you emails, we may keep a record of ones you have opened and any links in those emails that you may click on.
  • Information from third parties: when investigating a dispute with one of our members, we may need to share details or correspondence you have supplied to us to help us resolve the dispute with our member.

Non-Members

  • Information you give us: when you make an enquiry or raise a dispute with us via email or the contact forms on our website. We will store personal information you give us such as your name, email address, postal address, telephone number as well as details of your enquiry or dispute.
  • Information about your interactions with us: we will store any correspondence we have with you against the details of your dispute or enquiry. If you supply information on paper then we will scan it and store it electronically with those other details. If we send you emails, we may keep a record of ones you have opened and any links in those emails that you may click on.

Why we collect your information

STAR will generally collect and use your personal information for the following purposes:

  • to operate and make improvements to our website;
  • to enable us to be able to accept and address any enquiries or complaints that are received;
  • to deliver the services you have requested, including processing, administering and communicating with you regarding your membership application;
  • to process payments related to membership fees; and/or
  • to otherwise promote, administer and keep appropriate records of our activities, including through maintaining marketing distribution lists and issuing invitations to events.

We have set out in greater detail below the purposes and lawful bases of processing your personal data.

However, please note that we may process your personal data for more than one lawful ground depending on the specific purpose for which we are using your data.

Website Users

Purpose/Activity

Type of data

Lawful basis for processing

How long we will keep your personal data

To respond to and deal with enquiries or complaints

Identity Data

Contact Data

Communications Data

Necessary for our legitimate interests in engaging with you in relation to our website and services and necessary for your legitimate interests in enabling us to respond to your enquiry or complaint

6 years from receipt/collection.

To conduct statistical analysis in relation to access and usage of our site and to make improvements as a result

Technical Data

Usage Data

Your consent to analytics (see cookie policy for further details)

12 months from collection.

Complainants

Purpose/Activity

Type of data

Lawful basis for processing

How long we will keep your personal data

To receive, investigate and respond to complaints

Identity Data

Contact Data

Complaints Data

Financial Data

Transaction Data

Necessary for our legitimate interests and those of both our members and complainants in properly resolving complaints

Where Complaints Data includes sensitive data (e.g. related to health), the additional condition for processing this data will be your explicit consent

6 years from receipt/collection

To keep records on the nature and amount of complaints made against STAR members

Identity Data

Complaints Data

Financial Data

Transaction Data

Necessary for our legitimate interests and those of our members in accurately understanding and recording the nature and prevalence of complaints raised against members

Where Complaints Data includes sensitive data (e.g. related to health), the additional condition for processing this data will be your explicit consent

6 years from receipt/collection

To provide and fulfil our role as an approved ADR (alternative dispute resolution) provider

Identity Data

Contact Data

Complaints Data

Financial Data

Transaction Data

Necessary for our legitimate interests and those of both our members and complainants in

properly resolving complaints

Where Complaints Data includes sensitive data (e.g. related to health), the additional condition for processing this data will be your explicit consent

6 years from receipt/collection

To conduct statistical analysis in relation to the nature, quantity and resolution of complaints submitted against STAR members

Identity Data

Contact Data

Complaints Data

Financial Data

Transaction Data

Necessary for our legitimate interests and those of both our members and complainants in being able to understand and analyse trends in complaints made against STAR members

Where Complaints Data includes sensitive data (e.g. related to health), the additional condition for processing this data will be your explicit consent

6 years from receipt/collection

Members

Purpose/Activity

Type of data

Lawful basis for processing

How long we will keep your personal data

To receive, process and administer membership applications and to respond to any related enquiries

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests and those of our members in being able to grow our membership and to be able to operate and provide membership services (corporate memberships)

Necessary to take steps to enter into a contract at your request and subsequently to perform that contract (personal memberships)

6 years from cessation of membership

To check the identity and business status of member employees, officers and other representatives

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests in being able to verify the identity and status of member representatives

6 years from cessation of membership

To manage memberships, including processing any payments made and keeping appropriate records of membership accounts

 

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our and your legitimate interests in being able to manage and administer your membership account (corporate memberships)

Necessary for the performance of the contract (personal members)

6 years from cessation of membership

To develop and improve our services to you and other members

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests and those of our members in developing and improving our service offering

6 years from cessation of membership

To send direct marketing communications to you via email, for example in relation to events invitations, and to administer those events

Identity Data

Contact Data

Financial Data

Transaction Data

Health Data

Necessary for our legitimate interests in promoting and advancing our services through business to business marketing

Where you provide Health Data, the additional condition for processing this sensitive data will be your explicit consent

Until cessation of membership or unsubscribe from business to business marketing

6 years from event date

To protect our financial and legal interests, including in taking steps towards recovering debts owed by members

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests in bringing and defending legal claims

6 years from cessation of membership

To conduct statistical analysis in relation to STAR membership

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests in analysing and understanding STAR’s membership base and to enable us to make improvements to our service offering

6 years from cessation of membership

Non-Members

Purpose/Activity

Type of data

Lawful basis for processing

How long we will keep your personal data

To respond to enquiries

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests in appropriately responding to enquiries received

6 years from receipt/collection

To receive, consider and process membership applications

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests in appropriately responding to enquiries received

6 years from receipt/collection

To send direct marketing communications to you via email, for example in relation to events invitations, and to administer those events

Identity Data

Contact Data

Financial Data

Transaction Data

Health Data

Necessary for our legitimate interests in promoting and advancing our services through business to business marketing

Where you provide Health Data, the additional condition for processing this sensitive data will be your explicit consent

Until you unsubscribe from our marketing list.

6 years from event date

To conduct statistical analysis in relation to STAR membership

Identity Data

Contact Data

Financial Data

Transaction Data

Necessary for our legitimate interests in analysing and understanding STAR’s membership base and to enable us to make improvements to our service offering

6 years from receipt/collection

If you fail to provide personal information

Please note that if you fail to provide certain personal data when requested, then we may not be able to progress your organization’s membership application. In addition, where you have made an enquiry or complaint, then failing to provide us with the information needed may prevent us from being able to properly address that enquiry or complaint.

Where we rely on your consent to process your personal data, then you may withdraw that consent at any time by contacting us using the contact details provided below. However, please note that withdrawal of your consent does not affect the lawfulness of any processing that has already occurred on that basis and your refusal to provide or subsequent withdrawal of consent may mean that we are not able to progress your complaint, or to ensure that access needs, allergy and other dietary requirements are met in connection with your attendance at one of our events.

Third parties

There may be certain circumstances under which we need to disclose your personal information to certain trusted third parties. The recipients of your personal data will depend on the nature of your relationship with us, as further described below.

Website Users

We may share your personal data with the following third parties:

  • Service providers we rely on to process personal data on our behalf, such as specialist providers of IT and other technology-based services.
  • Our professional advisors.
  • Regulatory authorities, law enforcement agencies and courts.
  • In the event of a reorganisation of all or part of STAR’s activities, the party ultimately assuming conduct of those activities and their professional advisors, including in connection with any sale, restructure, merger or takeover of STAR.

Complainants

We may share your personal data with the following third parties:

  • Service providers we rely on to process personal data on our behalf, such as specialist providers of IT and other technology-based services.
  • Our professional advisors.
  • Regulatory authorities, law enforcement agencies, trade organisations and bodies (such as the Chartered Trading Standards Institute) and courts.
  • In the event of a reorganisation of all or part of STAR’s activities, the party ultimately assuming conduct of those activities and their professional advisors, including in connection with any sale, restructure, merger or takeover of the STAR.
  • Our members as described above, when it is necessary for us to discuss your dispute with them.

Members

We may share your personal data with the following third parties:

  • Service providers we rely on to process personal data on our behalf, such as specialist providers of IT and other technology-based services.
  • Our professional advisors.
  • Regulatory authorities, law enforcement agencies and courts.
  • Relevant complainants.
  • In the event of a reorganisation of all or part of STAR’s activities, the party ultimately assuming conduct of those activities and their professional advisors, including in connection with any sale, restructure, merger or takeover of the STAR.
  • The STAR Council, to meet our duties to report anyone who breaches our Code of Practice and help raise standards within the industry.
  • The Better Regulation Delivery Office (BRDO) in order that you/your business can join the Primary Authority Scheme.

Non-Members

We may share your personal data with the following third parties:

  • Service providers we rely on to process personal data on our behalf, such as specialist providers of IT and other technology-based services.
  • Our professional advisors.
  • Regulatory authorities, law enforcement agencies and courts.
  • Relevant complainants.
  • In the event of a reorganisation of all or part of STAR’s activities, the party ultimately assuming conduct of those activities and their professional advisors, including in connection with any sale, restructure, merger or takeover of the STAR.

Storing your personal information

STAR will keep and process your personal information only for as long as it is necessary for the purposes for which it was collected, unless we have a legal right or obligation to retain the data for a longer period. We have set out the relevant periods above.

To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements. Any data deemed no longer relevant is deleted.

Generally where information is related to a contractual relationship then we will store data for 6 years from the date of termination of the contract. However, other types of information will be retained for reduced periods in line with the criteria above. For more information about how long we store specific types of data then please contact us using the contact information provided below.

Security of your personal information

We will put in place appropriate safeguards (both in terms of our procedures and the technology we use) to keep your personal information as secure as possible. We will ensure that any third parties we use for processing your personal information do the same.

International transfers

In some circumstances we may need to may transfer your personal data to recipients located in jurisdictions outside of the UK/EEA, including some destinations which do not have equivalent data protection laws to the UK/EEA.

However, when we transfer your personal data in this way we always ensure that an equivalent degree of protection is in place by ensuring that the recipient enters into specific contractual safeguards approved for use by the ICO. For more information about how we use approved contractual safeguards, please contact us using the contact information provided below.

Your rights to to your personal information

In certain circumstances you have the right to:

  • Request access to your personal data (data subject access request).
  • Request correction of any incomplete or inaccurate personal data that we hold about you.
  • Request erasure (deletion or removal) of your personal data.
  • Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party). In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your right to object.
  • Request restriction of processing of your personal data.
  • Withdraw consent at any time where we are relying on consent to process your personal data. This will not affect the lawfulness of any processing carried out before you withdrew your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

You will not have to pay a fee to access your personal data or exercise any of the other rights set out above. However, if your request is clearly unfounded, repetitive or excessive, we may charge a reasonable fee or refuse to comply with your request in these circumstances.

Please note that we may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

Please use the contact details at the end of this notice if you would like to exercise this right.

Our use of cookies

Our website uses cookies to help maintain the security of our site and improve your online experience. A cookie is a text file that is placed on your computer by a web page server. Cookies cannot be used to run programs or deliver viruses to your computer. Cookies are uniquely assigned to you, and can only be read by a web server in the domain that issued the cookie to you. Our website uses cookies and similar technologies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and allows us to improve our website.

When you first visit our website, we will ask you whether you consent to us setting cookies that are not essential to provide you with our online service. In addition, you can change your cookie preferences at any time by accessing our Privacy Overview or you can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.

For more information about the cookies we use, please see our Cookies Policy.

Complaints

In the event that you have a complaint about our treatment of your personal information, then we would welcome the opportunity to address this with you in the first instance. However, you also have the right to lodge a complaint with the supervisory body, the ICO, and details of how do to this are set out at https://ico.org.uk/make-a-complaint/.

Changes to the Privacy Notice

We may change this notice from time to time to account for changed regulatory conditions or processing activities. You can always find the most up-to-date privacy notice on our website at www.star.org.uk.

Contact details

Please get in touch with us if you have any questions about any aspect of this privacy notice.

Postal address: STAR, Blake House, 18 Blake Street, York, YO1 8QG
Email address: info@star.org.uk

Last updated: July 2022, Version 1.1