privacy Notice

Autograph ABP (“Autograph”, “we”, “us”, or “our”) is committed to protecting your personal information and being transparent about how we use it. This Privacy Notice explains what personal data we collect, how and why we use it, and your rights under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

1. Who we are (Data Controller)

Autograph ABP
Registered Charity No. 1127712
Registered Address: 1 Rivington Place, London, EC2A 3BA
Email: info@autograph-abp.co.uk

2. What personal data we collect
We collect personal data when you:
• Purchase or book tickets
• Make a donation
• Buy items from our online shop
• Subscribe to our newsletter
• Complete surveys, feedback forms or registration forms
• Participate in open calls, events or programmes
• Interact with our website
• Engage with us on social media

This may include:
• Name, postal address, email address, phone number
• Payment and transaction information
• Booking and attendance records
• Donation history and Gift Aid information
• Customer service communications Interests, preferences and demographic information (non-identifying)
• Technical data: IP address, browser type, device information, and cookie/analytics data

3. Purpose and lawful basis for processing
We rely on the following lawful bases for different types of processing:

a) To fulfil orders, bookings, shop purchases and donations
• Purpose: processing bookings, payments, fulfilling orders, providing customer service
• Lawful basis: Contract

b) To send you our email newsletter
• Purpose: sending news, event updates and opportunities
• Lawful basis: Consent
You can withdraw consent at any time.

c) Marketing to previous customers (“soft opt-in”)
• Purpose: sending updates about similar events or products
• Lawful basis: Legitimate interests and PECR soft opt-in

d) Supporter engagement & fundraising research
• Purpose: understanding engagement, identifying potential supporters, maintaining accurate donor records
• Lawful basis: Legitimate interests
Our assessment shows this processing is low-risk and proportionate.
e)
Analytics and website improvement
• Purpose: analysing website use to improve functionality
• Lawful basis:
- Consent for non-essential cookies (e.g. Google Analytics)
- Legitimate interests for essential security/operational data

f) Administrative, financial and legal obligations
• Purpose: accounting, reporting, fraud prevention, Gift Aid records
• Lawful basis: Legal obligation

g) Social media advertising and insights
• Purpose: receiving anonymised statistical insights into campaign performance
• Lawful basis: Legitimate interests
We do not receive personal data from platforms about individual users. We do not sell your data and do not share it with third parties for their own marketing.

4. Who we share personal data with
We use trusted third-party suppliers who process data on our behalf. These may include:
• Ticket Tailor – exhibition ticket bookings
• Eventbrite – event ticket bookings
• Mailchimp – email newsletters
• Beacon – CRM database
• E-commerce and payment processors – shop orders and donations
• Google Analytics – website analytics (anonymised)

All third parties must comply with UK data protection law and may only process data in line with our instructions.

5. International transfers
Some of our suppliers (e.g., Mailchimp, Eventbrite, Google) store data outside the UK. Where this occurs, we ensure appropriate safeguards are in place, such as:
• The International Data Transfer Agreement (IDTA)
• The UK Addendum to the EU Standard Contractual Clauses, or
• Other ICO-approved mechanisms

You may contact us for details of specific safeguards.

6. Data security
We use appropriate technical and organisational measures to protect your personal data from loss, unauthorised access or misuse. All suppliers processing data on our behalf are required to meet the same standards.

7. How long we keep your data
We only keep your data for as long as necessary for each purpose. Typical retention periods include:
• Ticketing & shop transactions: 6 years (accounting/legal)
• Newsletter subscribers: until you unsubscribe or after 2 years of inactivity
• Donor records: 6 years (or longer where Gift Aid applies)
• CRM supporter information: reviewed every 3 years
• Analytics data: typically 26 months (Google Analytics default)

Where possible, we anonymise data so you can no longer be identified.

8. Your rights
Under the UK GDPR you have the right to:
1) Be informed about how your data is used
2) Access your personal data
3) Rectify incorrect or incomplete data
4) Erasure (“right to be forgotten”)
5) Restrict processing
6) Data portability
7) Object to processing, including direct marketing
8) Rights related to automated decision-making and profiling

To exercise any of these rights, email: info@autograph-abp.co.uk
If we cannot fulfil your request due to legal requirements or exemptions, we will explain why.

9. Email marketing
With your consent, we send a newsletter containing news, events, offers and opportunities. You may unsubscribe at any time via the link in the email or by contacting us. For customers who purchased or booked previously, we may email you about similar products or events, permitted under PECR. You can opt out at any time.

We use Mailchimp to deliver our newsletters. Mailchimp securely stores your data on our behalf.

10. Social media
You may see our content or adverts on platforms like Meta or TikTok. Depending on your platform settings, we may receive anonymised insights such as demographic information or engagement reports. This information does not identify you.

11. Links to other websites
Our website contains links to external sites. We are not responsible for their privacy practices. Please review their privacy notices.

12. Cookies
We use cookies and similar technologies to operate our website, improve functionality and analyse usage. Non-essential cookies will only be set with your consent.

13. Contact and complaints
If you have questions about this Privacy Notice, contact:
lois@autograph-abp.co.uk

For independent advice or to make a complaint, you can contact the ICO:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
www.ico.org.uk

cookies Notice

We use cookies and similar technologies on our website. Cookies are text files placed on your computer or device when you browse the website. They are used to remember your preferences, improve functionality, analyse usage and support marketing and advertising.

What are cookies?

Cookies are small data files stored on your computer or device when you browse this website. They are used to 'remember' information including pages and items viewed, items placed into the shopping basket and items purchased. The cookies store this information in order for to you use and purchase from this website. They cannot harm your computer or store any personally identifiable information such as your name, address, credit card or other contact details.

Cookies are essential to the effective operation of this website and enable you shop online with us. If you don't wish to enable cookies, you'll still be able to browse the website but not purchase from it. Most web browsers have cookies enabled, but please refer to 'How do I manage cookies?' below for help how to turn cookies on and off should you need to.

To manage your cookie preferences click here.

Types of cookies

Necessary Cookies: These cookies are essential in the operation of this website. They are used for a variety of purposes such as remembering the pages visited, items placed in the shopping basket and that the website is in use. This website does not store any personally identifiable information within any cookie or cookie type including any text fields you have completed and credit card information.

Performance cookies: These cookies collect anonymous information on how users browse the website, the data is merged and used to help us understand how users operate the website so we can make improvements to enhance your online experience. For example we employ Google Analytics cookies to help us record how users arrive and find the website, how they browse and use the website, so we can improve areas such as navigation, shopping experience and marketing campaigns. Other cookies may include tracking purchases for 3rd party affiliate partners, royalty schemes and promotions. Again the data stored by these cookies is not personally identifiable and cannot be used to identify any individual users.

Functionality cookies: These cookies remember your choices and preferences such as currency, items viewed, search parameters, wish-lists and any items saved for later. These cookies provide the user with an enhanced user experience making their visits more personalised and pleasant. Again any information collected and stored by these cookies is merged and is not personally identifiable and cannot be used to identify any individual users.

Targeting cookies or advertising cookies: These 3rd party cookies collect information about your browsing habits in order to make advertising decision relevant to your interests. PLEASE NOTE that this website does NOT use any of these types of cookies or collect data for third parties.

Managing cookies

You can choose to accept or reject cookies. Most web browsers allow you to refuse all or some cookies or alert you when a cookie is being placed. If you disable or refuse cookies, please note that some parts of our website may become inaccessible or unable to function properly.