1. Who is responsible
The data controller is TBF HOLD CO LTD, trading as SparkleUp Events, registered in England and Wales. One controller covers all our websites and festivals.
Contact for privacy questions and requests: contact@tunisiabachatafestival.com.
2. What we collect
We collect only what we need to sell tickets, run safe events and keep in touch with our community.
- Buyer and pass holder details: name, email, phone, country and city, identity card or passport number, gender, dance role where a product needs it, and the details you give for hotel packages.
- Order details: products, prices, codes used, payment status and the policy versions you accepted. Payments are processed by our payment provider; we do not receive card numbers.
- Checkouts started but not completed, so that we can help you finish your order and understand our sales.
- Messages you send us (contact form, email, social media) and applications (promoter, show).
- Entry records at the event (ticket scans).
- Website data: only with your consent, analytics and advertising cookies (see the cookie policy).
3. Why we use it
To perform our contract with you (orders, tickets, transfers, entry, hotel bookings); to meet legal obligations (accounting, tax, safety); for our legitimate interests (event safety, fraud prevention, reconciling duplicate records, improving our events); and, for cookies, with your consent.
As stated in our terms of sale, buying a ticket includes receiving information and marketing emails about our festivals. You can unsubscribe at any time with the link in every marketing email.
4. Who receives it
Our service providers, under contract and for our purposes only: payment providers, email providers, hosting and database providers, and our customer-relationship tool. Hotels receive the names they need for rooming lists, never identity document numbers. We share data with authorities only when the law requires it.
Some providers are outside the United Kingdom and the European Economic Area; transfers use the safeguards the law requires.
5. How long we keep it
Orders and accounting records are kept as long as accounting and tax law requires. Identity document numbers are stored encrypted and reviewed once a year. Records of incomplete checkouts and past editions are kept in our archive. Marketing data of people who no longer interact with us is removed after 36 months; unsubscribe choices are kept so that we never email you again.
6. Your rights
You can ask for access to your data, correction, deletion, restriction, portability, and you can object to processing based on our legitimate interests or to marketing at any time. Write to us at the address above. You can also complain to the UK Information Commissioner's Office (ico.org.uk) or to the authority where you live.
7. Security
Access to personal data is limited to the staff who need it and is logged. Identity document numbers are encrypted. No system is perfectly secure; we will tell you and the authorities about a breach when the law requires it.