Privacy Policy
Effective Date: March 2026
Last Reviewed: March 2026 (Superseding December 2024 version)
Introduction
Rebel International (“we,” “us,” or “our”) is committed to safeguarding your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, share, and protect your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU GDPR (where applicable).
Data Controller Identity: For the purposes of data protection law, REBEL INTERNATIONAL LTD (Private Limited by Shares), company number 13252088, located at 41 Stanley Road North, Rainham, England, RM13 8AX, acts as the Data Controller.
This policy applies to all users of our websites, ticketing systems, and marketing platforms. We review our policy annually, and any significant changes will be communicated via email and posted on our website.
Information We Collect and Why
We collect only the personal data necessary for clearly defined purposes, following the GDPR principle of data minimization.
Identity Data: Name, email address, and postal address.
Purpose: For event bookings, communication, and account management.
Legal Basis: Contractual necessity.
Contact Data: Phone number.
Purpose: Customer support and urgent event notifications only.
Legal Basis: Legitimate interests (for support) and Contractual necessity (for urgent event updates).
Transaction Data: Purchase details, amount paid, transaction ID, and limited payment information (processed securely by Easol, our ticketing partner).
Purpose: To process and fulfill event ticket purchases.
Legal Basis: Contractual necessity.
Technical Data: Device, browser, IP address, and usage data (collected via cookies and Easol analytics).
Purpose: To maintain site security and optimize user experience.
Legal Basis: Legitimate interests.
Marketing and Communications Data: Marketing preferences, event interest categories, and engagement metrics (via Brevo).
Purpose: To manage and send marketing communications based on your preferences.
Legal Basis: Consent.
How We Use Personal Data
We process your personal data for the following lawful purposes:
To administer bookings and payments via Easol and its payment sub-processors (such as Stripe).
To send marketing communications and event updates via Brevo, only where explicit consent has been provided.
To improve our services using aggregated, anonymized analytics.
To respond to customer inquiries and support requests.
To comply with legal obligations related to financial transactions and accounting.
Note: We do not use automated decision-making or profiling that produces legal or significant effects.
Our Lawful Bases for Processing
We rely on:
Contractual necessity – to deliver our services to you (tickets, event access, essential communications).
Consent – for receiving marketing communications.
Legitimate interests – for analytics, fraud prevention, and service improvement, provided these interests do not override your fundamental rights.
Data Sharing and Disclosures
We never sell personal data. We share it only with trusted service providers operating under signed Data Processing Agreements, including:
Easol Ltd. – Ticketing and payment processor (Data Processor). Easol Privacy Policy
Brevo (Sendinblue SAS) – Email marketing and CRM (Data Processor). Brevo Privacy Policy
All third parties are required to process data only on our instructions, maintain strict GDPR compliance, and implement strong technical and organizational security measures. If data is transferred outside the UK or EEA, safeguards such as Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) are utilized to ensure equivalent protection.
Data Retention
We retain your data only for as long as necessary:
Transaction Data (Easol): 7 years to comply with UK financial and tax record-keeping laws.
Marketing Data (Brevo): Retained for 24 months after your last engagement with us, or until consent is withdrawn.
Technical Data: 13 months, after which it is anonymized or securely deleted.
Data Security & Breach Notification
We employ industry-standard measures to protect your data, including:
End-to-end encryption (SSL/TLS) in transit and AES-256 at rest.
Role-based access control and Multi-factor authentication (MFA) for our team.
Regular penetration testing and vulnerability management via our platform partners.
Breach Protocol: A documented Data Breach Response Policy. In the event of a breach posing a risk to your rights, we will notify the Information Commissioner's Office (ICO) within 72 hours of detection. If the breach poses a high risk to your personal data, we will notify you directly and without undue delay.
Your Rights
You have specific rights under the UK and EU GDPR:
Access, rectify, or erase your personal data.
Restrict or object to our processing of your data.
Withdraw consent at any time (this does not affect the lawfulness of processing prior to withdrawal).
Data portability: Request your data in a structured, machine-readable format.
Lodge a complaint with the Information Commissioner’s Office (ICO) in the UK (https://ico.org.uk/) or your local supervisory authority.
Children’s Data
Our services and events are not intended for persons under 21. We actively employ measures to prevent the collection of such data.
Cookies and Tracking
We use cookies and similar tools (including Easol and Brevo tracking technologies) to analyze traffic and personalize your experience. Non-essential cookies are only activated with your consent, which you can withdraw at any time via your browser settings. See our Cookie Policy for detailed control options.
Third-Party Links
External links on our site (including to sponsors, partners, or social media platforms) operate under their own privacy policies. We are not responsible for third-party data practices.
Contact Us
If you have questions, require support, or wish to exercise any of your data rights, please contact our Data Protection representative at:
Email: rebel@rebelinternational.co.uk