Website Privacy Policy Page of
Page of

vesnaclub.co.uk Privacy Policy

Type of website: Ecommerce
Effective date: 27th day of October, 2025

vesnaclub.co.uk (the "Site") is owned and operated by Vesna Club Ltd. Vesna Club Ltd is the data controller and can be contacted at:

info@vesnaclub.co.uk
07724 112108
4-8 Ludgate Circus, London EC4M 7LF

Purpose
The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:

  1. The personal data we will collect;
  2. Use of collected data;
  3. Who has access to the data collected; and
  4. The rights of Site users.

This Privacy Policy applies in addition to the terms and conditions of our Site.

GDPR
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR.

Consent
By using our Site users agree that they consent to:

  1. The conditions set out in this Privacy Policy.
  2. If you tick an optional box to receive marketing, you consent to us sending you occasional emails about upcoming events, news, and exclusive offers. You can withdraw this consent at any time by using the “unsubscribe” link in those emails or by contacting us. Withdrawing consent will not affect transactional or service emails related to your bookings.

Legal Basis for Processing
We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR.

We rely on the following legal bases to collect and process the personal data of users in the EU:

  1. Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the personal data necessary to perform a contract the consequences are as follows: We will be unable to provide our services, such as processing your ticket purchase, delivering your ticket, or contacting you about your booking; and
  2. Processing of user personal data is necessary for us to comply with a legal obligation. If a user does not provide the personal data necessary for us to perform a legal obligation the consequences are as follows: We cannot comply with our legal obligations (for example, to HMRC) and therefore will be unable to complete your purchase.
  3. With your consent (Article 6(1)(a) GDPR) for optional marketing communications. If you do not provide consent, you will not receive marketing emails, but you may still receive transactional/service communications related to your purchases. You can withdraw marketing consent at any time using the “unsubscribe” link in our emails or by contacting us.

Personal Data We Collect
We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.

Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our Site:

  1. First and last name;
  2. Email address;
  3. Phone number; and
  4. Payment information.
  5. Marketing preferences (opt-in/opt-out).

This data may be collected using the following methods:

  1. Creating an account; and
  2. Purchasing tickets.

How We Use Personal Data
Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.

The data we collect when the user performs certain functions may be used for the following purposes:

  1. To provide our services;
  2. To communicate with you;
  3. To meet our legal obligations; and
  4. To issue receipts.
  5. With your consent, to send you marketing emails about upcoming events, news, and exclusive offers.

You can withdraw your marketing consent at any time by clicking the “unsubscribe” link in any marketing email or by contacting our privacy officer. Transactional/service emails about your orders and account may still be sent.

Who We Share Personal Data With
Employees
We may disclose user data to any member of our organisation who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Third Parties
We may share user data with the following third parties:

  1. MongoDB Atlas (database provider);
  2. Render (hosting provider);
  3. Stripe (secure payment provider); and
  4. Resend (trusted email provider).
  5. Cloudflare (DNS, content delivery network).

We may share the following user data with third parties:

  1. Full name;
  2. Email address;
  3. Phone number;
  4. Order and receipt details;
  5. User IP address;
  6. Browser information;
  7. Activity logs; and
  8. Payment information (card brand, last four digits, transaction IDs).

We may share user data with third parties for the following purposes:

  1. Database hosting and storage of account and order information;
  2. Website hosting, performance monitoring, DNS/CDN, DDoS protection, and ensuring site security; and
  3. Secure payment processing, fraud prevention, and issuing receipts.
  4. Email delivery of transactional messages and, where you have opted in, marketing communications.

Third parties will not be able to access user data beyond what is reasonably necessary to achieve the given purpose.

Other Disclosures
We will not sell or share your data with other third parties, except in the following cases:

  1. If the law requires it;
  2. If it is required for any legal proceeding;
  3. To prove or protect our legal rights; and
  4. To buyers or potential buyers of this company in the event that we seek to sell the company.

If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.

How Long We Store Personal Data
User data will be stored until the purpose the data was collected for has been achieved.

You will be notified if your data is kept for longer than this period.

How We Protect Your Personal Data
We take appropriate technical and organisational measures to protect users’ personal data against loss, misuse, and unauthorised access. All data is transmitted over secure connections using HTTPS/TLS encryption, and stored in databases hosted on MongoDB Atlas, which provides encryption at rest and industry-standard security controls. Access to personal data is restricted to authorised personnel only, and role-based permissions are applied to limit unnecessary access. Passwords and authentication credentials are securely hashed and never stored in plain text. We regularly review our security practices, keep software up to date, and rely on trusted third-party providers such as Render, Cloudflare, and Stripe, who are themselves certified to high security and compliance standards (including PCI DSS for payment data).

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

International Data Transfers
We transfer user personal data to the following countries:

  1. Belgium.

When we transfer user personal data we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally.

If you are located in the United Kingdom or the European Union, we will only transfer your personal data if:

  1. The country your personal data is being transferred to has been deemed to have adequate data protection by the European Commission or, if you are in the United Kingdom, by the United Kingdom adequacy regulations; or
  2. We have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient.

Your Rights as a User
Under the GDPR, you have the following rights:

  1. Right to be informed;
  2. Right of access;
  3. Right to rectification;
  4. Right to erasure;
  5. Right to restrict processing;
  6. Right to data portability; and
  7. Right to object.

Children
We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our privacy officer.

How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our privacy officer here:

Veronika Khudenko
info@vesnaclub.co.uk
07724 112108
4-8 Ludgate Circus, London EC4M 7LF

Modifications
This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

Complaints
If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority. You can lodge a complaint with a supervisory authority by contacting the Information Commissioner’s Office (ICO).

Contact Information
If you have any questions, concerns or complaints, you can contact our privacy officer, Veronika Khudenko, at:

info@vesnaclub.co.uk
07724 112108
4-8 Ludgate Circus, London EC4M 7LF