Skip to content
← Trust CentrePRIVACY

Privacy Policy

How BOOYAKKA LTD handles personal information.

Version 1.0Effective 1 August 2026Last updated 22 July 2026

Who we are

BOOYAKKA LTD is responsible as controller for account, billing, support, security and direct business relationship data. For personal information entered by an organisation about its members, customers, staff, ticket buyers or subscribers, the organisation will usually be the controller and BOOYAKKA will usually act as its processor.

Information we use

  • Account and organisation details.
  • Contact, support and complaint communications.
  • Subscription, invoice and transaction references.
  • Usage, security, device and audit information.
  • Content and records entered into organisation workspaces.
  • Marketing preferences where applicable.

Purposes and lawful bases

We use information to provide and secure the service, administer contracts and payments, support users, comply with law, prevent misuse and improve BOOYAKKA. Depending on the purpose, our lawful basis may be contract, legal obligation, legitimate interests or consent.

Sharing

We use service providers for hosting, infrastructure, payments, communications and customer support. We share only what is reasonably required and use contractual and other safeguards appropriate to the relationship.

Retention

We retain information only as long as reasonably necessary for service delivery, legal, accounting, security and dispute purposes. Different records require different periods. Organisation-controlled data may be retained for a limited period after closure to support recovery, export and legal obligations before deletion or anonymisation.

Your rights

Depending on the circumstances, individuals may have rights of access, correction, erasure, restriction, objection and portability. Requests concerning organisation-controlled data should normally be made first to that organisation.

Complaints

Use the contact route shown on this site for privacy requests or complaints. We will acknowledge a data-protection complaint within 30 days and investigate it appropriately. You may also complain to the Information Commissioner's Office.