Legal
GDPR Compliance
Last updated: 22 June 2026
GRABBYS Events Limited complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the UK GDPR. This page summarises your rights and how we honour them. It complements our Privacy Policy.
1. Data controller
GRABBYS Events Limited is the controller for personal data processed through the Service. Contact: privacy@grabbys.app.
2. Lawful bases we rely on
- Contract — to deliver tickets, packages and event services you purchase.
- Legitimate interests — to secure the Service, prevent fraud, and improve features.
- Consent — for marketing emails, push notifications, and non-essential cookies. You can withdraw at any time.
- Legal obligation — to meet tax, accounting and other statutory requirements.
3. Your rights
- Access — request a copy of personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — request deletion ("right to be forgotten") subject to legal retention.
- Restriction — ask us to limit processing in certain cases.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests or for direct marketing.
- Automated decisions — we do not make decisions producing legal effects based solely on automated processing.
- Withdraw consent — without affecting prior lawful processing.
4. How to exercise your rights
Email privacy@grabbys.app from the address linked to your account, or use the data-export and delete-account tools in your Account page. We respond within one month and may extend by two months for complex requests, notifying you of the reason.
5. International transfers
Where personal data is transferred outside the EEA/UK we use Standard Contractual Clauses, the UK International Data Transfer Addendum, or another approved safeguard.
6. Data retention
We retain personal data only as long as needed for the purposes described, after which it is deleted or anonymised. Order, invoicing and tax records are kept for the statutory period (typically 6–10 years).
7. Security measures
- Encryption in transit (TLS) and at rest where supported by our infrastructure.
- Hashed passwords and support for passkey (WebAuthn) authentication.
- Row-level security policies on database tables.
- Least-privilege access for staff and time-limited service-role credentials.
8. Cookies
We use strictly necessary cookies to operate the Service and, with your consent, analytics cookies to understand usage. You can change preferences at any time via the cookie banner or your browser settings.
9. Complaints
If you believe we have not handled your data properly, please contact us first. You also have the right to lodge a complaint with your local supervisory authority — in the UK the Information Commissioner's Office (ICO).