LEGAL INFRASTRUCTURE // KV-POL-01

PRIVACY POLICY

UPDATED: August 2026
CONTROLLER: KLUB VERBOTEN

We take the privacy of our users very seriously. We ask that you review this Privacy Policy carefully, as it contains important information about how we collect, use, and safeguard your personal data.

We know privacy is paramount to all of our members and users of our services. Klub Verboten has got your back. We aim to ensure you always know exactly how and when we process your personal data, and what your statutory rights are.

INDEX:
§ 01

WHAT DATA DO WE COLLECT?

If you browse our website as a guest, we may collect technical and usage information:

  • Technical information regarding your device, browser type, and navigation patterns.
  • Your IP address and network diagnostics.

If you apply for membership, hold a ticket, or subscribe to our services, we may collect:

  • Your full legal name.
  • Your verified email address.
  • Direct links to your active social media accounts (for identity verification).
  • Your phone number (for safety, critical event communications, and door access control).
  • Your date of birth (for mandatory 18+ age verification).
  • Photo(s) of yourself (for membership verification and in-person door verification).

Accessibility & Carer Access Documentation:

Not part of standard membership. To grant complimentary carer/personal assistant tickets, we may ask you to provide proof of eligibility (such as PIP/DLA documentation, Deaf or Blind Registration, or a CredAbility Access Card). This data is strictly restricted and retained for a maximum of 90 days following the event.

§ 02

HOW DO WE USE YOUR DATA & LEGAL BASES

Device Data & Telemetry

We collect telemetry regarding your device and interaction with our services via server logs and anonymous edge metrics to protect against cyber threats, mitigate malicious traffic, and optimize performance.

Legal Basis: GDPR Art. 6(1)(f) – Legitimate interests in maintaining operational stability and security.

Full Name & Identity Vetting

Required to accurately assess applications for private membership and ensure the safety of our private community.

Legal Basis: GDPR Art. 6(1)(f) – Legitimate interests in verifying attendee identity for venue safety.

Email & Direct Communications

Used to manage your membership, dispatch booking confirmations, transmit safeguarding guidelines, and provide critical policy updates.

Legal Basis: GDPR Art. 6(1)(b) – Performance of a contract / Art. 6(1)(f) Legitimate interests.

Social Media Profiles

Reviewed strictly during the vetting process to assess suitability for our private members club. We will never ask for your passwords or private credentials.

Legal Basis: GDPR Art. 6(1)(f) – Legitimate interests in community safeguarding.

Phone Number & Door Access Control

Used for door check-in, emergency security alerts when necessary, and restricting access to ticket facilities if a guest has breached rules or been banned.

Legal Basis: GDPR Art. 6(1)(f) – Legitimate interests in protecting members and enforcement of venue safety rules.

Date of Birth & Age Verification

Strictly required to verify that all applicants and event attendees are above the statutory age of 18.

Legal Basis: GDPR Art. 6(1)(c) – Compliance with legal obligations and licensing regulations.

§ 03

THIRD PARTIES & DATA PROCESSORS

We partner with trusted third-party infrastructure and service providers to run our modern digital platform securely. We never sell your personal information. Categories of data processors include:

Cloud Hosting & Edge Infrastructure

Our web application and digital services are deployed across certified enterprise cloud edge infrastructure. Server logs and anonymised network diagnostics are processed to maintain site availability, prevent unauthorized intrusion, and protect against distributed denial-of-service (DDoS) threats.

Content Delivery & Database Infrastructure

We utilize enterprise cloud-hosted database and content delivery networks to securely store and serve site media, rules, and event schedules. Editorial data is encrypted in transit and at rest across European and global edge points.

Transactional Messaging & Email Service Providers

We partner with GDPR-compliant email infrastructure providers to deliver booking confirmations, membership notices, and critical event updates. Your email address and notification status are securely handled through certified EU-compliant transmission infrastructure.

Authorized Ticketing Platforms & Venue Access Control

Ticket sales, digital admission passes, and in-person door check-in are managed through authorized third-party ticketing platforms (such as Weeztix) and our venue door management systems.

Financial Accounting & Statutory Reporting

Accounting and business transaction reconciliation are processed via certified accounting systems for financial auditing and statutory tax reporting.

Enterprise Workspace & Internal Operations

We use secure enterprise cloud productivity and administrative suites for internal administrative coordination, access audits, and member safeguarding.

Social Media Syndication

We interface with official social platform APIs to syndicate approved promotional announcements and community media.

§ 04

DATA RETENTION & STORAGE

We retain your personal information for as long as your membership is active. Upon membership termination or request for deletion, we will securely erase your personal record within 30 days.

Exceptions to immediate deletion include:

  • Statutory tax and accounting records retained for 7 years under UK financial legislation.
  • Safety and exclusion registers: Records of individuals banned or ejected for safeguarding violations are retained indefinitely to uphold venue safety and protect community members.
  • Accessibility & carer documentation: Purged 90 days post-event.
§ 05

YOUR STATUTORY RIGHTS (UK GDPR)

Under the UK Data Protection Act 2018 and UK GDPR, you have the following rights:

  • Right of Access: Request a copy of your personal data held by Klub Verboten (Subject Access Request).
  • Right to Rectification: Request correction of inaccurate or incomplete personal records.
  • Right to Erasure ('Right to be Forgotten'): Request deletion of your personal data where no legal override applies.
  • Right to Restriction: Restrict processing of your data under specific statutory conditions.
  • Right to Object: Object to processing based on legitimate interests.

To exercise any of these rights, contact our Data Protection team directly via community@klubverboten.com.

You also hold the right to lodge a formal complaint with the UK supervisory authority: the Information Commissioner's Office (ICO).

§ 06

DATA CONTROLLER & DOCUMENT REVISIONS

The Data Controller for Klub Verboten is Klub Verboten. For inquiries, email community@klubverboten.com.

We regularly review and update this Privacy Policy to reflect changing operational practices and legal requirements. Revisions will be published directly to this page with an updated timestamp.

SUBJECT ACCESS & PRIVACY INQUIRIES

Questions about your data?

To submit a Subject Access Request (SAR), request data rectification, or ask about our privacy practices, email our data team directly.

Contact Data Team
MATRIX HERO MONITOR

NO ACTIVE ASSEMBLIES DETECTED

SYSTEM STANDBY // RE-ROUTING TO ARCHIVAL TIMELINES

KV Radio
Connecting…
0:000:00