Privacy Policy
Burton Agnes Hall & Gardens Privacy Policy
Burton Agnes Hall Preservation Trust Ltd. Privacy Policy
Burton Agnes Hall Preservation Trust Ltd and its trading subsidiary Burton Agnes Hall Trading Ltd (hereafter referred to as Burton Agnes Hall) are committed to protecting and respecting your privacy.
This policy sets out the basis on which any personal data collected from you, or that you provide, is used by Burton Agnes Hall.
Why does this policy exist?
The privacy policy ensures that Burton Agnes Hall:
· Complies with data protection law and follows good practice
· Protects rights of staff, customers and partners
· Is open about how it stores and processes individuals’ data
· Protects itself from risk of a data breach
Why do we collect personal information?
Burton Agnes Hall may collect and process the following data about you:
Information you give us
You may provide information about yourself by filling in forms or by corresponding with Burton Agnes Hall by phone, e-mail or otherwise. For example, this includes information you provide when you become a member, purchase tickets, enter competitions or prize draws, or subscribe to e-newsletters. The information you provide may include, for example, your name, address, e-mail address or phone number.
Information collected about you
With each of your visits to our website, we may automatically collect the following information:
· Anonymous demographic information, which is not unique to you, such as your postcode, age, gender, preferences, interests and favourites;
· Technical information about your computer hardware and software, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, domain names, time zone setting, browser plug-in types and versions and referring website addresses.
The personal information we collect
· We collect information from, amongst others, customers, members, tenants, employees, volunteers, suppliers, enquirers, supporters and job applicants.
· Personal information includes, for example: name, email, address and phone number.
How we use cookies
A cookie is a small file that asks permission to be placed on your computer’s hard drive. Once you agree, the file is added and the cookie helps analyse web traffic or lets you know when you visit a particular site. We use traffic log cookies to identify which pages are being used. This helps us analyse data about webpage traffic and improve our website and tailor it to customer needs. We only use this information for statistical analysis purposes and then the data is removed from the system. Overall, cookies help us provide you with a better website, by enabling us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to your computer or any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. This may prevent you from taking full advantage of the website.
Links to other websites
Our website may contain links to other websites of interest. However, once you have used these links to leave our site, you should note that we do not have any control over that other website. Therefore, we cannot be responsible for the protection and privacy of any information that you provide whilst visiting such sites and such sites are not governed by this privacy statement. You should exercise caution and look at the privacy statement applicable to the website in question.
Keeping information secure:
We are committed to digital security. We will never sell your personal data and we will never share it with another organisation for marketing purposes. Information is only shared when we are required to by law or with carefully selected partners who work for us.
Data protection risks
This policy helps protect Burton Agnes Hall from data security risks, including:
· Breaches in confidentiality
· Failing to offer choice (individuals are free to choose how a company uses data relating to them)
· Reputational damage (caused if hackers gained access to sensitive information)
Responsibilities
All Burton Agnes Hall employees have responsibility to ensure that data is collected, stored and handled appropriately and in line with the privacy policy. However, these people have particular responsibility:
The Governing Body and Directors are ultimately responsible for ensuring that Burton Agnes Hall meets its legal obligations.
The Data Protection Officer is responsible for:
· Keeping the trustees and directors updated about data protection risks and responsibilities
· Reviewing all data responsibilities
· Arranging data protection training
· Handling data protection questions
· Dealing with data requests
The IT Manager is responsible for:
· Ensuring all systems, services and equipment used for storing data meets security standards
· Performing regular scans to ensure security hardware is working correctly
The Marketing Manager is responsible for:
· Approving any data protection statements attached to communications such as emails and letters
· Addressing any data protection queries from press
· Ensuring all marketing initiatives abide by data protection principles
General staff guidelines
· The only people able to access data covered by this policy should be those who need it for their work
· Data should not be shared informally
· Burton Agnes Hall will provide training to all employees to help them understand their responsibilities when handling data
· Employees should keep all data secure by following guidelines
· Passwords must be kept strong and never shared
· Personal data should not be disclosed to unauthorised people
· Data should be regularly updated and reviewed and deleted and disposed of if out of date or no longer required
· Employees should request help from line managers if they have any queries regarding data protection.
Data storage
· When working with personal data, employees should ensure screens are locked when unattended
· Data must be encrypted before being transferred electronically
· Personal data should not be transferred outside the European economic area
· Employees should not save copies of personal data to their computers.
Data accuracy
The law requires that Burton Agnes Hall takes reasonable steps to ensure data is kept accurate and up to date.
· Data should be held in as few places as necessary
· Staff should take every opportunity to ensure data is updated
· Burton Agnes Hall must ensure it is easy for data subjects to update information easily
· Data should be updated as inaccuracies are discovered
Disclosing data for other reasons
In certain circumstances the Data Protection Act allows personal data to be disclosed to law enforcement agencies with consent of the data subject.
Under these circumstances, Burton Agnes Hall will disclose requested data. However, the data controller will ensure the request is legitimate and seek advice from legal advisers where necessary.
Subject access requests
Subjects are entitled to:
· Ask what information is stored about them
· Ask how to gain access to it
· Be informed of how to keep their information up to date
· Be informed about how the company is meeting data protection obligations
Changes to data and data removal
You can decide not to receive marketing communications, or change how we contact you, at any time. If you wish to do this or if you have any questions concerning your personal data and how we look after it, please contact us at office@burtonagnes.com, write to us at Burton Agnes Estate Office, Burton Agnes, Driffield, YO25 4NB or call the estate office on 01262 490324.
Data breach
Should a data breach occur, where unauthorised access or alteration has occurred and the breach of security could lead to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data, the Information Commissioner’s Office will be informed within 72 hours of the breach. An exeption to this is if the data breach is unlikely to cause risk to individuals; however the breach should still be documented.
Access to information
The Act gives you the right to access information held about you. Your right of access can be exercised in accordance with the Act. Any access request may be subject to a fee of £10 to meet costs in providing you with details of the information we hold about you.
Contact
Questions, comments and requests regarding this Privacy Policy are welcomed and should be addressed to office@burtonagnes.com.
Changes to this policy
This Privacy Policy will be amended from time to time to ensure it remains up to date and accurately reflects how and why we use personal data. The current version of our Privacy Policy will always be on the Burton Agnes website.
DigiTickets Privacy Policy
Policy Owner
This policy is owned and distributed by IT and Compliance manager of Digital Ticketing Systems Limited
Who we are
In this Privacy Policy, references to "we", "us", and "our"" are to Digital Ticketing Systems Limited (Company number 07044584). References to "our Website" or "the Website" are to *.digitickets.co.uk.
Digital Ticketing Systems Limited is the data controller responsible for the personal information collected through this Website.
Information We Collect
We may collect and process the following categories of personal information:
Information You Provide Directly
When you contact us, make a purchase, register for services, or complete forms on our Website, we may collect information such as:
- Name
- Postal address
- Email address
- Telephone number
- Purchase and booking information
- Any other information voluntarily provided by you
Payment Information
Payments made through our Website are processed by authorised payment service providers. We do not store your full credit or debit card details on our systems.
Our payment providers may process payment information and carry out fraud prevention and verification checks. Where international transfers are required, appropriate safeguards will be applied in accordance with applicable data protection laws.
Digital Ticketing Systems is PCI DSS v4.0.1 compliant and are annually assessed/certified.
Website Usage Information
When you visit our Website, we may automatically collect:
- IP address
- Browser type and version
- Device information
- Screen resolution
- Operating system
- Referral source
- Pages visited and actions taken on the Website
- Date and time of access
Marketing Preferences
If you choose to receive marketing communications, we will record your preferences and any interactions with our emails, including whether emails are opened or links are clicked.
Cookies and Similar Technologies
We use cookies and similar technologies to operate our Website, remember your preferences, analyse usage, and improve user experience. Further information is provided in our Cookie Policy below.
How We Use Your Information
We process personal information for the following purposes:
- To provide products and services you request
- To process transactions and fulfil orders
- To provide customer support and after-sales services
- To manage bookings and accounts
- To improve our Website, products, and services
- To ensure Website security and prevent fraud
- To comply with legal and regulatory obligations
- To send marketing communications where we have your consent or another lawful basis to do so
Lawful Basis for Processing
Under UK GDPR, we rely on one or more of the following lawful bases:
- Performance of a contract: to provide goods or services you have requested.
- Legal obligation: where processing is necessary to comply with legal requirements.
- Legitimate interests: to manage and improve our business, Website security, and customer experience.
- Consent: where required, including for certain cookies and marketing communications.
Where we rely on consent, you may withdraw it at any time.
Sharing Your Information
We may share your personal information with:
- Payment processors
- Hosting and IT service providers
- Delivery and fulfilment partners
- Marketing and communications providers
- Analytics and Website performance providers
- Professional advisers and auditors
- Regulatory authorities, law enforcement agencies, or courts where required by law
All third-party service providers are required to process personal information only on our instructions and in accordance with applicable data protection laws.
We do not sell personal information to third parties.
International Transfers
Where personal information is transferred outside the United Kingdom, we will ensure appropriate safeguards are in place, such as:
- Transfers to countries deemed to provide an adequate level of protection; or
- Approved contractual safeguards, such as the UK International Data Transfer Agreement (IDTA) or equivalent mechanisms.
Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, regulatory, and reporting requirements.
Retention periods vary depending on the type of information and the purpose for which it is processed.
Cookie Policy
What Are Cookies?
Cookies are small text files stored on your device when you visit a website. They help websites function properly, remember preferences, improve performance, and provide analytics information.
How We Use Cookies
We use the following categories of cookies:
Strictly Necessary Cookies
These cookies are essential for the operation of the Website and cannot be disabled through our cookie management tools.
Cookie |
Purpose |
Duration |
|---|---|---|
PHPSESSID |
Maintains user session and shopping basket functionality |
Session / 24 minutes |
dtAnalyticsConsent |
Records cookie consent preferences |
1 year |
Analytics Cookies
These cookies help us understand how visitors interact with the Website so that we can improve performance and usability.
These cookies are only placed with your consent.
Google Analytics
Examples include:
- _ga
- _ga<container-id>
- _gid
- _gat_<tracker-name>
Used to collect aggregated statistical information about Website usage.
Google Privacy Information:
https://support.google.com/analytics/answer/6004245
Microsoft Clarity
Examples include:
- _clck
- _clsk
- CLID
- ANONCHK
- MR
- MUID
- SM
Used to analyse user interactions and improve Website usability.
Microsoft Clarity Information:
Performance Monitoring Cookies
Performance monitoring tools help us identify technical issues and improve Website reliability.
Examples may include cookies used by services such as New Relic.
Managing Cookies
When you first visit our Website, you will be presented with a cookie banner allowing you to:
- Accept all cookies
- Reject non-essential cookies
- Choose your cookie preferences
You may change your preferences at any time through our cookie settings tool.
You can also manage cookies through your browser settings. Disabling certain cookies may affect Website functionality.
Your Data Protection Rights
Under UK GDPR, you may have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your information
- Restrict processing
- Object to processing
- Request portability of your data
- Withdraw consent where processing is based on consent
- Lodge a complaint with the Information Commissioner's Office (ICO)
For more information about your rights, visit:
https://ico.org.uk/
Automated Decision-Making
We do not generally make decisions producing legal or similarly significant effects using solely automated processing.
Where automated tools are used for fraud prevention, security monitoring, or service administration, appropriate safeguards will be applied in accordance with applicable data protection legislation.
Childrens Data
Our Website is not intended to knowingly collect personal information from children unless necessary to provide services requested by a parent, guardian, school, attraction, venue, or authorised organisation.
Where we process children's personal information, we take additional care to ensure appropriate protections are in place.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact:
Digital Ticketing Systems (t/a DigiTickets)
Sentio House, Pynes Hill, Exeter, Devon, EX2 5AZ
www.digitickets.co.uk/compliance-request
If you have concerns about how we use your personal information, you may submit a privacy complaint to us using the contact details above.
We will acknowledge your complaint and investigate it in accordance with applicable data protection legislation. We aim to respond without undue delay and within the timescales required by law.
If you remain dissatisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO).
Other Websites
This Privacy Policy applies only to this Website. Links to third-party websites are provided for convenience only. We are not responsible for the privacy practices of those websites, and we encourage you to review their privacy policies before providing any personal information.
Last Updated: 5 August 2026