Thomley Ticket Portal

Privacy Policy

Thomley Privacy Policy

Privacy Policy – The Thomley Hall Centre Ltd

Effective Date: 19th May 2026

Privacy Policy

Welcome to The Thomley Hall Centre Ltd (Thomley).

We are committed to protecting your privacy and handling your personal information in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and other applicable laws.

This Privacy Policy explains how we collect, use, store, and protect personal information when you use our website and purchase day tickets for activities and services at our disability activity centre.

1. Who We Are

Thomley

Address:
The Thomley Hall Centre Ltd
Menmarsh Road
Worminghall
Buckinghamshire
HP18 9JZ

Email: enquiries@thomley.org.uk

Telephone: 01844 338380

We are the data controller responsible for your personal data.

2. Information We Collect

We may collect and process the following information.

Personal Information

This may include your full name, email address, telephone number, billing address, and emergency contact details.

Booking Information

This may include ticket purchases, attendance dates, participant details, and activity selections.

Accessibility and Health Information

Where voluntarily provided and necessary for participation or safety, we may collect information relating to accessibility requirements, mobility assistance needs, medical conditions or allergies, and carer or support worker details.

This information is treated as special category data under GDPR and is processed only where necessary and with appropriate safeguards.

Payment Information

Payments are securely processed by third-party payment providers. We do not store full card details on our servers.

Technical Information

We may collect technical information such as your IP address, browser type, device information, cookies, and website analytics data.

3. How We Use Your Information

We use personal information for a variety of purposes, including processing ticket bookings, managing attendance and activities, providing accessibility support, ensuring participant safety and wellbeing, communicating booking confirmations and updates, responding to enquiries, providing statistics for funders, improving our services and website, and meeting our legal and safeguarding obligations.

4. Legal Basis for Processing

Under UK GDPR, we rely on the following lawful bases for processing personal data:

  • Processing bookings – Contract

  • Providing accessibility support – Vital interests and/or explicit consent

  • Safeguarding and safety – Legal obligation

  • Customer communications – Legitimate interests

  • Marketing communications – Consent

5. Sharing Your Information

We may share information with activity staff and support personnel, payment processing providers, IT and website service providers, emergency services where necessary, and regulatory or safeguarding authorities where legally required.

We do not sell personal information to third parties.

6. Data Retention

We retain personal data only for as long as necessary for booking administration, safeguarding obligations, financial and legal recordkeeping, and resolving disputes.

Special category data is securely deleted when it is no longer required.

7. Your Rights

Under UK GDPR, you have the right to access your personal data, correct inaccurate information, request deletion of your data, restrict processing, object to processing, withdraw consent, and lodge a complaint with the UK Information Commissioner’s Office (ICO).

For any requests relating to your personal data, please contact: enquiries@thomley.org.uk

8. Cookies

We use cookies to ensure website functionality, improve user experience, and monitor website performance and analytics.

You can manage cookie preferences through your browser settings.

9. Security

We implement appropriate technical and organisational measures to protect your information. These measures include SSL encryption, restricted data access, secure payment systems, and confidential staff handling procedures.

10. Children and Vulnerable Individuals

We recognise the importance of safeguarding children and vulnerable individuals. Personal information relating to children or vulnerable adults is handled with additional care and appropriate protections.

Parents, guardians, carers, or authorised representatives may provide information on behalf of participants where appropriate.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Any updates will be posted on this page together with a revised effective date.

12. Contact Us

Thomley

Address:
The Thomley Hall Centre Ltd
Menmarsh Road
Worminghall
Buckinghamshire
HP18 9JZ

Email: enquiries@thomley.org.uk

Telephone: 01844 338380

DigiTickets Privacy Policy

Policy Owner

This policy is owned and distributed by IT and Compliance manager of Digital Ticketing Systems Limited

Who we are

In this Privacy Policy, references to "we", "us", and "our"" are to Digital Ticketing Systems Limited (Company number 07044584). References to "our Website" or "the Website" are to *.digitickets.co.uk.

Digital Ticketing Systems Limited is the data controller responsible for the personal information collected through this Website.

Information We Collect

We may collect and process the following categories of personal information:

Information You Provide Directly

When you contact us, make a purchase, register for services, or complete forms on our Website, we may collect information such as:

  • Name
  • Postal address
  • Email address
  • Telephone number
  • Purchase and booking information
  • Any other information voluntarily provided by you

Payment Information

Payments made through our Website are processed by authorised payment service providers. We do not store your full credit or debit card details on our systems.

Our payment providers may process payment information and carry out fraud prevention and verification checks. Where international transfers are required, appropriate safeguards will be applied in accordance with applicable data protection laws.

Digital Ticketing Systems is PCI DSS v4.0.1 compliant and are annually assessed/certified.

Website Usage Information

When you visit our Website, we may automatically collect:

  • IP address
  • Browser type and version
  • Device information
  • Screen resolution
  • Operating system
  • Referral source
  • Pages visited and actions taken on the Website
  • Date and time of access

Marketing Preferences

If you choose to receive marketing communications, we will record your preferences and any interactions with our emails, including whether emails are opened or links are clicked.

Cookies and Similar Technologies

We use cookies and similar technologies to operate our Website, remember your preferences, analyse usage, and improve user experience. Further information is provided in our Cookie Policy below.

How We Use Your Information

We process personal information for the following purposes:

  • To provide products and services you request
  • To process transactions and fulfil orders
  • To provide customer support and after-sales services
  • To manage bookings and accounts
  • To improve our Website, products, and services
  • To ensure Website security and prevent fraud
  • To comply with legal and regulatory obligations
  • To send marketing communications where we have your consent or another lawful basis to do so

Lawful Basis for Processing

Under UK GDPR, we rely on one or more of the following lawful bases:

  • Performance of a contract: to provide goods or services you have requested.
  • Legal obligation: where processing is necessary to comply with legal requirements.
  • Legitimate interests: to manage and improve our business, Website security, and customer experience.
  • Consent: where required, including for certain cookies and marketing communications.

Where we rely on consent, you may withdraw it at any time.

Sharing Your Information

We may share your personal information with:

  • Payment processors
  • Hosting and IT service providers
  • Delivery and fulfilment partners
  • Marketing and communications providers
  • Analytics and Website performance providers
  • Professional advisers and auditors
  • Regulatory authorities, law enforcement agencies, or courts where required by law

All third-party service providers are required to process personal information only on our instructions and in accordance with applicable data protection laws.

We do not sell personal information to third parties.

International Transfers

Where personal information is transferred outside the United Kingdom, we will ensure appropriate safeguards are in place, such as:

  • Transfers to countries deemed to provide an adequate level of protection; or
  • Approved contractual safeguards, such as the UK International Data Transfer Agreement (IDTA) or equivalent mechanisms.

Data Retention

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, regulatory, and reporting requirements.

Retention periods vary depending on the type of information and the purpose for which it is processed.

Cookie Policy

What Are Cookies?

Cookies are small text files stored on your device when you visit a website. They help websites function properly, remember preferences, improve performance, and provide analytics information.

How We Use Cookies

We use the following categories of cookies:

Strictly Necessary Cookies

These cookies are essential for the operation of the Website and cannot be disabled through our cookie management tools.

Cookie

Purpose

Duration

PHPSESSID

Maintains user session and shopping basket functionality

Session / 24 minutes

dtAnalyticsConsent

Records cookie consent preferences

1 year

Analytics Cookies

These cookies help us understand how visitors interact with the Website so that we can improve performance and usability.

These cookies are only placed with your consent.

Google Analytics

Examples include:

  • _ga
  • _ga<container-id>
  • _gid
  • _gat_<tracker-name>

Used to collect aggregated statistical information about Website usage.

Google Privacy Information:

https://support.google.com/analytics/answer/6004245

Microsoft Clarity

Examples include:

  • _clck
  • _clsk
  • CLID
  • ANONCHK
  • MR
  • MUID
  • SM

Used to analyse user interactions and improve Website usability.

Microsoft Clarity Information:

Performance Monitoring Cookies

Performance monitoring tools help us identify technical issues and improve Website reliability.

Examples may include cookies used by services such as New Relic.

Managing Cookies

When you first visit our Website, you will be presented with a cookie banner allowing you to:

  • Accept all cookies
  • Reject non-essential cookies
  • Choose your cookie preferences

You may change your preferences at any time through our cookie settings tool.

You can also manage cookies through your browser settings. Disabling certain cookies may affect Website functionality.

Your Data Protection Rights

Under UK GDPR, you may have the right to:

  • Access your personal information
  • Correct inaccurate information
  • Request deletion of your information
  • Restrict processing
  • Object to processing
  • Request portability of your data
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with the Information Commissioner's Office (ICO)

For more information about your rights, visit:

https://ico.org.uk/

Automated Decision-Making

We do not generally make decisions producing legal or similarly significant effects using solely automated processing.

Where automated tools are used for fraud prevention, security monitoring, or service administration, appropriate safeguards will be applied in accordance with applicable data protection legislation.

Childrens Data

Our Website is not intended to knowingly collect personal information from children unless necessary to provide services requested by a parent, guardian, school, attraction, venue, or authorised organisation.

Where we process children's personal information, we take additional care to ensure appropriate protections are in place.

Contact Us

If you have any questions about this Privacy Policy or wish to exercise your rights, please contact:

Digital Ticketing Systems (t/a DigiTickets)

Sentio House, Pynes Hill, Exeter, Devon, EX2 5AZ

www.digitickets.co.uk/compliance-request

If you have concerns about how we use your personal information, you may submit a privacy complaint to us using the contact details above.

We will acknowledge your complaint and investigate it in accordance with applicable data protection legislation. We aim to respond without undue delay and within the timescales required by law.

If you remain dissatisfied with our response, you have the right to complain to the Information Commissioner's Office (ICO).

Other Websites

This Privacy Policy applies only to this Website. Links to third-party websites are provided for convenience only. We are not responsible for the privacy practices of those websites, and we encourage you to review their privacy policies before providing any personal information.

Last Updated: 5 August 2026