Fernwood Events Limited
Registered Office:
15 Fernwood Close
Bromley
Kent
BR1 3EZ
United Kingdom
Company Registration Number: 15009944
Website: www.fernwoodevents.com
Email: enquiry@fernwoodevents.com
Last reviewed: August 2026
1. About this Privacy Policy
Fernwood Events Limited (“Fernwood Events”, “we”, “us” or
“our”) is a UK-based global venue-finding and event services agency.
We provide venue-finding, event sourcing, enquiry management
and related services to clients and work with hotels, venues, destinations,
Destination Management Companies (DMCs), transport providers and other event
suppliers internationally.
This Privacy Policy explains how we collect, use, store,
disclose and protect personal information when you:
We are committed to handling personal information
responsibly, transparently and in accordance with applicable UK data-protection
legislation.
This Privacy Policy should be read together with any
applicable terms and conditions, booking conditions, cookie information and
other notices that we may provide to you.
2. Who is responsible for your personal information?
Fernwood Events Limited is the data controller for the
personal information that we process for our own business purposes.
Our contact details are:
Fernwood Events Limited
15 Fernwood Close
Bromley
Kent
BR1 3EZ
United Kingdom
Email: enquiry@fernwoodevents.com
If you have a question about how we use your personal
information, wish to exercise one of your data-protection rights, or have a
privacy concern, please contact us using the details above.
Fernwood Events is not required to appoint a Data Protection
Officer (DPO) where the legal requirements for mandatory appointment do not
apply to our business. We nevertheless maintain a designated contact point for
data-protection matters through the contact details above.
3. The personal information we may collect
The information we collect depends on how you interact with
Fernwood Events.
This may include:
Contact and identification information
Event and enquiry information
Where relevant to an event enquiry, we may process
information such as:
Individual event requirements
Where necessary for arranging an event, we may process
information relating to:
Some information of this nature may constitute special
category personal data under applicable data-protection legislation. We
will only process such information where there is an appropriate legal basis
and, where required, an additional condition for processing special category
data.
We will seek to minimise the amount of sensitive information
collected and only share it with relevant suppliers where necessary to provide
the requested service or where otherwise permitted by law.
Booking and service information
We may maintain records relating to:
Financial and transaction information
Where necessary for our services, we may process:
Fernwood Events does not routinely need to store
customers’ full payment-card details. Where payment-card information is
required by a hotel, venue, DMC or other supplier, the information may be
provided directly to that supplier or handled by an appropriate payment service
provider rather than being retained by Fernwood Events.
We will not request or retain payment-card information
unless there is a genuine business requirement and appropriate safeguards are
in place.
Technical and website information
When you use our website, certain technical information may
be collected automatically, depending on the technologies used on the website.
This may include:
Some of this information may be collected through cookies or
similar technologies. Where required, consent will be obtained before
non-essential cookies or similar technologies are used.
Communications
We may retain communications between you and Fernwood
Events, including emails, enquiry forms, telephone records where lawfully
recorded, and other correspondence.
This helps us provide our services, maintain accurate
records, resolve enquiries and protect our legitimate business interests.
4. How we collect personal information
We may collect personal information:
Where we obtain personal information from another source, we
will provide the privacy information required by applicable law, subject to any
lawful exceptions.
5. Why we use personal information
We may use personal information for the following purposes:
Providing our services
To:
Managing our business
To:
Legal and regulatory compliance
To:
Marketing and business development
Where lawful, we may use business contact information to
communicate information about Fernwood Events, our venue-finding services,
event services and relevant business opportunities.
We will comply with applicable direct-marketing and
electronic-communications requirements, including the Privacy and Electronic
Communications Regulations (PECR).
The rules can differ depending on whether we are contacting
an individual, sole trader, partnership or corporate business contact. For
example, the PECR rules for electronic marketing to corporate subscribers
differ from those applying to individuals and certain other subscribers. (ICO)
Where consent is required, we will obtain valid consent
before sending the relevant marketing.
Where legitimate interests may lawfully be relied upon, we
will consider whether the processing is necessary, proportionate and consistent
with the individual’s rights and reasonable expectations.
You can object to direct marketing at any time.
Every marketing communication will provide an appropriate
method of opting out or unsubscribing.
6. Lawful bases for processing
We will only process personal information where we have a
lawful basis to do so.
Depending on the circumstances, these may include:
Contract
Where processing is necessary to enter into or perform a
contract with you or your organisation.
For example, this may include processing information
necessary to manage an event enquiry, booking or service.
Legal obligation
Where processing is necessary for Fernwood Events to comply
with a legal or regulatory obligation.
For example, accounting, tax and legally required
record-keeping.
Legitimate interests
Where processing is necessary for our legitimate business
interests or those of a third party, provided those interests are not
overridden by the individual’s rights and freedoms.
Examples may include:
Where we rely on legitimate interests, we will consider the
nature of the processing, its necessity and its impact on individuals.
Consent
Where the law requires consent, we will request it.
For example, consent may be required for certain marketing
activities or certain uses of special category personal data.
Consent can be withdrawn at any time.
Withdrawing consent does not affect the lawfulness of
processing carried out before consent was withdrawn.
Vital interests
In exceptional circumstances, personal information may be
processed where necessary to protect someone’s vital interests.
Legal claims
Personal information may be processed where necessary for
the establishment, exercise or defence of legal claims.
7. Special category personal information
Some information that may be provided for event arrangements
can constitute special category personal data, including certain information
concerning health, medical requirements or religious beliefs.
Fernwood Events will only process such information where
lawful and necessary.
Where appropriate, we may ask for explicit consent or rely
on another lawful condition available under applicable data-protection
legislation.
We will:
Clients should avoid providing medical or other sensitive
information unless it is genuinely necessary for the event arrangements.
8. Who we may share personal information with
Depending on the service being provided, we may share
relevant personal information with:
We aim to share only the information reasonably necessary
for the particular purpose.
For example, where a hotel needs a guest’s name and
accessibility requirement to provide an appropriate room, we will seek to
provide the relevant information rather than unnecessary personal details.
Some suppliers may act as independent controllers of the
personal information they receive. In those circumstances, their own privacy
policies may also apply.
Where a third party processes personal information on our
behalf, we will seek to ensure that appropriate contractual and security
arrangements are in place.
9. International transfers
Because Fernwood Events operates internationally and works
with venues, hotels, DMCs and suppliers around the world, personal information
may sometimes be transferred to or accessed from countries outside the United
Kingdom.
Where a transfer is legally considered a restricted
international transfer, we will only make the transfer where an appropriate
lawful mechanism or safeguard is available.
Depending on the circumstances, this may include:
Where appropriate safeguards are required, we will take
reasonable steps to ensure that they are implemented.
The ICO recognises mechanisms including the UK IDTA and UK
Addendum as standard contractual safeguards for restricted transfers. (ICO)
10. Data processors and technology providers
Fernwood Events uses third-party technology and service
providers to operate its business.
These may include providers of:
Where these providers process personal information on our
behalf, we seek to ensure that appropriate contractual, technical and
organisational safeguards are in place.
We do not permit service providers to use personal
information for their own purposes where they are acting solely as our
processor, except where otherwise permitted by law or contract.
11. Data security
Fernwood Events takes reasonable and proportionate technical
and organisational measures to protect personal information.
Depending on the circumstances, these measures may include:
No method of transmission or storage can be guaranteed to be
completely secure.
We therefore cannot guarantee absolute security of
information, but we continually seek to maintain appropriate safeguards
proportionate to the nature and risks of our business.
12. Data breaches
Fernwood Events maintains procedures for identifying,
assessing, containing, recording and responding to personal-data breaches.
If a personal-data breach occurs, we will assess the
incident and determine whether notification to the Information Commissioner’s
Office (ICO) is required.
Where a breach is notifiable to the ICO, we will report it
without undue delay and, where feasible, within 72 hours of becoming aware of
it.
Where a breach is likely to result in a high risk to the
rights and freedoms of affected individuals, we will communicate the breach to
those individuals without undue delay, subject to any applicable legal
restrictions.
We will maintain appropriate records of personal-data
breaches and the steps taken in response.
We will not automatically notify every individual of every
security incident because the law requires an assessment of the nature and risk
of each breach.
The ICO states that breach reporting is assessed on a
case-by-case basis and that reportable breaches must generally be notified
within 72 hours. (ICO)
13. How long we keep personal information
We do not retain personal information indefinitely.
We retain information for as long as reasonably necessary
for the purposes for which it was collected, taking into account:
Different categories of information may therefore be
retained for different periods.
As a general approach, client, enquiry and transaction
records may be retained for the duration of the relevant business relationship
and for an appropriate period afterwards where necessary for legal, accounting,
tax, regulatory or legitimate business purposes.
Where a specific statutory retention period applies, we will
retain information for at least the period required by law.
We will periodically review retained information and
securely delete or anonymise information that is no longer required, subject to
lawful reasons for continued retention.
14. Your data-protection rights
Depending on the circumstances and applicable law, you may
have the following rights:
Right of access
You can request a copy of the personal information we hold
about you.
Right to rectification
You can ask us to correct inaccurate or incomplete
information.
Right to erasure
You may ask us to delete personal information in certain
circumstances.
This right is not absolute and does not apply where we have
a lawful reason to retain or process the information.
Right to restriction
You may ask us to restrict the processing of your
information in certain circumstances.
Right to object
You may object to certain processing where the law gives you
that right.
You have an absolute right to object to direct marketing.
Right to data portability
In certain circumstances, you may ask us to provide personal
information you have supplied to us in a structured, commonly used and
machine-readable format, or request that it is transferred to another
organisation.
Right to withdraw consent
Where we rely on consent, you may withdraw your consent at
any time.
Rights relating to automated decision-making
You may have rights relating to decisions made solely by
automated processing, including profiling, where those decisions have legal or
similarly significant effects.
Fernwood Events does not currently make decisions solely by
automated processing that have legal or similarly significant effects on
individuals.
The availability of individual rights depends on the
circumstances and the lawful basis for processing. We will explain if a
particular right does not apply to a specific request.
15. How to exercise your rights
To exercise a data-protection right, please contact:
Email: enquiry@fernwoodevents.com
Please provide enough information to allow us to identify
you and understand your request.
We may need to request additional information to verify your
identity before releasing or changing personal information.
We will respond to valid requests within the applicable
legal timeframe.
Requests are normally handled without charge. We may charge
a reasonable fee or refuse a request where the law permits this because a
request is manifestly unfounded or excessive.
16. Complaints
If you have concerns about how Fernwood Events has handled
your personal information, please contact us first at:
We will investigate your concern and seek to resolve it
appropriately.
You also have the right to complain directly to the UK’s
data-protection regulator, the Information Commissioner’s Office (ICO).
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom
Telephone: 0303 123 1113
Further information is available through the ICO website.
You are not required to contact Fernwood Events before
contacting the ICO.
The ICO’s published contact details are Wycliffe House,
Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113. (ICO)
17. Marketing preferences
If you receive marketing communications from Fernwood
Events, you can unsubscribe at any time.
You can:
We will respect valid marketing objections and unsubscribe
requests.
Please note that opting out of marketing does not prevent us
from sending essential service-related communications, such as information
concerning an enquiry, booking, contract, payment or event.
18. Cookies and similar technologies
Our website may use cookies and similar technologies.
Some cookies are necessary for the operation, security and
functionality of the website.
Other cookies, including certain analytics, advertising or
tracking technologies, may require consent depending on how they operate and
the applicable legal requirements.
Where consent is required, we will seek consent before
placing or using the relevant non-essential cookies.
You can manage cookies through your browser settings and,
where available, our website cookie-management tools.
Our Cookie Policy should be read together with this Privacy
Policy.
19. Third-party websites
Our website may contain links to third-party websites,
including hotels, venues, DMCs, suppliers, industry organisations and other
websites.
Fernwood Events is not responsible for the privacy
practices, security or content of third-party websites.
You should review the privacy policy of any third-party
website before providing personal information to it.
20. Children
Our services are primarily intended for businesses,
organisations, event professionals and adults.
We do not knowingly seek to collect personal information
from children for marketing purposes.
Where information relating to a child is genuinely required
for an event or booking, it should be provided by an appropriate parent,
guardian, organiser or authorised adult.
We will take appropriate care when processing children’s
information and will only collect information that is reasonably necessary.
21. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to
reflect:
Where material changes are made, we will take appropriate
steps to bring them to your attention.
The current version will always be published on our website.
Last reviewed: September 2026