Privacy Policy

Fernwood Events Limited

Registered Office:
15 Fernwood Close
Bromley
Kent
BR1 3EZ
United Kingdom

Company Registration Number: 15009944

Website: www.fernwoodevents.com

Email: enquiry@fernwoodevents.com

Last reviewed: August 2026

1. About this Privacy Policy

Fernwood Events Limited (“Fernwood Events”, “we”, “us” or “our”) is a UK-based global venue-finding and event services agency.

We provide venue-finding, event sourcing, enquiry management and related services to clients and work with hotels, venues, destinations, Destination Management Companies (DMCs), transport providers and other event suppliers internationally.

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you:

  • visit or use our website;
  • contact us by email, telephone or other communication methods;
  • submit an event, venue or accommodation enquiry;
  • request or use our venue-finding or event-related services;
  • communicate with us as a client, prospective client, supplier or business contact;
  • attend or participate in an event arranged or supported by us; or
  • otherwise interact with Fernwood Events.

We are committed to handling personal information responsibly, transparently and in accordance with applicable UK data-protection legislation.

This Privacy Policy should be read together with any applicable terms and conditions, booking conditions, cookie information and other notices that we may provide to you.

2. Who is responsible for your personal information?

Fernwood Events Limited is the data controller for the personal information that we process for our own business purposes.

Our contact details are:

Fernwood Events Limited
15 Fernwood Close
Bromley
Kent
BR1 3EZ
United Kingdom

Email: enquiry@fernwoodevents.com

If you have a question about how we use your personal information, wish to exercise one of your data-protection rights, or have a privacy concern, please contact us using the details above.

Fernwood Events is not required to appoint a Data Protection Officer (DPO) where the legal requirements for mandatory appointment do not apply to our business. We nevertheless maintain a designated contact point for data-protection matters through the contact details above.

3. The personal information we may collect

The information we collect depends on how you interact with Fernwood Events.

This may include:

Contact and identification information

  • Name and surname.
  • Job title or position.
  • Company or organisation name.
  • Business address.
  • Personal or business email address.
  • Telephone or mobile number.
  • Other contact details that you choose to provide.

Event and enquiry information

Where relevant to an event enquiry, we may process information such as:

  • Event dates.
  • Destination and venue requirements.
  • Number of delegates or guests.
  • Accommodation requirements.
  • Rooming information.
  • Meeting-room requirements.
  • Event schedules.
  • Travel and transfer requirements.
  • Venue preferences.
  • Budget information.
  • Event type and purpose.
  • Supplier preferences.
  • Other information necessary to source and coordinate suitable venues and event services.

Individual event requirements

Where necessary for arranging an event, we may process information relating to:

  • Dietary requirements and allergies.
  • Accessibility or mobility requirements.
  • Room preferences.
  • Special assistance requirements.
  • Cultural or religious requirements where voluntarily provided and relevant to the event.
  • Other information necessary to make appropriate arrangements for an individual.

Some information of this nature may constitute special category personal data under applicable data-protection legislation. We will only process such information where there is an appropriate legal basis and, where required, an additional condition for processing special category data.

We will seek to minimise the amount of sensitive information collected and only share it with relevant suppliers where necessary to provide the requested service or where otherwise permitted by law.

Booking and service information

We may maintain records relating to:

  • Enquiries.
  • Quotations and proposals.
  • Venues and suppliers considered.
  • Confirmations.
  • Bookings and event arrangements.
  • Correspondence.
  • Changes and cancellations.
  • Supplier communications.
  • Client preferences and service history.

Financial and transaction information

Where necessary for our services, we may process:

  • Invoices.
  • Payment records.
  • Bank details.
  • Commission information.
  • Billing information.
  • Transaction records.

Fernwood Events does not routinely need to store customers’ full payment-card details. Where payment-card information is required by a hotel, venue, DMC or other supplier, the information may be provided directly to that supplier or handled by an appropriate payment service provider rather than being retained by Fernwood Events.

We will not request or retain payment-card information unless there is a genuine business requirement and appropriate safeguards are in place.

Technical and website information

When you use our website, certain technical information may be collected automatically, depending on the technologies used on the website.

This may include:

  • IP address.
  • Browser type and version.
  • Device type.
  • Operating system.
  • General location information derived from technical data.
  • Website pages visited.
  • Referring website.
  • Date and time of visits.
  • Technical information about your interaction with the website.

Some of this information may be collected through cookies or similar technologies. Where required, consent will be obtained before non-essential cookies or similar technologies are used.

Communications

We may retain communications between you and Fernwood Events, including emails, enquiry forms, telephone records where lawfully recorded, and other correspondence.

This helps us provide our services, maintain accurate records, resolve enquiries and protect our legitimate business interests.

4. How we collect personal information

We may collect personal information:

  • Directly from you.
  • From your employer or organisation.
  • From an event organiser or authorised representative.
  • From colleagues, assistants, travel managers or other authorised contacts.
  • From hotels, venues, DMCs and other event suppliers.
  • From event platforms or intermediary organisations where appropriate.
  • Through our website and enquiry forms.
  • Through business networking and industry events.
  • From publicly available professional or business sources.
  • From third-party systems or platforms used to manage enquiries or events.
  • From other organisations where this is lawful and necessary for providing our services.

Where we obtain personal information from another source, we will provide the privacy information required by applicable law, subject to any lawful exceptions.

5. Why we use personal information

We may use personal information for the following purposes:

Providing our services

To:

  • Respond to enquiries.
  • Source venues, hotels and event suppliers.
  • Prepare quotations and proposals.
  • Communicate with clients and suppliers.
  • Coordinate event requirements.
  • Manage bookings and arrangements.
  • Communicate dietary, accessibility and other relevant requirements to appropriate suppliers.
  • Provide information requested by clients.
  • Manage changes, cancellations and amendments.
  • Provide customer support.

Managing our business

To:

  • Maintain business records.
  • Manage supplier and client relationships.
  • Process invoices and payments.
  • Calculate and receive commissions.
  • Manage accounts and financial records.
  • Obtain professional advice where required.
  • Protect our business and legal interests.
  • Prevent fraud and misuse.
  • Resolve complaints and disputes.
  • Enforce contractual rights.

Legal and regulatory compliance

To:

  • Comply with applicable laws and regulations.
  • Meet accounting, tax and financial-record requirements.
  • Respond to lawful requests from regulators, authorities or law-enforcement bodies.
  • Establish, exercise or defend legal claims.

Marketing and business development

Where lawful, we may use business contact information to communicate information about Fernwood Events, our venue-finding services, event services and relevant business opportunities.

We will comply with applicable direct-marketing and electronic-communications requirements, including the Privacy and Electronic Communications Regulations (PECR).

The rules can differ depending on whether we are contacting an individual, sole trader, partnership or corporate business contact. For example, the PECR rules for electronic marketing to corporate subscribers differ from those applying to individuals and certain other subscribers. (ICO⁠)

Where consent is required, we will obtain valid consent before sending the relevant marketing.

Where legitimate interests may lawfully be relied upon, we will consider whether the processing is necessary, proportionate and consistent with the individual’s rights and reasonable expectations.

You can object to direct marketing at any time.

Every marketing communication will provide an appropriate method of opting out or unsubscribing.

6. Lawful bases for processing

We will only process personal information where we have a lawful basis to do so.

Depending on the circumstances, these may include:

Contract

Where processing is necessary to enter into or perform a contract with you or your organisation.

For example, this may include processing information necessary to manage an event enquiry, booking or service.

Legal obligation

Where processing is necessary for Fernwood Events to comply with a legal or regulatory obligation.

For example, accounting, tax and legally required record-keeping.

Legitimate interests

Where processing is necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by the individual’s rights and freedoms.

Examples may include:

  • Managing business relationships.
  • Responding to business enquiries.
  • Venue and supplier sourcing.
  • Business administration.
  • Fraud prevention.
  • IT and information security.
  • Protecting our legal rights.
  • Certain forms of business-to-business marketing where lawful.
  • Improving our services.

Where we rely on legitimate interests, we will consider the nature of the processing, its necessity and its impact on individuals.

Consent

Where the law requires consent, we will request it.

For example, consent may be required for certain marketing activities or certain uses of special category personal data.

Consent can be withdrawn at any time.

Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Vital interests

In exceptional circumstances, personal information may be processed where necessary to protect someone’s vital interests.

Legal claims

Personal information may be processed where necessary for the establishment, exercise or defence of legal claims.

7. Special category personal information

Some information that may be provided for event arrangements can constitute special category personal data, including certain information concerning health, medical requirements or religious beliefs.

Fernwood Events will only process such information where lawful and necessary.

Where appropriate, we may ask for explicit consent or rely on another lawful condition available under applicable data-protection legislation.

We will:

  • Collect only information that is reasonably necessary.
  • Avoid requesting unnecessary medical information.
  • Limit access to people who need the information.
  • Share information only with relevant suppliers or parties where necessary and lawful.
  • Take reasonable steps to protect the information.
  • Delete or anonymise information when it is no longer required.

Clients should avoid providing medical or other sensitive information unless it is genuinely necessary for the event arrangements.

8. Who we may share personal information with

Depending on the service being provided, we may share relevant personal information with:

  • Hotels.
  • Venues.
  • Destination Management Companies (DMCs).
  • Destination organisations.
  • Transport providers.
  • Restaurants.
  • Event suppliers.
  • Conference and meeting facilities.
  • Accommodation providers.
  • Event technology providers.
  • Payment providers where applicable.
  • CRM and enquiry-management providers.
  • IT, email and cloud-service providers.
  • Professional advisers, including accountants, lawyers and insurers where necessary.
  • Regulators, government bodies, law-enforcement authorities or courts where legally required.

We aim to share only the information reasonably necessary for the particular purpose.

For example, where a hotel needs a guest’s name and accessibility requirement to provide an appropriate room, we will seek to provide the relevant information rather than unnecessary personal details.

Some suppliers may act as independent controllers of the personal information they receive. In those circumstances, their own privacy policies may also apply.

Where a third party processes personal information on our behalf, we will seek to ensure that appropriate contractual and security arrangements are in place.

9. International transfers

Because Fernwood Events operates internationally and works with venues, hotels, DMCs and suppliers around the world, personal information may sometimes be transferred to or accessed from countries outside the United Kingdom.

Where a transfer is legally considered a restricted international transfer, we will only make the transfer where an appropriate lawful mechanism or safeguard is available.

Depending on the circumstances, this may include:

  • An applicable adequacy regulation or adequacy decision.
  • The UK International Data Transfer Agreement (IDTA).
  • The UK Addendum to EU Standard Contractual Clauses.
  • Other lawful transfer mechanisms or exceptions permitted by applicable law.

Where appropriate safeguards are required, we will take reasonable steps to ensure that they are implemented.

The ICO recognises mechanisms including the UK IDTA and UK Addendum as standard contractual safeguards for restricted transfers. (ICO⁠)

10. Data processors and technology providers

Fernwood Events uses third-party technology and service providers to operate its business.

These may include providers of:

  • Email and communications.
  • Website hosting.
  • CRM and enquiry-management systems.
  • Cloud storage.
  • Accounting and financial systems.
  • Website analytics.
  • Cybersecurity and IT services.
  • Event-management platforms.
  • Online forms and communication tools.

Where these providers process personal information on our behalf, we seek to ensure that appropriate contractual, technical and organisational safeguards are in place.

We do not permit service providers to use personal information for their own purposes where they are acting solely as our processor, except where otherwise permitted by law or contract.

11. Data security

Fernwood Events takes reasonable and proportionate technical and organisational measures to protect personal information.

Depending on the circumstances, these measures may include:

  • Password protection.
  • Access controls.
  • Limiting access to information on a need-to-know basis.
  • Secure email and cloud services.
  • Device security.
  • Software and system updates.
  • Security awareness.
  • Secure disposal of information.
  • Appropriate supplier and processor controls.
  • Back-up and recovery arrangements.
  • Procedures for responding to suspected data breaches.

No method of transmission or storage can be guaranteed to be completely secure.

We therefore cannot guarantee absolute security of information, but we continually seek to maintain appropriate safeguards proportionate to the nature and risks of our business.

12. Data breaches

Fernwood Events maintains procedures for identifying, assessing, containing, recording and responding to personal-data breaches.

If a personal-data breach occurs, we will assess the incident and determine whether notification to the Information Commissioner’s Office (ICO) is required.

Where a breach is notifiable to the ICO, we will report it without undue delay and, where feasible, within 72 hours of becoming aware of it.

Where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will communicate the breach to those individuals without undue delay, subject to any applicable legal restrictions.

We will maintain appropriate records of personal-data breaches and the steps taken in response.

We will not automatically notify every individual of every security incident because the law requires an assessment of the nature and risk of each breach.

The ICO states that breach reporting is assessed on a case-by-case basis and that reportable breaches must generally be notified within 72 hours. (ICO⁠)

13. How long we keep personal information

We do not retain personal information indefinitely.

We retain information for as long as reasonably necessary for the purposes for which it was collected, taking into account:

  • The nature of the information.
  • The purpose for which it was collected.
  • Whether there is an ongoing client or supplier relationship.
  • Contractual requirements.
  • Legal and regulatory requirements.
  • Accounting and tax obligations.
  • Potential or actual disputes.
  • Legal claims.
  • Fraud prevention.
  • Our legitimate business requirements.

Different categories of information may therefore be retained for different periods.

As a general approach, client, enquiry and transaction records may be retained for the duration of the relevant business relationship and for an appropriate period afterwards where necessary for legal, accounting, tax, regulatory or legitimate business purposes.

Where a specific statutory retention period applies, we will retain information for at least the period required by law.

We will periodically review retained information and securely delete or anonymise information that is no longer required, subject to lawful reasons for continued retention.

14. Your data-protection rights

Depending on the circumstances and applicable law, you may have the following rights:

Right of access

You can request a copy of the personal information we hold about you.

Right to rectification

You can ask us to correct inaccurate or incomplete information.

Right to erasure

You may ask us to delete personal information in certain circumstances.

This right is not absolute and does not apply where we have a lawful reason to retain or process the information.

Right to restriction

You may ask us to restrict the processing of your information in certain circumstances.

Right to object

You may object to certain processing where the law gives you that right.

You have an absolute right to object to direct marketing.

Right to data portability

In certain circumstances, you may ask us to provide personal information you have supplied to us in a structured, commonly used and machine-readable format, or request that it is transferred to another organisation.

Right to withdraw consent

Where we rely on consent, you may withdraw your consent at any time.

Rights relating to automated decision-making

You may have rights relating to decisions made solely by automated processing, including profiling, where those decisions have legal or similarly significant effects.

Fernwood Events does not currently make decisions solely by automated processing that have legal or similarly significant effects on individuals.

The availability of individual rights depends on the circumstances and the lawful basis for processing. We will explain if a particular right does not apply to a specific request.

15. How to exercise your rights

To exercise a data-protection right, please contact:

Email: enquiry@fernwoodevents.com

Please provide enough information to allow us to identify you and understand your request.

We may need to request additional information to verify your identity before releasing or changing personal information.

We will respond to valid requests within the applicable legal timeframe.

Requests are normally handled without charge. We may charge a reasonable fee or refuse a request where the law permits this because a request is manifestly unfounded or excessive.

16. Complaints

If you have concerns about how Fernwood Events has handled your personal information, please contact us first at:

enquiry@fernwoodevents.com

We will investigate your concern and seek to resolve it appropriately.

You also have the right to complain directly to the UK’s data-protection regulator, the Information Commissioner’s Office (ICO).

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
United Kingdom

Telephone: 0303 123 1113

Further information is available through the ICO website.

You are not required to contact Fernwood Events before contacting the ICO.

The ICO’s published contact details are Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, telephone 0303 123 1113. (ICO⁠)

17. Marketing preferences

If you receive marketing communications from Fernwood Events, you can unsubscribe at any time.

You can:

We will respect valid marketing objections and unsubscribe requests.

Please note that opting out of marketing does not prevent us from sending essential service-related communications, such as information concerning an enquiry, booking, contract, payment or event.

18. Cookies and similar technologies

Our website may use cookies and similar technologies.

Some cookies are necessary for the operation, security and functionality of the website.

Other cookies, including certain analytics, advertising or tracking technologies, may require consent depending on how they operate and the applicable legal requirements.

Where consent is required, we will seek consent before placing or using the relevant non-essential cookies.

You can manage cookies through your browser settings and, where available, our website cookie-management tools.

Our Cookie Policy should be read together with this Privacy Policy.

19. Third-party websites

Our website may contain links to third-party websites, including hotels, venues, DMCs, suppliers, industry organisations and other websites.

Fernwood Events is not responsible for the privacy practices, security or content of third-party websites.

You should review the privacy policy of any third-party website before providing personal information to it.

20. Children

Our services are primarily intended for businesses, organisations, event professionals and adults.

We do not knowingly seek to collect personal information from children for marketing purposes.

Where information relating to a child is genuinely required for an event or booking, it should be provided by an appropriate parent, guardian, organiser or authorised adult.

We will take appropriate care when processing children’s information and will only collect information that is reasonably necessary.

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes in legislation.
  • Regulatory guidance.
  • Changes to our services.
  • Changes to technology.
  • Changes to the way we process personal information.
  • Changes to our suppliers or service providers.
  • Changes to our business practices.

Where material changes are made, we will take appropriate steps to bring them to your attention.

The current version will always be published on our website.

Last reviewed: September 2026

Fernwood Events Limited.