Privacy Policy

FUTURE FORUM FESTIVAL LTD PRIVACY POLICY

We are Future Forum Festival Ltd, trading as ‘Future Forum’ and ‘FuFo’, a private company limited by shares incorporated and registered in England and Wales under company number 16883521 and have our registered office at C/O Buckworths 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB (“Future Forum”, “we”, “our” or “us”).

We believe in protecting your privacy. This Policy will inform you as to how we look after your information when you interact with us as a user (“user” or “you”) and tells you about your privacy rights and how the law protects you.

This Policy applies to you if you buy or hold a ticket for, register for, or attend the Future Forum event (the “Event”), if you visit our website or use our event app, if you subscribe to our communications, or if you are a speaker, exhibitor, sponsor contact, supplier contact or media representative. Separate privacy notices apply to our employees and job applicants.

Future Forum is the “controller” of the personal data described in this Policy. That means we decide why and how it is used, and we are responsible for it. Where we share your personal data with our sponsors, partners or advertising platforms, those organisations decide independently how they use it and are separate controllers in their own right – see clause 4 (Who we share your information with).

We are registered with the Information Commissioner’s Office under registration number ZC205310.

1. IMPORTANT INFORMATION AND WHO WE ARE

Purpose of this Policy

1.1. This Policy aims to give you information on how Future Forum collects and processes your information, including any data you may provide.

1.2. It also explains your rights in relation to your information and how to contact us or the relevant regulator in the event that you have a complaint. Our collection, storage, use and sharing of your information is regulated by law, including under the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018 (“DPA 2018”) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (“PECR”), in each case as amended by the Data (Use and Access) Act 2025.

1.3. We may change this Privacy Policy from time to time. Where we make a material change to this Policy – in particular a change to the purposes for which we use your personal data or to the categories of recipient with whom we share it – we will notify you by email before that change takes effect. The version number and effective date at the top of this Policy will tell you which version applies. Changes to this Policy do not operate retrospectively and do not extend any consent you have previously given.

1.4. It is important that the information we hold about you is accurate and current. Please keep us informed if your information changes during your relationship with us.

1.5. We will not use your personal data for any purpose that is materially different from the purposes described in this Policy without first telling you and, where the law requires it, obtaining your consent.

How to contact us

1.6. If you have any questions about this Policy or our privacy practices, please contact us in the following ways:

  • Full name of legal entity: Future Forum Festival Ltd (CRN: 16883521)
  • E-mail address: info@futureforum.co
  • Postal address: C/O Buckworths 2nd Floor, 1-3 Worship Street, London, England, EC2A 2AB
  • ICO registration number: ZC205310

1.7. You have the right to make a complaint at any time to the Information Commissioner’s Office (the “ICO”), the United Kingdom’s supervisory authority for data protection issues (www.ico.org.uk). We would, however, appreciate the chance to deal with your concerns before you approach the ICO so please contact us in the first instance.

1.8. Making a complaint to us. If you are unhappy with how we have handled your personal data you can complain to us at info@futureforum.co. We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to investigate it, and tell you about the outcome without undue delay.

2. THE INFORMATION WE COLLECT ABOUT YOU

Depending on how you interact with us, we collect and use the following categories of personal data about you. Not all of these will apply to every individual:

  • Identity Data” includes your name, job title and company name;
  • Contact Data” includes your email address and mobile number;
  • Usage Data” includes information about how you interact with our emails; and
  • Public Information Data” includes your business contact information from publicly accessible sources.
  • Ticket and Registration Data” includes your booking reference, ticket type, the sessions and workshops you register for, your badge details and any group or company booking you form part of;
  • Transaction Data” includes details of the payments you make to us and the date and amount of those payments. Card payments are processed by our payment provider; we do not receive or store your full card number;
  • Marketing and Communications Data” includes your marketing preferences, and a record of any consent you give or withdraw (including the date, the wording you were shown and the channel through which you gave it);
  • Technical Data” includes your IP address, device and browser type, operating system, and identifiers set by cookies and similar technologies when you use our website or event app;
  • Event Participation Data” includes the sessions you attend, when your badge is scanned at entry points and at exhibitor or sponsor stands, your use of any networking or matchmaking feature in our event app, and any questions or contributions you submit during sessions;
  • Image and Recording Data” includes photographs, film and audio recordings of the Event in which you appear or are heard – see clause 10 (Photography, filming and recording);
  • Accessibility and Dietary Data” includes any access requirement, mobility requirement, dietary requirement or allergy you tell us about so that we can make appropriate arrangements for you; and
  • Correspondence Data” includes the content of enquiries, complaints and other correspondence between you and us.

2.1. Special category data. Some of the Accessibility and Dietary Data you give us may reveal information about your health, or about your religious or philosophical beliefs. Data protection law treats this as “special category data” and gives it extra protection. We only use it to make arrangements for you at the Event and to meet our health and safety obligations, we only use it on the basis of your explicit consent (or, in a medical emergency, to protect your or another person’s vital interests), we share it only with the venue and caterers to the extent they need it, and we delete it within 30 days after the Event.

2.2. Where we obtain your information. We collect most of your personal data directly from you when you register or buy a ticket, correspond with us, or attend the Event. We also receive personal data from: (a) our ticketing platform and our event app provider; (b) your employer or a colleague, where they book a ticket on your behalf; (c) sponsors and exhibitors, where you have asked them to pass your details to us; and (d) publicly accessible sources such as company websites, LinkedIn and industry directories, from which we compile Public Information Data. Where we obtain your business contact details from a publicly accessible source and go on to contact you, we will tell you where we obtained them in our first communication with you.

2.3. Children. The Event is intended for adults and we do not knowingly collect personal data relating to anyone under 18. If you believe a child has provided us with personal data, please contact us and we will delete it.

2.4. If you do not provide your information. Where we need your personal data in order to perform our contract with you (for example, to issue and validate your ticket) and you do not provide it, we may not be able to supply your ticket or admit you to the Event. We will tell you if this is the case at the time.

3. HOW WE USE YOUR INFORMATION

Under data protection law we can only use your personal data if we have a lawful basis for doing so. The lawful bases we rely on are set out below, and the purposes for which we use your personal data (and the basis we rely on for each) are set out at clause 3.1.

  • Consent – this may apply where you sign up to a mailing list or otherwise request to be sent certain information by us;
  • Processing your personal data is necessary for our legitimate interests (or those of a third party) and our interests do not override your fundamental rights. For example, this would apply where you have provided us with your personal data or we have otherwise acquired your personal data from another source and we contact you in respect of a matter that we believe will be of interest, value and relevance to you.
  • Performance of a contract – where we need to process your personal data in order to issue your ticket, admit you to the Event and provide the services you have paid for, or to take steps at your request before entering into that contract;
  • Compliance with a legal obligation – for example, keeping accounting and VAT records, and responding to lawful requests from regulators, the police or the courts;
  • Vital interests – in a medical emergency at the Event, where you are physically or legally incapable of giving consent; and
  • Explicit consent – which is the condition we rely on where we process special category data (see clause 2.1).

3.1. What we use your personal data for. We use your personal data for the following purposes:

  • to sell you a ticket, take payment, issue your booking confirmation and badge, and administer your booking – performance of a contract;
  • to plan, run and steward the Event, including access control, session capacity management and health and safety – performance of a contract and our legitimate interests in running a safe and well-organised event;
  • to communicate with you about the Event you have booked, including joining instructions, programme updates and changes – performance of a contract;
  • to send you our own marketing about future Future Forum events – your consent, or our legitimate interests where you have previously bought a ticket from us and we are marketing similar events and you did not opt out when we collected your details and are given the opportunity to opt out in every message;
  • to share your contact details with our sponsors and partners so that they can market their own products and services to you – your consent only. We will never do this unless you have opted in, and your ticket purchase does not depend on your doing so – see clause 4;
  • to match your contact details against user accounts on advertising platforms so that you and people like you can be shown advertising for the Event – your consent – see clause 4.6;
  • to make accessibility, dietary and medical arrangements for you – your explicit consent;
  • to photograph, film and record the Event and to use that material to promote Future Forum – our legitimate interests in promoting our events, subject to your right to object (see clause 10);
  • to improve our events, website and app, and to compile aggregated statistics and post-event reports for sponsors (which do not identify you) – our legitimate interests;
  • to keep proper accounting records and comply with our legal and regulatory obligations – compliance with a legal obligation; and
  • to establish, exercise or defend legal claims and to protect our business – our legitimate interests.

3.2. Legitimate interests. Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interests against your rights and freedoms, and we have recorded the outcome. You can ask us for a copy of that assessment, and you have the right to object to processing carried out on this basis (see clause 8).

3.3. Marketing. We will only send you marketing by email or SMS where you have consented to receive it, or where you have previously bought a ticket from us and we are marketing our own similar events (in which case you may opt out at any time). We will only pass your details to a sponsor or partner for their own marketing where you have specifically opted in to receive communications from that organisation. You can opt out of our marketing at any time by clicking “unsubscribe” in any message or by contacting us at info@futureforum.co. Opting out of marketing will not stop us sending you service messages about a ticket you have bought.

3.4. Automated decision-making. We do not make decisions about you that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing. If that changes, we will update this Policy and tell you about the safeguards that apply under Articles 22A to 22D UK GDPR.

3.5. Please note that we may process your personal data without your knowledge or consent where this is required or permitted by law.

4. WHO WE SHARE YOUR INFORMATION WITH

We may share your personal data with the categories of recipient set out in this clause 4. Some of them act as our processors, meaning they only use your personal data on our instructions. Others act as separate controllers, meaning they decide for themselves how to use it and are responsible to you for that use under their own privacy policies. We tell you below which is which. Our service providers include our ticketing platform, event app provider, payment provider, email marketing platform, customer relationship management system, badge production supplier, IT hosting providers and professional advisers (together, “External Third Parties”).

4.1. We only allow External Third Parties to handle your information if we are satisfied that they take appropriate measures to protect your information. We require all third parties to respect the security of your personal data and to treat it in accordance with the law.

4.2. We or the External Third Parties occasionally also need to share your information with certain recipients who will be bound by confidentiality obligations as follows:

  • Service providers acting as our processors, including our ticketing platform, event app provider, payment provider, email and CRM platform, badge production supplier, and hosting and IT support providers. They act only on our documented instructions under a written contract that meets the requirements of Article 28 UK GDPR;
  • The venue and its security and stewarding contractors, so that they can admit you, keep the Event safe and comply with their own legal obligations. The venue operates CCTV in and around the Event space and is a separate controller in respect of that footage;
  • our or their external auditors;
  • our or their professional advisors (such as lawyers and other advisors);
  • law enforcement agencies, courts or tribunals and regulatory bodies to comply with legal and regulatory obligations; and
  • other parties that have or may acquire control or ownership of our business (and our or their professional advisors) in connection with a significant corporate transaction or restructuring, including a merger, acquisition, asset sale, initial public offering or in the event of our insolvency. Usually such information will be anonymised, but this may not always be possible.

4.3. Sponsors and partners. When you register for the Event, we will ask you whether you want to receive communications from our sponsors and partners. We will show you the name of each organisation at the point at which we ask, and you can choose which (if any) you are happy to hear from. We will only pass your Identity Data and Contact Data to a sponsor or partner where you have specifically opted in to receive communications from that organisation. Your ticket purchase does not depend on you opting in, you can change your mind at any time, and we will not add organisations to the list after you have opted in without asking you again.

4.4. Each sponsor and partner receives your personal data as a separate controller. That means it decides for itself how to use your details, it is responsible to you for that use, and its own privacy policy will apply. We require each of them by contract to use your details only for the purpose you agreed to, not to sell or pass them on, to honour any objection or unsubscribe request promptly, and to delete your details if you withdraw your consent. Because they are separate controllers, if you want them to stop using your details you will need to contact them directly – we can tell you who received your details and when, but we cannot delete data from their systems.

4.5. Lead capture at the Event. Sponsors and exhibitors may offer to scan the QR code on your badge when you visit their stand or enter a competition. Scanning is entirely voluntary and only happens if you present your badge. If you allow your badge to be scanned, the exhibitor will receive your name, job title, company name and email address, and will use those details as a separate controller for its own purposes, which will normally include contacting you about its products and services. Clear signage at each stand will tell you what will happen before you are scanned. If you do not want to be contacted by an exhibitor, do not allow your badge to be scanned.

4.6. Advertising platforms and audience matching. If you consent, we will provide a hashed (scrambled) version of your email address and mobile number to advertising platforms including TikTok, Meta and LinkedIn so that they can identify whether you hold an account with them and show you advertising for the Event, and so that they can build “lookalike” audiences of people with similar characteristics. For that matching operation we and the relevant platform act as joint controllers under Article 26 UK GDPR, and we have entered into an arrangement with each platform that allocates responsibility between us. You can ask us for the essence of that arrangement at any time. You can withdraw your consent at any time by contacting us at info@futureforum.co and you can also control advertising directly in your account settings on each platform.

4.7. Aggregated reporting. We provide sponsors and partners with aggregated and anonymised statistics about attendance and engagement (for example, how many people visited a stand or attended a session). This information does not identify you and is not personal data.

5. TRANSFERRING YOUR INFORMATION OUTSIDE THE UK

5.1. Some of our service providers, sponsors, partners and advertising platforms are established outside the United Kingdom, or store or access personal data outside the United Kingdom.

5.2. Whenever we transfer your personal data out of the United Kingdom, we ensure a similar degree of protection is afforded to it by relying on one of the following: (a) the country has been designated by the Secretary of State as providing protection that is not materially lower than the standard of protection under UK data protection law; (b) we use the International Data Transfer Agreement, or the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, backed by a documented transfer risk assessment; or (c) another safeguard permitted by Chapter V UK GDPR.

6. KEEPING YOUR INFORMATION SECURE

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.

6.1. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

6.2. Our security measures include encryption of personal data in transit and at rest, role-based access controls, multi-factor authentication on our administrative systems, security due diligence on our suppliers before we appoint them, and staff training. No transmission of information over the internet can be guaranteed to be completely secure, and any transmission is at your own risk.

6.3. Where we are required to do so, we will report a personal data breach to the ICO within 72 hours of becoming aware of it and will tell you without undue delay where the breach is likely to result in a high risk to your rights and freedoms.

7. HOW LONG YOUR INFORMATION WILL BE KEPT

7.1. We will only retain your personal data for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

7.2. To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

7.3. We are required to keep records relating to your transactions with us for at least six years from the end of the financial year to which they relate, in order to comply with our obligations under the Companies Act 2006 and VAT legislation.

7.4. Unless a longer period is required by law or is necessary in connection with a dispute, our standard retention periods are:

  • Ticket and Registration Data and Transaction Data – 7 years from the end of the financial year in which the Event took place;
  • Marketing and Communications Data, including records of consent – for as long as you remain subscribed and for 2 years after you unsubscribe or withdraw consent, so that we can demonstrate that we handled your preferences correctly;
  • Event Participation Data – 12 months after the Event;
  • Accessibility and Dietary Data – 30 days after the Event;
  • Image and Recording Data – 3 years after the Event, or until you object; and
  • Correspondence Data – 3 years from the date of the last correspondence, or 6 years where it relates to a complaint or potential claim.

8. YOUR LEGAL RIGHTS

Under certain circumstances, you may have the following legal rights under data protection laws in relation to your personal data:

  • Right to request access to your personal data;
  • Right to request correction of your personal data;
  • Right to request erasure of your personal data;
  • Right to object to processing of your personal data;
  • Right to request restriction of processing your personal data;
  • Right to request transfer of your personal data; and
  • Right to withdraw consent, at any time and as easily as you gave it, where we are relying on consent; and
  • Right to object at any time to our use of your personal data for direct marketing. This is an absolute right – if you exercise it we must stop.

8.1. These rights are not all absolute and some of them only apply in certain circumstances. If we are unable to act on your request we will explain why.

8.2. You will not have to pay a fee to exercise your rights. We may charge a reasonable fee, or refuse to act, if your request is manifestly unfounded or excessive. We may need to ask you for information to confirm your identity before we act.

8.3. We aim to respond to all legitimate requests within one month of the later of (a) receiving your request, (b) receiving any identity confirmation we have asked you for and (c) receiving any fee we have asked you for. Occasionally it may take us longer if your request is particularly complex or you have made a number of requests, in which case we will tell you within that first month and keep you updated.

8.4. Withdrawing your consent does not affect the lawfulness of anything we did with your personal data before you withdrew it. If you withdraw your consent to sponsor and partner communications, we will stop sharing your details from that point and will notify the organisations that have already received them, but you may also need to contact them directly – see clause 4.4.

8.5. If you wish to exercise any of your legal rights set out above, please contact us.

8.6. For further information on each of your legal rights, including the circumstances in which they do and do not apply, please contact us. You may also find it helpful to refer to the guidance from the ICO (https://ico.org.uk/your-data-matters/).

9. COOKIES AND SIMILAR TECHNOLOGIES

9.1. Our website and event app use cookies and similar technologies, including advertising and analytics tags operated by TikTok, Meta, LinkedIn and Google. Except for those that are strictly necessary to provide a service you have requested, and a small number of low-risk technologies for which the law now permits an opt-out, we only set them where you have consented through our cookie banner.

9.2. You can change or withdraw your cookie preferences at any time through the “Cookie settings” link in the footer of our website.

10. PHOTOGRAPHY, FILMING AND RECORDING AT THE EVENT

10.1. We and our appointed photographers and film crew will photograph, film and record the Event, and will use that material to report on and promote Future Forum and future events. We rely on our legitimate interests in doing so. Where we want to feature you prominently – for example, in a close-up portrait, a testimonial or an advertisement – we will ask for your separate written consent.

10.2. If you would prefer not to appear in photography or film, please tell us in advance by emailing us at info@futureforum.co or speak to a member of staff at the registration desk on arrival, and we will provide you with a marker on your badge and take reasonable steps to avoid capturing you or to remove you from material we use. We cannot control photography or filming by other attendees, the press or exhibitors.