PRIVACY POLICY

Hedingham Castle

Last updated: January 2026

Hedingham Castle ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Notice explains how we collect, use, and protect your personal data when you visit our website, purchase tickets, attend events, or contact us.

This notice is provided in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who we are

Hedingham Castle
Castle Hedingham
Halstead
Essex
CO9 3DJ

Telephone: 01787 460 261
Email: mail@hedinghamcastle.co.uk

For the purposes of data protection law, Hedingham Castle is the Data Controller.

2. The personal data we collect

We may collect and process the following personal data:

Information you provide directly:

  • Name

  • Email address

  • Billing address

  • Telephone number (if provided)

  • Ticket purchase details

  • Any information provided when contacting us

Information collected automatically:

  • IP address

  • Browser type and version

  • Website usage information via cookies

Event photography and video:

We may take photographs and video recordings at public events for marketing and promotional purposes.

3. How we collect your data

We collect personal data when you:

  • Purchase tickets via our website using the Tyg Tickets platform

  • Contact us via email, telephone, or website

  • Sign up to receive marketing communications

  • Visit our website

  • Attend events at Hedingham Castle

4. How we use your personal data

We use your personal data to:

  • Process ticket purchases and provide admission

  • Send ticket confirmations and event information

  • Respond to enquiries

  • Provide customer service

  • Send marketing communications (where you have consented or where permitted by law)

  • Improve our website and services

  • Promote Hedingham Castle through photography and media

5. Lawful basis for processing

We rely on the following lawful bases under UK GDPR:

Contract:
To process your ticket purchase and provide services.

Legitimate interests:
To operate and improve our business and services.

Consent:
For sending marketing emails where required.

Legal obligation:
Where required to comply with legal or regulatory requirements.

6. Third-party ticket provider – Tyg Tickets

We use TygTickets.com, operated by Tyg Limited, to provide our online ticketing platform.

When you purchase tickets, your personal data is processed by Tyg Limited on our behalf. Tyg Limited acts as a data processor and processes your data in accordance with their privacy policy and applicable data protection laws.

We remain responsible for your personal data as the Data Controller.

7. Marketing communications

We may send you marketing emails about events, offers, and news from Hedingham Castle where:

  • You have given consent, or

  • You have purchased tickets from us and have not opted out.

You may unsubscribe at any time by:

8. Photography and video at events

Photography and video may be taken at public events for promotional and marketing purposes.

These images may be used:

  • On our website

  • On social media

  • In promotional materials

If you do not wish to be photographed, please inform a member of staff at the event.

9. Cookies

Our website uses cookies to improve your browsing experience and help our website function properly.

Cookies may collect technical information such as browser type and website usage.

You can control cookies through your browser settings.

10. How long we keep your data

We retain personal data only as long as necessary, including:

  • Ticket purchase records: up to 7 years (for accounting and legal purposes)

  • Marketing data: until you unsubscribe or withdraw consent

  • Enquiry data: as long as necessary to resolve your enquiry

11. How we protect your data

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse.

12. Your rights

Under UK GDPR, you have the right to:

  • Access your personal data

  • Request correction of inaccurate data

  • Request deletion of your data

  • Restrict processing

  • Object to processing

  • Withdraw consent at any time

  • Request transfer of your data

To exercise these rights, please contact us at mail@hedinghamcastle.co.uk

13. Complaints

If you are unhappy with how we handle your personal data, you may contact us.

You also have the right to complain to the Information Commissioner’s Office (ICO):

Information Commissioner’s Office
www.ico.org.uk
Telephone: 0303 123 1113

14. Changes to this Privacy Notice

We may update this Privacy Notice from time to time. Any updates will be posted on this page.