Legal

How Hi Events Protects Your Data

Hi Events ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal information when you enquire about, book, or attend an event with us, or visit our website. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025), we are the "data controller" of the personal information described in this policy. If you have any questions about this policy or how we handle your data, contact us at hello@hievents.world.

1. The Information We Collect

We collect different information depending on how you interact with us. This includes: 1.1 Enquiry and contact information - when you get in touch via our website contact form, email, Instagram or other social media DMs, or phone, we may collect your name, email address, phone number, company name and role (for corporate enquiries), and the details of your enquiry. 1.2 Booking and event information - if you go on to book an event with us, we collect information needed to plan and deliver it, which may include: • Billing and invoicing details (name, company name, billing address, VAT number where applicable) • Event details (dates, venue, guest numbers, budget, preferences) • Guest/attendee information you provide on behalf of others (names, dietary requirements, accessibility needs, contact details) 1.3 Special category data - dietary requirements and accessibility/access needs can reveal information about health (e.g. allergies, medical conditions, disabilities). This is classed as "special category data" under UK GDPR and requires extra care, as set out in Section 3 below. 1.4 Photographs and video - we (or photographers/videographers we engage) may take photographs and video footage at events for portfolio, marketing, and social media purposes, as set out in Section 6. 1.5 Website usage data - when you visit our website, we (and our analytics and advertising partners) automatically collect technical information via cookies and similar technologies, including your IP address, browser type, device information, pages visited, and how you arrived at our site. 1.6 Marketing preferences - if you sign up to our mailing list or otherwise consent to marketing, we collect your name and email address and a record of your marketing preferences and engagement (e.g. opens/clicks), via Mailchimp. 1.7 Payment information - we do not store full card details. Payments are processed by our third-party payment provider, who handle and store this data in accordance with their own privacy policy and applicable payment security standards (PCI DSS).

2. How and Why We Use Your Information

We use your information for the following purposes, and only where we have a valid legal basis to do so: • Responding to your enquiry (contact details, enquiry content) - Legitimate interests (responding to business enquiries) / Steps prior to entering a contract • Preparing proposals and quotes (contact details, event requirements) - Steps prior to entering a contract • Planning and delivering your event (booking, billing, and guest information) - Performance of a contract • Liaising with venues and suppliers on your behalf (relevant booking and guest details) - Performance of a contract • Accommodating dietary or accessibility needs (special category data - see Section 3) - Explicit consent • Invoicing and accounting (billing details) - Performance of a contract / Legal obligation • Event photography and marketing use (photos/video) - Consent (or legitimate interests where notified - see Section 6) • Sending you marketing/newsletters (name, email) - Consent (or "soft opt-in" for existing clients - see Section 7) • Website analytics and ad targeting (cookies, device/usage data) - Consent (via cookie banner) • Preventing fraud, resolving disputes, complying with the law (relevant contract/financial data) - Legal obligation / Legitimate interests 2.1 Where we rely on "legitimate interests," we have considered that this use is reasonable, expected, and does not override your rights and freedoms. You can ask us for more detail on any specific legitimate interests assessment at any time. 2.2 We do not use your personal information for any automated decision-making or profiling that produces legal or similarly significant effects on you.

3. Special Category Data (Dietary and Accessibility Needs)

3.1 Information about dietary requirements, allergies, medical conditions, or accessibility needs is "special category data" under Article 9 of UK GDPR, because it can reveal information about health. 3.2 We only collect this information where you or your event guests choose to provide it, for the specific purpose of ensuring guest safety and comfort at the event (for example, passing allergy information to a caterer, or access requirements to a venue). 3.3 We rely on your explicit consent as the legal basis for collecting and using this information. You (or your guests, where you are providing information on their behalf) can withdraw this consent at any time by contacting us, though this may affect our ability to safely accommodate the relevant need. 3.4 We only share this information with Suppliers (such as caterers or venues) who need it to deliver the event safely, and only to the extent necessary for that purpose. 3.5 Where you provide us with dietary, accessibility, or other personal information about another person (such as a guest, colleague, or employee), you confirm that you have informed them of this Privacy Policy and that they are happy for you to share their information with us, or that you otherwise have a valid basis to do so.

4. Who We Share Your Information With

We share personal information only where necessary, with: 4.1 Suppliers - venues, caterers, entertainment providers, transport companies, AV suppliers, and other third parties engaged in connection with your event, to the extent needed to deliver the Services. See our Terms & Conditions for how Suppliers are engaged. 4.2 Service providers who support our business operations, including: • Website hosting and analytics providers (e.g. Google Analytics) • Advertising platforms (e.g. Meta/Instagram Ads) for marketing purposes • Email marketing platform (Mailchimp) for newsletters and client communications • Payment processors for handling payments • Accounting and invoicing software • Cloud storage and productivity tools (e.g. Google Drive, Microsoft 365) 4.3 Professional advisers such as our accountant, solicitor, or insurer, where reasonably necessary. 4.4 Regulators and authorities where we are required to do so by law, or to protect our legal rights. 4.5 We do not sell your personal information to third parties. 4.6 International transfers - some of our service providers (for example, Google, Meta, and Mailchimp) may store or process data outside the UK, including in the United States. Where this happens, we ensure appropriate safeguards are in place, such as the UK's International Data Transfer Agreement (IDTA), an adequacy decision, or the provider's participation in an approved data protection framework (such as the UK Extension to the EU-US Data Privacy Framework, where applicable). You can request more information about these safeguards by contacting us.

5. Cookies and Website Tracking

5.1 Our website uses cookies and similar technologies, including: • Strictly necessary cookies - required for the website to function (no consent required) • Analytics cookies (e.g. Google Analytics) - to understand how visitors use our site • Marketing/advertising cookies (e.g. Meta/Instagram Pixel) - to measure and improve our advertising, and to show you relevant ads on social media 5.2 Non-essential cookies are only set with your consent, given via the cookie banner on our website. You can change or withdraw your consent at any time through your browser settings or our cookie preference tool. 5.3 This use of cookies is governed by the Privacy and Electronic Communications Regulations (PECR) in addition to UK GDPR.

6. Photography and Video at Events

6.1 We (or photographers/videographers we engage) may take photographs and video footage at events for our portfolio, website, social media, and marketing purposes. 6.2 Where photography is planned, we will make this clear in advance wherever reasonably possible (for example, in your Proposal or Event Schedule), so that you can inform your guests. 6.3 If you, or any of your guests, do not wish to be photographed or featured in marketing materials, please let us know in advance, or speak to the photographer/videographer on the day, and we will take reasonable steps to accommodate this. 6.4 Special care is taken regarding any guests under the age of 18 - please notify us in advance of any children attending so that appropriate consent arrangements can be agreed with their parent or guardian. 6.5 Where you engage your own photographer or videographer, their use of personal data is governed by their own privacy practices, and we are not responsible for it.

7. Marketing Communications

7.1 We will only send you marketing emails or newsletters (via Mailchimp) if: • You have actively opted in to receive them (for example, via a sign-up form), or • You are an existing client and we are marketing similar services to those you have previously enquired about or booked, under the "soft opt-in" exception in the Privacy and Electronic Communications Regulations (PECR) 7.2 Every marketing email includes a clear and simple way to unsubscribe. You can also unsubscribe at any time by contacting us directly. 7.3 We will never sell or share your details with third parties for their own marketing purposes.

8. How Long We Keep Your Information

8.1 We keep personal information only for as long as necessary for the purposes it was collected, taking into account: • Enquiries that don't proceed to a booking - 12 months from last contact • Client and booking records - 6 years from end of contract, to meet accounting/tax obligations • Special category data (dietary/access needs) - Deleted or anonymised shortly after the event, unless needed for an ongoing relationship (within 3 months) • Event photography/video - Retained for ongoing portfolio/marketing use unless you ask us to remove it • Marketing list (Mailchimp) - Until you unsubscribe or 24 months of inactivity • Financial records (invoices, payment records) - 6 years, as required by HMRC 8.2 Where we no longer need personal information, we will securely delete or anonymise it.

9. How We Protect Your Information

9.1 We use appropriate technical and organisational measures to protect personal information against unauthorised access, loss, misuse, or disclosure, including secure storage, access controls, and working only with reputable service providers. 9.2 No method of online transmission or storage is 100% secure, and we cannot guarantee absolute security, but we take data protection seriously and review our practices regularly. 9.3 In the unlikely event of a data breach affecting your personal information, we will notify the Information Commissioner's Office (ICO) and affected individuals where required to do so by law.

10. Your Rights

Under UK GDPR, you have the following rights in relation to your personal information: • Right of access - to ask us for a copy of the personal information we hold about you • Right to rectification - to ask us to correct inaccurate or incomplete information • Right to erasure - to ask us to delete your information, in certain circumstances • Right to restrict processing - to ask us to limit how we use your information, in certain circumstances • Right to data portability - to ask us to transfer your information to you or another organisation, in certain circumstances • Right to object - to object to our use of your information, including for direct marketing (which we will always stop on request) or where we rely on legitimate interests • Rights related to automated decision-making - though, as noted in Section 2.2, we do not currently carry out automated decision-making that affects you • Right to withdraw consent - where we rely on your consent (e.g. for special category data or marketing), you can withdraw it at any time To exercise any of these rights, contact us at hello@hievents.world. We will respond within one month, as required by law. 10.1 Complaints - if you are unhappy with how we have handled your personal information, please contact us first so we can try to resolve it. You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.

11. Children's Information

11.1 Our Services are aimed at businesses and adults. We do not knowingly collect personal information directly from children. 11.2 Where children attend an event as guests (for example, at a family or private event), any information about them is provided to us by a parent, guardian, or the organising adult, in accordance with Section 3.5 above.

12. Changes to This Policy

12.1 We may update this Privacy Policy from time to time, for example to reflect changes in our practices or in the law. The "last updated" date at the top of this policy shows when it was last revised. 12.2 Where changes are significant, we will take reasonable steps to make this clear, such as a notice on our website.

13. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal information, please contact us: Email: hello@hievents.world

Last updated: 19 June 2026
Hi Events - hello@hievents.world