Privacy & data
Short version: we collect the minimum we need to run an agency, we never sell data, and you can ask us to delete yours at any time.
Who we are
Roar Talent Agency Ltd (“Roar”, “we”, “us”) is the data controller for personal data collected through roartalent.co.uk and roartalentagency.co.uk. Based in Nottingham, United Kingdom. Contact: bookings@roartalent.co.uk.
What we collect & why
- Booking enquiries — your name, email, organisation, event date, budget and message, so we can reply and quote (legitimate interest / pre-contract).
- Roster applications — artist alias, contact details, links and bio, so we can assess your application.
- Newsletter — your email address, only if you subscribe (consent). Unsubscribe any time by emailing us.
- Site analytics — page views counted via a daily anonymous hash. No IP addresses, no tracking cookies, no profiles, no third-party trackers.
- Team accounts — usernames, display names, password hashes and MFA secrets for people who work on the site.
- Server logs — standard technical logs kept by our hosting provider for security and debugging.
How long we keep it
- Booking enquiries — up to 24 months, or the life of the booking relationship.
- Roster applications — up to 12 months if unsuccessful.
- Subscribers — until you ask to be removed.
- Analytics — daily totals only, kept up to 60 days.
Who we share it with
Our hosting provider processes data on our behalf to run this site, and our email provider to deliver messages. We never sell personal data or share it for third-party marketing.
Cookies
This site sets no tracking cookies. The only cookie used is a sign-in cookie on our private team area. Analytics are cookieless.
Your rights
Under UK GDPR you can ask to access, correct, export or erase your personal data, and to object to processing. Email bookings@roartalent.co.uk and we will respond within 30 days. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk.
Security
Access to submitted data is restricted to authorised team members under role-based permissions with optional two-factor authentication. Data in transit is protected by TLS.