Privacy Policy

Last updated: 22 August 2026

This Privacy Policy explains how LitLounge (“LitLounge”, “we”, “us” or “our”) collects, uses and protects your personal data when you visit https://litlounge.org (the “Website”), subscribe to our newsletter, contact us, or attend our events. Tickets for events are sold through a third-party platform — what happens to your data during a purchase is described below. This Policy also sets out your rights under the UK GDPR and the Data Protection Act 2018 and how to exercise them.

Please read this Policy carefully. By using the Website, you acknowledge that you have read and understood it.

1. Who we are (Data Controller)

The data controller responsible for processing your personal data is:

  • LitLounge 

  • Email: contact@litlounge.org

  • [ICO registration line — add only once the ICO fee is paid, otherwise omit]

If you have any questions about this Policy or about how we handle your data, please contact us using the details in the “Contact us” section.

2. What data we collect and store

LitLounge stores only a minimum of data that you provide yourself:

  • first and last name;

  • phone number;

  • email address.

You give us these when you subscribe to our newsletter or email us. We do not store any other data about you.

3. Buying tickets for our events

Ticket sales and payments do not take place on our website, but on third-party platforms: tickets through Fienta, and card payments through Maksekeskus. You enter your data directly on those platforms, and they collect and store it under their own rules. We do not receive this data or store it ourselves. How it is processed is described in the services’ own privacy policies:

  • Fienta — fienta.com/help/legal/privacy

  • Maksekeskus — maksekeskus.ee

4. How we use your data and legal bases

The data we store is processed in only two situations, each with a lawful basis under the UK GDPR:

  • Newsletter — to send you news about events; basis: your consent, which you can withdraw at any time.

  • Replying to your emails — if you email us, we process your message and contact details in order to reply; basis: legitimate interest.

5. Sharing of data

The data we store (name, phone number, email) is not sold, transferred or disclosed to third parties for their own purposes.

The LitLounge website and email run on the infrastructure of the hosting provider Kualo — your data is physically stored there, but Kualo only keeps the website running and does not use the data for its own purposes.

Data may only be disclosed where required by law.

6. Cookies and analytics

We use cookies and similar technologies when you use the Website:

  • Strictly necessary cookies are required for the Website to work and do not require your consent.

  • Analytics cookies (Google Analytics) help us understand how visitors use the Website — which pages they open and how long they stay. This data is anonymised and used only to improve the Website. Analytics cookies are set only with your consent, which we request via a cookie banner on your first visit.

You can accept or reject non-essential cookies through the banner and change your choice at any time. You can also manage or delete cookies through your browser settings, though some features of the Website may not work correctly if you do.

7. International data transfers

The data we store is held on the servers of our hosting provider Kualo (data centre in London, United Kingdom), so it remains within the United Kingdom.

The analytics service Google Analytics is operated by Google, and data associated with it may be processed outside the United Kingdom. In such cases, appropriate safeguards apply (for example an adequacy decision or standard contractual clauses).

Data related to ticket purchases is processed by Fienta and Maksekeskus within the European Economic Area (EEA).

8. How long we keep your data

Since we store only a minimum of data, retention is simple:

  • newsletter data — until you unsubscribe or withdraw consent;

  • email correspondence — for as long as needed to resolve your query, and a reasonable period afterwards.

When data is no longer needed, we delete it.

9. How we protect your data

We take reasonable technical and organisational measures to protect data against unauthorised access, loss or misuse (including encryption in transit via HTTPS and secure hosting). However, no method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

10. Your rights

Under the UK GDPR, you have the right to:

  • access the data we hold about you;

  • rectify inaccurate or incomplete data;

  • erase your data;

  • restrict or object to processing;

  • data portability;

  • withdraw consent at any time, where processing is based on consent;

  • lodge a complaint with a supervisory authority.

To exercise these rights, contact us using the details in the “Contact us” section. We will respond within one month. You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner’s Office (ICO): ico.org.uk/concerns.

11. Children’s privacy

The Website is not intended for children under the age of 13, and we do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us and we will delete it.

12. Third-party links

The Website may contain links to third-party websites or services. We are not responsible for their data practices, and we encourage you to review their privacy policies.

13. Changes to this Policy

We may update this Policy from time to time. Changes take effect once the updated version is posted on the Website, with an updated date in the “Last updated” field.

14. Contact us

For any questions, requests or concerns about this Policy or your personal data, please contact us:

Scroll to Top