GDPR Policy
GDPR Compliance Statement
Last Updated: 31 August 2026
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the Data Controller is Reindeer Lodge LTD, registered and operating from Black Meadows Farm, Leeswood, Mold, CH7 4SQ.
1. Our Lawful Bases for Processing Data
Under the UK GDPR, we must establish a clear legal justification (lawful basis) to hold, process, or use your personal data. We rely on the following separate legal grounds:
- Performance of a Contract: We process your Identity, Contact, and Financial Transaction data because it is structurally necessary to fulfill your ticket order, generate and deliver your digital e-tickets, and safely manage your admission to the event gates.
- Legitimate Interests: We process site-wide safety CCTV footage, real-time grotto audio/video feeds, and general trail crowd photography for our legitimate business operations. These interest parameters include maintaining public site safety, protecting our high-value live animals, protecting property, optimizing real-time crowd safety, and creating general promotional marketing materials.
- Consent: We only ever distribute marketing updates or seasonal newsletters if you explicitly click the opt-in checkbox during checkout. You retain the absolute right to withdraw this consent instantly at any time by clicking the ‘unsubscribe’ button in any email.
2. Data Retention Limits
We enforce structured retention limits to ensure we do not hold data longer than required for operational or statutory legal mandates:
- Financial & Booking History: Retained securely for a minimum of 6 years to satisfy formal UK tax laws, corporate accounting mandates, and financial auditing guidelines.
- CCTV Footage: Securely stored on a rolling local drive for a maximum duration of 28 days before being systematically and permanently overwritten.
- Grotto Digital Images: Completely deleted and purged from our processing cards within 24 hours at the conclusion of each active event day.
- Marketing Mail Lists: Stored securely until you independently elect to unsubscribe or request complete profile deletion.
3. Your Statutory Rights Under GDPR
As a UK resident, you hold strict statutory legal protections regarding how commercial entities process your personal information. You can exercise these data protections at any time by writing to our team. Your specific rights include:
- The Right of Access: You have the right to request a formal copy of all personal information Reindeer Lodge LTD currently stores about you.
- The Right to Rectification: You have the right to request that we immediately correct any clerical mistakes, outdated contact items, or incomplete booking records.
- The Right to Erasure (‘The Right to be Forgotten’): You can ask us to permanently delete your data records from our databases, provided it does not conflict with overriding UK corporate tax retention laws (such as core booking invoices).
- The Right to Object or Restrict Processing: You hold the right to limit how we process your information, object to legitimate interest profiles, or block marketing communications entirely.
4. Regulatory Complaints
If you believe Reindeer Lodge LTD has compromised your privacy or has failed to manage your data in line with UK statutory frameworks, you have the full legal right to lodge a formal report with the national supervisory regulator:
Information Commissioner’s Office (ICO)
Website: www.ico.org.uk
We would structurally appreciate the professional opportunity to investigate and completely resolve any data handling disputes or customer queries with you directly before you approach the ICO regulator, so please reach out to our administration office first at: info@reindeerlodge.co.uk
