Legal & Trust

Privacy Policy

Last updated: 31 August 2026 · Effective: 31 August 2026

This Privacy Policy explains how ADVCY Ltd (“ADVCY”, “we”, “us” or “our”) handles personal information.

ADVCY Ltd is registered in England and Wales under company number 16926771 and has its registered office at 40 Queens Road, Teddington, England, TW11 0LR.

We are registered with the UK Information Commissioner’s Office under registration number C1934810.

You can contact us about privacy at community@advcy.ai.

1. What ADVCY does

ADVCY provides technology that helps events, communities, brands, artists and creators build relationships with their audiences.

Our services can include:

  • AI-powered concierge experiences;
  • WhatsApp and other messaging services;
  • Apple Wallet and Google Wallet passes;
  • attendee and member communications;
  • event information and recommendations;
  • registration and preference collection;
  • access or pass verification;
  • community engagement;
  • analytics; and
  • related software and integrations.

2. An important point about who controls your information

ADVCY can process personal information in two different roles.

When we provide a service for an organisation

If you are using an ADVCY-powered experience provided for an event organiser, artist, brand, community or other organisation, that organisation will normally decide why your personal information is being used.

In those circumstances:

  • the organisation is normally the controller; and
  • ADVCY is normally its processor.

For example, an event organiser may decide to provide attendees with a digital wallet pass, decide what information the pass contains and decide which event updates should be sent. ADVCY then provides the technology needed to deliver those instructions.

The organisation should identify itself when you sign up for or use the relevant service. The organisation’s own privacy notice may also apply.

When ADVCY decides why information is used

ADVCY acts as a controller for personal information we use for our own purposes, including:

  • operating advcy.ai;
  • responding to enquiries;
  • managing our customers and suppliers;
  • managing contracts and billing;
  • protecting our systems;
  • preventing abuse or fraud;
  • maintaining business records;
  • complying with legal obligations; and
  • marketing ADVCY itself where permitted.

If ADVCY and another organisation jointly determine the purpose and essential means of a particular processing activity, we will assess whether we are joint controllers and provide appropriate information where required.

3. Information we may process

The information processed depends on which ADVCY service you use.

Identity and contact information

This can include:

  • name;
  • email address;
  • mobile number;
  • organisation;
  • job title;
  • messaging profile information; and
  • account identifiers.

Event and community information

This can include:

  • the event or community you are interacting with;
  • registrations;
  • tickets or entitlements;
  • RSVP status;
  • attendance information;
  • timetable or session selections;
  • interests;
  • preferences;
  • accessibility requests you choose to provide;
  • questions;
  • recommendations;
  • matchmaking preferences; and
  • other information you choose to give us.

Messaging information

Where you communicate with an ADVCY-powered concierge we may process:

  • your messaging identifier;
  • your telephone number where applicable;
  • message content;
  • images, files or voice messages you choose to send;
  • message timestamps;
  • delivery information;
  • message IDs;
  • opt-in and opt-out information; and
  • information derived from the conversation where necessary to provide the service.

We do not obtain access to your unrelated private conversations on WhatsApp, Telegram, Slack or another messaging service merely because you interact with an ADVCY service.

Wallet pass information

Where you use an Apple Wallet or Google Wallet pass we may process information such as:

  • pass serial number;
  • pass type;
  • wallet object identifier;
  • ticket, membership or access information;
  • event information;
  • pass status;
  • barcode or QR identifier;
  • entitlement information;
  • pass creation and update records;
  • expiry information;
  • verification information; and
  • information needed to personalise the pass.

Apple Wallet update identifiers

Where an Apple Wallet pass supports remote updates, Apple’s Wallet technology can register the installed pass with the infrastructure responsible for updating it. This may involve processing:

  • the pass serial number;
  • pass type identifier;
  • device library identifier;
  • push token;
  • registration status; and
  • update information.

These identifiers help the system determine which installed passes need to receive an update. We treat these identifiers as personal information where they can identify, relate to or single out a pass holder.

Google Wallet information

Where Google Wallet is used, we may process the Wallet class, object, pass identifier and other information required to issue, manage and update the pass. Google may separately process device, account, notification and location information under its own privacy terms.

Verification and scanning information

If a pass is scanned, redeemed or checked, we may process:

  • pass or token identifier;
  • verification result;
  • redemption status;
  • date and time;
  • event;
  • venue;
  • checkpoint;
  • scanner or verifier identifier; and
  • related security information.

We aim to provide verification systems with only the information genuinely needed to verify the pass.

Website and technical information

When you use our website or services, we may process:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • pages viewed;
  • referring page;
  • approximate location derived from IP address;
  • diagnostic information;
  • security logs; and
  • cookie or analytics information where permitted.

4. Wallet notifications and pass updates

Digital wallet passes can change after they have been installed. For example, an event pass may be updated because:

  • a start time changes;
  • a stage or room changes;
  • access information becomes available;
  • a venue changes;
  • important event information changes;
  • an entitlement changes; or
  • other information displayed on the pass needs updating.

The Wallet platform and your device ultimately control whether and how an update or notification appears.

Apple Wallet

Apple Wallet allows an installed pass to register for updates. ADVCY or its authorised wallet infrastructure may send Apple a signal that the pass has changed, after which the device may request the updated pass.

Apple Wallet change messages are intended for important or time-sensitive pass information. ADVCY does not use Apple Wallet change messages for advertising or non-critical marketing.

Google Wallet

Google Wallet supports pass updates and certain issuer-triggered messages and notifications. The availability and presentation of those messages are controlled in part by Google and by the user’s notification settings.

ADVCY and its clients must use these functions in accordance with Google’s applicable platform rules as well as applicable marketing and privacy law.

5. Service communications and marketing are different

We distinguish between communications needed to provide a service and direct marketing.

Service communications

These are factual communications genuinely connected with the event, pass, membership or service you are using. Examples can include:

  • event timing changes;
  • venue or room changes;
  • access instructions;
  • safety information;
  • cancellation information;
  • material timetable changes; and
  • important information about an existing booking or entitlement.

Direct marketing

A communication may be direct marketing if its purpose includes promoting:

  • another event;
  • tickets;
  • merchandise;
  • memberships;
  • upgrades;
  • offers;
  • products or services;
  • a sponsor or commercial partner;
  • fundraising;
  • an organisation’s campaigns or aims; or
  • another commercial opportunity.

Adding promotional content to an otherwise operational communication can cause the whole communication to be treated as marketing.

Where consent is required for electronic direct marketing, we or the relevant controller will obtain it before sending that marketing.

Installing a wallet pass is not, by itself, treated as consent to unrelated marketing. Marketing consent will not be hidden inside acceptance of these terms.

Where you withdraw marketing consent or object to direct marketing, marketing based on that permission will stop. We may retain a minimal suppression record to make sure your preference continues to be respected.

6. Location and wallet relevance

Digital wallets can use location information to make a pass easier to find when it is relevant. For example, an event pass may appear on your Lock Screen when you arrive near the event venue.

When Apple or Google handles the location

ADVCY or the event organiser may add the coordinates of an event or venue to the pass. Apple Wallet or Google Wallet can then use the location of your device and your device permissions to determine whether the pass is relevant nearby.

Where this happens, ADVCY and the event organiser do not receive your precise device location merely because the wallet uses it to surface your pass.

Your device and Wallet location permissions are controlled through Apple, Google and your operating-system settings.

If ADVCY actually collects your location

A different privacy position applies if an ADVCY service asks you to share your live, precise or historical location with ADVCY or one of our clients. Before doing this, we will provide appropriate information about:

  • what location information will be used;
  • why it is needed;
  • how long it will be retained;
  • who will receive it; and
  • how you can stop the processing.

Where applicable law requires consent, a separate positive opt-in will be requested. We will not treat acceptance of general terms or a privacy policy as consent to collect precise location information where separate consent is legally required.

7. Where information comes from

We may receive personal information:

  • directly from you;
  • from the organisation providing the event or service;
  • from a ticketing or registration service;
  • from a CRM or community platform;
  • from a messaging platform;
  • from Apple Wallet or Google Wallet as part of pass functionality;
  • from a pass verifier;
  • from a venue or access-control provider;
  • from a client-authorised integration; or
  • automatically from your interaction with our systems.

If a client supplies information to ADVCY, that client is responsible for ensuring it has authority to provide the information to us.

8. Why personal information is used

Where ADVCY acts as processor, the relevant client determines the purposes and lawful basis for processing.

Where ADVCY acts as controller, we may process personal information for the following purposes.

Providing a service or performing a contract

We may process information where necessary to:

  • provide a service you requested;
  • administer an ADVCY customer account;
  • manage a contract;
  • process an enquiry; or
  • provide customer support.

Legitimate interests

We may process information where necessary for legitimate interests such as:

  • operating our business;
  • maintaining and improving our services;
  • protecting our systems;
  • preventing fraud and abuse;
  • understanding service performance;
  • managing business relationships; and
  • establishing, exercising or defending legal claims,

provided those interests are not overridden by your rights and freedoms.

Consent

We rely on consent where it is appropriate or legally required, including certain:

  • marketing activities;
  • optional cookies and analytics;
  • optional processing of precise location information; and
  • other optional activities we clearly describe when consent is requested.

You can withdraw consent at any time. Withdrawal does not make processing carried out before withdrawal unlawful.

Legal obligations

We may process information where necessary to comply with law, regulatory requirements, court orders or lawful requests from authorities.

9. Special category information

ADVCY services are not generally designed to require information concerning matters such as:

  • health;
  • racial or ethnic origin;
  • religion;
  • political opinions;
  • trade union membership;
  • genetic or biometric identification data;
  • sex life; or
  • sexual orientation.

Please avoid providing this information unless the relevant service specifically asks for it and explains why it is required.

If special category information is intentionally processed, an appropriate Article 6 lawful basis and Article 9 condition will be identified. We do not rely merely on the fact that a person voluntarily sent sensitive information as blanket permission to use it for unrelated purposes.

10. Children and young people

Some events using ADVCY may be open to children or young people. Where a client intends an ADVCY service to be used by children, the service must be configured and assessed appropriately for that audience.

Additional safeguards may include:

  • collecting less information;
  • age-appropriate privacy information;
  • limiting profiling;
  • limiting marketing;
  • parental or guardian involvement where appropriate;
  • stronger default privacy settings; and
  • a data protection impact assessment.

ADVCY does not knowingly use children’s information for its own unrelated direct marketing.

11. AI

Some ADVCY services use artificial intelligence to:

  • understand questions;
  • generate responses;
  • retrieve relevant information;
  • recommend content;
  • organise information; or
  • help personalise an experience.

Where a client controls the service, ADVCY uses AI to perform the client’s instructions.

We do not use attendee or concierge information to train a public AI model unless this has been specifically agreed, lawfully implemented and transparently explained.

Unless you are expressly told otherwise, an ADVCY concierge does not make a decision based solely on automated processing that produces a legal or similarly significant effect about you. If a service introduces significant solely automated decision-making, additional safeguards and information will be provided as required.

12. Who information may be shared with

Depending on the service, personal information may be disclosed to or processed by:

The organisation providing the service

For example, the relevant event organiser, artist, brand, creator or community. What that organisation receives depends on the particular service and its instructions.

Service providers and subprocessors

We use selected technology providers to help operate ADVCY. These can include providers of:

  • cloud infrastructure;
  • databases;
  • security;
  • AI services;
  • messaging infrastructure;
  • email;
  • analytics;
  • digital wallet infrastructure;
  • customer support; and
  • related technical services.

Where they process personal information on our behalf, appropriate contractual protections are put in place. Our current material subprocessors are listed at advcy.ai/subprocessors.

Apple and Google

Apple Wallet and Google Wallet are third-party platforms. Apple and Google may process information independently in connection with the operation of their devices, accounts, Wallet services, notifications and location functionality. Their own privacy terms also apply.

Pass verifiers and access providers

Where required to provide access or verify an entitlement, information may be made available to authorised:

  • venues;
  • ticketing providers;
  • scanner operators;
  • access-control providers; or
  • other verification partners.

We seek to minimise the information disclosed. Where a verifier acts as an independent controller rather than as a processor, this will be identified where required.

Professional advisers and authorities

Information may also be disclosed where necessary to:

  • lawyers;
  • accountants;
  • insurers;
  • auditors;
  • regulators;
  • law enforcement;
  • courts; or
  • other authorities.

Corporate transactions

Information may be disclosed where reasonably necessary in connection with a financing, investment, merger, acquisition, restructuring or sale of all or part of ADVCY, subject to appropriate confidentiality and data-protection safeguards.

13. We do not sell personal information

ADVCY does not sell attendee, fan, member or concierge personal information.

We do not provide individual conversational profiles to unrelated third parties so that those third parties can independently market to you unless you have been clearly told about that sharing and an appropriate lawful basis has been established.

If a client wants to share your information with a sponsor or other third party for that third party’s own marketing, the client is responsible for ensuring the required transparency and permissions are in place.

14. International transfers

ADVCY uses modern technology services that may involve processing personal information outside the United Kingdom.

Where ADVCY is responsible for a restricted international transfer, we use an appropriate transfer mechanism where required. Depending on the destination and provider, this may include:

  • UK adequacy regulations;
  • the UK Extension to the EU-US Data Privacy Framework where applicable;
  • the International Data Transfer Agreement;
  • EU Standard Contractual Clauses together with the UK Addendum;
  • EU Standard Contractual Clauses where EU GDPR applies; or
  • another lawful transfer mechanism.

Where required, we assess the transfer and any supplementary safeguards. You may contact community@advcy.ai for more information about safeguards relating to a particular transfer.

15. How long we keep information

We keep personal information only for as long as reasonably necessary for the purpose for which it is processed. The precise period depends on the service and our legal role.

Where ADVCY acts as processor, the client normally determines the retention period through its instructions and our contract. Where ADVCY acts as controller, retention is based on the purpose, sensitivity, legal requirements and whether the information is still required.

As general principles:

  • Wallet registration and update identifiers are retained while required to maintain the relevant pass and are deleted or invalidated when they are no longer required, subject to normal technical and backup cycles.
  • Event-specific information is retained for the period required by the relevant event or community and is then deleted or anonymised according to the client’s instructions and our retention procedures.
  • Conversation information is retained for the period needed to operate the relevant service, support the relationship and comply with the client’s instructions.
  • Marketing consent records may be retained while we or our client relies on that consent so that the permission can be demonstrated.
  • Suppression records may be retained after an opt-out in minimal form so that the person’s choice not to receive marketing continues to be respected.
  • Security logs are kept only for an appropriate period needed for security, fraud investigation and system integrity.
  • Business and contractual records may be retained for applicable tax, accounting, contractual and legal limitation periods.
  • Deleted information may remain in encrypted backups for a limited period before normal backup rotation removes it.

16. Removing a wallet pass

You can remove a pass using the controls provided by Apple Wallet or Google Wallet. Removing a pass may cause the Wallet platform to unregister that pass from update services.

Removing a pass does not necessarily delete other personal information held by the event organiser or ADVCY for another lawful purpose. You may separately request deletion where the right to erasure applies.

17. Your rights

Depending on the circumstances and lawful basis, you may have rights including:

  • access to your personal information;
  • correction of inaccurate information;
  • erasure;
  • restriction of processing;
  • data portability;
  • objection to processing;
  • withdrawal of consent; and
  • safeguards relating to automated decision-making.

You have an absolute right to object to the use of your personal information for direct marketing.

Where ADVCY is controller, you can exercise your rights by contacting community@advcy.ai. Where ADVCY processes the information for a client, we may refer your request to that client and assist them in responding.

We may need proportionate information to confirm your identity before disclosing or deleting personal information.

Further information is available at advcy.ai/data-rights.

18. Subject access requests

You can ask whether we process your personal information and request a copy of information to which you are entitled.

Where ADVCY is responsible for responding, we will respond without undue delay and normally within one month of receiving a valid request. The law permits the response period to be extended in certain circumstances, including complex or multiple requests.

Where reasonably necessary to understand the personal information you are seeking, we may ask you to clarify your request. Applicable statutory timing rules will apply.

19. Privacy complaints

You have the right to complain to us about how your personal information has been used.

You can make a complaint by emailing community@advcy.ai. Please write Privacy Complaint in the subject line where possible.

We will acknowledge a data-protection complaint within 30 days and will investigate and respond without undue delay.

You can also complain to the UK Information Commissioner’s Office at ico.org.uk. You do not need to complain to ADVCY before exercising your right to contact the ICO.

20. Security

ADVCY uses technical and organisational measures designed to protect personal information according to the risks involved. Depending on the system, these can include:

  • encryption in transit;
  • appropriate encryption at rest;
  • access controls;
  • least-privilege permissions;
  • authentication controls;
  • secrets management;
  • logging and monitoring;
  • backup and recovery;
  • vulnerability management;
  • environment separation;
  • incident-management procedures; and
  • supplier security controls.

No internet-connected service can guarantee absolute security.

21. Data breaches

ADVCY maintains procedures for identifying, investigating and responding to personal data breaches.

Where ADVCY acts as processor, we notify the relevant controller without undue delay after becoming aware of a personal data breach affecting Client Personal Data.

Where ADVCY acts as controller, we assess whether notification to the ICO and affected individuals is required by law.

22. Cookies and similar technologies

Our website uses necessary technologies required for core functionality. Optional analytics, advertising or other non-essential storage and access technologies are used only where permitted by applicable law.

You can find more information and manage your choices at advcy.ai/cookies.

23. Changes to this policy

We may update this Privacy Policy when:

  • our products change;
  • our processing changes;
  • our providers change; or
  • applicable law or regulatory guidance changes.

We will update the date at the top of this page.

Where a change materially affects how existing personal information is used, we will take appropriate steps to bring the change to the attention of affected people before the new processing begins where required.

24. Contact

ADVCY Ltd

40 Queens Road

Teddington

England

TW11 0LR

Company number: 16926771

ICO registration: C1934810

Privacy enquiries: community@advcy.ai