All legal documents
On this page
Effective Date: 22 June 2026 Last updated: 15th July 2026
This Privacy Policy explains how the Kayana collects, uses, discloses, and protects personal data in connection with the Kayana ticketing Platform, and should be read alongside the Kayana Ticketing Platform Global Terms and Conditions. It applies to Merchants, Buyers, and other individuals whose personal data we process in the course of operating the Platform, across all territories in which the Kayana Group operates.
1. SCOPE AND DATA CONTROLLER
1.1 Who This Policy Covers
This Policy applies to personal data processed by any member of the Kayana Group in connection with: (a) Merchant registration, account management, and use of the Platform; (b) Buyer purchases of Tickets; (c) payment facilitation and settlement; and (d) our websites, apps, and related communications.
1.2 Data Controller
The data controller (or, in jurisdictions using different terminology, the equivalent responsible party) for your personal data is the Kayana Group entity that is your Contracting Entity, as identified in Clause 2 of the Kayana Global Terms and Conditions:
| Territory | Controller Entity | Registered Number | Registered Address |
|---|---|---|---|
| United Kingdom | Kayana World Limited | 12782000 | Arch 58, Ingate Place, London, SW8 3AG, United Kingdom |
| United States | Kayana For Business USA Inc | 2025-001835267 | 30 North Gould Street, Ste R, Sheridan, Wyoming, 82801, United States |
| Canada | Kayana Canada Inc | 1001438570 | 75 Bayly St W, Unit 15, Ajax, Ontario, L1S 7K7, Canada |
| European Union (incl. Spain and the Netherlands) | Kayana For Business Ireland | 737092 | 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland |
| Australia | Kayana For Business Australia Pty Ltd | 693 838 014 | 368 Sussex Street, 526, Sydney, New South Wales, 2000, Australia |
| All other territories | Kayana World Limited | 12782000 | As above |
EU Merchants and Buyers, including those in Spain and the Netherlands, are controlled by Kayana For Business Ireland; local supervisory authorities (the AEPD in Spain, the Autoriteit Persoonsgegevens in the Netherlands) remain relevant contact points for those individuals under Clause 9.2. Registered addresses and registration numbers are as confirmed by Kayana.
Where a Merchant is itself the data controller for Buyer personal data collected through its Events (as set out in Clause 17 of the Terms and Conditions), Kayana acts as a data processor or service provider for that data, and processes it only on the Merchant’s instructions and for the purposes described in this Policy.
1.3 Group Processing
Members of the Kayana Group may process personal data on each other’s behalf, or share it among themselves, as reasonably necessary to operate the Platform, perform compliance and risk functions, and meet regulatory obligations, as described in Clause 2.4 of the Terms and Conditions. Each Kayana Group entity remains responsible for personal data it controls in accordance with Applicable Law.
2. PERSONAL DATA WE COLLECT
2.1 Merchant Data
When a business registers as a Merchant, we collect: business and contact details (name, trading name, address, email, phone number); identity and verification documents for KYC, anti-money laundering and sanctions screening purposes (Clause 4.4 and Clause 18 of the Terms and Conditions); financial and banking details for settlement; tax identification numbers; licence and permit information; usage data relating to the Merchant’s activity on the Platform; and communications with our support and compliance teams.
2.2 Buyer Data
When a Buyer purchases a Ticket, we (or our Payment Service Providers, on our behalf) collect: name, contact details, billing and delivery information; payment card or payment account details (processed primarily by our Payment Service Providers — see Clause 5); Ticket and order history; and, where relevant to an Event (for example, age-restricted Events), age-verification information.
2.3 Technical and Usage Data
We automatically collect technical data when you use the Platform or our websites, including IP address, device and browser information, log data, and information collected through cookies and similar technologies (see Clause 6).
2.4 Special Category / Sensitive Data
We do not seek to collect special category or sensitive personal data (such as health, biometric, or similar data) except where an Event specifically requires it (for example, accessibility requirements communicated by a Buyer to a Merchant), in which case such data is processed on the basis described in Clause 3.4 and handled with additional care.
3. HOW AND WHY WE USE PERSONAL DATA
3.1 Purposes
We use personal data to: operate and provide the Platform; process Transactions and facilitate payments and settlement; verify Merchant and Buyer identity; detect, prevent and investigate fraud, money laundering, and sanctions violations; comply with legal and regulatory obligations (including tax reporting); communicate with Merchants and Buyers about Transactions, Events, and account matters; provide customer support; improve and secure the Platform; and, where you have consented or we otherwise have a lawful basis, send marketing communications.
3.2 Legal Bases (UK/EU/EEA)
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases: performance of a contract (processing necessary to provide the Platform and process Transactions); legal obligation (for example, AML/KYC, tax, and sanctions compliance); legitimate interests (for example, fraud prevention, Platform security, and service improvement, balanced against your rights); and consent (for example, for marketing communications, which you may withdraw at any time).
3.3 Legal Bases — Other Jurisdictions
In jurisdictions that do not use the “legal basis” framework (including the United States, Canada, and Australia), we process personal data on grounds equivalent in substance to those in Clause 3.2, and in accordance with the specific requirements of Clause 9.
3.4 Sensitive Data
Where accessibility or other sensitive information is shared in connection with an Event, we process it solely to pass it to the relevant Merchant to facilitate the Buyer’s attendance, and do not use it for any other purpose.
4. COOKIES AND TRACKING TECHNOLOGIES
We and our service providers use cookies and similar technologies on our websites and within the Platform for purposes including authentication, security, remembering preferences, analytics, and (where you consent, where consent is required) marketing and personalisation. You can control cookies through your browser settings and, where required by Applicable Law (including under the EU ePrivacy framework, the UK Privacy and Electronic Communications Regulations, and equivalent Dutch and Spanish implementing legislation), through a cookie consent tool presented on first use of our websites.
5. HOW WE SHARE PERSONAL DATA
5.1 Payment Service Providers
We share Transaction and payment-related personal data with Payment Service Providers, including acquiring banks, card schemes, and digital wallet providers, solely to process payments and facilitate settlement, as described in Clause 5.6 of the Terms and Conditions.
5.2 Kayana Group
We share personal data among members of the Kayana Group as described in Clause 1.3 above.
5.3 Service Providers
We share personal data with third-party service providers who support our operations, including cloud hosting, customer support, identity verification, fraud prevention, analytics, and marketing service providers, under contractual terms that require them to protect personal data and use it only for the purposes we specify.
5.4 Merchants and Buyers
Buyer personal data reasonably necessary to fulfil a Ticket purchase (such as name and Ticket details) is shared with the relevant Merchant. Kayana is not responsible for a Merchant’s further use of Buyer personal data once shared, which is governed by the Merchant’s own privacy policy and its obligations under Clause 17 of the Terms and Conditions.
5.5 Legal and Regulatory Disclosures
We may disclose personal data where required by Applicable Law, to respond to lawful requests from courts, regulators, or government authorities (including tax authorities, financial regulators, and law enforcement in any jurisdiction in which the Kayana Group operates), or to protect the rights, property, or safety of Kayana, our users, or others.
5.6 Business Transfers
If a Kayana Group entity is involved in a merger, acquisition, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards and notice as required by Applicable Law.
5.7 No Sale of Personal Data
We do not sell personal data to third parties for money. Where Applicable Law (such as the CCPA/CPRA) defines “sale” or “sharing” more broadly to include certain forms of advertising-related data disclosure, see Clause 9.3 for details of our practices and your opt-out rights.
6. INTERNATIONAL DATA TRANSFERS
Because the Kayana Group operates across the United Kingdom, the European Union (through Kayana For Business Ireland, serving Spain and the Netherlands among other EU markets), the United States, Canada, and Australia, personal data may be transferred between these territories. Where we transfer personal data out of the UK or the EEA to a territory that has not been assessed as providing an adequate level of protection, we put in place appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, the UK’s International Data Transfer Addendum, or another lawful transfer mechanism, and, where required, carry out a transfer risk assessment. You may request further information about these safeguards by contacting us using the details in Clause 12.
7. DATA RETENTION
We retain personal data for as long as necessary to fulfil the purposes described in this Policy, including to provide the Platform, comply with legal, tax, and regulatory retention obligations (which vary by jurisdiction and can extend for several years after an account is closed, particularly for AML/KYC and financial records), resolve disputes, and enforce our agreements. When personal data is no longer needed, we securely delete or anonymise it, subject to any legal obligation to retain it for longer.
8. SECURITY
We implement technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, or alteration, including encryption in transit, access controls, and vendor security assessments. No system is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that requires notification under Applicable Law, we will notify affected individuals and/or the relevant regulator (such as the UK Information Commissioner’s Office, the AEPD, the Autoriteit Persoonsgegevens, or applicable US state authorities) as required.
9. YOUR RIGHTS — JURISDICTION-SPECIFIC PROVISIONS
9.1 United Kingdom
If the UK GDPR and Data Protection Act 2018 apply to you, you have the right to: access your personal data; request rectification of inaccurate data; request erasure; restrict or object to processing; request data portability; and withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
9.2 European Union (Spain and the Netherlands)
If the EU GDPR applies to you, you have the rights described in Clause 9.1 above under equivalent EU law, and may lodge a complaint with your local supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD), and in the Netherlands, the Autoriteit Persoonsgegevens — or with the supervisory authority of your EU Member State of residence.
9.3 United States
Depending on your state of residence, you may have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and similar laws in states including Virginia, Colorado, Connecticut, and Utah. These rights may include the right to know what personal data we collect and how it is used; the right to delete personal data; the right to correct inaccurate personal data; the right to opt out of the “sale” or “sharing” of personal data (including certain advertising-related data disclosures) and of targeted advertising; and the right to non-discrimination for exercising your rights. To exercise these rights, contact us using the details in Clause 12.
9.4 Canada
If PIPEDA or applicable provincial privacy legislation applies to you (including Quebec’s Law 25), you have the right to access personal data we hold about you, request correction of inaccurate information, and withdraw consent to processing where consent is the basis for that processing, subject to legal or contractual restrictions. You may also lodge a complaint with the Office of the Privacy Commissioner of Canada or the relevant provincial regulator.
9.5 Australia
If the Privacy Act 1988 and the Australian Privacy Principles (APPs) apply to you, you have the right to access and seek correction of your personal data, and to make a complaint about our handling of your personal data, including to the Office of the Australian Information Commissioner (OAIC) if you are not satisfied with our response.
9.6 How to Exercise Your Rights
To exercise any of the rights described in this Clause 9, contact us using the details in Clause 12. We may need to verify your identity before responding, and may decline requests where an exemption applies under Applicable Law. We aim to respond within the timeframe required by the law applicable to your request.
10. CHILDREN’S PRIVACY
The Platform is not directed at, and we do not knowingly collect personal data from, children below the age required to enter into a contract in their jurisdiction (generally 18, or 16 in respect of certain data protection consents under the GDPR framework, or as otherwise specified by local law). If we become aware that we have inadvertently collected personal data from a child in breach of this Clause, we will take steps to delete it.
11. CHANGES TO THIS POLICY
We may update this Policy from time to time to reflect changes in our practices or Applicable Law. Material changes will be notified in the same manner as amendments to the Terms and Conditions (Clause 19.2), with at least thirty (30) days’ advance notice where required. The “Effective Date” at the top of this Policy indicates when it was last revised.
12. CONTACT US
For questions about this Policy or to exercise your data protection rights, please contact:
Global / UK — Kayana World Limited (Company No. 12782000) Address: Arch 58, Ingate Place, London, SW8 3AG, United Kingdom Email: info@kayanaforbusiness.com Website: www.kayanaforbusiness.com
United States — Kayana For Business USA Inc (No. 2025-001835267) Address: 30 North Gould Street, Ste R, Sheridan, Wyoming, 82801, United States Email: info@kayanaforbusiness.com
Canada — Kayana Canada Inc (No. 1001438570) Address: 75 Bayly St W, Unit 15, Ajax, Ontario, L1S 7K7, Canada Email: info@kayanaforbusiness.com
European Union (incl. Spain and the Netherlands) — Kayana For Business Ireland (No. 737092) Address: 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland Email: info@kayanaforbusiness.com
Australia — Kayana For Business Australia Pty Ltd (No. 693 838 014) Address: 368 Sussex Street, 526, Sydney, New South Wales, 2000, Australia Email: info@kayanaforbusiness.com
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority, as identified in Clause 9.
This Privacy Policy was last updated on 15 July 2026.



