Skip to main content
RAMPAGE
What it does Features How it works FAQ
Manual Log in Request access
What it does Features How it works FAQ Manual Log in Request access
Legal

GDPR policy

Last updated: 26 August 2026

On this page

  1. Our commitment
  2. The principles we follow
  3. Controller and processor roles
  4. Lawful bases
  5. Data subject rights
  6. Processing on behalf of customers
  7. Sub-processors
  8. International transfers
  9. Data breaches
  10. Data processing agreement
  11. Contact

1. Our commitment

Tydeman Nar Limited is committed to protecting personal data and to meeting our obligations under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy sets out how those rules apply to RAMPAGE. It sits alongside our privacy policy, which describes in plain terms what we collect and why.

2. The principles we follow

We handle personal data in line with the UK GDPR principles. Personal data must be:

  • processed lawfully, fairly and in a transparent way;
  • collected for specified, explicit and legitimate purposes;
  • adequate, relevant and limited to what is needed;
  • accurate and kept up to date;
  • kept no longer than necessary; and
  • kept secure with appropriate technical and organisational measures.

We are accountable for meeting these principles and can demonstrate how we do so.

3. Controller and processor roles

We are the controller for the personal data of website visitors, enquirers and the account holders we deal with directly. We are a processor for the personal data our customers enter into their workspace, which they control. When we act as a processor, we process personal data only on the customer's documented instructions.

4. Lawful bases

We identify a lawful basis before processing personal data. Depending on the activity, we rely on legitimate interests, performance of a contract, compliance with a legal obligation, or consent. Where we rely on consent, it is freely given and can be withdrawn at any time. The bases we use are described in our privacy policy.

5. Data subject rights

We respect the rights that individuals have over their personal data, namely the right to be informed, of access, to rectification, to erasure, to restrict processing, to data portability, to object, and rights relating to automated decision making. RAMPAGE does not make decisions about individuals by solely automated means that produce legal or similarly significant effects.

Where a request concerns data held within a customer's workspace, we support that customer, as controller, in responding. We handle requests within the statutory time limit, usually one month, and will explain if we need to extend that in line with the law.

6. Processing on behalf of customers

When we process personal data as a customer's processor, we commit to:

  • process it only on the customer's documented instructions;
  • ensure that people authorised to process it are under a duty of confidentiality;
  • apply appropriate security measures;
  • engage sub-processors only under written terms and with appropriate safeguards;
  • assist the customer with data subject requests and with their own compliance duties, taking account of the nature of the processing;
  • tell the customer without undue delay if we become aware of a personal data breach affecting their data; and
  • return data before closure where the customer requests an available export, then permanently and irreversibly delete the customer’s workspace data, including existing backup copies, when the customer’s organisation account is closed, unless UK law requires a limited record to be retained.

7. Sub-processors

We use a small number of trusted providers to help deliver RAMPAGE, for example hosting and email delivery. Each is bound by contract to protect personal data and to process it only as needed to provide their service. The providers we use are named in section 6 of our privacy policy, and a current list is also available on request. We will tell customers before we add or replace a sub-processor that handles their data.

8. International transfers

Most personal data in RAMPAGE is hosted in the United Kingdom. One exception applies. Transactional email is delivered by Resend, a provider based in the United States, so a recipient address and the content of that message are processed there. Resend is certified under the UK Extension to the EU to US Data Privacy Framework, and its data processing agreement includes standard contractual clauses covering the transfer. Where any other transfer outside the UK is necessary, we put an appropriate safeguard in place, such as reliance on UK adequacy regulations or the International Data Transfer Agreement, and we assess the transfer where required.

9. Data breaches

We have procedures to detect, report and investigate personal data breaches. Where a breach is likely to result in a risk to people's rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it. Where we act as a processor, we will notify the affected customer without undue delay so that they can meet their own obligations.

10. Data processing agreement

Customers who need a data processing agreement (DPA) that sets out the Article 28 terms for our processing on their behalf can request one from privacy@rampagehq.co.uk, and we will provide our standard DPA for signature.

11. Contact

For any data protection question, or to exercise a right, contact privacy@rampagehq.co.uk or write to Tydeman Nar Limited, The Depot, Cutting Road, Great Abington, CB21 6AJ. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

RAMPAGE

RAMS and crew management software for UK live events production.

Product

What it does Features How it works Manual Other industries

Get started

Log in Request access FAQ

Legal

Terms and conditions Privacy policy GDPR policy Cookies policy Data policy
© 2026 Tydeman Nar Limited. All rights reserved. rampagehq.co.uk