Skip to main content
RAMPAGE
What it does Features How it works FAQ
Manual Log in Request access
What it does Features How it works FAQ Manual Log in Request access
Legal

Privacy policy

Last updated: 26 August 2026

On this page

  1. Who we are
  2. Controller and processor
  3. What we collect
  4. How we use it
  5. Lawful bases
  6. Who we share it with
  7. International transfers
  8. How long we keep it
  9. Security
  10. Your rights
  11. Cookies
  12. Changes
  13. Contact and complaints

1. Who we are

This policy explains how Tydeman Nar Limited ("we", "us", "our") handles personal data in connection with RAMPAGE, our RAMS and crew management software. We are registered in England and Wales (company number 16164153), with our registered office at The Depot, Cutting Road, Great Abington, CB21 6AJ.

We follow the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. Controller and processor

Our role depends on the data:

  • For people who visit our website or ask us for access, and for the account holders we deal with directly, we are the controller of that personal data.
  • For the content our customers put into their RAMPAGE workspace, including any personal data about their own staff, crew or contacts, the customer is the controller and we act as their processor, handling that data on their instructions to provide the service.

3. What we collect

Information you give us

  • When you request access or contact us: your name, company, work email, phone number if you provide it, what your business does, and anything you write in your message.
  • When you hold an account: your name, email, job title, phone number, and your role and permissions within your organisation.

Information within a customer workspace

Customers may enter personal data about their own people and contacts, for example crew names and phone numbers, site contacts, and details on crew information packs. We process this on the customer's behalf as described above.

Information collected automatically

  • Basic technical data needed to run the service securely, such as your IP address, browser type and log records of activity.
  • A small number of cookies that are necessary for the service to work. See our cookies policy.

4. How we use personal data

  • To respond to access requests and enquiries.
  • To set up, provide, secure and support the service.
  • To manage accounts and administer our relationship with customers.
  • To improve and maintain RAMPAGE, and to keep it secure.
  • To handle billing where a plan is chargeable.
  • To meet our legal and regulatory obligations.

5. Lawful bases

We rely on the following lawful bases under UK GDPR:

  • Legitimate interests: to respond to enquiries, run and secure the service, and manage our business, where those interests are not overridden by your rights.
  • Contract: to provide the service to a customer and to the users of that customer's workspace.
  • Legal obligation: to comply with laws that apply to us.
  • Consent: where we ask for it, for example for any optional marketing. You can withdraw consent at any time.

6. Who we share personal data with

We do not sell personal data. We share it only where needed:

  • With service providers who help us run RAMPAGE, such as our hosting provider and email delivery, under contracts that require them to protect the data and use it only for the agreed purpose.
  • Where a customer connects an integration, such as Current RMS, data is exchanged with that service on the customer's instruction and under that provider's own terms.
  • With professional advisers, or with authorities, where we are required to by law.
  • With a buyer or successor if we reorganise, sell or transfer part of our business, subject to appropriate protections.

The providers we rely on to deliver RAMPAGE are:

  • Krystal Hosting Ltd, application and database hosting, United Kingdom.
  • Resend, transactional email delivery, United States. See the Resend GDPR and data processing information.
  • Current RMS, only where a customer chooses to connect the integration, and under that customer's own account with them.

7. International transfers

Most personal data in RAMPAGE is hosted in the United Kingdom. One exception applies. Transactional email is delivered by Resend, a provider based in the United States, so a recipient address and the content of that message are processed there. Resend is certified under the UK Extension to the EU to US Data Privacy Framework, and its data processing agreement includes standard contractual clauses covering the transfer. Where any other transfer outside the UK becomes necessary, we make sure an appropriate safeguard is in place, such as UK adequacy regulations or the International Data Transfer Agreement.

8. How long we keep it

We keep personal data only as long as we need it for the purposes above, or as the law requires. In practice that means enquiry and access request data is kept for 24 months from your last contact with us. Account and workspace data is kept only for the life of the customer’s account. When the customer’s organisation account is closed, its workspace content and account-access data are permanently and irreversibly deleted as part of the closure process, including from backups and other copies under our control. There is no post-closure recovery period and the closed workspace cannot be restored. See our data ownership and deletion policy. Billing and accounting records are kept for six years, as UK tax law requires.

9. Security

We take appropriate technical and organisational measures to protect personal data, including access controls, encryption in transit, hashed passwords, and keeping our systems up to date. No online service can be completely secure, but we work to protect your data and to respond quickly if something goes wrong.

10. Your rights

Under UK data protection law you have rights over your personal data, including the right to:

  • ask for a copy of the personal data we hold about you;
  • ask us to correct data that is wrong or incomplete;
  • ask us to delete data in certain circumstances;
  • object to, or ask us to restrict, certain processing;
  • ask us to transfer your data to another provider where that right applies; and
  • withdraw consent where we relied on it.

If the data sits within a customer's workspace, we will usually direct your request to that customer, since they are the controller. To exercise a right, contact us using the details below. We may need to verify your identity, and we will respond within the time the law allows.

11. Cookies

We use a small number of cookies that are necessary to run the service. Full detail is in our cookies policy.

12. Changes to this policy

We may update this policy from time to time. The date at the top shows when it last changed. Where changes are significant we will take reasonable steps to let affected people know.

13. Contact and complaints

For any privacy question or to exercise a right, contact privacy@rampagehq.co.uk, or write to Tydeman Nar Limited, The Depot, Cutting Road, Great Abington, CB21 6AJ. Our data protection contact is the Director.

If you are not happy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put things right first.

RAMPAGE

RAMS and crew management software for UK live events production.

Product

What it does Features How it works Manual Other industries

Get started

Log in Request access FAQ

Legal

Terms and conditions Privacy policy GDPR policy Cookies policy Data policy
© 2026 Tydeman Nar Limited. All rights reserved. rampagehq.co.uk