Headfirst Data Sharing Agreement
Version 1.0 — Effective 20 August 2026
This Data Sharing Agreement ("DSA") forms part of the Headfirst Supplier Agreement between you, the Supplier, and Headfirst Bristol Limited ("Headfirst", "we", "us"). Defined terms have the meanings given in the Supplier Agreement. This DSA governs the personal data made available to you through the Headfirst Platform and the personal data you bring to it.
1. Definitions and law
1.1. "Data Protection Law" means the UK GDPR and the Data Protection Act 2018, together with the Privacy and Electronic Communications Regulations 2003 (PECR) so far as they apply, and, where processing falls within its scope, the EU GDPR.
1.2. "Controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in Data Protection Law.
1.3. "Shared Data" means personal data we make available to you through the Platform, including Customer names, email addresses, postcodes, ticket details, doorlist entries, and marketing permission markers, in each case relating to your Events.
2. Relationship of the parties
2.1. You and we are each independent controllers of the personal data we each process in connection with the Platform. We are controller of the Platform, of Customer accounts and of the customer relationship; you are controller of the Shared Data from the point you access it, and of any personal data you collect yourself.
2.2. Neither party processes personal data as the processor of the other. Each party is separately responsible for its own compliance with Data Protection Law, including its own lawful basis, its own transparency obligations and its own handling of data subject rights.
3. What we share, and why
3.1. We make Shared Data available to you solely so you can run, administer and (where permission exists) market the Events it relates to. The categories, purposes and lawful bases are set out in Annex 1.
3.2. We use third-party service providers in operating the Platform. The current list of recipients of personal data, with the purpose and any international transfer safeguard for each, is maintained at headfirstbristol.co.uk/terms/data-recipients. We may update that list from time to time; the list in force at any time is the one published there.
4. Your obligations for Shared Data
4.1. Purpose limitation. You may use Shared Data only in connection with the Event it relates to, save that contacts who have given marketing permission for your organisation may be contacted about your future Events in accordance with clause 16 of the Supplier Agreement.
4.2. Marketing markers are binding. Where Shared Data is marked with whether a person has given marketing permission, you must honour that marker. Contacts without permission may receive service messages about their Event only, and never marketing.
4.3. Security. You must protect Shared Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration or disclosure, and ensure it is processed only by people bound by enforceable obligations of confidentiality who have received the instruction needed to process it competently.
4.4. Exports. Where you download or export Shared Data (including email, postcode, sales and doorlist exports), you must hold it securely, use it only for the purposes in clause 4.1, delete it when it is no longer needed for those purposes, and never sell it or pass it to any third party except your own staff and contractors under clause 4.3.
4.5. Doorlists. Doorlist data and the access codes that unlock it are confidential. Clause 17.1 of the Supplier Agreement applies: access codes may be shared only with people who need them to operate your Event, and you are responsible for what those people do with the data.
4.6. Aggregate insights. Statistics we provide (such as customer locations, loyalty and scan-time insights) are aggregate and are not personal data, and are provided for use in running and marketing your own Events only. You must not sell them, share them commercially, or attempt to identify any individual from them.
5. Data you bring to the Platform
5.1. Where you import personal data to the Platform (including ticket imports from other sales channels), you warrant that it was collected lawfully, that you are entitled to share it with us, and that its use on the Platform is compatible with what the individuals were told when it was collected.
5.2. To map the columns of an imported file, a bounded sample of its contents may be processed by a third-party artificial intelligence service listed at headfirstbristol.co.uk/terms/data-recipients. By importing a file you acknowledge and accept that step.
6. Sharing you initiate
6.1. Where you grant a third party access to Event data through the Platform (for example a sales dashboard link), you warrant that you are entitled to share that data with them, you remain responsible for what they do with it, and you will indemnify us against claims arising from that sharing.
7. Data subject rights and cooperation
7.1. Each party handles the data subject requests it receives in respect of the processing for which it is controller. Where a request received by one party concerns processing by the other, the receiving party will pass it on without undue delay, and each party will give the other the cooperation reasonably needed to respond within statutory deadlines.
8. Personal data breaches
8.1. If either party suffers a personal data breach affecting Shared Data, it must notify the other without undue delay, and in any event within 48 hours of becoming aware of it, giving enough detail for the other party to assess its own notification obligations.
8.2. Each party is responsible for its own notifications to the Information Commissioner's Office and to data subjects.
9. Indemnity
9.1. You will indemnify us against all losses, damages, liabilities, costs, expenses and fines we incur as a result of your breach of this DSA or of Data Protection Law in your handling of Shared Data.
10. Termination
10.1. When your use of the Platform ends, you must delete all Shared Data in your possession once it is no longer needed for a lawful purpose. We retain the data we hold in accordance with our own retention policy, including where retention is needed for tax, accounting, dispute and legal purposes.
10.2. This DSA survives termination of the Supplier Agreement for as long as either party holds data governed by it.
Annex 1 — Categories, purposes and lawful bases
| # | Shared Data | Made available via | Your purpose | Expected lawful basis (yours) | |---|---|---|---|---| | 1 | Customer name, ticket type, ticket status | Doorlists, orders views, doorlist exports | Admitting guests, operating the door | Legitimate interests (running the event) | | 2 | Customer email addresses, marketing permission marker | Email exports | Service messages about the Event; marketing only where the marker permits | Legitimate interests (service); consent (marketing) | | 3 | Customer postcodes | Postcode exports, location insights | Understanding your audience | Legitimate interests | | 4 | Order and sales data | Sales views and exports, sales dashboards | Accounting, reconciliation, event planning | Legitimate interests / legal obligation | | 5 | Sign-up page registrant details | Registrations views, email exports | Contact in line with the permission captured at registration | Consent | | 6 | Imported ticket data (brought by you) | Ticket imports | Admitting guests sold through other channels | Yours to establish at collection (clause 5.1) |
Annex 2 — Security measures expected of you
- Shared Data stored on devices and accounts protected by access controls (passwords or better).
- Access limited to people working on the Event concerned.
- No storage in shared or public locations (public folders, unprotected spreadsheets, group chats).
- Deletion once the purpose is served (clause 4.4), including from exports, downloads and email attachments.
- Loss or suspected compromise reported under clause 8.1.