DS Experiences

DS Experiences LLP

Privacy & Cookie Policy

This Privacy & Cookie Policy explains how DS Experiences LLP collects, uses, stores, discloses and protects personal data when you visit our website, contact us, submit an enquiry, request a quotation, make a booking, receive a service arranged by us or otherwise interact with DS Experiences.

Effective date: Last updated: Version: 3.0

DS Experiences LLP, trading as DS Experiences and DS Experiences Group, provides access to sporting events, concerts, festivals, hospitality experiences and, where requested, related accommodation, transport, travel or concierge arrangements.

This Policy applies to dsexperiencesgroup.com , our enquiry and booking processes, customer-service interactions and communications through email, telephone, WhatsApp and social media.

Merely visiting our website does not constitute consent to optional cookies, behavioural advertising or marketing communications. Where consent is required, it will be requested separately.

1. Who is responsible for your personal data

The organisation responsible for determining why and how personal data covered by this Policy is processed is:

Legal entity: DS Experiences LLP

Trading names: DS Experiences and DS Experiences Group

Country of registration: India

Registered office: White Arch, Mathuradas Road, Kandivali West, Mumbai, Maharashtra 400067, India

Website: https://dsexperiencesgroup.com/

Privacy and grievance email: enquiries@dsexperiencesgroup.com

Depending on the law applicable to the relevant processing, DS Experiences LLP may be referred to as the Data Fiduciary or data controller.

Event organisers, venues, ticketing providers, payment providers, accommodation providers, transport providers and other independent service providers may separately determine how they use personal data. Where they do so, they act under their own privacy notices.

2. Scope of this Policy

This Policy applies when you:

  • visit or interact with our website;
  • submit a contact form, enquiry or availability request;
  • request a quotation or personalised proposal;
  • contact us through email, telephone, WhatsApp or social media;
  • request or purchase tickets, hospitality or another experience;
  • request accommodation, transport, travel or related assistance;
  • receive customer support relating to an enquiry or booking;
  • attend an event or experience arranged through us;
  • participate in a survey, promotion or competition operated by us;
  • communicate with us as a customer, supplier, service provider or business contact;
  • receive marketing communications from us; or
  • otherwise provide personal data to DS Experiences LLP.

This Policy does not govern the independent privacy practices of event organisers, venues, payment providers, ticketing providers, accommodation providers, transport providers, social-media platforms or other third parties. Their privacy notices may apply in addition to this Policy.

3. Personal data we collect

The information we collect depends on how you interact with us and the service you request. We seek to collect only the information reasonably necessary for the relevant purpose.

3.1 Identity and contact information

  • full name, title and preferred name;
  • email address and telephone or WhatsApp number;
  • postal, billing or delivery address;
  • country of residence, nationality and preferred language;
  • company name, professional designation and business contact details;
  • customer, enquiry, quotation, invoice or booking reference; and
  • social-media username where you contact us through a social platform.

3.2 Enquiry and booking information

  • the event, match, concert, festival or experience requested;
  • preferred dates, city, venue, seating area or hospitality category;
  • number of attendees and guest names;
  • budget, currency and quotation preferences;
  • booking reference, order history and ticket-delivery details;
  • accommodation, transportation or itinerary requirements;
  • special-occasion, gifting or hosting information voluntarily provided by you;
  • customer preferences and previous enquiry or booking history; and
  • messages, instructions, complaints, feedback and customer-service records.

3.3 Guest, identity and travel information

Certain named tickets, hospitality products, venue procedures or travel arrangements may require:

  • guest names and contact information;
  • date of birth or age confirmation;
  • nationality or country of residence;
  • passport or government-issued identity-document information;
  • photograph or identity-verification information where required;
  • flight, hotel, transfer and itinerary details;
  • visa, immigration or entry information where relevant;
  • emergency-contact information; and
  • information required by an organiser, venue, accommodation provider, transport provider or competent authority.

We request this information only where reasonably necessary to provide the requested service, satisfy an event or venue requirement, comply with law, protect security or verify identity.

3.4 Payment and transaction information

  • billing name and billing address;
  • invoice, tax and business-billing information;
  • bank-transfer and payment-reference details;
  • payment status, payment method and transaction identifier;
  • refund, cancellation, dispute and chargeback information;
  • limited card information made available by a payment provider, such as the card type or final digits; and
  • fraud-prevention or payment-verification results.

Full payment-card details are normally collected directly by the relevant bank or payment provider. We do not intentionally collect or store card verification values such as CVV or CVC.

3.5 Website and technical information

  • internet protocol address;
  • device type, browser and operating system;
  • screen, language and regional settings;
  • approximate location derived from an internet protocol address;
  • referring page, campaign source or search information;
  • pages viewed, links selected and website interactions;
  • session, error, performance and security logs;
  • cookie identifiers and similar device identifiers, where permitted; and
  • records of cookie and privacy choices.

3.6 Communications and preference information

  • email, telephone, WhatsApp and social-media communications;
  • sports, events, artists, destinations and experiences of interest;
  • marketing and communication preferences;
  • newsletter, email and campaign engagement;
  • survey, promotion or competition responses; and
  • records of consent, withdrawal and unsubscribe requests.

3.7 Information about other people

You may provide personal data about guests, family members, employees, clients or other attendees. You must have appropriate authority to provide their information and should make this Policy available to them before sharing their personal data with us.

Where another person makes an enquiry or booking on your behalf, we may receive your information from that person.

4. Sensitive personal data

We do not ordinarily seek sensitive or special-category personal data. Limited sensitive information may nevertheless be necessary for an accessibility request, dietary requirement, medical need, emergency, identity-verification process or travel arrangement.

This may include:

  • accessibility or disability-assistance requirements;
  • medical information necessary for safe service delivery or emergency assistance;
  • allergy or dietary information that may reveal health or religious information;
  • biometric or identity-verification information required by an organiser, venue or competent authority; and
  • other sensitive information voluntarily provided where relevant to your request.

We process such information only where necessary and permitted by law, including with explicit consent, to protect vital interests, comply with a legal obligation or establish, exercise or defend legal claims.

We do not use sensitive personal data for behavioural advertising.

5. How we obtain personal data

We may obtain personal data:

  • directly from you;
  • from a person making an enquiry or booking on your behalf;
  • from your employer or another organisation where the interaction is business-related;
  • from an event organiser, venue, ticketing provider or other service provider involved in your request;
  • from an accommodation, transport or travel provider involved in your request;
  • from a payment provider, bank or fraud-prevention service;
  • from social-media or messaging platforms when you communicate with us through those services;
  • from publicly available professional or business sources where permitted by law; and
  • automatically through cookies, server logs and similar technologies.

6. How and why we use personal data

We process personal data for specified and lawful purposes. Where Indian data-protection law applies, processing may be based on consent or another use permitted by law.

Where the EU or UK General Data Protection Regulation applies, we rely on one or more of the following legal bases:

  • your consent;
  • taking steps at your request before entering into a contract;
  • performing a contract with you;
  • complying with a legal obligation;
  • protecting a person’s vital interests;
  • our legitimate interests or those of another person, provided those interests are not overridden by your rights; or
  • establishing, exercising or defending legal claims.
Purpose Information commonly used EU / UK legal basis where applicable
Responding to enquiries and preparing quotations Identity, contact, event-preference and communication information Steps before entering a contract, legitimate interests or consent
Arranging tickets, hospitality and other requested experiences Identity, contact, guest, booking, payment and delivery information Performance of a contract and steps before entering a contract
Satisfying ticket-personalisation, venue-access and security requirements Guest names, contact details, identity information and booking information Performance of a contract, legal obligation and legitimate interests
Arranging accommodation, transport or travel-related services Identity, guest, itinerary, passport, contact and accessibility information Performance of a contract and explicit consent where required
Processing payments, invoices, refunds and cancellations Billing, transaction, payment, tax and communication information Performance of a contract, legal obligation and legitimate interests
Providing customer service and resolving complaints Identity, contact, booking, transaction and communication information Performance of a contract, legal obligation and legitimate interests
Sending booking, payment, delivery and service communications Contact, booking, itinerary and transaction information Performance of a contract and legitimate interests
Protecting our website, customers, bookings and payment processes Identity, technical, security, payment and transaction information Legal obligation and legitimate interests
Preventing fraud, misuse, unauthorised transactions and chargebacks Identity, payment, transaction, device and communication information Legal obligation and legitimate interests
Operating, maintaining and improving the website and services Technical, usage, cookie and aggregated information Consent where required and legitimate interests
Sending promotional communications Contact, interest, preference, consent and engagement information Consent or legitimate interests where permitted
Complying with accounting, tax, regulatory and legal obligations Relevant booking, payment, identity and communication records Legal obligation and legitimate interests
Establishing, exercising or defending legal and contractual rights Information relevant to the matter Legitimate interests and legal claims

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.

7. Bookings, tickets and guest information

Events, tickets, hospitality and related services may be delivered or operated by independent event organisers, venues, ticketing providers, rights holders, accommodation providers, transport providers or other service providers.

Some tickets or experiences are personalised, named, non-transferable or delivered through an external ticketing service or mobile application. To process and fulfil a request, we may need to:

  • collect and confirm attendee names;
  • provide necessary attendee information to the relevant service provider;
  • use the email address or telephone number required for ticket delivery;
  • verify identity, nationality, residency or age;
  • communicate venue-access, collection, transfer or security instructions;
  • communicate event, schedule, venue, access or delivery changes;
  • coordinate accommodation, transfers or travel arrangements where requested; and
  • assist with complaints, cancellations, refunds or service issues.

The relevant service provider may process personal data independently and may require you to accept its own contractual terms and privacy policy.

8. Payments, refunds and fraud prevention

Payments may be completed through bank transfer, card payment, a payment gateway or another payment method made available for the relevant transaction.

We may process payment and transaction information to:

  • confirm, reconcile and allocate payments;
  • issue invoices, receipts and credit notes;
  • calculate and account for applicable taxes;
  • process refunds, cancellations and payment adjustments;
  • investigate duplicate, disputed, unsuccessful or unauthorised payments;
  • prevent fraud, misuse and chargebacks;
  • respond to banks and payment providers; and
  • establish, exercise or defend contractual and legal claims.

Banks, card networks and payment providers process payment information under their own terms and privacy policies.

9. Marketing communications

Subject to applicable law and your preferences, we may send information about sporting events, concerts, festivals, hospitality, travel and other experiences through email, telephone, SMS, WhatsApp or similar communication channels.

We may send such communications where:

  • you have expressly consented;
  • the communication concerns similar services and is otherwise permitted by law;
  • it constitutes a proportionate business-to-business communication permitted by law; or
  • another valid legal basis applies.

You may unsubscribe through an unsubscribe link, reply with an opt-out instruction where available, change your preferences or contact us directly.

We may retain a minimal suppression record so that we continue to respect your opt-out request.

Opting out of marketing does not prevent us from sending necessary booking, payment, security, ticket-delivery or customer-service communications.

10. Cookies and similar technologies

Our website may use cookies, local storage, pixels, tags, scripts and similar technologies that store or access information on a browser or device.

Category Purpose Consent position
Strictly necessary Website security, network management, fraud prevention, form functionality and recording privacy choices. Used where necessary to operate the website or provide a service expressly requested by you.
Functional Optional features such as remembered preferences, external media, maps, chat or enhanced website functionality. Disabled until consent where consent is legally required.
Analytics Measuring website traffic, technical performance, page usage and visitor interactions. Disabled until consent where consent is legally required.
Marketing Campaign measurement, advertising attribution and relevant promotional activity. Disabled until consent where consent is legally required.

Rejecting non-essential cookies will not prevent you from accessing the principal content of the website or submitting a basic enquiry. Certain optional features, embedded content, analytics or personalisation may not function.

You can change or withdraw your cookie choices at any time using the cookie-settings control displayed on the website:

This button will operate after the website’s cookie-consent mechanism has been installed and connected to the data-dse-open-cookie-settings attribute.

11. Who we share personal data with

We disclose personal data only where reasonably necessary for the purposes described in this Policy.

11.1 Event and service providers

  • event organisers and promoters;
  • venues, stadiums, circuits, theatres and hospitality operators;
  • sports clubs, federations, rights holders and ticketing providers;
  • ticket-delivery and mobile-ticket service providers;
  • suppliers involved in arranging or fulfilling the requested service; and
  • other service providers where disclosure is necessary to fulfil your request.

11.2 Travel and experience providers

  • hotels and accommodation providers;
  • airlines, rail operators and transport providers;
  • ground-transfer and destination-service providers;
  • tour and activity operators;
  • travel-assistance providers; and
  • identity, visa or entry-assistance providers where requested or necessary.

11.3 Technology and operational providers

  • website-hosting, cloud-storage and cybersecurity providers;
  • email, telephone, messaging and communication providers;
  • website-maintenance and customer-support providers;
  • analytics and cookie-consent providers;
  • marketing and advertising providers where the necessary consent has been obtained;
  • identity and fraud-prevention providers; and
  • providers supporting the secure operation of our business.

11.4 Payment, professional and legal recipients

  • payment gateways, banks, card networks and financial institutions;
  • accountants, auditors and tax advisers;
  • lawyers, insurers and professional advisers;
  • courts and dispute-resolution bodies;
  • regulators, law-enforcement agencies and public authorities; and
  • other recipients where disclosure is required or permitted by law.

11.5 Persons acting on your behalf

We may disclose relevant information to a person or organisation that made an enquiry or booking on your behalf where we reasonably believe that person or organisation is authorised to receive it.

Providers acting solely on our instructions are expected to process personal data only for authorised purposes and subject to appropriate confidentiality, security and data-protection obligations.

DS Experiences LLP does not sell personal data for monetary consideration.

12. International data transfers

DS Experiences provides services involving events and experiences in multiple countries. Personal data may therefore be processed or accessed outside the country in which it was originally collected.

A transfer may be necessary where an event, venue, accommodation, transport, payment, technology or other relevant service provider is located in another country.

Privacy laws and regulatory protections may differ between countries. Where required by applicable law, we use an appropriate transfer mechanism, which may include:

  • an applicable adequacy decision;
  • approved standard contractual clauses;
  • a recognised international data-transfer agreement or contractual addendum;
  • contractual confidentiality, security and data-protection provisions;
  • supplementary technical and organisational safeguards;
  • explicit consent where legally permitted; or
  • another lawful transfer mechanism.

We will comply with legally applicable restrictions or governmental requirements concerning international transfers of personal data.

13. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including contractual, tax, accounting, fraud-prevention, customer-service and legal requirements.

Type of information Indicative retention period
Enquiries that do not result in a booking Normally up to 24 months after the last meaningful interaction, unless a longer period is necessary for a dispute or legal requirement.
Booking, invoice, payment and contractual records For the period required by applicable tax, accounting, contractual and limitation laws, normally up to eight years after completion.
Passport, identity-document and verification information Only for as long as reasonably necessary to fulfil the relevant booking, verification, security or legal requirement.
Guest, accommodation and travel information Normally deleted, restricted or minimised after the relevant event, trip and customer-support period unless longer retention is required.
Customer-service communications Normally up to three years after the matter is concluded, subject to any legal, contractual or dispute requirement.
Marketing records Until consent is withdrawn, you object, or the information is no longer required, with a minimal suppression record retained afterwards.
Website security and technical logs Normally up to 12 months unless required for an investigation, security incident or legal claim.
Cookie-consent and preference records Normally up to 12 months, until you change your preference or for another period necessary to demonstrate consent.
Complaints, disputes and legal claims For the duration of the matter and the applicable legal limitation period.

A retention period may be extended where information is subject to a legal hold, audit, fraud investigation, chargeback, complaint, regulatory enquiry or pending dispute.

Information may be anonymised and retained in aggregated form where it no longer identifies an individual.

14. Data security and personal-data breaches

We use reasonable technical and organisational measures appropriate to the nature and risk of the personal data processed.

These measures may include:

  • access controls and authentication procedures;
  • restricted access to booking, payment and identity information;
  • encryption in transit where supported;
  • secure hosting and backup procedures;
  • system, malware and security monitoring;
  • confidentiality obligations;
  • service-provider due diligence;
  • data-retention and secure-deletion procedures;
  • fraud and payment-security controls; and
  • incident-response and breach-management procedures.

No internet transmission, website or electronic-storage system can be guaranteed to be completely secure. You should also protect your devices, passwords, email accounts and ticket-delivery information.

If a personal-data breach occurs, we will assess its nature, scope and likely consequences, take reasonable containment and remediation measures, document the incident and notify affected individuals and competent authorities where required by law.

15. Your privacy rights

Your rights depend on the law applicable to the relevant processing. You may have some or all of the following rights.

15.1 Rights under applicable Indian data-protection law

  • to obtain information about personal data being processed and the relevant processing activities;
  • to request correction of inaccurate or misleading information;
  • to request completion or updating of incomplete information;
  • to request erasure where the information is no longer required and no legal basis requires continued retention;
  • to withdraw consent;
  • to submit and escalate a grievance;
  • to nominate another person to exercise applicable rights in legally specified circumstances; and
  • to complain to the competent data-protection authority or board where and when applicable.

15.2 Rights under the EU or UK GDPR

  • the right to access personal data;
  • the right to correct inaccurate personal data;
  • the right to request deletion;
  • the right to restrict processing;
  • the right to data portability;
  • the right to object to processing based on legitimate interests;
  • the right to object to direct marketing at any time;
  • the right to withdraw consent at any time;
  • rights relating to decisions based solely on automated processing where those decisions produce legal or similarly significant effects; and
  • the right to complain to a competent data-protection supervisory authority.

15.3 Rights under other privacy laws

Where another privacy law applies, you may have additional rights to access, know, correct, delete or obtain a portable copy of personal data, and to opt out of certain advertising, sale or sharing practices.

15.4 How to exercise your rights

Send your request to enquiries@dsexperiencesgroup.com using the subject line Privacy Request.

Please describe the request clearly and identify the relevant enquiry, quotation or booking where applicable.

We may request proportionate information to verify your identity, prevent unauthorised disclosure and confirm your authority to act for another person.

Privacy rights are not absolute. A request may be restricted or refused where permitted by law, including where information must be retained for legal obligations, fraud prevention, legal claims or the rights of another person.

We will respond within the period required by applicable law and explain any legally permitted refusal or limitation.

16. Children and minors

Our website and direct booking services are intended for adults. Individuals under 18 should not make a booking or provide personal data without the involvement of a parent or lawful guardian.

A parent, guardian or responsible adult may provide a minor’s information where necessary for a family booking, ticket allocation, accommodation, travel arrangement or venue-access requirement.

We may request parental or guardian confirmation where required by law.

We do not knowingly conduct behavioural monitoring, profiling or targeted advertising directed at children.

17. Automated processing and decision-making

We may use limited automated processes to support website security, payment verification, fraud prevention, enquiry administration, booking administration, communication management and website analytics.

We do not ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects on an individual.

If such processing is introduced and applicable law requires specific safeguards, we will provide appropriate information and applicable rights, which may include the right to request human review or contest the outcome.

18. Third-party services, websites and links

Our website or communications may contain links to or content from event organisers, venues, ticketing providers, payment providers, maps, social-media platforms, messaging services, video platforms or other third parties.

These third parties may independently collect personal data and use cookies or similar technologies. We do not control their independent privacy practices.

You should review the privacy policy and cookie information of the relevant third party before submitting personal data or enabling optional content.

Communications sent through WhatsApp, email, social media or another external platform are also subject to that platform’s own privacy terms.

19. Business or organisational changes

Personal data may be disclosed or transferred where reasonably necessary in connection with a reorganisation, merger, acquisition, transfer of business, insolvency or similar legal or corporate change.

Any such disclosure or transfer will be subject to appropriate confidentiality, security and data-protection safeguards. Additional notice will be provided where required by law.

20. Changes to this Policy

We may update this Policy to reflect changes in our services, website, payment methods, service providers, legal obligations or data-handling practices.

The updated version will be published on this page with a revised effective date.

Where a change materially affects your rights or how personal data is used, we will provide additional notice or obtain new consent where required by law.

21. Contact, privacy requests and grievances

Privacy questions, rights requests, consent withdrawals and grievances may be addressed to:

Contact designation: Privacy and Grievance Contact

Organisation: DS Experiences LLP

Email: grievances@dsexperiencesgroup.com

Suggested email subject: Privacy Request or Privacy Grievance

Postal address: White Arch, Mathuradas Road, Kandivali West, Mumbai, Maharashtra 400067, India

Please provide sufficient information for us to identify the relevant records and understand the nature of the request.

We will acknowledge, investigate and respond to requests and grievances within the period required by applicable law.

You may also submit a complaint to the competent data-protection authority in the country where you live, work or believe that a privacy infringement occurred.