Legal

Privacy Policy

How Squadron Web Limited, trading as frequentix, handles personal data — and the rights you have over it.

Last updated 13 July 2026

This policy explains how Squadron Web Limited (trading as frequentix, “we”, “us”) collects and uses personal data when you use our registration and ticketing platform and this website. We are registered with the UK Information Commissioner’s Office (ICO) under reference ZC193207.

frequentix is a platform used by event organisers. That means we act in two different roles, and which one applies changes your rights and who you should contact:

  • As a data controller — for the accounts of organisers and their staff, our billing, website visitors, and keeping the platform secure. Here we decide how and why data is used, and this policy governs it.
  • As a data processor — for the attendee and contact data an organiser collects, imports and manages through frequentix (for example ticket buyers and registrants). For that data the organiser is the controller: they decide how it is used, their own privacy notice applies, and requests about it should go to them. We only act on their instructions, under the Data Processing Agreement.

1. Who we are

Squadron Web Limited is a company registered in England & Wales (company number 08622468), trading as frequentix. We are the controller for the personal data described in this policy except where we say we act as a processor for an organiser.

For any privacy question, or to exercise your rights, contact us at privacy@frequentix.com.

2. The personal data we collect

Depending on how you use frequentix, this can include:

  • Organiser account data — the name, email address, password (stored only as a secure hash) and language preference of organiser staff, plus the organiser’s own business and billing details.
  • Account security data — the second factor that protects your account: an encrypted authenticator (TOTP) secret and/or a record that email one-time codes are enabled, plus single-use recovery codes kept only as hashes. If you use Sign in with Google, your Google account identifier.
  • Attendee and registration data (handled on the organiser’s behalf) — the name, email address and, where collected, mobile number of ticket buyers and registrants, along with the answers to any registration questions the organiser chooses to ask. The identity details held inside each issued ticket are encrypted at rest.
  • Order and payment data — what was bought, amounts, currency and references to the payment. We do not receive or store full card numbers; card payments are handled by Stripe (see “How we share data”).
  • Communications data — the emails we send on an organiser’s behalf (such as order confirmations and event updates), and basic delivery and open information used to keep sending reliable and to measure engagement for marketing messages.
  • Mobile wallet data — where an attendee adds a ticket to Apple Wallet or Google Wallet, a device identifier used to deliver pass updates.
  • Technical and usage data — limited information needed to operate and secure the service, such as authentication and audit records.

3. How we use personal data

We use personal data to:

  • provide and operate the platform and this website;
  • take payment for tickets and pay out to organisers through our payment provider;
  • send service messages such as confirmations, tickets and account notices, and — where relevant — event communications on an organiser’s behalf;
  • keep the platform secure and prevent fraud and abuse;
  • provide support and respond to enquiries;
  • meet our legal and accounting obligations and enforce our terms;
  • understand and improve the service, using aggregated or de-identified information wherever we can.

5. How we share data

We do not sell personal data. We share it only as needed to run the service, with the following categories of recipient (our sub-processors):

  • Amazon Web Services (AWS) — hosting of files, sending of email and handling of delivery notifications, in the UK (London) region.
  • Stripe — payment processing for ticket sales and platform billing. Card details are entered directly with Stripe; we never see them.
  • Apple and Google — where an attendee chooses to add a ticket to a mobile wallet.
  • Laravel Cloud — application hosting.
  • Google (Sign in with Google) — if a staff member chooses to sign in with Google, Google verifies their identity and provides us with basic profile information (their Google account identifier, email address and whether Google has verified it).

We also share data as directed by the organiser — for example, where an organiser configures an integration (“webhook”) that sends order or attendee information to a system of their choice. Those onward recipients are the organiser’s responsibility, not ours.

We may disclose data where required by law, to protect our rights, or in connection with a sale or reorganisation of our business. A current list of sub-processors is set out in the Data Processing Agreement.

6. International transfers

Our primary systems store personal data in the United Kingdom. Some of our providers may process data outside the UK. Where they do, we rely on appropriate safeguards recognised under UK law — such as UK ‘adequacy’ regulations or the UK International Data Transfer Agreement (or the Addendum to the EU Standard Contractual Clauses) — so that your data remains protected.

7. How long we keep data

We keep personal data for as long as needed for the purposes above — in practice, while an organiser’s account is active and their events are being run and supported, and afterwards only as long as we need it (for example to meet accounting and legal record-keeping obligations).

Attendee data is retained in line with the organiser’s instructions. When an organiser erases a contact, we anonymise that person’s record and invalidate their tickets so they can no longer be identified from them.

8. Your rights

Under UK data protection law you have the right to:

  • ask for a copy of your personal data;
  • have inaccurate data corrected;
  • have your data erased in certain circumstances;
  • restrict or object to certain processing;
  • data portability;
  • withdraw consent where we rely on it.

To exercise any of these, email privacy@frequentix.com. If your request is about data an organiser holds about you (for example your ticket or registration for their event), you may need to contact that organiser directly, as they are the controller — we will help point you in the right direction.

You can also complain to the ICO (ico.org.uk), though we’d welcome the chance to resolve things first.

9. Cookies

We keep cookies to a minimum. Our website and apps use only strictly necessary cookies — for example to keep you signed in and to keep the service secure. Because these are essential to provide a service you have asked for, we do not need a cookie consent banner and we do not use them to track you.

We do not use advertising or third-party analytics cookies. If that ever changes, we will update this policy and ask for your consent before any non-essential cookies are set.

10. How we protect data

We take security seriously. Passwords are stored only as secure hashes, the identity details inside tickets are encrypted at rest, data is encrypted in transit, and access is controlled and logged. Reaching sensitive information — personal data, exports, billing and team management — requires staff to confirm a second factor beyond their password: email one-time codes or an authenticator app (with single-use recovery codes), or Sign in with Google. Our data is hosted in the UK. No system is perfectly secure, but we work to protect your data and will notify you and the ICO of a personal data breach where the law requires.

11. Changes to this policy

We keep this page under review and may update it from time to time. Where a change is material we will take reasonable steps to let affected organisers know. The date at the top shows when it was last revised.

12. Contact us

Questions about this policy or your data? Email us at privacy@frequentix.com, or write to us at the address at the foot of this page.

Legal information

frequentix is a trading name of Squadron Web Limited, a company registered in England & Wales (company number 08622468).

Registered office: 128 City Road, London, EC1V 2NX.

Registered with the UK Information Commissioner’s Office under reference ZC193207.

Not VAT-registered.

Contact: privacy@frequentix.com