Skip to main content

Back to policies

Privacy Policy

Privacy Policy

Midnight Mango Ltd

Introduction

We are Midnight Mango Ltd (“we”, “our” and “us”), also known as Midnight Mango. This Privacy Policy explains when, how and why we collect your personal data (any information relating to an identified or identifiable individual), how it is used, and the circumstances under which we may share it. We only use personal data lawfully and in accordance with UK data protection law.

Midnight Mango Ltd is a company registered in England, company registration number 07987730. We are the “controller” responsible for the processing of your personal data.

Most of the personal data we hold is professional contact information about people working in the live music industry — promoters, venue and festival programmers, agents, artists and suppliers. “Personal data” is a legal term that covers any information identifying a living individual, including business contact details such as a work email address or a professional phone number. It does not mean we collect people’s private or home contact details; for the most part we hold professional information, much of it gathered from the industry sources described below rather than provided to us directly.

The law that applies to our processing is the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. We are registered with the Information Commissioner’s Office (ICO) under registration number A8335007, to collect, retain, store and share personal data relating to artists, hirers, suppliers, industry contacts and other agents.

Our internal point of contact for data protection matters is Matt Bartlett. If you have any questions about this policy or how we handle your data, please use the contact details at the end of this document.

What Personal Data We Collect

Personal data is information capable of identifying an individual. It does not include anonymised data. We collect various types of personal data, including:

  • Data that personally identifies you, such as your name, postal address, email address, telephone and mobile numbers, social media profiles, or similar.
  • Data that relates to you but does not identify you on its own, such as your company, job description, related venues, venue sizes, or comments you provide.
  • Data about your internet connection, the equipment used to access our website, and usage details.

Special category (sensitive) data is information about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, health, and genetic or biometric data. We do not collect special category data about our industry and contact-database contacts (such as promoters, programmers and venues). We may collect limited special category data about the artists on our roster — for example, to monitor and support diversity across our roster — but only where you have given us explicit consent, only for that specific purpose, and we never share this data with third parties.

How We Collect Your Personal Data

We collect this information in the following ways:

  • Directly from you, when you provide it by filling out forms on our website or by corresponding with us by email, phone, post or other channels.
  • Automatically, through your interactions with our website — including usage details, IP addresses, and information collected through cookies, tracking technologies, server logs and similar technologies.
  • From publicly available professional and industry sources, including venue and festival websites, industry association and membership directories, conference and event databases, and publicly available records such as Companies House and the Electoral Register.
  • From search information providers such as Bing and Google Search.
  • From agents who join Midnight Mango, who may bring with them their own professional contact databases, which are incorporated into our industry contact records.

How We Organise and Share Contact Data

We organise the contact data we hold into two address books according to its purpose, which determines how it is used and who can access it:

  • Our programming-contacts book (“Mango Book 🥭”) — venues, festivals, promoters and other programming leads used for booking. This is the only contact data we make available to partner agencies, and then only on a view-only basis (see “Sharing Your Personal Data” below).
  • Our internal book (“Mango Admin 🥭”) — staff contacts, artists, artists’ points of contact (such as managers and tour managers), and our service and business contacts. This book is used internally only and is never shared with partner agencies. Access is further restricted so that an artist’s contacts are visible only to the agent who works with them.

Across all of these, we only hold contact details that have been provided or used for professional, work-related purposes, and we use them only for those purposes.

How We Use Your Information and Our Lawful Bases

We use the personal data we collect for the purposes below. For each purpose we rely on one or more lawful bases under the UK GDPR:

  • To provide our website and its content to you — legitimate interests.
  • To send you information about products and services we provide — consent, or legitimate interests where you are a business contact.
  • To facilitate live music bookings, including maintaining and using our industry contact database — legitimate interests.
  • To perform our obligations and enforce our rights under any contract between us, including billing and collection — performance of a contract.
  • To share contact data with partner agencies operating on our platform (see “Sharing Your Personal Data” below) — legitimate interests.
  • To comply with a legal or regulatory obligation — legal obligation.
  • To fulfil any other purpose for which you provided the information, or which we describe at the point of collection — consent or legitimate interests, as applicable.

Where we rely on legitimate interests, we have assessed that our interests (or those of a third party) are not overridden by your interests, rights and freedoms. You have the right to object to processing carried out on this basis — see “Your Rights” below. We do not carry out solely automated decision-making or automated profiling.

Sharing Your Personal Data

We disclose personal data only in limited circumstances. These are:

Partner agencies operating on our platform

Midnight Mango operates a platform that supports other booking agencies. As part of this, we may share, or provide controlled access to, certain industry contact data — such as the details of venues, promoters, festival organisers and similar professional contacts — to partner agencies operating on our platform, for the purpose of facilitating live music bookings.

Where we do this, the contact data remains under our control. We share only our lead programming contacts — the promoters, venues and festival programmers used for booking. Partner agencies access these contacts on a view-only basis through our contact platform’s cloud (Contactzilla); they cannot download or export them. Access is limited to booking purposes and on terms set by us, and is removed when their arrangement with us ends (or for an individual member of their staff who leaves). We do not share our business-services, management, finance or press contacts, and we do not share artist contacts or any special category data — these are kept in our separate, internal-only book (Mango Admin 🥭), with artist contacts further restricted to the agent who works with them. Where a partner books a show with one of our shared contacts, that contact may be recorded in the partner’s own systems as a record of their own dealing.

Our lawful basis for this sharing is legitimate interests — specifically our interest, and that of our partner agencies, in facilitating bookings and supporting the live music sector. You have the right to object to this processing at any time, and we will stop unless we have compelling legitimate grounds to continue. To object, please use the contact details at the end of this policy.

Third-party data processors

We use a number of third parties to process personal data on our behalf. These processors act only on our instructions and are bound by contract to keep your data secure. They include:

  • Google — website statistics, analytics and advertising
  • Cloudflare — spam protection
  • MailerLite — mailing lists
  • FreeAgent — accounting and invoicing
  • Overture — contracting and invoicing
  • Contactzilla — hosting and management of our industry contact database
  • Music Glue — ticket sales
  • Meta (Facebook), including the Facebook Pixel — website statistics, analytics and advertising
  • Hotjar — website statistics and analytics

Legal and regulatory disclosures

We may disclose personal data where we are required to do so by law, or to establish, exercise or defend our legal rights.

International Transfers

We work with artists, contacts and partners across the UK, the European Union and beyond, and some of the third-party processors we use are based outside the UK. Where those processors transfer personal data overseas, they do so under the safeguards required by UK law — such as the UK International Data Transfer Agreement (IDTA), the UK Addendum to the European Commission’s Standard Contractual Clauses, or an approved data bridge (for example the UK–US Data Bridge). These safeguards form part of our agreements with those processors. We only use reputable processors who provide this protection as part of their service.

How Long We Keep Your Personal Data

We keep personal data only for as long as we need it for the purposes set out in this policy. In practice:

  • Industry and contact data is retained for as long as it remains relevant to our booking activity, and is reviewed and updated on an ongoing basis.
  • Financial and transaction records are kept for at least six years, to meet our legal and tax obligations.
  • Where you ask us to delete your data, we will do so unless we are required to retain it for legal, accounting or regulatory reasons.

Keeping Your Personal Data Secure

The personal data we hold is stored within established third-party platforms — including Contactzilla for our contact database, Overture for booking and contracting, and Microsoft 365 — which maintain recognised security standards and certifications, such as encryption of data in transit and at rest. We rely on these providers’ security measures to protect personal data from being accidentally lost, or used or accessed unlawfully. For our part, we limit access to your personal data to those who have a genuine business need, and we control the level of access granted to each member of our team and to any partner agency.

Website Cookies

We and third-party organisations use cookies and other technologies, such as pixel tags, on our websites and in our emails. If you disable or refuse cookies, some parts of this website may become inaccessible or may not function properly. For full details of the cookies we use and how to manage them, please see our separate Cookie Policy.

Links to External Websites

Our website may contain links to external websites of interest or relevance. This Privacy Policy applies only to this website and the services we provide, so we cannot be responsible for the protection or privacy of any information you provide while visiting external websites. We encourage you to read the privacy policies of those websites.

Relating to Children

The services we provide are not directed to individuals under the age of sixteen (16). We do not knowingly collect personal data from children under sixteen. If we become aware that a child under sixteen has provided us with personal data, we will take steps to delete it.

Your Rights

Under UK data protection law, you have the following rights in relation to your personal data:

  • The right to be informed about how we use your data (which this policy provides).
  • The right of access to the personal data we hold about you.
  • The right to rectification of inaccurate or incomplete data.
  • The right to erasure of your data in certain circumstances.
  • The right to restrict processing in certain circumstances.
  • The right to data portability — to receive your data in a portable format.
  • The right to object to processing based on legitimate interests, including the partner sharing described above, and to direct marketing.
  • The right to withdraw consent at any time, where we rely on consent.

To exercise any of these rights, please contact us using the details below. To help us respond, please give us enough information to identify you, proof of your identity where appropriate, and details of the right you wish to exercise and the data your request relates to. We will respond within the statutory time limit.

How to Make a Complaint

If you are unhappy with how we have handled your personal data, you can complain to us directly using the contact details below. We will acknowledge your complaint within 30 days and aim to resolve it without undue delay, keeping you informed of progress and the outcome.

You also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection, at ico.org.uk. We would, however, appreciate the chance to address your concerns before you approach the ICO.

How to Contact Us

Please contact us by post, email or telephone if you have any questions about this Privacy Policy or the information we hold about you:

Policy Changes

This document is reviewed and updated as our data usage changes, as new products and services are introduced, and as new best-practice guidelines and legislation come into effect. As the policy is updated, we list the changes below. Please check the website regularly for any changes.

Latest Updates

  • 18 June 2026 — Full review and update: brought into line with UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025; added partner agency data sharing, international transfers, data retention, expanded rights and complaints handling.
  • 19 October 2023 — Third Party Data Processors updated
  • 06 September 2023 — Company postal address removed
  • 07 March 2023 — Third Party Data Processors updated
  • 19 May 2021 — Third Party Data Processors updated
  • 24 May 2018 — Complete refresh of the Privacy Policy

Appendix — Summary of Changes

For internal reference only — not part of the published policy. Split this section off before publishing.

The following changes were made in the 18 June 2026 update, against the previous version (last fully refreshed 24 May 2018):

  1. Legislation references corrected. Replaced references to “EU General Data Protection Regulation 2018 / GDPR 2018” with the correct current framework: UK GDPR, Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.
  2. Data protection contact corrected. The previous policy named Ian Luxon as our “Data Processor” — a mislabel (a data processor is an external party, such as those listed under third-party processors). The internal point of contact for data protection is now correctly stated as Matt Bartlett.
  3. New “Sharing Your Personal Data” section. Adds explicit disclosure that we may share or give controlled access to industry contact data to partner agencies on our platform, for booking purposes, on a legitimate interests basis, with a clear right to object. This is the change that supports the partner agency model.
  4. Lawful bases mapped. Each processing purpose is now matched to a specific lawful basis under the UK GDPR, rather than listed without one.
  5. New International Transfers section. Explains how data transferred outside the UK is protected (adequacy, IDTA, UK Addendum to SCCs).
  6. New Data Retention section. Sets out how long we keep data and the criteria used — previously absent and required under UK GDPR.
  7. Expanded “Your Rights” section. Previously covered only view, amend and delete. Now lists the full set of UK GDPR rights, including the rights to restrict, to data portability, to object (key for the partner sharing) and to withdraw consent.
  8. New Complaints section. Adds a direct complaints route (acknowledge within 30 days, resolve without undue delay) to meet the new duty under the Data (Use and Access) Act 2025, and adds the right to complain to the ICO — previously not mentioned at all.
  9. Processor list refreshed. Retained and tidied; Facebook referred to as Meta (Facebook); Contactzilla added as the processor hosting our contact database. Confirm each is still in use before publishing.
  10. Security section reworded. Now reflects that technical security measures (encryption etc.) are provided by our established platforms, while our own responsibility is controlling who has access. More accurate than implying we build these measures ourselves.
  11. Children’s age unchanged. Kept at 16 (the UK threshold for information society services is 13, so 16 is simply more cautious — no change needed).
  12. Special category data clause revised. Now distinguishes the two data populations: we do not collect sensitive data on industry/database contacts, but may collect limited special category data on roster artists (e.g. diversity monitoring) with explicit consent, for that purpose only, and never shared with third parties. The partner-sharing section now states explicitly that sharing never includes artist data or special category data.
  13. New “How We Organise and Share Contact Data” section. Sets out our two-book structure — the programming-contacts book (Mango Book 🥭), shared with partners; and the internal book (Mango Admin 🥭) holding staff, artist and service contacts — and explains that only Mango Book 🥭 is shared with partners, view-only, while Mango Admin 🥭 is internal and access-restricted.

How to Contact Us

Please contact us by post, email or telephone if you have any questions about this Privacy Policy or the information we hold about you:

Matt Bartlett 01 July 2026