Privacy Policy
Last updated: 3 July 2026
Fansurge Limited ("Fansurge", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share and protect personal data, and describes your rights under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and, where applicable, the EU General Data Protection Regulation (EU GDPR).
For the purposes of applicable data protection law, the data controller is Fansurge Limited, a company registered in England and Wales (company number 17174695), with its registered office at 14 Sollershott West, Letchworth Garden City, SG6 3PX, United Kingdom.
If you have any questions about this policy or how we handle personal data, you can contact us at privacy@fansurge.ai.
1. Who this policy applies to
Fansurge provides a business-to-business audience-intelligence platform for the live-music industry. This policy applies to:
- Customers and their users — employees and representatives of the promoters, agencies, brands and other organisations that hold a Fansurge account.
- Website visitors — anyone who visits fansurge.ai or requests a demo.
- Individuals whose data appears in our market-intelligence datasets — see section 2(d). If you are an artist or a member of an artist's audience, please read that section and section 8, which explain your rights.
2. Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
(a) Account and identity data. When an account is created, we (via our authentication provider) collect your name, email address, profile image (if you provide one), the organisation you belong to, and your role within it. We do not store your password — authentication is handled by our provider, Clerk.
(b) Usage and technical data. When you use the platform or visit our website, we automatically collect technical information such as your IP address, device and browser type, operating system, pages viewed, actions taken, timestamps and referring URLs, together with server and application logs.
(c) Communications data. If you request a demo, contact us, or use support, we collect the information you provide (such as your name, email, company and the content of your message).
(d) Market-intelligence data. The core of our service is the aggregation and analysis of data about artists, events and audiences. This data is drawn from publicly available and third-party sources, including public social-media profiles and pages, music-streaming services, radio-airplay data, ticketing and event listings, festival line-ups, chart and end-of-year lists and industry awards, and specialist music-industry data providers (such as Soundcharts). We obtain this data from those sources and not directly from the individuals it concerns; how we provide transparency to those individuals is explained in section 8.
The personal data in these datasets may include:
- for artists and performers — name and performer name, images, career and release information, social-media handles and follower or engagement metrics, streaming and radio-airplay statistics, event and festival appearances, chart positions and awards; and
- for members of artists' audiences — no names or contact details, and no identifiers that single out an individual; only aggregated, statistical attributes, such as approximate demographic splits (for example age band and gender balance), aggregate location, and interest and brand-affinity signals derived from public audience data.
We use this data to produce audience clusters, demographic estimates and statistical insights. We do not use it to identify, contact, track or make decisions about individual audience members — it is processed in aggregate to produce statistical and predictive insights for our customers.
We do not intentionally collect special-category data (such as data revealing health, religion, sexuality or political opinions). Where aggregate audience-interest data could indirectly reflect such characteristics at a group level, we treat it with additional care and do not use it to infer special-category data about, or to make decisions about, identifiable individuals.
3. Where we get your data
We collect personal data:
- directly from you — when you create an account, request a demo, or contact us;
- automatically — through your use of the platform and our website (see cookies, section 6); and
- from third-party and public sources — for the market-intelligence data described in section 2(d).
4. How and why we use personal data (and our lawful bases)
We use personal data for the following purposes, relying on the lawful bases noted for each under the UK/EU GDPR:
- To provide, operate and secure the platform and your account — using account and usage data. Lawful bases: performance of a contract; our legitimate interests in running and securing our service.
- To respond to demo requests, enquiries and support — using communications data. Lawful bases: performance of a contract or steps prior to a contract; legitimate interests.
- To produce audience insights, clusters and predictions for customers — using market-intelligence data. Lawful basis: our legitimate interests (and those of our customers) in providing market analytics, balanced against the rights of data subjects.
- To improve, develop and train our models and features — using usage and market-intelligence data. Lawful basis: legitimate interests in improving our products.
- For analytics and measuring website/platform performance — using usage data. Lawful basis: consent (where required for non-essential cookies) or legitimate interests.
- To send service and, where permitted, marketing communications — using account and communications data. Lawful basis: legitimate interests or consent, as applicable; you can opt out at any time.
- To comply with legal obligations and enforce our terms — using any of the above. Lawful bases: legal obligation; legitimate interests.
Where we rely on legitimate interests, we have carried out (or will carry out, and can provide) a balancing assessment to ensure our interests do not override your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
5. Automated processing and profiling
Our platform uses machine-learning models to cluster audiences and estimate demographics and preferences in aggregate. These outputs are statistical estimates about groups, not automated decisions that produce legal or similarly significant effects on identifiable individuals. Our customers are responsible for how they use the insights we provide.
6. Cookies and similar technologies
We and our providers use cookies and similar technologies for essential purposes (such as authentication and security) and, where you consent, for analytics. Essential cookies are necessary for the site to function and do not require consent under the Privacy and Electronic Communications Regulations (PECR). You can manage non-essential cookies through your browser settings or any cookie controls we provide.
7. Who we share personal data with
We do not sell personal data. We share it only with:
- Service providers (processors) who help us run our business under contract, including our authentication provider (Clerk), cloud-hosting and database providers (Amazon Web Services, in the UK/EU region), our application and deployment provider (Vercel), our network, content-delivery and email-routing provider (Cloudflare), and our AI provider (Anthropic), accessed via the Vercel AI Gateway, which processes queries and related data to generate the AI-assisted insights and narratives available in the platform. We may also use analytics, email and payment providers. A current list of sub-processors, including their locations, is available on request at privacy@fansurge.ai.
- Professional advisers, such as lawyers, auditors and insurers, where necessary.
- Authorities and third parties where required to comply with the law, to enforce our terms, or to protect our rights, property or safety.
- A buyer or successor in the event of a merger, acquisition, financing, reorganisation or sale of assets, in which case personal data may be transferred as part of that transaction, subject to this policy.
8. Market-intelligence data — transparency and your rights
Because our market-intelligence data comes from public and third-party sources rather than from the individuals themselves, we are usually not able to contact those individuals directly to tell them we hold data about them. Where personal data has not been obtained directly from you, data-protection law (Article 14 of the UK GDPR) allows us to rely on the "disproportionate effort" exemption from giving individual notice — given the scale of the datasets, the absence of any direct relationship, and the fact that individual audience data is held only in aggregate. In place of individual notice, this Privacy Policy is the public information we provide about that processing, and we take steps to keep the impact on individuals low (for example, by holding audience data only in aggregate and not singling out individuals).
If you are an artist, or an individual whose personal data may appear in our market-intelligence datasets, and you wish to object to that processing, or to request access, correction or erasure, please contact privacy@fansurge.ai with enough detail for us to locate the relevant data. We will assess and respond to your request in accordance with your rights under applicable data-protection law (see section 10), and we will stop processing your personal data in these datasets unless we have compelling legitimate grounds that override your interests or the data is needed for the establishment, exercise or defence of legal claims.
9. International transfers
We host customer and account data in the United Kingdom / European Union (Amazon Web Services, London region). Some of our providers are based in, or process personal data in, the United States — in particular our authentication provider (Clerk), our deployment provider (Vercel) and our AI provider (Anthropic, accessed via the Vercel AI Gateway). Where personal data is transferred outside the UK/EEA, we rely on appropriate safeguards, such as UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework), the UK International Data Transfer Agreement (IDTA), or the UK addendum to the EU Standard Contractual Clauses. You can request more information about these safeguards, and a copy of the relevant transfer mechanism, at privacy@fansurge.ai.
10. Your rights
Subject to applicable law, you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to processing; data portability; and, where processing is based on consent, to withdraw consent. You also have the right to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact privacy@fansurge.ai. We will respond within the timeframes required by law (generally within one month). We may need to verify your identity before acting on a request.
If you are in the UK, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk. If you are in the EU, you can complain to your local data-protection authority.
11. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, including to provide the service, comply with our legal obligations, resolve disputes and enforce our agreements. In general:
- Account and identity data — for the life of the account and up to [12] months after it is closed;
- Communications and demo-request data — up to [24] months after our last contact with you;
- Usage and technical logs — up to [12] months;
- Market-intelligence data — for as long as it remains available from its source and relevant to our analytics; it is refreshed periodically and removed when it is no longer sourced, or following a valid objection or erasure request (see section 8); and
- Records we must keep for legal, tax or accounting reasons — for the period required by law (for example, financial records for [six] years).
When personal data is no longer needed, we delete or anonymise it. The periods shown in brackets are our current retention targets and may be adjusted where a longer or shorter period is justified.
12. Security
We use appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, hosting with reputable cloud providers, and delegating credential storage to a specialist authentication provider. No system is completely secure, but we work to protect your data and to respond promptly to any incident.
13. Children
Fansurge is a business tool and is not directed at children. We do not knowingly collect personal data directly from anyone under 18. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps.
14. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Please review this page periodically.
15. Contact us
Fansurge Limited Registered in England and Wales, company number 17174695 Registered office: 14 Sollershott West, Letchworth Garden City, SG6 3PX, United Kingdom
Privacy enquiries: privacy@fansurge.ai Data protection contact: dpo@fansurge.ai