[WORLDUNITE.ORG] │ Last updated: [24.02.26]
1. Who We Are, And What This Is
We are
[WORLD UNITE LUCIFER YOUTH FOUNDATION] (“we”, “us”, “our”). We operate the website at [WORLDUNITE.ORG] and any related platforms or services we run (together, the “Site”).
Most privacy policies exist to obscure. The machine that runs modern commercial culture has trained us to scroll past walls of legal language, clicking “I agree” to things we never read, surrendering our data the way we surrender our attention — by default, without choice, without understanding. This is not that.
This policy tells you plainly what personal information we collect when you use the Site, why we collect it, what we do with it, and what rights you hold over it. We have written it in plain language not because we are obliged to, but because transparency where it heals is one of our commitments. Read it. If anything is unclear, contact us before you use the Site. We would rather you ask.
Your use of the Site does not by itself constitute consent to the processing of your personal data where consent is required under applicable law. Where we rely on consent, we will ask for it directly, as a clear and affirmative act — never buried in a terms page you have already scrolled past.
This policy should be read alongside our Cookies Policy, which you can find at [LINK TO COOKIES POLICY].
For the purposes of UK data protection law — the UK General Data Protection Regulation and the Data Protection Act 2018 (together, “UK GDPR”) — the data controller is:
[STEVEN PILLING], [13 COTTON HOUSE, 21 BLOSSOM STREET, M4 5EP]
If you have questions, or want to exercise any of your rights, reach us at [LUCIFERYOUTH@WORLDUNITE.ORG]. Full contact details are in section 13.
2. What We Know About You — And How
“We share what serves the work, withhold what feeds the ego.” — LYF Whitepaper
The machine collects everything it can and asks questions later. We collect the minimum necessary to do what we say we will do. Here is what that looks like in practice.
2.1 What You Tell Us Directly
When you use the Site or reach out to us, you may share:
- Your name and contact details — email address, phone number, postal address
- Account login credentials, if you register
- Date of birth or age verification information
- Billing and payment details when you buy merchandise, tickets or other items
- A delivery address for physical orders
- Messages you send us — correspondence, press enquiries, feedback, fan messages
- Preferences and interests you share when subscribing to our mailing list or membership
- Responses to any competitions, giveaways or surveys
2.2 What We Collect Automatically
When you visit the Site, certain technical information is collected automatically — either by us or by the third-party services we use to keep it running. This is the basic infrastructure of the internet, not surveillance for its own sake:
- IP address and approximate geographic location
- Device type, operating system and browser
- Pages visited, links clicked, time spent, and other browsing behaviour on the Site
- The site or search query that brought you here
- Cookie identifiers and similar technology data (see our Cookies Policy)
- Advertising identifiers and pixel data — only where you have given consent
2.3 What Reaches Us From Elsewhere
We may also receive information about you from:
- Ticketing and event platforms, if you purchase tickets through them and they share data with us
- Merchandise platforms and fulfilment partners
- Social media platforms, where you interact with our accounts or we run advertising
- Streaming and music platforms, where aggregated or pseudonymised analytics are shared
- Pre-save and fan engagement platforms — such as Linkfire, Feature.fm, Laylo or ToneDen — where you interact with release or event campaigns
- Publicists, press contacts and music industry databases, in a professional context
2.4 What We Do Not Want
We do not intentionally collect special category personal data — information about your health, ethnicity, religion, sexual orientation or similar. Please do not send us this. If you do, we will delete it unless we are required by law to keep it.
We are not interested in knowing more about you than we need to in order to serve the work.
3. What We Do With It — And Why
Every use of your data has a reason and a legal basis. We do not use your data to profile you for sale, to feed it into an advertising machine, or to harvest the patterns of your attention. The table below sets out what we do, why, and the legal ground under UK GDPR on which we stand. Where we rely on consent, you can withdraw it at any time — see section 10 for how.
| Why we use it | What data is involved | Legal basis (UK GDPR) | Our legitimate interest (where relevant) |
| Keeping the platform running and diagnosing faults | Usage data, device info, IP address | Legitimate interests | Making sure the platform works and stays secure |
| Sending you word about music, shows and releases — where you’ve asked us to | Name, email, preferences | Consent | N/A |
| Processing your purchase of records, merchandise or tickets | Name, billing/delivery address, payment details, order history | Performance of a contract | N/A |
| Managing your account | Name, email, account credentials | Performance of a contract / Legitimate interests | Providing account access and a personal experience |
| Responding to your messages and correspondence | Name, contact details, content of message | Legitimate interests | Responding to people honestly and directly |
| Running competitions, giveaways and surveys | Name, contact details, responses | Consent / Performance of a contract | N/A |
| Understanding how people use the platform (non-essential cookies only) | Usage data, cookie data, IP address | Consent (required under PECR) | N/A — consent required; we do not rely on legitimate interests here |
| Targeted advertising on third-party platforms (if applicable) | Cookie/pixel data, email address (custom audiences) | Consent (required under PECR) | N/A — consent required |
| Meeting our legal obligations: tax, fraud prevention, regulatory requirements | As required by the relevant legal obligation | Legal obligation | N/A |
| Protecting the safety of members, staff and others; detecting fraud and unauthorised access | Usage data, contact details, transaction data | Legitimate interests / Legal obligation | Preventing fraud, abuse and harm; protecting the community |
We do not use your data for any purpose not listed above without first updating this policy and, where the law requires, seeking fresh consent.
4. When We Reach Out
“We need intelligent opposition to keep us honest and grounded.” — LYF Whitepaper
We will only send you marketing communications — news about releases, shows, merchandise, or anything else we are working on — where you have given us your clear, freely given, prior consent. That means you signed up. We do not assume permission. We do not pre-tick boxes. We do not bury consent in terms and conditions.
We use the following platform to manage our mailing list: [OPEN STAGE].
In limited circumstances, privacy law (PECR) also permits what is called a “soft opt-in” — meaning we may contact you about similar products or services if you have previously made a purchase, you were given a clear chance to opt out at the time and did not do so. We only use this where all those conditions are genuinely met. It does not extend to communications on behalf of third parties, and it does not allow us to share your details with anyone else for their own marketing.
You can unsubscribe at any time. Use the link in any email we send, or write to us directly. We will act on your request promptly and within 10 business days at the latest. Unsubscribing from marketing will not affect messages we need to send you about an order or an account matter.
5. Who Else Sees Your Data
“Revenue flows horizontally through the network rather than vertically to corporate platforms.” — LYF Whitepaper
We do not sell your data. We have never sold your data. The only circumstances in which we share personal information are the ones below — and in each case, there is a specific, legitimate reason. We name them here because you deserve to know who is in the room.
5.1 People Who Help Us Run the Platform
We use third-party service providers who process data on our behalf, under our instruction, for specific purposes only. These include:
- Website hosting, content delivery and IT infrastructure
- Email marketing and communications platforms
- Analytics and audience measurement services (only with your cookie consent)
- Payment processors for merchandise and ticketing
- Fulfilment and logistics partners for physical orders
- Customer service tools
These providers may not use your data for anything other than the specific purpose we have engaged them for. They operate under contracts that require them to protect it.
5.2 Ticketing and Merchandise Platforms
If you buy tickets or merchandise through a third-party platform — such as [E.G. TICKETMASTER, SEE TICKETS, AXS, EVENTBRITE, SANDBAG, SHOPIFY] — your data is processed by that platform under their own privacy policy. We encourage you to read it. Where they share data with us, we process it in accordance with this policy.
5.3 Record Label and Management
We may share certain information with [L Y F RECORDINGS] for purposes connected with promoting and managing the artist’s work — including release planning, audience analysis and live event promotion.
Depending on the context, these recipients may act as independent data controllers (where they determine the purpose and means of processing for their own activities) or as data processors acting on our instruction. In either case, they will be bound by appropriate obligations of confidentiality.
5.4 Advertising Platforms
Where we use social media advertising tools — such as Meta’s Custom Audiences or TikTok’s advertising platform — certain data (such as hashed email addresses) may be shared with those platforms to enable targeted advertising. This only happens where you have given your consent through our cookie mechanism. We do not share data with those platforms for any other purpose.
5.5 Joint Controller Arrangements
Where we use advertising technologies from platforms such as Meta Platforms Ireland Limited (Facebook and Instagram) and Google Ireland Limited (YouTube and Google Ads), those platforms may act as joint controllers with us in respect of certain data collected through those technologies. Both we and the platform are then responsible for complying with data protection law in relation to that processing.
Further detail about how those platforms use the data — including their own legal basis and how to exercise your rights directly against them — is in their privacy policies:
5.6 Legal and Regulatory Disclosure
We may disclose personal data to law enforcement, regulators or other authorities where required by law, or where we genuinely believe disclosure is necessary to protect our rights, the rights of others, or to prevent fraud or illegal activity. We are not in the business of handing data over casually.
5.7 If the Business Changes Hands
If there is a reorganisation, merger, acquisition or sale of assets affecting the business behind the Site, your personal data may transfer to the relevant successor entity — subject to that entity providing equivalent privacy protections.
5.8 The Line We Will Not Cross
We do not sell, and have never sold, your personal data to any third party. This applies regardless of how “sale” is defined under any applicable law, including US state privacy laws such as the California Consumer Privacy Act. Where we share data with third parties as described above, we do so for specific purposes only, and not in exchange for money.
Your data does not feed the machine.
6. When Data Crosses Borders
Some of our service providers are based outside the United Kingdom and the European Economic Area (“EEA”). Where we transfer personal data to a country not recognised by the UK ICO or European Commission as providing an adequate level of data protection, we ensure appropriate safeguards are in place. These may include:
- Standard contractual clauses (SCCs) approved by the UK ICO (UK IDTA) or the European Commission
- Binding corporate rules
- Participation in an applicable adequacy framework, such as the EU-US Data Privacy Framework for transfers to the USA
You can ask for further information about the safeguards applying to any specific transfer by contacting us at [LUCIFERYOUTH@WORLDUNITE.ORG].
7. How Long We Hold It
“Physical artifacts that can’t be deleted by platform changes.” — LYF Whitepaper
We hold your data only for as long as it is needed. We do not hoard. Here is how that works in practice:
- Mailing list and marketing data: held for as long as you remain subscribed. When you unsubscribe, we remove your details from the active list promptly, though we may keep a suppression record to ensure we do not contact you again in error.
- Transaction and purchase records: kept for at least six years from the end of the relevant financial year, to meet our legal and tax obligations.
- Account data: held for as long as your account is active. If you request deletion, we will act within 30 days unless we are legally required to retain certain information.
- Website usage and analytics data: retained in identifiable form for no longer than 26 months (in line with ICO guidance), after which it is deleted or anonymised — subject to your cookie preferences.
- Correspondence: kept for up to three years from the date of last contact, unless a longer period is required by law or for the purposes of any legal claim.
If you want to know the specific retention period applicable to your data, contact us at [LUCIFERYOUTH@WORLDUNITE.ORG].
8. Cookies and the Tracking Question
“No algorithmic distribution. No data harvesting.” — LYF Whitepaper
Our full cookies approach lives in our Cookies Policy at [LINK TO COOKIES POLICY]. The short version: under PECR and UK/EU GDPR, we require your prior, freely given and informed consent for all non-essential cookies. The only exception is strictly necessary cookies — those required for the platform to function at all. Those are set without separate consent because without them there is no service to deliver.
We do not use cookies to profile you for sale. We do not feed your browsing behaviour into advertising algorithms without your knowledge and your express agreement.
9. Children
The Site is not directed at children under the age of [13 OR 16 — NOTE: Under UK GDPR the age of digital consent is 13; under EU GDPR it is 16 unless a lower age is set by national law (minimum 13). Choose the age appropriate for your audience and jurisdiction]. We do not knowingly collect personal data from children below that age without verifiable parental or guardian consent.
If you believe we have inadvertently collected a child’s personal data, contact us immediately at [LUCIFERYOUTH@WORLDUNITE.ORG] and we will delete it promptly.
10. What You Can Demand of Us
“Creating celebratory spaces… recognising that consciousness exists in bodies, and that the sacred organises itself horizontally through networks of relationship rather than vertical hierarchies of power.” — LYF Whitepaper
Power over your own data belongs to you — not to us, not to any platform, not to any algorithm. Subject to applicable law and certain limited conditions and exceptions, these are your rights:
- Know what we hold: You can ask for a copy of all personal data we hold about you. This is called a Subject Access Request.
- Correct the record: You can ask us to fix data about you that is wrong or incomplete.
- Ask us to forget: You can ask us to delete your data in certain circumstances — for example, where it is no longer needed for the original purpose, or where you withdraw consent and we have no other legal basis for continuing.
- Pause the processing: You can ask us to restrict how we process your data in certain circumstances.
- Take your data with you: Where we process data on the basis of consent or a contract, and processing is automated, you can receive your data in a structured, machine-readable format. You own what you gave us.
- Push back: You can object to processing carried out on the basis of our legitimate interests. We will stop unless we can demonstrate compelling grounds that genuinely override your interests.
- No machine decides your fate: You have the right not to be subject to decisions made solely by automated processing that significantly affect you. We do not currently make such decisions.
- Change your mind: Where we rely on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before you withdrew.
To exercise any of these rights, contact us at [LUCIFERYOUTH@WORLDUNITE.ORG]. We will respond within one calendar month — extendable by two months for complex requests, with notice to you. We may ask you to verify your identity before acting. We do not charge for most requests, but may decline or charge a fee where a request is manifestly unfounded or excessive.
11. How We Protect What You Have Shared
“Tend the flame without burning out.” — LYF Whitepaper
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or alteration. In practice, that includes:
- HTTPS encryption for data in transit
- Access controls restricting access to personal data to authorised people only
- Regular review of our security practices and the arrangements we have with third-party processors
No system is completely impenetrable. We cannot guarantee absolute security across the open internet. If you believe your data has been compromised through our systems, contact us immediately.
If a data breach occurs that is likely to risk your rights and freedoms, we will notify the UK ICO within 72 hours of becoming aware of it — as required by UK GDPR — and we will notify you directly where the breach is likely to result in a high risk to you personally.
12. Other Places the Site May Lead
The Site may link to third-party websites, streaming platforms, social media profiles and other external services. This policy does not govern those sites. We are not responsible for what they do with your data. Read their privacy policies before you share anything with them. The machine that runs those platforms operates by different rules to ours.
13. How to Reach Us
“The platform enables what corporate social media promises but cannot deliver: genuine peer-to-peer connection.” — LYF Whitepaper
If you have questions about this policy, want to exercise your rights, or want to make a complaint, here is where we are. We are real people and we will respond.
Data Controller: [CC]
Address: [13 OTTON HOUSE, 21 BLOSSOM STREET, M4 5EP]
Email: [LUCIFERYOUTH@WORLDUNITE.ORG]
Website: [WORLDUNITE.ORG]
You also have the right to complain to the UK Information Commissioner’s Office (“ICO”) — the UK supervisory authority for data protection — if you believe we have not met our obligations under UK GDPR or PECR. They are the independent authority, and you should know how to reach them:
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
ICO helpline: 0303 123 1113 │ https://ico.org.uk
14. When This Changes
We will update this policy when the law changes, when our practices change, or when what we offer changes. When we do, we will update the “last updated” date at the top and — where changes are material — we will take reasonable steps to let you know, either by email or by a notice on the Site.
We encourage you to read this again periodically. Your continued use of the Site after changes take effect means you have seen those changes. Where we rely on consent as the legal basis for any processing, we will seek fresh consent where the law requires it.
The work evolves. This document will evolve with it. But the principle stays the same: your data is yours. We are only its temporary stewards.