Privacy Policy

Effective date: 1 January 2026
Last updated:

1. Who we are

Oper8 Events L.L.C-FZ ("Oper8 Events," "we," "us," or "our") is a business-to-business event operations company based in the United Arab Emirates, delivering trackside retail structures and event infrastructure for international sport organizations, rights holders, and their appointed agencies.

  • Legal entity: Oper8 Events L.L.C-FZ

  • Registered address: Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

  • Commercial licence number:

  • Jurisdiction of incorporation: United Arab Emirates

  • Contact for data protection matters:privacy@oper8events.com

For the purposes of the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"), Oper8 Events acts as the Controller of the personal data described in this policy. Where our activities involve personal data of individuals located in the United Kingdom or European Economic Area, we also act as a Controller under the UK GDPR and EU GDPR (Regulation (EU) 2016/679) respectively.

2. Who this policy applies to

Oper8 Events provides services exclusively to legal-entity clients — sport federations, event rights holders, licensed brand partners, agencies, venues, and their appointed suppliers. We do not sell products or services to consumers, and we do not knowingly collect personal data from individuals under 18.

This policy applies to:

  • Representatives of our current, past, or prospective business clients, suppliers, and partners

  • Visitors to www.oper8events.com

  • Individuals who contact us through the website, by email, or through professional networks

We do not collect, control, or process personal data of end consumers who attend the events we help operate. That data belongs to our clients and their ticketing, retail, or hospitality partners, and is governed by their own privacy policies.

3. What personal data we collect

We deliberately collect as little personal data as possible. In practice, we collect the following categories:

When you contact us through the website contact form or by email:

  • Your name

  • Your business email address

  • The organization you represent

  • Any information you choose to include in your message

When we work with you as a client, supplier, or partner:

  • Business contact details (name, job title, work email, work phone number, work address)

  • Correspondence and meeting records related to a project

  • Information necessary to contract with, invoice, and coordinate on-site delivery for your organization

When you visit our website:

  • Standard technical data collected automatically by our website host (Squarespace) and analytics services: IP address, browser type, device type, referring URL, pages visited, and approximate geographic location derived from IP.

  • Data set by cookies — see our Cookie Policy for detail.

We do not collect or process:

  • Payment card details from individuals (all client payments are business-to-business bank transfers).

  • Special category / sensitive personal data (health, biometric, genetic, political, religious, or similar), unless explicitly required for site access credentialing at a venue and provided by the individual with consent.

  • Personal data of members of the public attending the events we help operate.

4. Why we use personal data, and on what legal basis

We only use personal data for clearly defined purposes:

PurposeLegal basisResponding to enquiries you send usLegitimate interests / consent by initiationNegotiating, entering, and performing contracts with clients, suppliers, and partnersPerformance of a contractIssuing invoices, receiving payments, and keeping financial recordsCompliance with a legal obligation (UAE commercial and tax law; equivalent laws in countries where we deliver)Coordinating on-site event operations, including credentialing and access control at venuesPerformance of a contract; legitimate interestsOccasional business communications with existing contacts (e.g. checking in on an upcoming event season)Legitimate interestsWebsite security, fraud prevention, and technical operationLegitimate interests

We do not carry out direct-to-consumer marketing, do not send bulk marketing emails, and do not build behavioural profiles or use personal data for automated decision-making that produces legal or similarly significant effects.

5. Who we share personal data with

We share personal data only where necessary, and only with the following categories of recipients:

  • Our website host and infrastructure provider: Squarespace, Inc. (United States) — hosts www.oper8events.com and receives contact form data.

  • Our email and productivity provider: the provider through which we operate our @oper8events.com email addresses and business documents.

  • Our accountants, auditors, and tax advisors: for invoicing, financial reporting, and statutory obligations.

  • Our banks and payment intermediaries: where required to receive and issue payments.

  • Professional advisors: lawyers and insurers, where necessary.

  • Our clients and their appointed contractors: where we need to share your business contact details to coordinate the delivery of a specific project — for example, sharing your details with a venue operator, promoter, or co-supplier working on the same build.

  • Public authorities and regulators: where required by law, court order, or lawful regulatory request in the UAE or in a country where we are delivering an event.

We do not sell personal data, and we do not share personal data with advertisers or data brokers.

6. International transfers of personal data

Because we operate in over 20 countries, personal data will be transferred across borders — both to and from the UAE — in the ordinary course of our work.

For transfers of personal data outside the UAE, we rely on the mechanisms permitted under Articles 22 and 23 of the UAE PDPL, including transfers to jurisdictions recognised by the UAE Data Office as providing an adequate level of protection, transfers made under appropriate contractual safeguards, or transfers necessary for the performance of a contract with the Data Subject or in their interest.

For transfers of personal data of individuals located in the UK or EU/EEA, where the recipient is outside those regions, we rely on the mechanisms permitted under Article 46 UK/EU GDPR — typically Standard Contractual Clauses (SCCs) approved by the UK Information Commissioner or the European Commission, or transfers to jurisdictions recognised as providing an adequate level of protection.

7. How long we keep personal data

  • Enquiries that do not become a project: retained for up to 24 months, then deleted.

  • Client, supplier, and partner records for delivered projects: retained for the duration of the business relationship and thereafter for the periods required by UAE commercial and tax law and equivalent laws in the country where the project was delivered (typically 5–10 years for financial and contractual records).

  • Website server logs and analytics data: retained per our host's and analytics provider's standard retention windows (typically 14 months or less).

We periodically review the personal data we hold and delete data we no longer need.

8. How we protect personal data

We apply appropriate technical and organisational measures for a business of our size and profile:

  • Access to project files, contracts, and correspondence is limited to team members who need it to do their job.

  • We use reputable, security-audited business software (website hosting, email, accounting, file storage).

  • We do not store personal data on unencrypted personal devices or removable media.

  • We require the same standards from suppliers who handle personal data on our behalf, through contractual data-protection commitments.

If a personal data breach occurs that is likely to result in a risk to affected individuals, we will notify the UAE Data Office and, where required, affected individuals — as well as any other supervisory authority (such as the UK ICO or an EU supervisory authority) where the breach affects data subjects in their jurisdiction, within the timeframes required by applicable law.

9. Your rights

If you are located in the UAE, the UK, the EU/EEA, or another jurisdiction with equivalent data protection rights, you have the right to:

  • Access the personal data we hold about you

  • Correct inaccurate or incomplete data

  • Delete your data ("right to erasure") where we no longer have a lawful basis to keep it

  • Restrict or object to our processing of your data

  • Data portability — receive your data in a machine-readable format, where applicable

  • Withdraw consent at any time, where processing is based on consent

  • Not be subject to fully automated decision-making that produces legal or similarly significant effects (we do not carry out such processing)

To exercise any of these rights, email privacy@oper8events.com. We will respond within one month.

You also have the right to lodge a complaint with a data protection supervisory authority — for example the UAE Data Office (dataoffice.gov.ae), the UK Information Commissioner's Office (ico.org.uk), or the supervisory authority in the EU/EEA country where you live or work.

10. Cookies

Our website uses a small number of cookies for site functionality and analytics. See our Cookie Policy for full detail on what each cookie does and how to manage them.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of the page will always reflect the current version. Material changes will be highlighted on our homepage or communicated directly to affected clients.

12. Contact us

For any question about this Privacy Policy or how we handle personal data:

Oper8 Events L.L.C-FZ
Meydan Grandstand, 6th Floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates
Email: privacy@oper8events.com