Open today 10am - 5pm, Opening Times

Cheddar Gorge & Caves, The Cliffs, Cheddar, BS27 3QF , How to find us

Privacy Policy

Effective date: 26 August 2026

This Privacy Policy explains how Longleat Enterprises Limited (Company Number 00789512) (“we”, “us”, or “our”) collects, uses, stores, shares, and protects personal data of our visitors, customers, website users, and other individuals who interact with us. We are committed to handling personal data in accordance with applicable data protection laws, including the UK GDPR and the Data Protection Act 2018. We are registered with the UK supervisory authority, the Information Commissioner’s Office (“ICO”), in relation to our processing of Personal Data under registration reference Z6960463.

Who we are

Longleat Enterprises Limited is the controller of the personal data described in this policy. Our registered address is Longleat Estate Office, Longleat, Warminster, Wiltshire, BA12 7NW. You may contact our Data Protection Officer using the details in the ‘Contact us’ section below..

The data we collect

We collect and process the following categories of personal data, as appropriate to your interaction with us:

  • Identification and contact details, such as name, age, postal address, email address, and telephone number.
  • Purchase and account information, such as ticket and pass details, order history, booking references, payment method and transaction details. We do not store full card numbers; payments are processed by our authorised payment providers.
  • Visit information, such as visit dates, ride or event reservations, parking details, lost property records, incident reports, accessibility and medical equipment needs, dietary requirements and guest services correspondence.
  • Device and usage data, such as IP address, device identifiers, browser type, app activity, cookie and analytics data, Wi‑Fi session logs, online identifiers used for targeted advertising, such as cookie IDs, mobile ad IDs/SDK identifiers, pixel-derived identifiers, and similar tracking identifiers; and, where used for audience matching, contact identifiers (e.g., hashed email addresses) submitted in a privacy-protective form.
  • Marketing preferences and communications, including newsletter sign‑ups, competition entries, survey responses, feedback and advertising audience information generated from your interactions with our websites, apps, or posts/ads on third-party platforms (including Meta services), which may include inferred interests and segment membership derived from cookies/pixels/SDKs.
  • Images and CCTV footage captured on our premises for safety and security.
  • Accessibility and health-related information where you choose to provide it for ride access, catering services, assistance, or incident reporting. We will only process this information with your explicit consent or where necessary for reasons of substantial public interest, health and safety, or legal claims.

 

How we collect data

We collect data in the following ways:

  • Directly from you when you buy tickets or passes, create an account, make a booking, contact guest services, enter a competition, complete a survey, or sign up to marketing.
  • Automatically when you use our websites, apps, on‑site Wi‑Fi, and digital services, through cookies, similar technologies, system logs, this includes the use of advertising pixels, tags, cookies and SDKs (such as the Meta Pixel and Meta SDK) that record events (for example, page views, purchases or sign-ups) and associate them with online identifiers for ad measurement and remarketing.
  • On our premises through CCTV, body‑worn cameras (if used), incident reporting, access control, and ride reservation systems.
  • From third parties , such as payment processors, booking partners, travel and promotion partners, social media platforms (when you interact with our pages or ads), and social media platforms (including Meta when you interact with our pages or ads or when we use their business tools for advertising, measurement and audience services), and fraud prevention agencies, in accordance with the law.

Purposes and lawful bases for use

We use personal data for the following purposes and rely on the corresponding lawful bases:

  • To sell and provide tickets, passes, bookings, and on‑site services; to manage accounts; and to communicate about your visit. Lawful basis: performance of a contract and our legitimate interests in operating the park.
  • To ensure safety and security, including crowd management, incident prevention and investigation, and protection of property using CCTV. Lawful basis: our legitimate interests and, where applicable, legal obligations and substantial public interest.
  • To take and process payments and prevent fraud. Lawful basis: performance of a contract, our legitimate interests, and legal obligations.
  • To provide customer service, handle complaints, and resolve disputes. Lawful basis: performance of a contract and our legitimate interests.
  • To run promotions, competitions, and surveys, and to improve our services and visitor experience through analytics, to deliver and measure targeted online advertising and remarketing (including via Meta platforms such as Facebook and Instagram), create and manage advertising audiences, and assess the performance of our ads. Lawful basis: consent where required for the use of cookies and similar technologies; and our legitimate interests in promoting our services and reaching interested audiences and service improvement.
  • To send marketing communications by email, SMS, push notifications, or targeted online ads including the use of advertising platforms and tools (such as Meta Pixel/SDK, Custom Audiences and Conversions APIs) to show you relevant ads and to prevent showing you ads for products you already purchased. Lawful basis: consent for electronic direct marketing where required, consent where required for cookies and similar technologies used for advertising, and our legitimate interests for similar products and services to existing customers, always with the option to opt out or object.
  • To comply with legal and regulatory requirements and to establish, exercise, or defend legal claims. Lawful basis: legal obligations and legitimate interests.
  • To provide accessibility support and manage health and safety incidents. Lawful basis: explicit consent where required or substantial public interest and legal claims, as permitted by law.

Cookies and similar technologies

We use cookies and similar technologies to operate our websites and apps, enhance functionality, analyse usage, and personalise content and advertising. This includes advertising and social media cookies/pixels/SDKs (for example, the Meta Pixel and Meta SDK) that help us show you ads on Meta services and measure their effectiveness. You can manage your preferences through your browser or device settings, including turning off advertising and social media cookies. For more information, please see our Cookie Policy

Data sharing

We share personal data only as necessary and with appropriate safeguards. When we integrate with advertising platforms (including Meta), we determine the purposes of our advertising activities. In doing so, we may act as controller for our configuration and use of the tools, while the platform may act as an independent controller for its own purposes as described in its notices. Where a provider acts as our processor, we enter into contracts requiring appropriate data protection measures.

  • Service providers who help us operate our business, including payment processors, IT and hosting, analytics, marketing platforms, security providers, and customer support vendors.  Depending on the service, these providers may act as our processors (acting on our instructions) or as independent controllers (determining their own purposes and means.
  • Social media and advertising platforms, including Meta (Facebook/Instagram), when we use their business tools (such as pixels/SDKs, Conversions API and Custom Audiences) to deliver, measure and improve our ads. Depending on the tool and configuration: (a) Meta may act as our processor to provide advertising measurement and analytics on our instructions; and/or (b) Meta may act as an independent controller for its own processing (for example, to improve its ads and products and to provide reporting to advertisers). For Custom Audiences created using contact identifiers (e.g., hashed email addresses), we provide those identifiers in hashed form and require the platform to use them solely to match our audience and to delete them after use.
  • Booking, travel, or promotion partners where you engage with joint offers or packages.
  • Law enforcement, regulators, and public authorities where required by law or to protect safety and security.
  • Professional advisers, insurers, and legal representatives in connection with claims, audits, or compliance.
  • Prospective buyers and their advisers in the context of a business transaction, subject to confidentiality.
  • We do not sell your personal data.

Some recipients may be located outside the UK. Where we transfer data internationally, we will ensure appropriate safeguards, such as adequacy regulations or standard contractual clauses, and supplementary measures where necessary. Details are available on request. Where we use Meta’s advertising and measurement tools, data may be transferred to countries outside the UK (including to the United States and Ireland). We implement appropriate safeguards as described above.

Data security

We apply technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or loss. Measures include access controls, network monitoring, secure development practices, staff training, and incident response procedures. We regularly review our security controls and supplier assurances. Where we use advertising tools that transmit events to third parties (such as Meta), we implement measures designed to minimise personal data (for example, by hashing contact identifiers before upload and limiting the events shared to what is necessary for the stated purposes).

Data retention and deletion

We keep personal data only for as long as necessary for the purposes set out in this policy and to meet legal, accounting, or reporting requirements, after which it will be securely deleted or anonymised. For advertising and remarketing data, we retain audience membership and advertising event data only for as long as needed to run and evaluate campaigns, and in line with the controls available in the relevant platform(s) and our Cookie Policy. Typical retention periods include:

  • Ticketing, booking, and account records: 6 years after the end of the financial year of the last transaction.
  • Customer service correspondence and complaints: up to 3 years after resolution.
  • CCTV footage: up to 90 days unless required for an investigation.
  • Marketing preference data: until you withdraw consent or opt out, plus a short period to maintain suppression lists. Where you opt out of targeted advertising cookies or object to profiling for marketing, we will cease creating or updating advertising profiles for you and will implement suppression in our advertising platforms (including Meta) as soon as reasonably practicable.
  • Incident and health and safety records: in accordance with legal requirements, typically up to 6 years or longer where claims may arise. Specific retention periods are available on request.

When personal data is no longer required for the purposes for which it was collected and no longer needs to be retained to comply with legal or regulatory obligations, to resolve disputes, or to enforce our agreements, we will securely delete or anonymise it. Deletion will be carried out without undue delay and in accordance with our internal policies and procedures.

For further information on our retention schedules or deletion practices, or to make a deletion request, please contact us using the details below.

Your rights

You have the following rights under data protection law, subject to conditions and exemptions:

  • To request access to your personal data and to receive a copy.
  • To request correction of inaccurate or incomplete data.
  • To request deletion of your data where there is no lawful reason for us to continue processing.
  • To object to processing based on our legitimate interests, and to object to direct marketing at any time, including profiling to the extent it is related to such direct marketing (for example, targeted online advertising/remarketing).
  • To request restriction of processing in certain circumstances.
  • To request the transfer of your data to you or another provider (data portability) where technically feasible.
  • Where we rely on consent, to withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise these rights, please contact our Data Protection Officer using the details below. We may need to verify your identity before fulfilling your request. 

Complaints

You have the right to complain if you consider that we have not complied with the data protection law when handling your Personal Data. We will acknowledge receipt of your complaint within 30 days, investigate the matter without undue delay, and keep you informed of the progress and outcome. If you wish to complain please use our complaints form here.  We will do our best to resolve the matter to your satisfaction.

If you are not satisfied with the outcome of your complaint, you can complain to the supervisory authority. The Information Commissioners Office can be contacted online at:

Contact us | ICO

Or by telephone on 0303 123 1113

Children’s data

We do not knowingly collect personal data from children without appropriate consent where required. Parents or guardians purchasing tickets or managing bookings for children should ensure the accuracy of the information provided. If you believe a child has provided personal data without consent, please contact us so that we can delete it where appropriate.

Links to third‑party sites

Our websites, apps, or communications may contain links to third‑party sites and services. Those sites have their own privacy policies, and we are not responsible for their practices. Where our sites include third-party tags, pixels or SDKs (for example, Meta business tools), those providers also have their own privacy notices describing their processing.

Changes to this policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated effective date. We will notify you of significant changes by appropriate means.

Contact us

For questions, requests, or complaints about this policy or how we handle your data, please contact:


Data Protection Officer, Longleat Enterprises Limited, Longleat Estate Office, Longleat, Warminster, Wiltshire, BA12 7NW, datacontroller@longleat.co.uk
.