1. Data Controller
The controller within the meaning of Article 4(7) GDPR for the processing described in this policy is:
paytix S.à r.l.-S34 Duerfstrooss
L-9689 Tarchamps
Grand Duchy of Luxembourg
RCS Luxembourg: B301455
VAT: LU37150620
Business permit: 10187000/0
Email: contact@paytix.lu
We have not appointed a Data Protection Officer, as we do not meet the criteria of Article 37(1) GDPR. All data protection enquiries can be sent to the address above and are handled by our management.
2. Our Two Roles: Controller and Processor
Paytix is a ticketing and event discovery platform. Depending on the data concerned, we act in one of two distinct roles under the GDPR. This distinction determines who is responsible for your data and whom you should address to exercise your rights.
2.1. Where we are the controller
We decide on the purposes and means of processing — and are therefore the controller — for:
- organiser accounts and the organiser dashboard;
- buyer accounts on our platform (login, order history across events);
- visits to our websites, including paytix.lu and our event discovery platform;
- billing of our own service fees, accounting, fraud prevention and platform security;
- our own marketing communications and support requests.
2.2. Where we are a processor for the organiser
When you buy a ticket, register for an event, join a waiting list or subscribe to an organiser's updates, the event organiser is the controller and we process that data on their behalf and on their instructions, under a data processing agreement pursuant to Article 28 GDPR. This applies in particular to:
- attendee names, email addresses and order details;
- answers to registration forms whose fields the organiser defines themselves;
- waiting list entries and organiser follower/newsletter lists;
- ticket scanning and admission records at the event.
The organiser's own privacy policy applies to that data. If you send us a request concerning data we hold as a processor, we will forward it to the organiser without undue delay and inform you accordingly.
3. Categories of Personal Data We Process
- Organiser account data: first and last name, email address, username, password (stored only as a salted hash), organisation name, legal form, postal address, RCS and VAT number, website and social media links, profile image, account preferences and email opt-out settings.
- Buyer account data: name, email address, authentication identifiers of our login provider, and the orders linked to your account.
- Order and ticket data: purchaser name and email address, ticket type, quantity, price, order and ticket numbers, order and payment status, payment reference of our payment service provider, refund and cancellation records, invoices and credit notes.
- Payment data: card and bank details are entered directly with our payment service provider and are never stored on our servers. We receive only transaction metadata (amount, currency, date, status, last digits/brand where provided).
- Payout data (organisers): the identifiers and status information of your connected payment account, payout amounts and dates. Identity verification documents are submitted to and held by the payment service provider, not by us.
- Registration form answers: the fields defined by the organiser (for example meal choices, company name, consent statements).
- Admission data: time of scan, ticket status and the scanning device or account, in order to prevent multiple use of a ticket.
- Wallet passes: where you add a ticket to Apple Wallet or Google Wallet, the device push identifier required to deliver updates to that pass.
- Support and communication data: support tickets and messages, email delivery status (delivered, bounced, complaint) for transactional emails.
- Usage and log data: IP address, browser type and version, operating system, referring page, pages accessed, date and time of access, HTTP status and response times.
- Analytics and error diagnostics: as described in sections 7 and 8.
We do not intentionally collect special categories of personal data within the meaning of Article 9 GDPR. Should an organiser's registration form request such data (for example accessibility requirements or dietary information revealing religious beliefs), the organiser is responsible for obtaining the explicit consent required under Article 9(2)(a) GDPR.
4. Purposes, Legal Bases and Retention Periods
We process personal data only where a legal basis under Article 6(1) GDPR applies. The following table sets out each purpose, its legal basis and how long we keep the data.
| Purpose | Legal basis | Retention |
|---|---|---|
| Creating and managing organiser and buyer accounts, authentication | Art. 6(1)(b) GDPR — performance of a contract | For the lifetime of the account; deleted within 30 days of account closure, except for data subject to statutory retention |
| Processing ticket orders, issuing tickets, wallet passes and admission control | Art. 6(1)(b) GDPR — performance of a contract | Until 12 months after the event, for handling disputes and chargebacks; wallet push identifiers are deleted when the pass is removed |
| Payment processing, payouts to organisers and billing of our service fees | Art. 6(1)(b) GDPR and Art. 6(1)(c) GDPR — legal obligation (accounting, VAT, anti-money-laundering) | Kept for the statutory period, see accounting records below |
| Accounting records, invoices and supporting documents | Art. 6(1)(c) GDPR — Art. 16 of the Luxembourg Commercial Code and the VAT Law | 10 years from the end of the financial year concerned |
| Registration forms, waiting lists and organiser follower lists | Processed on behalf of the organiser (Art. 28 GDPR); the organiser relies on Art. 6(1)(b) or 6(1)(a) GDPR | On the organiser’s instructions; by default until 12 months after the event or until you unsubscribe |
| Newsletters and marketing communications from us | Art. 6(1)(a) GDPR — consent | Until you withdraw consent; the record of your consent and withdrawal is kept for 3 years as evidence |
| Customer support, handling enquiries and complaints | Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR — legitimate interest in answering enquiries | 3 years after the case is closed |
| Server logs, fraud prevention, abuse detection and IT security | Art. 6(1)(f) GDPR — legitimate interest in a secure and stable service | Log data up to 90 days; records of confirmed abuse or fraud up to 3 years |
| Reach measurement on ticket shops (cookie-free, aggregate) | Art. 6(1)(f) GDPR — legitimate interest in reach measurement | Aggregate figures up to 12 months |
| Analytics and marketing on the event discovery platform (cookies, Meta pixel) | Art. 6(1)(a) GDPR — consent via the cookie banner | Up to 12 months, or until you withdraw consent, whichever is earlier |
| Error tracking and sampled performance measurement (no session recording) | Art. 6(1)(f) GDPR — legitimate interest in a functioning, error-free service | 90 days |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) GDPR — legitimate interest in legal defence | Until the applicable limitation period expires (as a rule 10 years under Luxembourg law) |
Where we rely on a legitimate interest under Article 6(1)(f) GDPR, we have carried out a balancing test and concluded that our interest in operating a secure, functioning and economically viable platform is not overridden by your interests or fundamental rights. You may request further information on that assessment at any time.
After the stated periods expire, data is deleted or irreversibly anonymised. Data that is subject to a statutory retention obligation is blocked from further use rather than deleted, and removed once the obligation lapses. Copies contained in encrypted backups are overwritten in the ordinary backup rotation, at the latest 90 days after deletion from the live system.
5. Recipients and Processors
We use carefully selected service providers who process personal data on our behalf under a data processing agreement pursuant to Article 28 GDPR, or who act as independent controllers where indicated. We do not sell personal data.
| Recipient | Purpose | Processing location / safeguard |
|---|---|---|
| Stripe Payments Europe, Ltd. | Payment processing, payouts, identity verification of organisers, fraud checks. Acts as an independent controller for payment data. | Ireland; group companies in the USA — Standard Contractual Clauses |
| Fly.io, Inc. | Application and database hosting | Servers in Paris, France (EU); provider established in the USA — Standard Contractual Clauses |
| PostHog, Inc. | Product and reach analytics | EU Cloud (Germany); provider established in the USA — Standard Contractual Clauses |
| Sinch / Mailgun | Delivery of transactional and consented marketing emails | EU region endpoint; Standard Contractual Clauses |
| Resend, Inc. | Delivery of transactional emails and delivery-status webhooks | USA — Standard Contractual Clauses |
| Functional Software, Inc. (Sentry) | Error tracking and sampled performance measurement; no session recording | EU region (Germany); provider established in the USA — Standard Contractual Clauses |
| Clerk, Inc. | Authentication and session management for buyer accounts | USA — Standard Contractual Clauses |
| Google Ireland Limited / Google LLC | Cloud storage of files and ticket assets, Google Wallet passes, address and venue lookup | EU and USA — Standard Contractual Clauses and EU–U.S. Data Privacy Framework |
| Apple Distribution International Ltd. | Apple Wallet passes and their update notifications | Ireland; group companies in the USA — Standard Contractual Clauses |
| Meta Platforms Ireland Limited | Meta pixel on the event discovery platform, only where an organiser has configured one and only after your consent | Ireland; group companies in the USA — Standard Contractual Clauses |
In addition, personal data may be disclosed to:
- Event organisers, who receive the attendee data for their own event as controllers (see section 2.2);
- our tax advisors, auditors and lawyers, bound by professional secrecy, where necessary;
- public authorities and courts, where we are legally obliged to disclose data (Article 6(1)(c) GDPR);
- an acquirer, in the event of a merger, restructuring or sale of business assets, subject to the same protections and with prior notice to you where required.
6. Transfers to Third Countries
Our application servers, database and analytics are located within the European Union. Some of our providers are established in, or have parent companies in, the United States. Where personal data is transferred outside the EEA, we ensure an adequate level of protection through one or more of the following safeguards:
- Standard Contractual Clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR, complemented by supplementary technical and organisational measures following a transfer impact assessment;
- certification of the recipient under the EU–U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision pursuant to Article 45 GDPR.
You may request a copy of the safeguards in place by writing to contact@paytix.lu. Please note that transfers to third countries may mean that local authorities gain access to data and that enforcing your rights there can be more difficult than within the EEA.
8. Error Tracking
To detect and fix faults in the checkout process we use Sentry, with data stored in the provider's European region. When an error occurs, a technical error report is transmitted containing the URL concerned, browser and device information, the IP address, the error message and stack trace, and a short technical log of the preceding actions (for example "page opened", "button clicked"). We do not use session recording or session replay: no reconstruction of your screen, mouse movements or form entries is created.
In addition, a small random sample of page views — around one in ten, whether or not an error occurs — transmits technical performance measurements to the same service: the page requested, how long it took to load, and the browser and IP address involved. We use this solely to identify pages that have become slow or unreliable.
The legal basis for both is our legitimate interest in the security, stability and error-free operation of the service (Article 6(1)(f) GDPR). The data is deleted after 90 days. You may object to this processing at any time under Article 21(1) GDPR.
9. Emails and Communications
Transactional emails — order confirmations, tickets, invoices, refund notices, password resets and important service notices — are necessary to perform our contract or the organiser's contract with you (Article 6(1)(b) GDPR) and cannot be unsubscribed from while you hold an active order or account.
Newsletters, event updates and organiser follower emails are sent only on the basis of your consent (Article 6(1)(a) GDPR), given through a clear opt-in. Every such email contains a one-click unsubscribe link, and you can withdraw your consent at any time with effect for the future.
We process delivery status information (delivered, bounced, marked as spam) from our email providers in order to keep our mailing lists clean and protect our sending reputation (Article 6(1)(f) GDPR). We do not use tracking pixels to measure whether you have opened marketing emails unless you have consented to it.
10. Your Rights
As a data subject you have the following rights, which you can exercise free of charge:
- Right of access (Art. 15 GDPR) — to obtain confirmation as to whether we process data concerning you, a copy of that data and information about the processing.
- Right to rectification (Art. 16 GDPR) — to have inaccurate data corrected and incomplete data completed.
- Right to erasure (Art. 17 GDPR) — to have your data deleted, unless processing is still necessary, in particular to comply with a statutory retention obligation or to establish, exercise or defend legal claims.
- Right to restriction of processing (Art. 18 GDPR) — to have processing limited, for instance while the accuracy of your data is being verified.
- Right to data portability (Art. 20 GDPR) — to receive the data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to object (Art. 21 GDPR) — to object, on grounds relating to your particular situation, to processing based on legitimate interests. Where data is processed for direct marketing purposes, you have an unconditional right to object at any time; we will then stop that processing immediately.
- Right to withdraw consent (Art. 7(3) GDPR) — to withdraw any consent you have given at any time, with effect for the future.
- Right not to be subject to automated decision-making (Art. 22 GDPR) — see section 11.
To exercise your rights, write to contact@paytix.lu. We will respond within one month of receiving your request. That period may be extended by a further two months where the request is complex or where we receive a number of requests, in which case we will inform you within the first month (Article 12(3) GDPR). We may ask you for additional information to verify your identity where we have reasonable doubts about it.
Right to lodge a complaint
Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR). The competent authority for us is:
Commission nationale pour la protection des données (CNPD)15, boulevard du Jazz
L-4370 Belvaux
Grand Duchy of Luxembourg
Tel.: (+352) 26 10 60 - 1
cnpd.public.lu (opens in a new tab)
11. Automated Decision-Making and Profiling
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22(1) GDPR. Our payment service provider applies automated fraud and risk checks to transactions; where such a check results in a payment being declined, you may contact us to have the decision reviewed by a person, to express your point of view and to contest the decision.
12. Is Providing Your Data Required?
Providing personal data is neither required by law nor by contract in general. However, certain data is necessary to enter into and perform a contract: without a name and email address we cannot create an account, issue a ticket or send you an invoice, and without the information required by our payment service provider we cannot pay out ticket revenue to organisers. Invoice-related data must be collected to comply with Luxembourg accounting and VAT law. If you do not provide this data, we will not be able to provide the corresponding service.
13. Security of Processing
In accordance with Article 32 GDPR we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- TLS encryption of all data in transit and encryption at rest;
- storage of passwords exclusively as salted one-way hashes;
- role-based access control and the principle of least privilege for staff access;
- separation of payment data, which never reaches our systems, from our own databases;
- rate limiting, security headers and logging of security events;
- regular encrypted backups and restore testing;
- contractual commitments and confidentiality obligations for all processors.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the CNPD within 72 hours pursuant to Article 33 GDPR and, where the breach is likely to result in a high risk, inform you directly pursuant to Article 34 GDPR. Please note that no method of transmission over the internet can be guaranteed to be completely secure.
14. Children
Our services are not directed at children. Where processing is based on consent, we only offer our services to persons who have reached the age of 16, in accordance with Article 8(1) GDPR as applied in Luxembourg. Persons under 16 may only consent with the authorisation of the holder of parental responsibility. If we become aware that we have collected personal data from a child without the required authorisation, we will delete it without undue delay. If you believe this is the case, please contact us at contact@paytix.lu.
15. Changes to This Privacy Policy
We review this policy regularly and update it where our processing activities or the legal framework change. The current version, with its date, is always available on this page. If a change materially affects you — for example a new purpose of processing — we will inform you in advance by email or through a prominent notice in the service, and, where the change requires it, ask for your consent.
16. Contact
For any question about this policy or the processing of your personal data, contact us at contact@paytix.lu or by post at paytix S.à r.l.-S, 34 Duerfstrooss, L-9689 Tarchamps, Luxembourg. See also our GDPR information page and our Terms of Service.
This policy is provided in English. In case of divergence between language versions, the English version prevails.