Last updated: 2026-08-15
A short overview of how we meet our obligations under the General Data Protection Regulation. The full statutory information is set out in our Privacy Policy.
This page is a summary. The mandatory information under Articles 13 and 14 GDPR — the identity of the controller, each purpose of processing with its legal basis, retention periods, the full list of processors and third-country transfers — is contained in our Privacy Policy. Where the two differ, the Privacy Policy prevails.
The controller within the meaning of Article 4(7) GDPR is:
paytix S.à r.l.-SWe have not appointed a Data Protection Officer, as we do not meet the criteria of Article 37(1) GDPR. Data protection enquiries are handled by our management at the address above.
Paytix acts in two distinct roles, and this determines whom you should address:
We process personal data in line with the principles of Article 5(1) GDPR:
We are able to demonstrate compliance with these principles (accountability, Article 5(2) GDPR) through our record of processing activities, our agreements with processors and our documented consent records.
A purpose-by-purpose breakdown, including the retention period for each, is set out in section 4 of the Privacy Policy.
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21) — unconditionally so where data is processed for direct marketing. You may withdraw any consent at any time with effect for the future (Art. 7(3)).
Send your request to [email protected]. We respond within one month; where a request is complex, that period may be extended by two further months and we will tell you within the first month (Art. 12(3) GDPR). Exercising your rights is free of charge. Full details are in section 10 of the Privacy Policy.
Our application servers and database are hosted in the European Union. Data is encrypted in transit and at rest, passwords are stored only as salted one-way hashes, and card details never reach our systems — they are entered directly with our payment service provider.
Where a provider is established outside the EEA, transfers are covered by Standard Contractual Clauses under Article 46(2)(c) GDPR or by the EU–U.S. Data Privacy Framework. The Privacy Policy names every processor, its purpose and the safeguard that applies.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the CNPD within 72 hours (Article 33 GDPR) and inform affected individuals directly where the risk is high (Article 34 GDPR).
If you sell tickets through Paytix, you are the controller for your attendees' data and we are your processor. That means you are responsible for:
The data processing agreement between us forms part of our Terms of Service. Contact us if you require a signed copy for your records.
For any data protection matter, write to [email protected] or to paytix S.à r.l.-S, 34 Duerfstrooss, L-9689 Tarchamps, Luxembourg.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR). The authority competent for us is:
Commission nationale pour la protection des données (CNPD)This page summarises our approach to the GDPR. For the complete statutory information, see our Privacy Policy and our Terms of Service.