GDPR Compliance

Last updated: 2026-08-15

A short overview of how we meet our obligations under the General Data Protection Regulation. The full statutory information is set out in our Privacy Policy.

This page is a summary. The mandatory information under Articles 13 and 14 GDPR — the identity of the controller, each purpose of processing with its legal basis, retention periods, the full list of processors and third-country transfers — is contained in our Privacy Policy. Where the two differ, the Privacy Policy prevails.

1. Who Is Responsible

The controller within the meaning of Article 4(7) GDPR is:

paytix S.à r.l.-S
34 Duerfstrooss
L-9689 Tarchamps
Grand Duchy of Luxembourg

RCS Luxembourg: B301455
VAT: LU37150620
Email: [email protected]

We have not appointed a Data Protection Officer, as we do not meet the criteria of Article 37(1) GDPR. Data protection enquiries are handled by our management at the address above.

2. Controller or Processor — Which Applies to You

Paytix acts in two distinct roles, and this determines whom you should address:

  • We are the controller for organiser accounts, buyer accounts, visits to our websites, our own billing and accounting, platform security and our own marketing. Address these requests to us.
  • We are a processor for the attendee data of a specific event — order details, registration form answers, waiting lists, follower lists and admission scans. Here the event organiser is the controller and we act on their instructions under a data processing agreement pursuant to Article 28 GDPR. Their privacy policy applies. If you write to us anyway, we forward your request to the organiser without undue delay and let you know.

3. Principles We Apply

We process personal data in line with the principles of Article 5(1) GDPR:

  • lawfully, fairly and in a transparent manner;
  • for specified, explicit and legitimate purposes only, and not further processed in an incompatible manner;
  • limited to what is necessary for those purposes (data minimisation);
  • accurate and, where necessary, kept up to date;
  • kept in identifiable form no longer than necessary (storage limitation);
  • processed securely, with appropriate technical and organisational measures under Article 32 GDPR.

We are able to demonstrate compliance with these principles (accountability, Article 5(2) GDPR) through our record of processing activities, our agreements with processors and our documented consent records.

4. Legal Bases in Short

  • Article 6(1)(b) — accounts, ticket orders, delivery of tickets and invoices;
  • Article 6(1)(c) — accounting, VAT and other statutory obligations under Luxembourg law;
  • Article 6(1)(f) — security, fraud prevention, cookie-free reach measurement, error diagnostics and legal defence;
  • Article 6(1)(a) — newsletters, and any analytics or marketing technology that stores or reads information on your device.

A purpose-by-purpose breakdown, including the retention period for each, is set out in section 4 of the Privacy Policy.

5. Your Rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21) — unconditionally so where data is processed for direct marketing. You may withdraw any consent at any time with effect for the future (Art. 7(3)).

Send your request to [email protected]. We respond within one month; where a request is complex, that period may be extended by two further months and we will tell you within the first month (Art. 12(3) GDPR). Exercising your rights is free of charge. Full details are in section 10 of the Privacy Policy.

6. Security, Breaches and International Transfers

Our application servers and database are hosted in the European Union. Data is encrypted in transit and at rest, passwords are stored only as salted one-way hashes, and card details never reach our systems — they are entered directly with our payment service provider.

Where a provider is established outside the EEA, transfers are covered by Standard Contractual Clauses under Article 46(2)(c) GDPR or by the EU–U.S. Data Privacy Framework. The Privacy Policy names every processor, its purpose and the safeguard that applies.

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the CNPD within 72 hours (Article 33 GDPR) and inform affected individuals directly where the risk is high (Article 34 GDPR).

7. For Organisers: Your Own GDPR Obligations

If you sell tickets through Paytix, you are the controller for your attendees' data and we are your processor. That means you are responsible for:

  • having your own lawful basis and privacy information for the data you collect;
  • the fields you add to registration forms — collect only what you genuinely need, and obtain explicit consent where a field reveals special category data under Article 9 GDPR;
  • any tracking you enable yourself, such as a Meta pixel on your event pages;
  • answering data subject requests from your attendees, and using only consented lists for your own marketing.

The data processing agreement between us forms part of our Terms of Service. Contact us if you require a signed copy for your records.

8. Contact and Right to Complain

For any data protection matter, write to [email protected] or to paytix S.à r.l.-S, 34 Duerfstrooss, L-9689 Tarchamps, Luxembourg.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement (Article 77 GDPR). The authority competent for us is:

Commission nationale pour la protection des données (CNPD)
15, boulevard du Jazz
L-4370 Belvaux
Grand Duchy of Luxembourg
Tel.: (+352) 26 10 60 - 1
cnpd.public.lu

This page summarises our approach to the GDPR. For the complete statutory information, see our Privacy Policy and our Terms of Service.