Privacy policy
Last updated: 13 Aug 2026, 01:39
Privacy and Personal Data Protection Policy — StagePass.gr
Published: [FILL IN: DD/MM/YYYY] Version: 1.0
NOTE TO PUBLISHER (remove before publication): Draft. Fields in
[BRACKETS]must be completed with your actual infrastructure details — an inaccurate transfer register is worse than none. Legal or DPO review required before publication. SeeOPEN-ITEMS.md.This is the English version of the Greek policy (
stagepass-privacy-el.md). Section numbering is identical in both. In case of discrepancy, see the language clause in the Terms of Use (F.9).
1. Who we are
The controller of the data described in this policy is:
| Company name | [FILL IN: full legal name] |
| Trading name | StagePass.gr |
| Registered office | [FILL IN: street, number, postcode, city] |
| Tax ID / Tax Office | [FILL IN] |
| Business Registry (Γ.Ε.ΜΗ.) No. | [FILL IN] |
| Data protection contact email | [FILL IN: e.g. privacy@stagepass.gr] |
| Data Protection Officer (DPO) | [FILL IN or delete this row — see note below] |
[NOTE TO PUBLISHER: appointing a DPO is not mandatory for every business. Do not name a DPO unless one has actually been appointed. If there is none, simply give a contact point for data protection matters.]
This policy is an information notice, not a contract. You are not asked to “accept” it. It informs you, in accordance with Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), what we do with your data and what rights you have. Where consent is required, it is requested separately and specifically.
2. Scope
This policy covers processing in connection with the stagepass.gr website, our partner physical points of sale, and our customer service.
It does not cover processing carried out by event Organisers for their own purposes. Organisers act as independent controllers and have their own privacy policies (see section 6).
3. What data we collect and where it comes from
3.1 Data you give us
| Category | Examples | When |
|---|---|---|
| Account details | First name, last name, email, password (stored hashed) | Registration |
| Optional profile details | Telephone, date of birth, address, photograph | Completing your profile |
| Order details | Event, ticket category/seat, amount, ticket holder name | Purchase |
| Payment details | Card details are entered directly with the payment provider. We receive only a transaction reference, the last 4 digits and the transaction outcome | Payment |
| Resale details | Ticket listing, payout details [FILL IN: IBAN, if used] | Using the Resale Platform |
| Communications | Content of messages, support requests, complaints | Contacting us |
| Identification documents | Copy of ID or proof of card ownership, only where requested for fraud checks | Security review |
3.2 Data collected automatically
- Technical data: IP address, browser type and version, operating system, device type, language, pages visited, time and duration of visit.
- Cookies and similar technologies: see our Cookies Policy.
- Security data: login logs, in-account activity, indicators of automated (bot) use, failed login attempts.
- Ticket validation data: date and time the QR code was scanned at the venue entrance.
3.3 Data from third parties
- From the payment service provider: transaction outcome, fraud indicators, chargebacks.
- From partner physical points of sale: order details entered there on your behalf.
- From a third-party identity provider (if you choose to sign in that way): name and email address. [FILL IN or delete if not supported]
- From public authorities or financial institutions, where required by law.
We do not collect special categories of data (GDPR Article 9). If you buy a concession ticket requiring proof of disability, that proof is shown at the entrance to the Organiser and is not recorded by us.
4. Why we process your data and on what legal basis
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Creating and managing your account | Performance of a contract — 6(1)(b) |
| Processing your order, collecting payment, issuing and delivering your ticket | Performance of a contract — 6(1)(b) |
| Operating the Resale Platform (cancellation, reissue, payout) | Performance of a contract — 6(1)(b) |
| Validating tickets at the entrance and preventing double use | Performance of a contract — 6(1)(b) · Legitimate interests — 6(1)(f) |
| Customer service and complaint handling | Performance of a contract — 6(1)(b) |
| Notifying you of changes, postponement or cancellation of an event | Performance of a contract — 6(1)(b) |
| Preventing and detecting fraud, abuse and automated purchasing (bots); systems security | Legitimate interests — 6(1)(f) |
| Enforcing the Terms of Use; establishing and pursuing legal claims | Legitimate interests — 6(1)(f) |
| Statistics and service improvement (aggregated where feasible) | Legitimate interests — 6(1)(f) |
| Accounting, tax and other statutory obligations | Legal obligation — 6(1)(c) |
| Responding to requests from authorities and court orders | Legal obligation — 6(1)(c) |
| Sending marketing communications (newsletter) | Consent — 6(1)(a) (or 6(1)(f) with Article 11(3) of Law 3471/2006 for existing customers — see section 10) |
| Non-essential cookies and analytics | Consent — 6(1)(a) |
Where the basis is legitimate interests, we have balanced those interests against your rights. You may request a summary of that assessment and you may object (see section 12).
5. Automated decision-making
We use automated checks to detect fraud and automated ticket purchasing (bots). These checks may result in an order being rejected or an account suspended.
We do not carry out profiling for advertising purposes.
If you are affected by such a check, you have the right to human intervention, to express your point of view and to contest the decision, by contacting us at [FILL IN: email]. [NOTE TO PUBLISHER: make sure a human review process actually exists. If blocking is fully automated and produces legal or similarly significant effects, GDPR Article 22 is engaged.]
6. Who we share your data with
We do not sell your data. We share it only with the following categories of recipient:
6.1 Event Organisers — independent controllers
We pass to the Organiser of the event you selected the data necessary for staging the event and controlling entry: [FILL IN PRECISELY: e.g. name, ticket category, number of tickets, order reference — and whether email or telephone is passed on].
The Organiser acts as an independent controller for its own purposes (entry control, safety obligations, its own communications where you have consented) and is itself responsible for that processing. Its details appear on each event page.
6.2 Processors
We work with providers who process data on our instructions, under Article 28 GDPR agreements:
| Category | Provider | Location |
|---|---|---|
| Application and database hosting | [FILL IN] | [FILL IN] |
| Content delivery and image processing | [FILL IN] | [FILL IN] |
| Transactional email | [FILL IN] | [FILL IN] |
| SMS delivery | [FILL IN or delete] | [FILL IN] |
| Usage analytics | [FILL IN or delete] | [FILL IN] |
| Technical support and development | [FILL IN] | [FILL IN] |
6.3 Payment service provider
[FILL IN: PSP name] processes your payment data as an independent controller, under its own privacy policy and its obligations under payment services legislation.
6.4 Partner physical points of sale
When you buy or collect a ticket at a partner outlet, its staff have access to the details of that specific order, solely in order to serve you.
6.5 Other recipients
- Public authorities (tax, prosecuting, police, regulatory), where required by law.
- Legal and accounting advisers, under a duty of confidentiality.
- In the event of a corporate reorganisation (merger, acquisition), the successor entity, with prior notice to you.
6.6 Ticket resale
When you resell a ticket through the Platform, your personal details are not disclosed to the buyer and the buyer’s details are not disclosed to you. StagePass intermediates the entire transaction.
7. Transfers outside the EEA
Some of our providers may be established in, or store data in, countries outside the European Economic Area. Where that is the case, the transfer takes place under at least one of the following Chapter V GDPR safeguards:
- an adequacy decision of the European Commission,
- Standard Contractual Clauses (SCCs) together with a transfer impact assessment,
- other appropriate safeguards under Article 46 GDPR.
You may request a copy of the relevant safeguards at [FILL IN: email].
[NOTE TO PUBLISHER — IMPORTANT:] The current hosting and image-processing infrastructure appears to rely on providers established outside the EU. You need to confirm the storage region of each service, put Article 28 agreements and, where required, SCCs in place, and complete the table in section 6.2 with the real provider names. A generic statement with no supporting documentation is itself a breach.
8. How long we keep your data
| Category | Retention period |
|---|---|
| Account details | While the account is active, plus [FILL IN: e.g. 30] days after a deletion request |
| Accounting records and transaction data | 5 years from the end of the relevant financial year (Law 4308/2014 and tax legislation) |
| Ticket and entry validation data | [FILL IN: e.g. 12 months] from the event date |
| Customer service correspondence | [FILL IN: e.g. 24 months] from resolution of the request |
| Security logs | [FILL IN: e.g. 12 months] |
| Identification documents for fraud checks | Deleted immediately once the check is complete, unless a fraud incident is documented |
| Marketing consent and its audit trail | Until withdrawal, plus [FILL IN: e.g. 5] years as evidence of compliance |
| Data relating to legal claims | Until the claim is time-barred or the dispute is finally concluded |
After these periods, data is securely deleted or anonymised.
Deleting your account does not delete transaction records, which we are required by law to retain.
9. Security
We apply appropriate technical and organisational measures under Article 32 GDPR, including:
- encryption of data in transit (TLS) and at rest,
- storage of passwords in hashed form only,
- role-based access control and multi-factor authentication for privileged accounts,
- access logging and monitoring for suspicious activity,
- encrypted backups,
- dynamic QR codes on tickets, to prevent copying and double use,
- processing agreements with all our providers,
- a procedure for managing and notifying personal data breaches.
No transmission of data over the internet is entirely secure. In the event of a breach likely to result in a high risk to your rights, we will notify you in accordance with Articles 33 and 34 GDPR.
[NOTE TO PUBLISHER: remove from the list above any measure you do not actually implement. Stating measures that do not exist is a false statement to data subjects.]
10. Marketing communications
- You receive marketing messages only where you have given your consent, or where you have already purchased from us and the messages concern similar services, in which case Article 11(3) of Law 3471/2006 applies (with an opt-out in every message).
- You can stop receiving them at any time, via the unsubscribe link in every message or from your account settings.
- Marketing from Organisers is sent only where you have given separate consent. The Organiser is responsible for its content as an independent controller.
- Service messages (order confirmation, your ticket, notice of a change or cancellation) are not marketing and are always sent.
11. Unsolicited communications and abuse
We do not permit the use of our website or services to send bulk or unsolicited email, nor the harvesting of email addresses or user details by automated means. Where we detect such use, we take immediate technical blocking measures and delete the account concerned.
12. Your rights
You have the following rights:
| Right | What it means |
|---|---|
| To be informed | To know what data we process and why — that is what this policy does |
| Access | To obtain a copy of your data |
| Rectification | To correct inaccurate or incomplete data |
| Erasure | To request deletion where there is no lawful basis for us to keep it |
| Restriction | To ask us to limit processing in specific circumstances |
| Portability | To receive your data in a structured, commonly used format, or to have it transmitted directly to another organisation |
| Objection | To object to processing based on legitimate interests. For direct marketing the objection is absolute and is always honoured |
| Withdrawal of consent | At any time, without affecting the lawfulness of processing carried out beforehand |
| Human intervention | In automated decisions (see section 5) |
How to exercise them: send a request to [FILL IN: email]. We respond within one (1) month, extendable by a further two (2) months for complex requests, in which case we will tell you. Exercising your rights is free of charge. We may ask for identification, so that we do not disclose your data to someone else.
13. Right to complain
If you believe the processing of your data breaches the law, you have the right to complain to the Hellenic Data Protection Authority:
1-3 Kifissias Ave., 115 23 Athens, Greece · tel. +30 210 6475600 · www.dpa.gr
We would appreciate the chance to resolve the matter with you first.
14. Links to third-party websites
Our website may contain links to third-party sites (Organisers, payment providers, venues). We do not control and are not responsible for their content or privacy practices. We recommend reading their policies.
15. Minors
Our services are directed at people aged 18 and over and we do not knowingly collect data from minors. If we find that an account has been created by a minor, we delete it. If you are a parent or guardian and believe we hold data about a minor, please contact us.
16. Changes to this policy
We may update this policy. Each new version carries a date and version number. Where a change is material, we will actively notify you (by email or a prominent notice on the website) before it takes effect. Continuing to use the website is not treated as consent to new processing purposes; where consent is required, it is requested again and separately.
17. Contact
[FILL IN: full legal name] [FILL IN: address] Data protection email: [FILL IN] [FILL IN: DPO details, if one has been appointed]
Data controller
How long things are kept
- Names and emails on orders: 72 months after the event.
- Gate scan records: 180 days.
- Waiting-room records: 30 days.
- Consent log: 36 months.
You have the right to complain to the supervisory authority: Hellenic Data Protection Authority (dpa.gr).
Your data — See what we hold, download a copy, ask us to erase it, or change your cookie choices.