Privacy Notice for Organizers and Representatives
How contact, KYB, banking, contractual, security and audit data are used in the professional relationship.
1. Controller and data subjects
This notice applies to access applicants, legal representatives and authorized persons, beneficial owners, financial and operational contacts, portal users, and staff involved in events.
Controller for the platform's own purposes: [LEGAL NAME - TO BE COMPLETED], Tax ID (CUI) [TO BE COMPLETED], registered office [TO BE COMPLETED], legal and privacy contact [TO BE COMPLETED].
2. Categories of data
Identity and representation
- Name, position, contact details, signature, and relationship with the entity.
- Information from the identity document and authorization, limited to the necessary elements.
- Beneficial owner, control structure, and results of risk checks.
Entity, taxation, and payments
- Legal and trading name, Tax ID (CUI), register, registered office, country, VAT status, and corporate documents.
- IBAN, account holder, bank, currency, connected account, and statuses communicated by the PSP.
- Commission, invoices, settlement, reserve, refund, chargeback, and reconciliation.
Account, events, and security
- Portal address, role, event access, authentication events, and actions within the system.
- Venue documents, permits, contacts, incidents, and approvals.
- Communications, support requests, exports, and audit logs.
- Date and time of acceptances, document version and fingerprint, authentication method, and the browser's technical identifier (user-agent) used as audit evidence.
3. Purposes and categories of legal bases
The final purpose-and-legal-basis matrix, legitimate interests, and specific obligations are [TO BE COMPLETED AND LEGALLY VALIDATED].
- Assessment of the application and pre-contractual steps requested by the organizer.
- Conclusion and performance of the agreement, mandate, ticketing, support, and settlement.
- KYB verification, traceability, fraud prevention, and protection of buyers and the platform.
- Compliance with tax, accounting, invoicing, reporting, and authority-cooperation obligations.
- Legitimate interests in security, audit, establishment, exercise, or defense of rights, operational improvement, and risk management, following the necessary assessment.
- Separate consent for marketing or other optional purposes, if enabled.
4. Mandatory nature and sources of data
Data required for identification, representation, contracting, KYB, PSP, taxation, and security is necessary to assess or continue the collaboration. Failure to provide it may lead to rejection, conditional approval, suspension, or inability to settle funds.
Data is obtained from the individual and entity, supplied documents, official registers, the PSP, use of the portal, organizers or authorized partners, and proportionate incident investigations.
5. Categories of recipients
- Authorized legal, finance, operations, support, security, and management personnel.
- The PSP and its verification and anti-fraud providers, in accordance with their own roles and notices.
- Hosting, database, storage, authentication, email, signature, screening, and audit providers, only where contracted for production.
- Lawyers, accountants, auditors, insurers, and advisers subject to confidentiality obligations.
- Authorities, courts, and institutions where an obligation or legal basis exists.
6. Roles of the platform, organizer, and PSP
As a rule, the platform is an independent controller for onboarding, accounts, security, fraud, its own support, and the B2B relationship. The organizer is controller for its staff data and operation of the event. The PSP is an independent controller for payments and its controls.
Operations performed strictly on one party's instructions may require an Article 28 DPA, while purposes jointly determined may require an Article 26 assessment. The final role is documented for each flow.
7. International transfers
Where a provider involves access or storage outside the EEA, the legal mechanism, contractual safeguards, and supplementary measures are assessed. The specific countries, providers, and safeguards are [TO BE COMPLETED AFTER INVENTORYING].
8. Retention criteria
Periods differ for rejected applications, agreements, KYB, tax documents, transactions, settlement, refunds, chargebacks, security logs, and disputes. Criteria include legal obligations, the agreement term, limitation periods, the risk window, PSP requirements, and storage limitation.
A legal hold may suspend erasure of relevant documents. The matrix containing exact periods and the person responsible for erasure is [TO BE COMPLETED AND APPROVED].
9. Security and incidents
- Role-based access, separation of organizers, and prompt user revocation.
- Protection of KYB and banking documents and logging of views and exports.
- Secure authentication, encryption, backups, and tested restoration.
- Alerts for suspicious access, IBAN changes, bulk exports, and fraud.
- An incident procedure with role assessment and cooperation on required notifications.
10. Data subject rights
Requests are submitted through /gdpr and may require proportionate identity verification. Legal obligations and the rights of other persons may limit certain requests.
- Access and information about processing.
- Rectification and completion.
- Erasure and restriction, subject to the conditions of law.
- Objection to processing based on legitimate interests and objection at any time to direct marketing.
- Portability where the applicable conditions are met.
- Withdrawal of consent for optional purposes.
- Lodging a complaint with the Romanian National Supervisory Authority for Personal Data Processing.
11. Marketing, updates, and contact
Marketing to a representative is separate from messages necessary for the agreement, security, settlement, and incidents. The preference is optional, is not selected by default, and can be withdrawn easily.
Operational organizer channel: promoters@euphorictickets.ro. The official privacy contact, controller details, and any data protection officer are [TO BE COMPLETED]. New material versions are communicated and may require a new acknowledgment.

