Privacy Policy
Data categories, purposes, legal bases, recipients, retention criteria, security measures, and data subject rights.
1. Controller and scope of this notice
This policy applies to visitors, buyers, attendees, account users, persons requesting support, and persons reporting an event or content.
Data controller for the platform's own purposes: ART STUDIOS MANAGEMENT S.R.L., Tax ID (CUI) 53262231, trade register number J2026002109006, registered in Romania, legal email address management@euphorictickets.ro. The registered office is available to competent authorities and verified counterparties through the appropriate private channel.
2. Categories of data
Account, order, and ticket
- Email address, name, and information provided voluntarily during checkout or through the account.
- Order, event, category, quantity, total, and payment status identifiers.
- Ticket identifier, QR status, issuance, reissuance, cancellation, and scanning.
Payment and taxation
- References and statuses received from the PSP; the platform must not collect full card details where payment is hosted or tokenized by the PSP.
- Billing data requested only to the extent necessary for the selected tax flow.
- Information concerning refunds, disputes, chargebacks, and reconciliation.
Support, security, and use
- Messages, attachments, event, order reference, and resolution history.
- IP addresses or technical identifiers, authentication logs, administrative actions, and anti-fraud signals, to the extent configured and justified.
- Consent preferences, policy version, and evidence of confirmation.
3. Purposes and categories of legal bases
The final purpose-and-legal-basis matrix and the specific legitimate interests must receive legal approval before production use. Withdrawal of consent does not affect operations based on other valid legal bases.
- Taking requested steps before entering into a contract and providing account, ordering, issuance, recovery, and support services.
- Compliance with applicable legal, tax, accounting, reporting, and authority-cooperation obligations.
- The legitimate interest in protecting the platform, buyers, and organizers, preventing fraud, ensuring security, and establishing, exercising, or defending legal claims, following an appropriate assessment.
- Consent for marketing communications or non-essential technologies where these are used and consent is required.
- Protection of vital interests or performance of a task required by law, only in the applicable exceptional circumstances.
4. Data sources and mandatory nature of data provision
Data is obtained from the individual, from a buyer who designates an attendee, from the organizer, from the PSP, through interaction with the platform, and, where a legal basis exists, from official sources or operational partners.
Data marked as mandatory is required for ordering, ticket delivery, admission verification, invoicing, or responding to a request. Refusal to provide it may prevent provision of the service. Optional data is labeled separately.
5. Categories of recipients and providers
- The identified event organizer, solely for the purposes and data required to deliver the event, provide admission, handle complaints, or meet its obligations.
- The authorized payment service provider and its anti-fraud providers, in accordance with their own notices.
- Hosting, database, storage, authentication, email, support, security, and monitoring providers, within contractual limits and on the basis of the actual configuration.
- Accountants, auditors, lawyers, insurers, and advisers, where access is necessary and protected.
- Authorities, courts, or other persons where disclosure is required or permitted by law.
6. International transfers
Some technical services may involve access or storage outside the European Economic Area. Before they are enabled, their location, the applicable legal mechanism, contractual safeguards, and any necessary supplementary measures are assessed.
Processors used by the platform today: Vercel (application hosting and request handling, Edge in Frankfurt; server functions in the United States (us-east)); Supabase (database, authentication and file storage, European Union (eu-central-1, Frankfurt)); Stripe (card payments and hosted checkout, European Union and United States); Revolut (revolut pay payments, European Economic Area); Resend (transactional email delivery, including tickets, United States); Oblio (invoicing, Romania).
Of these, processing outside the European Economic Area currently takes place with Vercel (application hosting and request handling, Edge in Frankfurt; server functions in the United States (us-east)); Stripe (card payments and hosted checkout, European Union and United States); Resend (transactional email delivery, including tickets, United States). Customer records and files are held inside the European Union. The specific transfer instrument relied on for each provider is [TO BE CONFIRMED WITH COUNSEL].
7. Retention criteria
A single period does not apply to all data. Periods are set through a matrix that takes account of order performance, ticket validity, accounting and tax obligations, PSP and chargeback time limits, limitation periods, the defense of legal claims, security, and the storage limitation principle.
Once the applicable criterion expires, data is erased, anonymized, or retained only where a legal hold or justified obligation applies. The exact periods by category are [TO BE COMPLETED AND APPROVED].
8. Security and incidents
No measure eliminates risk completely. Individuals are asked not to publish QR codes, authentication links, or sensitive documents and to report suspicious activity promptly.
- Role-based access and the principle of least privilege for staff and partners.
- Secure authentication, protection of secrets, and logging of sensitive actions.
- Payment hosted or tokenized by the PSP and avoidance of full card-data storage.
- Backups, continuity, tested restoration, and component updates.
- An incident procedure covering assessment, containment, evidence preservation, and notification within applicable time limits.
9. Data subject rights
Rights may be exercised through the procedure published at /gdpr. A request may require proportionate identity verification, and some data may be retained where a legal obligation or applicable legitimate reason exists.
- Information and access to processed data.
- Rectification of inaccurate data and completion of incomplete data.
- Erasure or restriction, subject to the conditions of law.
- Objection to processing based on legitimate interests and objection at any time to direct marketing.
- Data portability where the applicable conditions are met.
- Withdrawal of consent without affecting prior processing.
- Lodging a complaint with the Romanian National Supervisory Authority for Personal Data Processing.
10. Marketing, cookies, and minors
- Platform marketing and organizer marketing use distinct options that are not selected by default and can be withdrawn easily.
- Messages concerning a ticket, payment, venue, admission, cancellation, or security are operational communications, not newsletters.
- Non-essential analytics, advertising, or tracking technologies are enabled only after the choice mechanism required by law has been used.
- For events intended for minors, data minimization, age-appropriate information, and avoidance of inappropriate marketing apply.
11. Automated decisions, updates, and contact
The platform takes no solely automated decision producing legal or similarly significant effects about a buyer. A card payment can be declined by the payment provider's own anti-fraud controls; that logic belongs to the provider and its notice explains how a decline is contested. Rate limits protect forms and sign-in against abuse and do not assess a person. Organizer risk levels exist for partner accounts and are set by a member of staff, not by a rule.
Operational management channel: management@euphorictickets.ro. The controller is ART STUDIOS MANAGEMENT S.R.L., registered in Romania; data protection requests are handled through the same email channel. No data protection officer has been appointed. Material changes to the policy will receive a new version and reference date.

