PRIVACY POLICY

Version 1.0.0 · effective Sat 1 Aug

Adopted on / Last updated on: 1 June 2026]

This Privacy Policy (Policy) provides information on how Partymaker Group a. s. collects, processes, protects and stores your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and related legislation. It applies to all users of www.partymaker.eu (Website) and the Partymaker mobile app (App) who use our services to search for, book and purchase tickets.

Contents: 1. Information about the data controller · 2. What personal data we process · 3. Purposes of processing and legal bases · 4. Retention period · 5. To whom we disclose data · 6. Rights of data subjects · 7. Transfers to third countries · 8. How to contact us

1. INFORMATION ABOUT THE CONTROLLER

The controller is the company: Partymaker Group a. s., with its registered office at Rajská 10A, 811 08 Bratislava – Staré Mesto district, Company Registration Number: 47 870 125, registered in the Commercial Register of the Municipal Court Bratislava III, Section Sa, File No. 7958/B (the Company).

2. WHAT PERSONAL DATA DO WE PROCESS

The Company operates online platforms – the Website and the App – through which it facilitates the sale of tickets and provides related services to visitors and event organisers. We process the following categories:

2.1. User account registration and management

Required information when creating an account:

  • email address
  • password (stored exclusively in encrypted form)
  • confirmation of age (that you are at least 16 years old), or consent from a legal guardian if this condition is not met

The platform is intended for people aged 16 or over. If you are under 16, you may only use the platform with the consent of a legal guardian, which must be provided at the time of registration.

Optional profile details: username, telephone number, date of birth, photograph, preferences (city, language, favourite types of events, genres, etc.).

In connection with the use of your account, we also record:

  • order history and status
  • technical and operational data – date and time of registration, login and logout information
  • payment method details and partial details of the stored payment card (e.g. the last four digits and expiry date); we never store full payment card details

2.2. Purchasing tickets

For every purchase:

  • email address – mandatory information to which we send the e-ticket and documentation
  • first name, surname and account/payment card number – provided by the bank solely as payment confirmation, to identify the transaction and for any refunds; we do not store full payment details
  • for certain events where required by law, for security reasons or by the organiser, additional identification details may be required (first name and surname, contact details, age)

2.3. Browsing the website and app

We automatically collect technical and operational data:

  • IP address, browser and operating system type, time and duration of visit, location data, mobile device information, the page from which you accessed the site

We also use cookies for these purposes — see the separate Cookie Policy.

2.4. Customer support and complaints

When you contact us (in writing, by email, by telephone or via online chat), we will retain the content of the communication and your contact details. We may also contact you to send satisfaction surveys.

2.5. Marketing communications

Upon registration or where you have given your consent, we may process your contact details (email, telephone) to send you marketing communications, including newsletters, text messages and display adverts. See Section 3 for the terms and conditions and how to unsubscribe.

3. PURPOSES OF PROCESSING AND LEGAL BASES

  • 3.1. Performance of a contract (Article 6(1)(b) of the GDPR): creating and managing an account; processing orders, payments and ticket delivery; customer support and complaints.
  • 3.2. Legal obligation (Article 6(1)(c)): retention of accounting and tax documents; compliance with the requirements of public authorities.
  • 3.3. Legitimate interests (Article 6(1)(f)): technical operation, platform security and fraud prevention; analytics and service improvement; satisfaction surveys; direct marketing (for customers). Right to object (Section 6).
  • 3.4. Consent (Article 6(1)(a)): marketing communications (email, SMS, display advertising); analytical cookies; advertising and marketing cookies. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing prior to withdrawal.

4. RETENTION PERIOD

We retain data only for as long as is necessary, or for the period required by law; after that, it is deleted or anonymised.

  • 4.1. Account and profile: for the entire duration of the account’s existence. If you have not logged in for more than 5 years, your account is considered inactive and will be deactivated. After the account is closed, we retain the necessary identification data for a further 3 years (legal claims, Article 6(1)(f)).
  • 4.2. Orders, payments, tax documents: 10 years from the transaction (tax and accounting regulations).
  • 4.3. Customer support: 3 years from the resolution of the request.
  • 4.4. Marketing: 5 years from consent or the last purchase, or until consent is withdrawn or an objection is upheld – whichever occurs first.
  • 4.5. Technical and security logs: (IP addresses, access times, logins/logouts, security logs) for a period of 24 hours.
  • 4.6. Cookies: a specific list and exact timeframes are set out in the Cookie Policy.

5. TO WHOM WE PROVIDE PERSONAL DATA

We only share data with partner organisations that guarantee an adequate level of protection.

  • 5.1. Event organisers – data necessary for admission and to fulfil legal obligations (first name, surname, age verification); the scope depends on the event/organiser.
  • 5.2. Payment service providers – card payments and bank transfers via payment gateways; transactions take place in the secure environment of the bank/gateway.
  • 5.3. IT infrastructure and hosting providers – operation and security of the platform; access only to the extent necessary.
  • 5.4. Communication service providers – transactional emails and SMS messages (confirmations, tickets, event information) and marketing.
  • 5.5. Analytics and marketing tool providers – traffic measurement, behavioural analysis, campaign targeting.
  • 5.6. Fraud and spam protection tools – form protection; technical data (IP address, browser behaviour).
  • 5.7. Customer support tools – external helpdesk / CRM.
  • 5.8. Professional advisers and public authorities – legal/tax/audit advisers; courts, the police, the tax office and other authorities, where required by law.

6. RIGHTS OF DATA SUBJECTS

Procedure and contact details in Section 8:

  • 6.1. Right of access – confirmation of processing + a copy of the data and information (purposes, categories, recipients, retention periods, rights). Most of this information is available directly in your account.
  • 6.2. Right to rectification – correction of incorrect/incomplete data; basic details are available directly in the account settings.
  • 6.3. Right to erasure (right to be forgotten) – e.g. if the data is no longer necessary, following withdrawal of consent without another legal basis, or following a successful objection. Closing an account does not necessarily mean that all data will be erased (statutory retention periods apply).
  • 6.4. Right to restriction of processing – e.g. where the accuracy of the data is disputed, in cases of unlawful processing where erasure is not an option, or where you require the data for legal claims.
  • 6.5. Right to data portability – data provided on the basis of a contract or consent, processed by automated means, in a structured, machine-readable format; also transfer to another controller, where technically feasible.
  • 6.6. Right to object – to processing based on legitimate interests (Article 6(1)(f)). In the case of direct marketing, the right to object at any time and without giving a reason → immediate cessation of processing for these purposes.
  • 6.7. Right to withdraw consent – at any time; without affecting the lawfulness of processing prior to withdrawal. Marketing: unsubscribing / account settings; cookies: cookie settings on the website/in the app.

7. TRANSFER TO THIRD COUNTRIES

We process data primarily within the EU/EEA; we do not actively transfer it to third countries. However, some partners may process data on servers in the USA:

  • Google LLC (Google Ireland Limited, Dublin 4 / parent company Google LLC, USA) – GA4, Google Ads, GTM. Transfer covered by the EU–US DPF, approved by the EC decision of 10 July 2023.
  • Meta Platforms Ireland Limited (Dublin 2 / parent company Meta Platforms Inc., USA) – Meta Pixel. The transfer is covered by the EU–US DPF.

The EU–US DPF is a certification framework approved by the European Commission. If the transfer is not covered by the DPF, we will ensure protection through Standard Contractual Clauses (SCCs) in accordance with Article 46(2)(c) of the GDPR.

8. HOW TO CONTACT US AND EXERCISE YOUR RIGHTS

  • by email: support@partymaker.eu
  • in writing: Partymaker Group a. s., Rajská 10A, 811 08 Bratislava – Staré Mesto district

We will process your request without undue delay, within one month at the latest (subject to a possible extension of a further two months). Complaints may be lodged with the Slovak Data Protection Authority, www.dataprotection.gov.sk.