Legal
Data Processing Agreement
This Data Processing Agreement (DPA) applies to organizers. It sets out how RaveTickets processes ticket-buyer personal data on your behalf, and forms part of the Terms of Service.
1. Roles
For ticket-buyer personal data, the organizer is the controller and RaveDragons V.O.F., operating RaveTickets, is the processor. We process this data only to provide the service and only on your documented instructions, which include your use of the platform and the Terms of Service.
2. Scope and duration
- Subject matter and purpose: selling and delivering tickets, personalizing passes, scanning entry, handling related support and refunds.
- Data subjects: the ticket buyers and attendees of your events.
- Categories of data: name, email address, order and ticket details, per-ticket attendee names where you enable them, door-scan records, and Wallet pass device identifiers. Payment card data is handled directly by Stripe and is not processed by us.
- Duration: for as long as you use the service, and then as set out in section 6.
3. Our obligations as processor
- process the data only on your instructions and for the purposes above;
- keep the data confidential and ensure the people who access it are bound by confidentiality;
- apply appropriate technical and organizational security measures (section 5);
- assist you, taking into account the nature of the processing, in responding to data-subject requests and in meeting your security, breach-notification and impact-assessment duties;
- notify you without undue delay after becoming aware of a personal data breach affecting your data;
- make available the information needed to show compliance and allow and contribute to reasonable audits.
4. Subprocessors
You give general authorization for us to use subprocessors to deliver the service. We impose data-protection obligations on them comparable to those in this DPA. Current subprocessors are:
- Stripe (payments and payout verification)
- Supabase (authentication and database, EU / Ireland)
- Vercel (hosting of the web application and ticket shop, functions in the EU / Ireland)
- A server in Germany (VPS) (door-scan processing, metrics and crash reports)
- An off-site backup storage provider (backups, encrypted before upload)
- Upstash (short-lived abuse protection counters, EU / Ireland)
- Resend and our SMTP email provider (transactional email)
- Mapbox (venue location on tickets)
- Apple Wallet and Google Wallet (pass delivery)
We will give you advance notice of any intended change to this list and an opportunity to object.
5. Security and international transfers
Personal data is stored within the European Economic Area: on Supabase and Upstash in Ireland, on Vercel in Ireland and on a server in Germany. Encrypted backup copies are also stored with an off-site storage provider in a country the European Commission has recognised as providing an adequate level of data protection. We protect it with encryption in transit, access controls and separation of duties, and we keep identity and payment data isolated at Stripe rather than on our own systems. Where a subprocessor processes data outside the EEA, the transfer is covered by appropriate safeguards, in particular the European Commission's Standard Contractual Clauses.
6. Return and deletion
On termination, we delete or return the data at your choice, except where we must keep certain records to meet a legal obligation, such as the 7-year retention of financial and invoice records under Dutch tax law. Copies in our encrypted backups are deleted when those backups expire, at most about 14 months later.
7. Precedence
If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails. Our own processing as a controller is described in the Privacy Policy.
RaveDragons V.O.F. (RaveTickets), Maasdijk 169, 4827 MA Breda, Netherlands. KVK 42007416, BTW NL869257110B01. Contact: info@ravedragons.com.