The purpose of this Privacy Notice is to describe the data processing activities carried out by OneTicket Kft., the rules governing the handling of personal data, and the rights afforded to data subjects under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and applicable Hungarian law.
Data Controller
- Company name
- OneTicket Kft.
- Registered seat
- 1143 Budapest, Francia út 41., Hungary
- Company registration no.
- 01-09-209443
- Tax number
- 25340585-2-42
- [email protected]
- Website
- https://www.oneticket.hu
- Postal address
- 1143 Budapest, Francia út 41., Hungary
OneTicket Kft. provides online ticketing and related services, and operates the IT systems necessary to run these services. Personal data is processed exclusively for specified, lawful purposes, in accordance with applicable data protection law.
The controller uses contracted data processors for certain processing operations. The processors engaged, the services they provide, and the details of the processing are described in the later chapters of this notice.
Under Article 37 of the GDPR, OneTicket Kft. is not required to appoint a Data Protection Officer (DPO), and therefore does not have a dedicated DPO.
Questions, requests or complaints regarding data processing may be submitted to [email protected] or by post to the address above.
OneTicket Kft. processes personal data in accordance with the principles set out in Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR). In particular, the controller applies the following principles.
- Lawfulness, fairness and transparency
- Personal data is processed only on a lawful basis, fairly, and in a manner that is transparent to data subjects.
- Purpose limitation
- Personal data is collected only for specified, explicit and legitimate purposes, and is not processed in a manner incompatible with those purposes.
- Data minimization
- We process only personal data that is necessary for, and proportionate to, the purpose of the given processing activity.
- Accuracy
- We take every reasonable step to ensure that the personal data we hold is accurate and, where necessary, kept up to date. Inaccurate data is corrected or erased without undue delay.
- Storage limitation
- Personal data is kept only for as long as necessary for the purpose of the processing, or as required by applicable law.
- Integrity and confidentiality
- We use appropriate technical and organizational measures to ensure the security of personal data and to prevent unauthorized access, alteration, disclosure, loss or destruction.
- Accountability
- The controller is responsible for, and must be able to demonstrate, compliance with the lawful processing of personal data at all times.
OneTicket Kft. carries out each processing operation on the basis of an appropriate legal basis set out in Article 6 of the GDPR. Depending on the nature of the processing, the legal basis may in particular be:
- the data subject's freely given consent
- performance of a contract, or steps taken prior to entering into a contract, at the request of the data subject
- compliance with a legal obligation
- protection of the vital interests of the data subject or another natural person
- performance of a task carried out in the public interest, or in the exercise of official authority
- the legitimate interests of the controller or a third party, provided these do not override the fundamental rights and freedoms of the data subject
OneTicket Kft. applies the principles of data protection by design and by default when developing and operating its IT systems, and strives to ensure that only the personal data necessary for each specific processing activity is processed.
OneTicket Kft. carries out the following data processing activities in the course of providing its services. The table below provides an overview of each processing activity, its legal basis, and its retention period.
- Registration and account management
- Performance of a contract — For the lifetime of the user account
- Sign-in with a Google account
- Performance of a contract — For the lifetime of the user account
- Ticket purchases and orders
- Performance of a contract — Until the end of the applicable accounting/tax retention period
- Customer support
- Performance of a contract or legitimate interest — Up to 5 years
- Newsletter and marketing
- Consent — Until consent is withdrawn
- Event-related notifications
- Performance of a contract — For as long as necessary / as required by law
- IT security and logging
- Legitimate interest — Up to 12 months
3.1 User registration and account management
Creating the user account, identifying the user, providing the services, and managing the user account.
- name
- email address
- encrypted password
- date of registration
- user ID
- technical data related to account usage
GDPR Art. 6(1)(b) — performance of the contract with the user, or steps taken prior to entering into the contract.
For the lifetime of the user account. After the account is deleted, data is retained only for the period required by law.
3.2 Signing in with a Google account
Secure authentication of the user and enabling fast sign-in (Google Sign-In).
- name
- email address
- unique Google account identifier
- profile picture, if shared by the user
GDPR Art. 6(1)(b). OneTicket Kft. does not process, access, or store the user's Google account password.
For the lifetime of the user account, or until it is deleted.
3.3 Ticket purchases and order management
Processing orders, issuing tickets, fulfilling purchases, and handling purchase-related administration.
- name
- email address
- phone number (if provided)
- order ID
- details of tickets purchased
- payment transaction data
GDPR Art. 6(1)(b).
For as long as necessary to perform the contract, and until the end of the retention period required by accounting and tax law.
3.4 Contact requests and customer support
Handling customer support inquiries, answering user questions, investigating error reports, and ensuring case handling.
- name
- email address
- phone number (if provided)
- content of the message
- technical data related to case handling
GDPR Art. 6(1)(b) or (f), depending on the nature of the case.
Up to five years after the case is closed, or as required by law.
3.5 Newsletters and marketing communications
Sending newsletters, promotions, offers and other marketing communications.
- name
- email address
Freely given consent under GDPR Art. 6(1)(a).
Until consent is withdrawn. Consent may be withdrawn at any time, without justification; this does not affect the lawfulness of processing carried out before withdrawal.
3.6 Event-related notifications
Sending important information related to purchased tickets: order confirmation, delivery of the electronic ticket, changes to date or venue, cancellations, and entry-related information.
- name
- email address
- order ID
- details of tickets purchased
GDPR Art. 6(1)(b). These are transactional messages and do not constitute marketing communications.
For as long as necessary to perform the contract, and until the end of the retention period required by law.
3.7 Electronic tickets and entry authorization
Issuing electronic tickets, verifying their authenticity, and preventing unauthorized use.
- ticket ID
- QR code or other unique identifier
- order ID
- date/time of entry, if recorded by the event
GDPR Art. 6(1)(b).
For the period required by applicable law after the event concludes, or, in the event of a legal dispute, until it is resolved.
3.8 IT security and logging
Ensuring the secure operation of the service, preventing unauthorized access, detecting abuse, and investigating system errors.
- IP address
- login events
- technical data about the browser and device
- system logs
- error logs
Legitimate interest under GDPR Art. 6(1)(f).
Up to twelve months, depending on the type of log, or until the resolution of a security incident or legal dispute.
3.9 Establishment, exercise or defense of legal claims
Bringing, exercising or defending legal claims, and cooperating in administrative or judicial proceedings.
Personal data necessary to resolve the given case.
Legitimate interest under GDPR Art. 6(1)(f), or, where applicable, compliance with a legal obligation.
Until the final resolution of the legal dispute or administrative proceeding, or until the end of the applicable limitation period.
OneTicket Kft. uses cookies and other similar technologies to ensure the proper functioning of the website and its online services.
A cookie is a small data file stored by the user's browser on their device. Cookies help ensure the website functions correctly, improve the user experience, and in some cases allow the collection of statistical or security-related information.
Cookies are not, by themselves, capable of directly identifying the user, but in certain cases they may be linked to personal data.
4.1 Strictly necessary cookies
These cookies are essential for the website to function and for core services to be provided. They help ensure, for example:
- management of the user's session
- secure sign-in
- management of user permissions
- proper functioning of the system
- prevention of fraud and unauthorized access
Under applicable law, no separate consent is required for the use of these cookies.
4.2 Functional cookies
Functional cookies are used to remember the settings chosen by the user, and to make the service more convenient to use.
Where the use of such cookies requires consent, they are applied only with the user's prior consent.
4.3 Statistical and marketing cookies
If OneTicket Kft. uses statistical, analytical, or marketing cookies, they are activated only after the user's prior consent.
Consent can be modified or withdrawn at any time using the cookie settings available on the website.
4.4 Cookies placed by third parties
OneTicket Kft. also uses the technologies of contracted partners to provide certain services.
Cloudflare
Website operational security, protection against denial-of-service attacks, and faster content delivery.
Technical cookies used by Cloudflare serve the secure operation of the website and are not used for marketing purposes.
OneTicket Kft. supports sign-in with a Google account (Google Sign-In).
The technical cookies required for authentication serve secure identification and do not contain the user's Google password.
Intercom
Providing online customer support.
May use technical cookies to operate chat, maintain conversation continuity, and manage customer support communication.
4.5 Managing cookie settings
The user has the right to modify or withdraw, at any time, their consent to the use of non-essential cookies.
Most web browsers allow you to manage, delete, or block cookies. However, blocking all cookies may affect the proper functioning of certain website features.
OneTicket Kft. strives to use only the cookies necessary for the operation of the service, or those authorized by the user.
To ensure the secure and high-quality operation of its services, OneTicket Kft. uses contracted data processors for certain processing operations.
Processors act solely on the instructions of OneTicket Kft., in accordance with applicable data protection law, and may not use the personal data provided to them for their own purposes.
Archi-Host Kft.
Hosting and server operation.
- operating OneTicket's IT infrastructure
- server operation
- ensuring data security
- creating backups
Personal data stored on the server, necessary for the operation of the IT system.
Cloudflare, Inc.
Content delivery network (CDN), web application firewall (WAF), DDoS protection, and performance optimization.
- increasing website security
- filtering malicious traffic
- protection against denial-of-service attacks
- faster content delivery
- IP address
- technical connection data
- information about the browser and device
- security log data
Google LLC
Google Sign-In authentication.
Enables users to securely sign in to OneTicket using their Google account.
- name
- email address
- unique Google account identifier
- profile picture, if shared by the user
Mailgun Technologies, Inc.
Transactional email service.
- order confirmations
- delivery of electronic tickets
- password-reset emails
- system notifications
- delivery of other emails necessary to perform the service
- name
- email address
- technical data about the emails sent
- delivery logs
Intercom R&D Unlimited Company
Online customer support system.
- online chat
- customer support communication
- ticket management
- management of customer interaction history
- name
- email address
- IP address
- device and browser data
- content of chat conversations
- information provided during customer support communication
International data transfers
Certain service providers used by OneTicket Kft. may process or transfer personal data outside the European Economic Area.
Such a transfer only takes place if it complies with the requirements set out in Chapter V of the GDPR, and is carried out with appropriate safeguards. A transfer is considered lawful if the data is transferred to a country covered by an adequacy decision of the European Commission, or if the transfer takes place on the basis of Standard Contractual Clauses (SCC) adopted by the European Commission, or other appropriate safeguards recognized by the GDPR.
OneTicket Kft. only works with providers that ensure the protection of personal data through appropriate technical and organizational measures.
To protect personal data, OneTicket Kft. applies appropriate technical and organizational measures to ensure that the confidentiality, integrity, availability and resilience of the data it processes is guaranteed in a manner proportionate to the risks involved.
To this end, OneTicket Kft. applies, among others, the following measures:
- access to personal data is subject to a permissions system
- administrative interfaces are accessible only after appropriate authentication
- data transfer takes place over an encrypted communication channel (HTTPS/TLS)
- servers and IT infrastructure are continuously monitored and protected
- regular backups are made to ensure business continuity
- security events necessary for the operation of the system are logged
- we take steps to prevent unauthorized access, loss, destruction, alteration, or disclosure of data
- our staff only have access to personal data to the extent necessary to perform their duties, and are subject to a duty of confidentiality
OneTicket Kft. selects its processors so that they provide appropriate data security guarantees and process personal data in accordance with applicable law.
Given the nature of transmission over the internet, complete security cannot be guaranteed; nevertheless, OneTicket Kft. takes every reasonable technical and organizational measure to ensure the highest possible level of protection for personal data.
If OneTicket Kft. becomes aware of a personal data breach that triggers a notification or reporting obligation under the GDPR, it will handle the breach in accordance with applicable law, and, where necessary, will notify the competent supervisory authority and the affected data subjects.
OneTicket Kft. ensures that data subjects can exercise, at any time, the rights afforded to them under the GDPR in connection with the processing of their personal data. Data subjects have the following rights.
7.1 Right to information and access
The data subject has the right to request information on whether OneTicket Kft. processes their personal data, and, if so, is entitled to obtain, in particular:
- the categories of personal data processed
- the purpose of the processing
- the legal basis for the processing
- the retention period for the personal data, or the criteria used to determine it
- the recipients of the personal data, including processors and any transfers
- the rights afforded to the data subject
- relevant information regarding any automated decision-making or profiling, where applicable
The data subject is also entitled to request a copy of the personal data provided by them, or otherwise processed about them.
7.2 Right to rectification
The data subject has the right to request the correction of inaccurate personal data, and the completion of incomplete personal data.
7.3 Right to erasure ("right to be forgotten")
The data subject has the right to request the erasure of their personal data where the conditions set out in the GDPR are met. The right to erasure does not apply, in particular, where the processing is:
- necessary for compliance with a legal obligation
- necessary for the establishment, exercise or defense of legal claims
- otherwise cannot be erased for a reason specified by law
7.4 Right to restriction of processing
The data subject may request the restriction of the processing of their personal data in the cases set out in Article 18 of the GDPR.
During the period of restriction, personal data — other than storage — may only be processed with the data subject's consent, or in cases specified by law.
7.5 Right to data portability
The data subject has the right to receive the personal data they have provided in a structured, commonly used, machine-readable format, and, where the legal conditions are met, to request that this data be transmitted to another controller.
7.6 Right to object
Where the legal basis for processing is the legitimate interest of OneTicket Kft. or a third party, the data subject may object at any time, on grounds relating to their particular situation, to the processing of their personal data.
In this case, OneTicket Kft. will examine the objection, and, unless compelling legitimate grounds can be demonstrated that override the interests, rights and freedoms of the data subject, will discontinue the processing.
7.7 Right to withdraw consent
Where processing is based on the data subject's consent, that consent may be withdrawn at any time, without justification.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
7.8 Submitting requests
The data subject may exercise the rights described in this chapter using the following contact details:
- [email protected]
- Postal address
- 1143 Budapest, Francia út 41., Hungary
OneTicket Kft. will examine and respond to requests without undue delay, but no later than one month from receipt.
Where justified by the complexity of the request or the number of requests being processed, the response period may be extended by a further two months. OneTicket Kft. will inform the data subject of any such extension within the initial one-month period.
Exercising these rights is free of charge. OneTicket Kft. may only charge a reasonable fee, or refuse to act on a request, in the cases set out in Article 12 of the GDPR.
OneTicket Kft. strives to resolve all questions and concerns regarding the processing of personal data directly, quickly and effectively. If a data subject believes that their rights have been violated in connection with the processing of their personal data, they are entitled to lodge a complaint with the supervisory authority, or to initiate judicial proceedings.
8.1 Lodging a complaint with the supervisory authority
The data subject may lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH).
- Registered seat
- 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- Phone
- +36 (1) 391-1400
- [email protected]
- Website
- https://www.naih.hu
8.2 Judicial remedy
The data subject has the right to go to court if they believe that OneTicket Kft. has infringed the GDPR, or other applicable data protection law, in the course of processing their personal data.
The case will be heard by the court with jurisdiction and competence. At the data subject's choice, proceedings may also be brought before the regional court (törvényszék) competent for their place of residence or habitual stay.
8.3 Compensation and damages
If a data subject suffers material or non-material damage as a result of unlawful processing of their personal data, they are entitled to claim compensation or damages under the conditions set out in applicable law.
In processing personal data, OneTicket Kft. always strives to resolve any disputes primarily through amicable, cooperative means.
OneTicket Kft. processes personal data in accordance with, among others, the following legislation:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.).
- Act CVIII of 2001 on Certain Aspects of Electronic Commerce Services and Information Society Services (Eker. tv.).
- Act C of 2003 on Electronic Communications (Eht.).
- Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activity (Grtv.).
- Act V of 2013 on the Civil Code (Ptk.).
- Act C of 2000 on Accounting.
- Act CXXVII of 2007 on Value Added Tax.
- Act CL of 2017 on the Rules of Taxation.
The applicable EU and Hungarian legislation on the processing of personal data, in force from time to time, as well as the guidelines and recommendations of the National Authority for Data Protection and Freedom of Information (NAIH).
For matters not covered by this Privacy Notice, the applicable legislation in force at any given time shall govern.