Privacy Policy
DRAFT — to be reviewed by a Spanish lawyer. Drafted for compliance with the GDPR (EU 2016/679) and the Spanish LOPDGDD (LO 3/2018). Last updated: 10 June 2026.
1. Data controller
- Controller:Francesco Mazza (autónomo), trading as “Dusk Events”
- NIE: [____________]
- Address: [____________], Segovia, Spain
- Privacy contact: [privacy@____________]
A Data Protection Officer (DPO) has not been appointed, as it is not required at the current scale and nature of processing (no large-scale special-category data or systematic monitoring). This will be reassessed as activities expand.
2. What we collect and why
| Data | Purpose | Legal basis (GDPR art. 6) |
|---|---|---|
| Name, email, phone (optional) | Ticket purchase, delivery of QR tickets, entry management | 6(1)(b) — performance of a contract |
| Payment data (handled by Stripe; card details never touch our servers) | Payment processing, anti-fraud, chargeback defence | 6(1)(b) contract; 6(1)(f) legitimate interest (fraud prevention) |
| Order and ticket records (incl. QR token, check-in time) | Admission control, accounting and tax obligations | 6(1)(b) contract; 6(1)(c) legal obligation (tax) |
| Support communications | Customer service | 6(1)(b) — contract |
| Marketing email to existing customers | Occasional news about similar Dusk Events nights, sent to ticket buyers unless they object | 6(1)(f) — legitimate interest in direct marketing to existing customers (GDPR Recital 47), under the LSSI art. 21.2 “similar products or services” exception. You can object at purchase (tick-box), via the unsubscribe link included in every email, or by writing to [privacy@____________] — free of charge, effective immediately (GDPR art. 21(2)–(3)) |
| Analytics cookies (only if you accept them) | Usage statistics | 6(1)(a) — consent; see Cookie Policy |
3. Recipients / processors
We use the following service providers as processors under art. 28 GDPR data processing agreements: Stripe (payments), Vercel (hosting), Supabase (database), Resend (transactional email), Airtable (CRM) and Sentry (error monitoring). We do not sell personal data.
4. International transfers
Where providers process data in the United States, we rely on (i) their certification under the EU-U.S. Data Privacy Framework where applicable, or otherwise (ii) the 2021 EU Standard Contractual Clauses together with transfer impact assessments and supplementary measures where needed.
5. Retention
- Ticketing and transaction data: up to 6 years (tax/accounting obligations, Código de Comercio art. 30).
- Support emails: 24 months.
- Marketing consents: until you withdraw.
- Technical logs: up to 12 months unless needed for a security investigation.
6. Your rights
You may exercise your rights of access, rectification, erasure, restriction, portability and objection — and withdraw consent at any time — by emailing [privacy@____________] with proof of identity. We respond within one month. You can also lodge a complaint with the Spanish supervisory authority, the AEPD (www.aepd.es).
7. Security
We apply encryption in transit and at rest, access controls and least privilege, signed session tokens, rate limiting, and an incident response process aligned with GDPR arts. 33–34 (breach notification within 72 hours where required).
8. Minors
Our events and website are intended exclusively for persons aged 18 or over. We do not knowingly process data of minors; tickets held by under-18s will be cancelled and entry refused.