Last Updated: October 15, 2025
Important Notice: This Privacy Policy is designed to comply with the Personal Data (Privacy) Ordinance (PDPO) of Hong Kong Special Administrative Region (HKSAR). By using our services, you consent to the collection, use, and disclosure of your personal data as described in this policy.
1. Introduction
This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use our Event Ticket Management System. We are committed to protecting your privacy and ensuring the security of your personal information in accordance with the Personal Data (Privacy) Ordinance (PDPO) of Hong Kong.
2. Data Controller
For the purposes of the PDPO, the data controller of your personal data is:
3. Types of Personal Data We Collect
3.1 Information You Provide Directly
- Account Information: Name, email address, password, role (admin/manager/user)
- Event Information: Event details, venue information, event dates
- Ticket Information: Ticket types, prices, purchase details
- Device Information: Device name, device type, IP address, user agent
- Validation Records: QR code scans, entrance times, validation details
3.2 Information We Collect Automatically
- Usage Data: Login times, session duration, feature usage
- Technical Data: Browser type, operating system, device identifiers
- Location Data: IP-based location information (if applicable)
4. Purposes of Data Collection
We collect and use your personal data for the following purposes:
- Service Provision: To provide event ticket management services
- Authentication: To verify user identity and manage access
- Ticket Validation: To validate tickets and record entrances
- Event Management: To manage events, tickets, and user accounts
- Security: To protect against fraud and unauthorized access
- Communication: To send important notifications and updates
- Analytics: To improve our services and user experience
- Legal Compliance: To comply with applicable laws and regulations
5. Legal Basis for Processing
Under the PDPO, we process your personal data based on the following legal grounds:
- Consent: When you have given clear consent for specific processing activities
- Contract Performance: To perform our contractual obligations to you
- Legitimate Interests: For our legitimate business interests, such as security and service improvement
- Legal Obligation: To comply with legal requirements
6. Data Sharing and Disclosure
6.1 Third-Party Service Providers
We may share your personal data with trusted third-party service providers who assist us in operating our services, including:
- Cloud hosting providers
- Email service providers
- Analytics service providers
- Payment processors (if applicable)
6.2 Legal Requirements
We may disclose your personal data if required by law or in response to valid legal requests from government authorities in Hong Kong.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the new entity, subject to the same privacy protections.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Staff training on data protection
- Incident response procedures
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law. Specifically:
- Account Data: Retained while your account is active and for 2 years after closure
- Event Data: Retained for 7 years for business and legal purposes
- Transaction Records: Retained for 7 years as required by Hong Kong law
- Log Data: Retained for 1 year for security and troubleshooting purposes
9. Your Rights Under PDPO
Under the Personal Data (Privacy) Ordinance, you have the following rights:
- Right of Access: Request access to your personal data we hold
- Right of Correction: Request correction of inaccurate personal data
- Right to Withdraw Consent: Withdraw consent for data processing where applicable
- Right to Object: Object to certain types of data processing
- Right to Erasure: Request deletion of your personal data in certain circumstances
10. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience on our platform. You can control cookie settings through your browser preferences. We use cookies for:
- Authentication and session management
- Remembering your preferences
- Analytics and performance monitoring
- Security purposes
11. International Data Transfers
If we transfer your personal data outside Hong Kong, we will ensure appropriate safeguards are in place to protect your data, including:
- Adequacy decisions by the Privacy Commissioner
- Standard contractual clauses
- Binding corporate rules
- Your explicit consent
12. Children's Privacy
Our services are not directed to children under 13 years of age. We do not knowingly collect personal data from children under 13. If we become aware that we have collected personal data from a child under 13, we will take steps to delete such information.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending email notifications to registered users
- Displaying prominent notices on our platform
14. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: