GDPR Compliance Statement
Last Updated: 22 May 2025
This statement describes how Ayatickets handles personal data under the EU General Data Protection Regulation (GDPR) and related data protection principles. It supplements our Privacy Policy and Technical Security & Data Handling Statement.
1. Data Controller
- Company: Aya Tickets Limited
- Platforms: Ayatickets, AyaCart, AyaBookings, Ayalogbook
- Website: https://ayatickets.com
- Data protection contact: support@ayatickets.com
2. Data We Collect and How We Use It
Personal and account data
- Name, email, phone number, and account login credentials
- Payment references processed through third-party gateways
- Billing or booking details where applicable
- Support tickets, emails, and chat logs
Technical and usage data
- IP address, browser, device, and operating system information
- Page visits, interaction logs, and referral source
- Time zone and language settings
Purposes of processing
- Service delivery: ticket sales, orders, bookings, and check-in
- Account administration: login, profile updates, and password resets
- Customer support and service communications
- Marketing, where consent has been given
- Compliance, fraud prevention, and security
3. Legal Bases for Processing
- Contract performance: to provide ticketing, orders, and bookings
- Legitimate interests: security, service improvement, and fraud prevention
- Consent: marketing communications and non-essential analytics or cookies where required
- Legal obligation: where processing is required by applicable law
4. Data Sharing and International Transfers
We may share data with payment processors, organizers, merchants, hosting providers, email and SMS providers, analytics tools, and support services as necessary to operate the platform.
Where personal data is transferred outside the EEA, we apply appropriate safeguards, including contractual protections such as Standard Contractual Clauses where required.
5. Data Security
- HTTPS/TLS encryption in transit
- Encryption and access controls for sensitive data at rest
- Access controls and security monitoring
- Ongoing security monitoring and incident handling procedures
See our Technical Security & Data Handling Statement for further detail.
6. Data Retention
For standard event ticketing and client event records, Ayatickets retains relevant data for twenty-four (24) months after completion of the event or the end of the client engagement, unless a longer period is required by law, regulation, payment investigation, tax or accounting obligations, audit requirements, fraud prevention, dispute resolution, or a specific written agreement with the client.
Other personal data is retained only for as long as necessary to provide services, meet legal obligations, resolve disputes, and enforce agreements, then securely deleted or anonymized where appropriate.
Children’s privacy: our services are not directed at children under 16. Contact us if you believe we have collected a minor’s data.
7. Your GDPR Rights
Where GDPR applies, you may have the right to:
- access your personal data
- rectify inaccurate data
- request erasure in certain circumstances
- restrict processing
- data portability
- object to certain processing
- withdraw consent where processing is based on consent
Deletion requests are handled under our Data Deletion Policy.
8. Cookies and Tracking
We use cookies to remember preferences, analyze usage, and—with consent where required—support marketing activities. You can manage cookies through our Cookie Policy and browser settings.
9. Complaints
If you believe your data protection rights have been infringed, you may contact us first at support@ayatickets.com. You also have the right to lodge a complaint with your local supervisory authority in the EEA or UK where applicable.
10. Contact
Email: support@ayatickets.com
Phone: +233-55-941-6230