Technical Security & Data Handling Statement
Last Updated: 22 May 2025
This statement supplements the Ayatickets Privacy Policy and describes the technical and security controls applied to personal information processed through the Ayatickets event ticketing and attendee management platform. It is published to support institutional, enterprise, and client security and data protection reviews.
1. Hosting Environment
Ayatickets production services are hosted in managed cloud infrastructure with network-level protections and monitored uptime. Operational environments are appropriately segregated. Administrative access to infrastructure is restricted to authorized personnel.
2. Role-Based Access Control
Access to platform data and administrative functions is governed by role-based access control (RBAC) on a least-privilege basis. Permissions are assigned according to job function and account scope, and access is reviewed as part of operational security practices.
3. Data Handling
Personal information is collected and processed only as required to deliver event ticketing, payment processing, attendee management, communications, and related support services. Data is stored using secure application storage with appropriate logging and access controls. Deletion requests are handled in accordance with the Data Deletion Policy.
For standard event ticketing and client event records, Ayatickets retains relevant data for twenty-four (24) months after completion of the event or the end of the client engagement, unless a longer period is required by law, regulation, payment investigation, tax or accounting obligations, audit requirements, fraud prevention, dispute resolution, or a specific written agreement with the client.
4. Data Encryption
- In transit: HTTPS/TLS is enforced for web, API, and dashboard traffic.
- At rest: Sensitive configuration and credentials are protected using encryption. Database and backup storage use provider-level encryption controls.
- Payments: Card and mobile-money processing is handled by certified third-party payment providers; Ayatickets does not store full card PAN data.
5. Data Classification
Data is classified to guide handling and access controls:
- Public: marketing pages, published event information.
- Internal: operational configuration and non-sensitive logs.
- Confidential: attendee personal data, order and ticket records, organizer account data.
- Restricted: security-sensitive credentials, payment references, and security logs.
6. Shared Responsibility
Security is a shared responsibility. Ayatickets secures the platform, infrastructure, and application layer. Clients (including event organizers, institutional customers, and enterprise clients) are responsible for controlling user access within their accounts, safeguarding credentials, and using the service in accordance with applicable policies and contractual terms.
7. Authentication Model
Account access is protected by industry-standard authentication controls, including secure credential handling, session management, and multi-factor authentication where enabled. Administrative and sensitive actions require appropriate authorization. Integration access is protected by authentication and abuse-prevention controls appropriate to its purpose.
8. Security Assurance
Ayatickets maintains ongoing security monitoring and periodic security assessments as part of its operational practices. Additional independent security reviews can be arranged under written agreement where required by a client engagement.
9. AI Functionality
Certain optional support features may use AI-assisted tooling for general customer support on the Ayatickets website. Personal data processed under an agreed client or institutional engagement is not used for unrelated analytics, profiling, resale, AI training, or marketing. Such data is processed solely to deliver the contracted ticketing and attendee management service.
10. Contact
Data Protection & Security Enquiries: legal@ayatickets.com
General Support: support@ayatickets.com