Data Processing Agreement
Last updated: 8 July 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between TICKTS LTD (Company No. 17029682), registered at 124-128 City Road, London, EC1V 2NX (“Tickts”, “Processor”) and the event organiser using the Tickts platform (“Organiser”, “Controller”). It governs the processing of personal data that Tickts carries out on the Organiser’s behalf and applies where the UK GDPR and the Data Protection Act 2018 apply. It is incorporated into the Organiser Terms; by using Tickts to sell tickets, the Organiser agrees to this DPA.
1. Roles of the parties
In respect of personal data relating to the Organiser’s attendees and customers (the “Attendee Data”), the Organiser is the controller and Tickts is the processor. Tickts processes Attendee Data only to provide the ticketing service to the Organiser. (Separately, Tickts acts as an independent controller for the limited purposes set out in our Privacy Policy, such as platform security, fraud prevention and meeting its own legal obligations; that processing is not governed by this DPA.)
2. Subject-matter and duration
The subject-matter of the processing is the provision of the Tickts ticketing platform. Processing continues for as long as the Organiser uses Tickts and for any retention period required to fulfil orders, support attendees and meet legal obligations, after which it is deleted or returned as set out in clause 9.
3. Nature and purpose of processing
Tickts processes Attendee Data to: create and fulfil ticket orders; issue, deliver, transfer, resell and scan tickets; process payments and refunds via our payment provider; send transactional communications (order confirmations, reminders, event updates); provide the Organiser with sales, attendance and reporting tools; and provide customer and dispute support. Tickts does not use Attendee Data for its own marketing.
4. Types of personal data and categories of data subjects
- Data subjects: the Organiser’s ticket buyers and attendees, and any guests named on an order.
- Personal data: name, email address, phone number (where provided), billing details, order and ticket history, attendance/scan records, marketing-consent status, and any information the buyer provides in answer to the Organiser’s checkout questions or accessibility requirements.
- Gift Aid declaration data: where the Organiser is a charity verified on the Platform and a donor chooses to Gift Aid a donation, donor name, home address, postcode, and the donor’s declaration that they are a UK taxpayer. Tickts processes this data on the charity Organiser’s behalf as controller, so the charity can claim Gift Aid from HMRC.
- Tickts does not require special-category data. The Organiser must not configure checkout questions that collect special-category data without its own lawful basis and appropriate safeguards.
5. The Organiser’s instructions
Tickts processes Attendee Data only on the Organiser’s documented instructions, including as set out in this DPA and the Organiser Terms, unless required to do otherwise by law (in which case Tickts will inform the Organiser, unless legally prohibited). The Organiser confirms it has a lawful basis to collect the Attendee Data and to have Tickts process it, and is responsible for the lawfulness of its own instructions and any marketing it sends to its attendees.
6. Confidentiality
Tickts ensures that persons authorised to process Attendee Data are bound by appropriate obligations of confidentiality and access it only on a need-to-know basis.
7. Security measures
Taking account of the state of the art and the risks involved, Tickts implements appropriate technical and organisational measures under Article 32 UK GDPR, including: encryption of data in transit (TLS); hashing of passwords; restricted, role-based access controls; redaction of sensitive fields in activity logs; segregation of card data to our PCI-compliant payment provider (Tickts does not store full card numbers); audit logging of privileged actions; regular patching; and monitored, backed-up hosting.
8. Sub-processors
The Organiser grants general authorisation for Tickts to engage sub-processors to deliver the service. Tickts imposes data-protection terms on each sub-processor no less protective than this DPA and remains liable for their performance. Our current key sub-processors are:
- Stripe , payment processing and payouts.
- Brevo (Sendinblue) , transactional and notification email.
- Cloudways / DigitalOcean , application hosting and database (UK/EU region).
- Cloudflare , CDN, DNS and security.
- Anthropic , AI writing assistance, only where the Organiser chooses to use the AI tools in the dashboard. Anthropic processes the event details and draft text the Organiser submits; it is not sent attendee records, and submitted content is not used to train Anthropic’s models.
Where the Organiser connects its own third-party integration to the Platform (for example the Organiser’s own Mailchimp account, Google Analytics property, or Meta Pixel), Tickts transmits Attendee Data to that service on the Organiser’s documented instruction. The Organiser, not Tickts, is responsible for its own processor relationship with that service.
We will give the Organiser advance notice of any intended addition or replacement of a sub-processor, giving the Organiser the opportunity to object on reasonable data-protection grounds.
9. Return and deletion of data
On termination of the Organiser’s use of Tickts, and at the Organiser’s choice, Tickts will delete or return the Attendee Data and delete existing copies, unless retention is required by law. Gift Aid declaration records may be retained to meet the charity Organiser’s HMRC record-keeping obligations. The Organiser can export its order and attendee data from the dashboard at any time.
10. Data-subject rights and assistance
Tickts provides tools that help the Organiser respond to data-subject requests (access, rectification, erasure, restriction, portability and objection) and, taking into account the nature of the processing, provides reasonable assistance with such requests and with data-protection impact assessments and prior consultations under Articles 32-36 UK GDPR. Tickts will promptly forward to the Organiser any request it receives that relates to the Organiser’s Attendee Data.
11. Personal-data breaches
Tickts will notify the Organiser without undue delay after becoming aware of a personal-data breach affecting the Attendee Data, with the information the Organiser reasonably needs to meet its own breach-notification obligations to the ICO and affected individuals.
12. International transfers
Attendee Data is processed within the UK/EU where practicable. Where a sub-processor processes data outside the UK, Tickts ensures an appropriate transfer mechanism is in place (such as the UK International Data Transfer Agreement / Addendum, or reliance on UK adequacy regulations).
13. Audits
Tickts makes available to the Organiser the information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and allows for and contributes to audits, including inspections, conducted by the Organiser or an auditor it mandates, subject to reasonable notice, confidentiality and frequency.
14. General
This DPA is governed by the laws of England and Wales. In the event of a conflict between this DPA and the Organiser Terms on the subject of data protection, this DPA prevails. Capitalised data-protection terms have the meaning given in the UK GDPR.
TICKTS LTD, registered in England and Wales (Company No. 17029682), 124-128 City Road, London, EC1V 2NX. ICO registration ZC108275. Questions: [email protected].