Privacy Policy
01Privacy First
At Affra, protecting your data is not just a legal obligation — it is a core principle of how we operate.
We believe that the businesses using our platform should own and control their data, not surrender it to the technology that supports them.
Unlike many technology platforms, Affra is designed to provide infrastructure, not ownership. Our role is to securely process information on behalf of our clients while ensuring they retain full control over their data.
02Our Role
For ticketing and event management services provided through our platform, Affra acts as a data processor on behalf of the event organiser, who is the data controller.
This means:
- The event organiser decides what personal data is collected and why it is processed.
- Affra processes that data solely in accordance with the event organiser's instructions.
- We do not use customer data for our own commercial purposes.
For information relating to your Affra account, billing, support requests, and operation of our own website, Affra acts as the data controller and processes that information in accordance with applicable data protection laws.
03Data Ownership
Your data belongs to you.
We do not claim ownership of any customer information, event data, ticketing records, sales information, or business intelligence stored within our platform.
Our clients retain ownership of all data processed through Affra.
04We Never Sell Your Data
Affra will never:
- Sell your personal data.
- Sell your customer lists.
- Sell behavioural or purchasing information.
- License your data to third parties.
- Monetise your information through advertising.
- Build advertising profiles using your customers.
Your information is never treated as a product.
05No Unauthorised Access
We do not access your data unless it is:
- Required to provide technical support you have requested;
- Necessary to maintain or secure the platform;
- Required to comply with a legal obligation; or
- Specifically authorised by you.
Where access is required for support purposes, it is limited to the minimum information necessary to resolve the issue.
06No Unauthorised Sharing
Your information will never be:
- Shared with third parties for marketing purposes;
- Transferred to another organisation for commercial gain;
- Used to compete with your business;
- Accessed by other Affra customers.
Any sharing of information occurs only where necessary to deliver the service, comply with legal obligations, or where you have provided explicit permission.
07Payment Processing
Affra facilitates secure payment processing on behalf of event organisers and venues through trusted, PCI DSS-compliant third-party payment service providers.
Affra does not store full payment card details, including complete card numbers, CVV/CVC security codes, or PINs. All payment information is transmitted securely and processed directly by the appointed payment processor in accordance with industry security standards.
Information associated with a payment transaction, such as transaction identifiers, payment status, payment method, timestamps and order references, may be processed by Affra where necessary to fulfil ticket purchases, issue refunds, provide customer support, prevent fraud, reconcile transactions and maintain accurate financial records.
08Customer Information Collected
The information collected from consumers when purchasing tickets is determined by the event organiser or venue, who acts as the Data Controller.
Affra provides the tools to collect and process this information but does so solely on the instructions of the event organiser.
Depending on the configuration chosen by the event organiser, information collected may include:
- Full name
- Email address
- Telephone number
- Postal address
- Date of birth
- Emergency contact details
- Accessibility or special assistance requirements
- Marketing preferences and communication consent
- Ticket holder details
- Membership or loyalty information
- Vehicle registration details (where required)
- Any additional information specifically requested by the event organiser to facilitate attendance or comply with legal or operational requirements.
The event organiser is responsible for determining what information is collected; whether particular fields are mandatory or optional; the lawful basis for processing that information; and how long the information is retained. Affra does not determine what customer information is collected beyond what is necessary to operate the platform and fulfil the services requested by the event organiser.
09Our Commitment
We collect and process only the information necessary to deliver secure, reliable ticketing services.
We do not use consumer information for advertising, profiling, or commercial resale, and we do not collect additional personal information beyond that required by the event organiser or necessary for the operation, security and integrity of the Affra platform.
10Security
We implement appropriate technical and organisational measures designed to protect your information against:
- Unauthorised access;
- Loss or destruction;
- Alteration;
- Disclosure;
- Misuse.
Security is built into every aspect of the Affra platform and is continually reviewed to meet modern industry standards.
11Transparency
We believe trust is earned through transparency.
If we process your information, we will do so lawfully, fairly, and only for the purposes for which it was collected.
We do not believe in hidden data practices or undisclosed commercial use of customer information.
12Your Rights
Depending on your relationship with Affra and applicable law, you may have rights including:
- Access to your personal information;
- Correction of inaccurate information;
- Deletion of personal information where appropriate;
- Restriction of processing;
- Data portability;
- Objection to certain types of processing.
Where Affra is acting as a data processor, requests relating to personal data should generally be directed to the relevant event organiser, who is responsible for determining how your data is processed.
13International Transfers
Where personal information is transferred internationally, Affra will ensure appropriate safeguards are in place in accordance with applicable data protection legislation.
14Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legislation, technology, or our services. The latest version will always be published on our website together with its effective date.
15Business Continuity, Sale or Acquisition
Affra has been built on the principle that our clients own their data — not us.
Accordingly, customer data is not considered a commercial asset of Affra and will never be bought, sold, licensed or otherwise traded as part of any business transaction.
Should Affra ever undergo a sale, merger, acquisition, investment, restructuring or change of ownership, our intention is that any transaction will be structured, wherever reasonably practicable, as a business asset purchase relating to our intellectual property, technology, software, brand and operational assets, excluding customer data.
Your customer information, sales records, ticketing data and business intelligence will remain under your control and will continue to be processed only in accordance with your instructions and applicable data protection law.
If any proposed transaction would require a different approach under applicable law, we will:
- Notify affected clients in advance wherever legally permitted;
- Continue to honour our contractual and data protection obligations;
- Never sell or transfer customer data as a commercial asset for financial gain; and
- Ensure any successor is bound by the same privacy, confidentiality and security obligations that apply to Affra.
Our commitment is simple: your data is yours. It is never part of the value of our business, and it will never be treated as a product that can be sold to another organisation.