Data Processing Addendum
How attendee data is handled between an organiser and MyTickets.
For organisers · 2 min read · Version 1.0, effective 29 August 2026
1.Who is what
For attendee data, MyTickets and the organiser are each independent data controllers under the Data Protection Act 2019. We collect it from the buyer, and we pass it to you so you can run your event.
Where we process data on your instructions — sending a message you compose to your own attendees, for instance — we act as your processor for that task.
2.What is covered
Names, phone numbers, email addresses, ticket and admission records of people who hold tickets to your events, and answers to any registration form you set up.
3.What you must do with it
Use it for running your event and for what the buyer agreed to, and nothing else.
Keep it secure, and limit access to the people on your team who need it.
Do not sell it, and do not pass it to a third party except a supplier who needs it to run the event and is bound to the same terms.
Delete it when you no longer have a reason to hold it.
Answer requests from your attendees about their data, and tell us promptly if one concerns something we hold.
4.What we do
Hold the data securely, restrict access to staff who need it, and log what they do.
Use sub-processors — hosting, SMS, email, payments — bound to equivalent obligations.
Tell you without undue delay if a breach affects your attendees, with what you need to meet your own obligations.
5.If something goes wrong on your side
Tell us within 24 hours of becoming aware of a breach affecting attendee data you received from us, so that whichever of us must notify the Office of the Data Protection Commissioner can do so in time.
6.When it ends
When you stop using MyTickets, delete the attendee data you exported, unless the law requires you to keep it. We keep our own copy for the retention periods in the Privacy Policy.