Privacy Policy
Last Updated: June 2025
1. Introduction
DigiTicket Africa ("DigiTicket," "we," "us," or "our") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with South Africa's Protection of Personal Information Act, 2013 (POPIA) and other applicable laws.
By using our website, mobile applications, or services, you consent to the collection and use of your personal information as described in this policy.
2. Information Officer
In compliance with POPIA, we have appointed an Information Officer responsible for data protection matters:
Email: privacy@digiticket.africa
Address: GEN Africa Building, Cnr. Winnie Mandela Drive & 22 Sloane, Bryanston, 2191
For any privacy-related queries or to exercise your rights, please contact our Information Officer.
3. What Personal Information We Collect
We collect personal information that you provide directly to us and information that is automatically collected when you use our services.
3.1 Information You Provide:
- Contact Information: Name, email address, phone number, physical address
- Account Information: Username, password, profile preferences
- Payment Information: Credit/debit card details, billing address, transaction history
- Event Information: Event attendance history, preferences, special requirements
- Communication: Customer service inquiries, feedback, survey responses
- Identity Verification: ID number (when required for age verification or specific events)
3.2 Information Automatically Collected:
- Device Information: IP address, browser type, device model, operating system
- Usage Data: Pages visited, time spent on site, click patterns, search queries
4. How We Use Your Personal Information
We process your personal information for the following purposes:
4.1 Primary Purposes:
- Transaction Processing: Complete ticket purchases and deliver digital tickets
- Account Management: Create and maintain your user account
- Customer Service: Respond to inquiries and provide support
- Event Delivery: Facilitate event access and venue entry
- Legal Compliance: Meet regulatory requirements and legal obligations
4.2 Secondary Purposes (with your consent where required):
- Marketing Communications: Send promotional emails about events and offers
- Personalization: Recommend events based on your preferences and history
- Analytics: Improve our services and website functionality
- Security: Prevent fraud and protect our platform
- Research: Conduct market research and customer satisfaction surveys
5. Legal Basis for Processing
We process your personal information based on the following legal grounds under POPIA:
- Consent: Where you have given explicit consent
- Contract Performance: To fulfill our ticketing services contract with you
- Legitimate Interest: For security, fraud prevention, and service improvement
- Legal Obligation: To comply with applicable laws and regulations
6. Information Sharing and Disclosure
We may share your personal information in the following circumstances:
6.1 Event Partners:
- Event Organizers: Name and contact details for event management purposes
- Venues: Information necessary for event access and security
6.2 Service Providers:
- Payment Processors: Secure payment processing services
- Technology Partners: Website hosting, email services, analytics platforms
- Customer Service: Third-party support platforms
- Marketing Services: Email marketing and advertising platforms (with consent)
6.3 Legal Requirements:
- Law Enforcement: When required by law or court order
- Legal Proceedings: To protect our rights or defend legal claims
- Emergency Situations: To protect safety and prevent harm
6.4 Business Transfers:
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.
7. International Data Transfers
If we transfer your personal information outside South Africa, we will:
- Ensure the recipient country has adequate data protection laws, or
- Implement appropriate safeguards such as standard contractual clauses, or
- Obtain your explicit consent for the transfer
8. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption: Data encryption in transit and at rest
- Access Controls: Limited access on a need-to-know basis
- Regular Audits: Periodic security assessments and updates
- Staff Training: Employee education on data protection practices
- Incident Response: Procedures for handling security breaches
9. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which it was collected.
Specific Retention Periods:
- Account Information: Until account deletion plus 7 years for audit purposes
- Transaction Records: 7 years from transaction date
- Marketing Data: Until you withdraw consent or 3 years from last interaction
- Cookies: As specified in our Cookie Policy
10. Your Rights Under POPIA
You have the following rights regarding your personal information:
10.1 Right to Access:
Request confirmation of what personal information we hold about you and obtain a copy.
10.2 Right to Correction:
Request correction of inaccurate or incomplete personal information.
10.3 Right to Deletion:
Request deletion of your personal information in certain circumstances.
10.4 Right to Object:
Object to processing based on legitimate interest or for direct marketing purposes.
10.5 Right to Restriction:
Request restriction of processing in certain circumstances.
10.6 Right to Data Portability:
Request transfer of your personal information to another service provider.
10.7 Right to Withdraw Consent:
Withdraw previously given consent at any time (this may affect our ability to provide services).
10.8 Right to Complain:
Lodge a complaint with the Information Regulator if you believe your rights have been violated.
11. Cookies and Tracking Technologies
We use cookies and similar technologies to enhance your experience. Our Cookie Policy provides detailed information about:
- Types of cookies we use
- How to manage cookie preferences
- Third-party cookies and analytics
- Your choices regarding cookies
12. Children's Privacy
Our services are not directed to children under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information.
For events that may be attended by minors, we require parental consent and may collect limited information necessary for safety and security purposes.
13. Marketing Communications
We may send you marketing communications about events, offers, and services. You can:
- Opt-out: Unsubscribe from marketing emails at any time
- Manage Preferences: Update your communication preferences in your account
- Contact Us: Email privacy@digiticket.africa to manage your preferences
We will not share your information with third parties for their marketing purposes without your explicit consent.
14. Data Breach Notification
In the event of a data breach that poses a risk to your privacy, we will:
- Notify the Information Regulator within 72 hours where required
- Inform affected individuals without undue delay when there is a high risk
- Provide clear information about the breach and steps being taken
15. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws. We will:
- Post the updated policy on our website
- Notify you of material changes via email or website notice
- Obtain your consent for significant changes where required by law
16. Contact Information
For any questions about this Privacy Policy or our data practices:
DigiTicket Africa
Email: privacy@digiticket.africa
Phone: +27 10 213 0327
Address: GEN Africa Building, Cnr. Winnie Mandela Drive & 22 Sloane, Bryanston, 2191
South African Information Regulator:
Website: www.justice.gov.za/inforeg
Email: inforeg@justice.gov.za
Phone: +27 12 406 4818
This Privacy Policy is governed by South African law and complies with the Protection of Personal Information Act, 2013.
