Skip to content

Ticket sales privacy policy

PRIVACY POLICY OF THE MUSIC CAFÉ AND BOOKSTORE OF PWM EDITION ONLINE TICKET SALES AND RESERVATION SYSTEM

1. General Information

This Privacy Policy sets out the principles governing the processing of personal data and provides the information required under Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation – GDPR) for users of the online ticket sales and reservation system (the "Ticketing System") operating via the bilety.una-krakow.pl subdomain and dedicated ticket purchase widgets embedded within the UNA website.

The Ticketing System is used to manage ticket reservations, ticket sales, and payment transactions for cultural events organised by the UNA Music Café and Bookstore of PWM Edition.

The controller of the personal data processed in connection with ticket sales and transaction processing within the Ticketing System is Punkt Wydawania Muzyki sp. z o.o., with its registered office at ul. Pawia 34/47, 31-154 Kraków, Poland (the "Controller"), Tax Identification Number (NIP): 5732856051, National Court Register (KRS): 0000572965, Statistical Business Number (REGON): 362328993

The Controller may be contacted by:

  • post: ul. Pawia 34/47, 31-154 Kraków, Poland,
  • e-mail: martyna.bartelak@punktwydawaniamuzyki.pl

The Controller has not appointed a Data Protection Officer.

The Controller is responsible for ensuring that the processing of personal data complies with applicable legal requirements, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

2. Technical Architecture and the Role of the Software Provider

Ticket sales and reservations are carried out using an external ticketing platform integrated with the UNA website via an API interface and an iframe-based ticket purchase widget. Data transmission and exchange within the ticketing subdomain are carried out through secure network connections.

The provider responsible for the operation and maintenance of the Ticketing System infrastructure is not an independent controller of purchasers' personal data. It processes personal data solely on the documented instructions of, and on behalf of, the Controller, acting as a data processor pursuant to a data processing agreement concluded in accordance with Article 28 of the GDPR.

Purchasing tickets does not require users to create or register an account. Tickets may be purchased using the guest checkout option.

The Controller applies the principle of data minimisation. Accordingly, only the personal data necessary for the conclusion and performance of the ticket purchase agreement are collected.

The Controller supervises the processor's compliance with applicable data protection requirements and periodically reviews the security measures implemented by the processor.

3. Scope, Purposes and Legal Bases for Processing Personal Data

The personal data of users of the Ticketing System are processed for the following purposes and on the following legal bases:

  • Performance of the ticket purchase agreement and provision of access to the event – the following data provided in the order form are processed: first name, last name, e-mail address, postal code, city, and, optionally, telephone number, as well as order details such as the event selected, seat numbers, event date and transaction value. Legal basis: Article 6(1)(b) GDPR (processing necessary for the performance of a contract or for taking steps at the request of the data subject prior to entering into a contract),
  • Compliance with accounting and tax obligations – personal and transaction data are processed for the purposes of issuing invoices, maintaining accounting records and fulfilling statutory tax reporting obligations. Legal basis: Article 6(1)(c) GDPR (processing necessary for compliance with a legal obligation imposed on the Controller under applicable accounting and tax legislation),
  • Handling transactional communications and complaints – the User's e-mail address and, where provided, telephone number are used to deliver electronic tickets (PDF format), payment status notifications, and information concerning changes affecting an event (such as cancellation or rescheduling). Legal basis: Article 6(1)(b) and Article 6(1)(f) GDPR (performance of a contract and the Controller's legitimate interest in efficiently managing customer relations and event logistics),
  • Establishment, exercise or defence of legal claims – system logs, order history and transaction data may be processed for evidential purposes. Legal basis: Article 6(1)(f) GDPR (the Controller's legitimate interest in protecting its legal and financial interests),
  • Marketing and promotional activities – where the User has given separate consent, the Controller may send newsletters and information concerning future events organised by the UNA Music Café and Bookstore of PWM Edition. Legal basis: Article 6(1)(a) GDPR (the User's freely given consent, which is independent of the ticket purchase process and may be withdrawn at any time).

4. Recipients of Personal Data

Personal data collected through the Ticketing System may be disclosed only to the following categories of recipients:

  • the provider operating and hosting the Ticketing System, acting as a data processor on behalf of the Controller,
  • the electronic payment service provider, PayPro S.A. (Przelewy24), for the purpose of processing and authorising payment transactions,
  • providers of IT support, equipment maintenance, legal and accounting services engaged by the Controller,
  • competent public authorities and courts, where disclosure is required under applicable law,
  • banks involved in processing financial transactions, as well as entities providing IT security and system audit services, where applicable.

5. Processing of Third-Party Data (Gift / Group Tickets)

Where the user purchases tickets on behalf of or for the benefit of third parties (e.g. tickets purchased for friends, gift tickets), the personal data of such persons (if provided, for example by specifying the name of the event participant) are processed on the basis of Article 6(1)(f) of the GDPR (legitimate interest consisting in enabling the performance of the agreement for the benefit of a third party). The purchaser is obliged to inform such persons about the transfer of their data to the Controller and about the content of this Privacy Policy.

6. Data Recipients and Transfers to Third Countries

Personal data are disclosed only to trusted partners supporting the ticketing process:

  • the entity maintaining the Ticketing System under a data processing agreement (processor),
  • the domestic operator of cashless payment services: PayPro S.A. (Przelewy24 service), for the purpose of authorising and securely processing financial transactions,
  • accounting offices and entities providing legal and IT support to the Controller.

Data processed within the Ticketing System are not transferred outside the European Union or the European Economic Area (EEA).

7. Data Retention Period

Personal data are stored only for periods strictly justified by business purposes and legal requirements:

  • data processed for the purpose of performing the ticket sales agreement – for the period necessary to conduct and settle the relevant cultural event,
  • data required for tax and accounting purposes – for a period of 5 years, calculated from the end of the calendar year in which the tax payment deadline related to the transaction expired,
  • data processed on the basis of consent (marketing purposes) – until the user formally withdraws such consent,
  • data processed for the purpose of defending against claims – until the expiry of statutory limitation periods for such claims,
  • after the expiry of the indicated periods, data are deleted unless further processing is required by applicable law.

8. Rights of Data Subjects

Every customer whose data are processed within the Ticketing System has the right to:

  • access their personal data, rectify them, and request their deletion ("right to be forgotten"),
  • restrict processing and transfer their data,
  • object to processing based on legitimate interest,
  • object to direct marketing.

The user also has the right to lodge a complaint with the supervisory authority – the President of the Personal Data Protection Office.

9. Session Cookies and Shopping Cart Security

The Ticketing System uses cookies and session identifiers (including a session identifier used by an application based on the Symfony framework), which are classified as strictly necessary cookies. These files are required for the technical maintenance of the shopping cart contents, reservation of selected seats during the completion of the purchase form, and ensuring the security of the payment transaction itself. They do not require the user's consent.

Session expiry period: for security reasons and in order to release unpaid seats for other customers, the contents of the shopping cart are automatically reset, and the related session data are deleted after 20 minutes of complete inactivity on the part of the user. Completely disabling cookies in the browser settings will prevent the purchase process from being completed and the electronic ticket from being generated.

10. Personal Data Security Measures

In order to prevent the loss of confidentiality, integrity or availability of transactional data, the Controller has implemented advanced technical safeguards:

  • all data transmission between the user's device, the Ticketing System and the payment operator is encrypted using the TLS 1.3 (or TLS 1.2) protocol,
  • access to the order database is granted exclusively to employees holding individual authorisations to process personal data,
  • the system does not record or store payment card numbers or customers' online banking credentials in its databases – this process takes place directly on the secured platform of the Przelewy24 operator.

11. Automated Decision-Making

Personal data are not used for making decisions that produce legal effects or similarly significantly affect the user in a solely automated manner, nor are they used for profiling within the meaning of Article 22 of the GDPR, except for standard statistical analysis and ensuring system security.

12. Final Provisions

This Privacy Policy enters into force on the date of its publication. The Controller periodically reviews its content and updates it in the event of changes in legal regulations, the operation of the Ticketing System, or the technologies used for processing personal data.

Version 2.0

Kraków, August 18, 2026