Legal · For organisers · Last updated 19 July 2026
Data Processing Addendum
When you sell tickets on 263tickets, you are the controller of the attendee personal data you receive and 263tickets is your processor. This addendum sets out how we process that data on your behalf. It forms part of our terms of service and applies to every organiser.
The addendum
These terms bind both of us under GDPR, POPIA, and Zimbabwe's Cyber and Data Protection Act.
Roles & scope
You are the data controller, and 263tickets is your processor, for the attendee personal data you receive through the platform — names, contact details, and order and ticket data. For our own purposes — running the marketplace, preventing fraud, and meeting legal obligations — we act as an independent controller, governed by our privacy policy.
Processing on your instructions
We process attendee personal data only on your documented instructions and only to provide the service, except where the law requires otherwise — in which case we tell you, unless the law forbids it. Using the platform as intended is your instruction to process.
Security & confidentiality
We apply appropriate technical and organisational measures — encryption in transit and at the column level for sensitive fields, restricted and audited access, and secure hosting. Everyone who processes the data is bound by confidentiality.
Subprocessors
You authorise us to engage the subprocessors we publish. We impose data-protection obligations equivalent to these on each, remain responsible for their performance, and give you notice before adding or replacing one so you can object. The current list is on our subprocessors page.
Assisting you
We help you meet your own obligations: responding to data-subject requests, notifying you without undue delay of any personal-data breach affecting attendee data, and supporting your impact assessments and regulator consultations.
International transfers
Where attendee data is transferred outside its country of origin, we do so under safeguards appropriate to the markets involved, consistent with GDPR, POPIA, and Zimbabwe's Cyber and Data Protection Act.
Return & deletion
On termination, or at your request, we return or delete the attendee data we hold for you, save what we must retain by law. Financial and transaction records are kept where record-keeping law requires.
Records & audits
We make available the information reasonably needed to demonstrate compliance with this addendum, and allow for audits on reasonable notice — subject to confidentiality and to protecting the security of the platform and other organisers' data.
How this applies
This is the standard addendum incorporated into our terms of service for every organiser. Where we enter a separately signed Data Processing Addendum, that signed agreement carries the full commercial terms and controls if it conflicts with this page. Questions? Email privacy@263tickets.com.