This policy explains what data TiketBurst collects, why, who it is shared with and how to exercise your rights, in accordance with Ivorian Law No. 2013-450 under the supervision of ARTCI.
This English text is an unofficial translation provided for convenience only. The French version is the sole legally binding text; in the event of any discrepancy or dispute as to interpretation, the French version prevails.
The controller of the data collected through TiketBurst is the company operating the platform, whose registered office is located in Côte d'Ivoire.
The processing described below is governed by Ivorian Law No. 2013-450 of 19 June 2013 on the protection of personal data, supervised by the Telecommunications/ICT Regulatory Authority of Côte d'Ivoire (ARTCI), and by ECOWAS Supplementary Act A/SA.1/01/10.
Data protection contact. For any question about your data or the exercise of your rights: privacy@tiketburst.com.
This policy applies to all data processed as part of the Service: the website, the access-control application, electronic communications and the interfaces provided to organizers.
Dual capacity. TiketBurst acts as data controller for ticket sales, account management, payments and fraud prevention. Where an organizer uses attendee data from their own event for their own purposes, they act as a separate controller and answer for their own obligations.
Data you provide to us
Data generated by your use of the Service
Data from third parties: confirmations and statuses sent by payment providers, and the outcome of identity verification sent by our specialist provider.
We do not collect sensitive data within the meaning of the law (political opinions, religious beliefs, health, sexual orientation). You are asked not to publish any such data in free-text fields.
Each processing operation rests on a specific legal basis:
Order-related communications. Confirmation, event reminder, change and cancellation messages form part of the performance of the contract and cannot be switched off for as long as you hold an active ticket.
We do not sell your personal data. It is disclosed only in the following cases:
Organizers. When you buy a ticket, the organizer receives the data needed for access control and for running the event: name, ticket type, scan status and, where you have provided it, your contact details. The organizer may not use that data for other purposes without your consent.
Processors and providers
Each processor acts only on documented instructions from TiketBurst, within the limits of its assignment and under confidentiality and security undertakings.
Authorities. We disclose data where the law requires it: judicial orders, requests from a supervisory authority, and reporting to CENTIF under AML/CFT rules.
Some of our providers process data from servers located outside Côte d'Ivoire, in particular in the European Union and the United States.
Those transfers are governed by contractual undertakings imposing an adequate level of protection and, where Ivorian regulation requires it, are subject to the necessary prior formalities with ARTCI.
You may obtain a copy of the safeguards in place by writing to privacy@tiketburst.com.
We keep data for no longer than is necessary for the purposes pursued:
Once those periods expire, data is irreversibly deleted or anonymised by automated processes.
Under Law No. 2013-450, you have the following rights:
How to exercise them. The rights of access, portability and erasure can be exercised directly from your "Settings" area: you can download an export of your data there and request deletion of your account. A deletion request opens a period during which you may cancel it before it is carried out.
You may also write to us at privacy@tiketburst.com. We reply within the applicable statutory period. Proof of identity may be requested in the event of reasonable doubt.
Complaints. If our response does not satisfy you, you may refer the matter to ARTCI, the personal data protection authority in Côte d'Ivoire.
In order to protect buyers, organizers and the platform, we operate automated fraud-detection checks: analysis of signals relating to the order, the payment method, the device and usage behaviour.
Those checks may lead us to request additional verification, delay a payout or block a transaction.
No decision producing significant effects is taken solely on the basis of automated processing without the possibility of review: you may request human intervention, express your point of view and contest the decision by writing to support@tiketburst.com. A prior appeal process applies before any final measure is taken against an account.
We implement proportionate technical and organisational measures: encryption of communications (TLS), separation of environments, role-based access control, logging of administrator access, expiry and rotation of authentication tokens, cryptographic signing of tickets, and masking of sensitive data in logs.
As no system is infallible, we cannot guarantee absolute security. In the event of a data breach likely to create a risk to your rights, we notify the competent authority and, where the law requires it, the individuals concerned.
You can report a vulnerability to us at security@tiketburst.com.
The Service is not intended for persons under 16. We do not knowingly collect their data.
If you hold parental authority and find that a minor has provided us with data, write to privacy@tiketburst.com and we will delete it.
This policy may change along with the Service and with regulation. Any substantial change is notified to you by appropriate means before it takes effect.
The date of the latest update appears at the top of the page. We encourage you to review it periodically.
For any question about this policy or about exercising your rights:
You also have the right to lodge a complaint with ARTCI.