Legal
Privacy Policy
How EazyPazz handles your personal data.
Effective from 5 August 2026
Version: 2026-08-05
1. Data Controller
The data controller for personal data processed on the EazyPazz platform is Ignace Mella, enterprise number 1003.713.438, with registered office in Belgium. For all questions regarding this privacy policy or the processing of your personal data, please contact [email protected].
2. Data We Collect
We collect the following personal data:
• Identification data: name, email address, phone number (optional)
• Account data: business name, enterprise number, VAT number, address, role
• Payment data: these are not stored by us — Stripe and Mollie process all financial data in compliance with PCI-DSS
• Event data: event name, venue, date, ticket types, prices
• Visitor data: name, email, phone (if provided by the organizer), QR codes, check-in data
• Cashless data: wristband number, balance, transaction history
• Technical data: IP address, browser type, device type, cookies
• Communication data: support tickets, email correspondence
3. Purpose of Processing
We process your personal data for the following purposes:
• Providing and managing the EazyPazz platform
• Processing ticket orders and payments
• Sending order confirmations and event reminders
• Offering scan and check-in functionality
• Offering the cashless payment system
• Communicating about your account, events and orders
• Improving our platform and services
• Complying with legal obligations
• Preventing fraud and abuse
4. Legal Basis
We process personal data based on:
• Performance of a contract: to deliver our services (ticket sales, scanning, cashless)
• Legal obligation: VAT declaration, invoicing, anti-money laundering legislation
• Legitimate interest: platform security, fraud prevention, platform improvement
• Consent: where we explicitly ask for it in advance
5. Retention Periods
We do not keep personal data longer than necessary for the purposes for which it was collected:
• Account data: deleted as soon as you delete your account
• Order and ticket data for paid orders: 7 years (Belgian accounting law)
• Personal data on orders that were never paid: 30 days
• IP address on an order: 90 days
• Scan history per ticket: 2 years
• Email log: 1 year
• Cashless: the wristband holder’s name and e-mail are erased 1 year after the event ends; wristband number, balance and transactions stay as an accounting record
• Cashless refund details (IBAN, account holder): 90 days after payout
• Payment data: kept by Stripe/Mollie under their own statutory periods
• Cookies: see our cookie policy below
• Anonymous aggregate data: indefinite
6. Data Subject Rights
Under the GDPR, you have the following rights:
• Right of access: you can request which personal data we process about you
• Right to rectification: you can have incorrect data corrected
• Right to erasure: you can request deletion of your data (within legal frameworks)
• Right to restriction: you can restrict the processing of your data
• Right to data portability: you can receive your data in a structured format
• Right to object: you can object to processing based on legitimate interest
Access and portability are self-service: download all your data from Account → Settings. Restriction and objection are activated there too, with immediate effect. For the other rights contact [email protected]; we respond within 30 days and log every request with a response deadline.
A restriction deletes nothing. Data we are legally required to keep — paid orders, 7 years of bookkeeping — stays, but is then used only for that legal purpose: no reminders, no waitlist notices, no analytics.
7. Recipients of Your Data
Your personal data may be shared with:
• Stripe, Inc. (US) — payment processing via Stripe Connect
• Mollie B.V. (Netherlands) — payment processing via Mollie Connect
• Resend, Inc. (US) — transactional emails
• Google Ireland Limited — website statistics via Google Analytics 4 and Google Tag Manager, on our public website only and only after your consent
• Infrastructure providers — hosting and storage
• Public authorities — when legally required
Organizers receive limited visitor data (name, email, ticket information) to manage their events.
8. International Transfers
Some processors are located outside the EEA:
• Stripe, Inc. processes payment data in the US under Standard Contractual Clauses (SCCs)
• Resend, Inc. processes email data in the US under Standard Contractual Clauses
• Google Ireland Limited processes statistics data within the EU, with possible onward transfer to Google LLC in the US under the EU-US Data Privacy Framework and Standard Contractual Clauses — only if you accepted statistics
For all transfers outside the EEA, we ensure appropriate safeguards in accordance with Chapter V of the GDPR.
9. Security Measures
We take appropriate technical and organizational measures to protect your personal data:
• Encryption of data in transit (TLS 1.3) and at rest (AES-256)
• Access control and authentication (two-factor authentication, session management)
• Regular security audits and penetration tests
• Separation of production and test environments
• Logging and monitoring of unauthorized access
• Incident response procedure
10. Cookies
By default, EazyPazz only places cookies that are necessary for the operation of the platform:
• Essential cookies: session management, authentication, language preference, security
• Functional cookies: remembering settings and preferences
On our public website (eazypazz.com) we additionally ask for consent for two categories: statistics via Google Analytics 4, and marketing via Google Ads. Those cookies are only placed after you accept the category concerned in the cookie banner; if you accept nothing, no request is sent to Google at all. The organizer dashboard, the scanner app and organizers' ticket shops carry no analytics or advertising technology, and therefore no banner.
Without consent for marketing, the advertising signals of Google Consent Mode stay denied and advertising identifiers are redacted. You can change your choice per category at any time via 'Cookie preferences' at the bottom of every page, and you can always delete or block cookies via your browser settings. The full per-cookie overview is in our cookie policy at eazypazz.com/cookies.
11. Changes to This Policy
We may change this privacy policy from time to time. The most recent version is always available at eazypazz.com/privacy. We will notify you by email of material changes. Continued use of the platform after a change constitutes your acceptance.
12. Applicable Law and Supervision
This privacy policy is interpreted in accordance with Belgian law. The Data Protection Authority (DPA) is the supervisory authority. You can always file a complaint with the DPA via gegevensbeschermingsautoriteit.be.
Contact
For all questions about this privacy policy or the processing of your personal data, you can contact: Ignace Mella — enterprise number 1003.713.438 Email: [email protected] Address: available upon request via the above email address