Webtickets Privacy Policy - Page 2

Sharing of Personal Data:

Webtickets Clients
Webtickets is a ticket marketplace and therefore hosts many independent clients selling ticket on their behalf.

Webtickets shares personal data of customers that purchase tickets hosted by the client on Webtickets. Webtickets shares the relevant customer data that is required for the fulfilment and execution of the ticket obligations. The customer data collected and shared is governed by the relevant regulations and laws in which the client operates.

Sharing of Data is permission based.

Confidential information is not shared unless explicit permission from the customer has been received.

External parties
Webtickets does not share personal data with 3rd unless compelled by the South African Law or court action.

Use of Personal Data

Communication to Customers

Fulfilment of ticket
Webtickets shall only communicate to customers in the fulfilment of their ticket obligation and legal mandate. Should the ticket conditions and obligation change since the customer purchase the ticket, Webtickets will communicate directly with the customer to outline the changes.

The following are examples of ticket condition changing:
1. Cancellation of event, race, or tour.
2. Outstanding information require by Webtickets to fulfil ticket mandate
3. Change in time, date and/or location of event
4. Information relating to refunds

Marketing and related services
Webtickets shall only send marketing communications to customers that have explicitly provided permission for Webtickets to contact them. Moreover, customers can decide any time to change permissions how Webtickets is allowed to communicate to them.

Clients based marketing is also permission based. Clients shall be permitted to send marketing-based communications to customers only after explicit consent.

Use of 3rd Party Service providers
Webtickets does use the services of independent service providers that make use of personal customer data. Webtickets employs the following principles when engaging service providers:

1. Webtickets preforms a due diligence on service provider to understand the risk and data security measure undertaken by the service provider.
2. Webtickets can request service provider to complete a risk assessment and questionnaire to assess security of data and risks
3. The measured understand need to be a higher standard and risks need to be lower than Webtickets for Webtickets to ensure use of service
4. Only bare minimal of data is shared with service provider
5. No confidential or sensitive information is shared without the permission of customer
6. Annual evaluation is performed to assess change in risks. In some cases, a 3rd-party handles the in-store registrations who is acting on our behalf and governed by this Privacy Policy in terms of capturing your personal information.

PCI/DSS Compliance
Webtickets, through their payment service providers subscribes to and is PCI/DSS compliant.

Webtickets use iVeri Payment Technologies which is PCI level 1 certified for the following services.

1. Payment Gateway/Switch
2. POS/Card Present
3. Internet/e-commerce
4. Clearing and Settlement

Webtickets does not store card details, ever.

Click here for page 3