TopEvent

Privacy Policy

Privacy Policy

1. Data Controller
The controller is EKDIS d.o.o., Vevška cesta 52, 1260 Ljubljana-Polje, Slovenia, registration number: 1922769000, VAT ID: SI83862978.
Contact: info@ekdis.si, tel. +386 1 5880 254, website: ekdis.si.

2. Purpose and Legal Basis of Processing
The company processes personal data of visitors and customers for the following purposes:

  • reservation and sale of tickets,
  • execution of payments and issuing of receipts/invoices,
  • event-related communication, changes, and customer support,
  • accounting and tax obligations (Accounting Act, Corporate Income Tax Act - ZDDPO-2).
     Legal bases for processing include: contracts, legal obligations, consent (e.g., newsletter), and legitimate interest (e.g., visit analytics, fraud prevention).

3. Types of Personal Data
The following data may be processed:

  • identification data (name, surname, date of birth, address),
  • contact data (email, phone number),
  • purchase-related data (payment information, order history),
  • technical and usage data (IP address, browser fingerprint data).

4. Data Recipients
Data may be shared with:

  • payment processors (e.g., Stripe, bank),
  • email service providers (e.g., Mailchimp),
  • external IT processors (e.g., hosting providers, etc.).
     All processors operate in compliance with GDPR and have signed data processing agreements.

5. Transfer of Personal Data
Transfers outside the EU are only carried out if appropriate safeguards are in place (e.g., Standard Contractual Clauses). Otherwise, data is processed within the EU.

6. Data Retention Period

  • Purchase and contract data: at least 10 years due to tax requirements.
  • Marketing and analytical data: up to 2 years, unless the user has consented to a longer period.

7. Data Subject Rights
You have the right to:

  • access your data, request correction or deletion (“right to be forgotten”),
  • restrict processing or request data portability,
  • object (opt-out) — especially regarding analytics or direct marketing,
  • withdraw consent at any time (if processing was based on consent),
  • lodge a complaint with the Information Commissioner of the Republic of Slovenia (IP-RS).

8. Security Measures
EKDIS d.o.o. uses technical measures (SSL/TLS encryption, server protection) and organizational measures (internal procedures, restricted access) to protect personal data from unauthorized access, loss, or misuse.

9. Cookies and Tracking Technologies
The website uses cookies for:

  • essential functionality (e.g., shopping cart sessions),
  • analytics (Google Analytics), and, if applicable,
  • personal settings and marketing functions (e.g., personalized advertising).
     Consent is obtained upon first use of the website. Users can manage cookies at any time via their browser settings.

10. Policy Updates
This privacy policy may change occasionally (e.g., due to legislation or service upgrades). Changes are published on the website with the date of the last update. We recommend checking it regularly.
Last updated: 29 July 2025