Skip to main content

KULT / PRIVACY

Privacy Policy

This Policy explains which personal data KULT processes, why it is needed and which rights you have under the GDPR.

Version
2026-10-01
Effective from

1. Data controller

The controller is Sargas group s.r.o., Ružová 92, 040 11 Košice – mestská časť Západ, Slovenská republika, Company ID 53 783 549. For privacy enquiries contact kult@sargasgroup.eu or +421 949 371 199.

2. Data we process

  • For checkout and orders: name, email, phone, locale, order and ticket details, amounts, payment-status identifiers and timestamps; plus UTM parameters and referrer when supplied to the current checkout flow.
  • KULT does not store the full payment-card number. Stripe processes payment details.
  • For the contact form: name, email, optional phone, message, locale and technical submission data.
  • For tickets and check-in: ticket identifiers and credential, status, check-in state and time, and refund, void or transfer state where applicable.
  • For operating and protecting the service: necessary request, error and security logs and, on public production pages, minimal performance data through Vercel Speed Insights.

3. Why we use data

We use data to create reservations and orders, coordinate payment, issue and deliver tickets, provide check-in, handle purchase support and refunds, keep the service secure and reliable, prevent abuse, and meet legal obligations.

4. Legal bases

  • Article 6(1)(b) GDPR — steps before and performance of a contract: reservation, order, payment coordination, ticket issue and delivery, purchase support, check-in and refunds.
  • Article 6(1)(c) GDPR — accounting, tax and other mandatory legal records.
  • Article 6(1)(f) GDPR — legitimate interests in security, fraud prevention, reliability, technical diagnostics, protection of legal claims and minimal performance measurement.
  • For the contact form, Article 6(1)(b) applies to contract-related requests and Article 6(1)(f) to general enquiries and responding to them.

5. Providers and recipients

We use Supabase for database and authentication, Vercel for hosting and application delivery, Stripe for payment checkout, and Resend for transactional email. They receive only data needed for the relevant function and may use their own subprocessors.

Stripe’s role depends on the processing activity: it may act as a processor for some activities and as an independent controller for its own legal obligations in others.

6. International transfers

Some providers or their subprocessors may process data outside the European Economic Area. Where the GDPR requires it, transfers rely on Chapter V mechanisms such as an adequacy decision, Standard Contractual Clauses (SCCs), or other applicable safeguards.

7. Retention

  • Accounting and tax documentation is retained for the applicable statutory period, commonly 10 years.
  • Order and ticket data is retained as needed for the contract, event admission, refunds, disputes and legal claims, plus applicable statutory duties.
  • Contact enquiries are retained for the time needed to respond and for reasonable follow-up communication.
  • Technical logs are retained only as operationally needed and according to relevant provider settings.

8. Your rights

Depending on the circumstances, you may request access, rectification, erasure, restriction, object to processing and receive data portability. Consent can be withdrawn only where processing is actually based on consent. Contact kult@sargasgroup.eu to exercise your rights.

You may also lodge a complaint with Úrad na ochranu osobných údajov Slovenskej republiky, the Slovak supervisory authority.

Úrad na ochranu osobných údajov Slovenskej republiky ↗

9. Security and changes

We use proportionate technical and organisational safeguards and role-based access controls. No internet system can guarantee absolute security. If this Policy changes materially, we will publish a new version and effective date.

TICKETS / EVENTS

Where are we meeting?

Choose an event.

Sales will open after the official announcement.