1. GDPR roles
E-TICKETS SALE AND MANAGEMENT LTD, a company registered in England and Wales, company number 16523217 acts as a data controller when it collects and determines the purposes and means of processing data related to requests, client files, KYC checks and service delivery.
In some cases our partners — lawyers, accountants, registrars, banks, payment institutions or KYC providers — may act as independent data controllers according to their legal role.
2. Categories of personal data
- Identification data: names, date of birth, citizenship, identity document.
- Contact data: email, phone, address, country.
- Corporate data: company role, beneficial owner, director, shareholder, representative.
- Financial and KYC data: source of funds, origin of funds, business activity.
- Technical data: IP address, logs, cookies, device and browser.
- Documents and communication: files, forms, emails and request notes.
3. Purposes of processing
We process personal data to receive and assess requests, perform KYC/AML checks, prepare documents, coordinate company formation, communicate with partners, support clients, handle accounting, protect legal interests, ensure security and prevent abuse.
4. Legal bases
Contract and pre-contract steps
To process requests, offers, correspondence and service delivery.
Legal obligations
For accounting, identification, AML/KYC, regulatory and tax-related requirements.
Legitimate interest
For security, fraud prevention, evidence of performance and dispute protection.
Consent
Where required for specific communication, voluntary information or additional actions.
5. KYC, AML and sensitive documents
We may request passport, ID card, proof of address, ownership documents, source of funds, activity description, contracts, invoices, bank references or other documents required for risk assessment.
Refusal to provide documents may result in refusal of service.
6. Data recipients
Data may be provided to local agents, registrars, legal and accounting partners, address providers, banks, payment institutions, KYC providers, couriers, hosting/IT providers and public authorities where necessary.
7. International transfers
Data may be processed in different countries depending on the jurisdiction selected by the client. Where applicable, we use reasonable contractual, organisational and technical measures to protect the data.
8. Retention periods
Retention depends on the type of data, service, legal obligations and risk. Requests, correspondence, contract data, invoices and KYC documents may be retained as necessary for accounting, AML/KYC, legal defence and evidence of performance.
9. Data subject rights
- Right of access.
- Right to rectification.
- Right to erasure where there is no lawful basis for retention.
- Right to restriction of processing.
- Right to object to processing based on legitimate interests.
- Right to portability where applicable.
- Right to complain to a competent supervisory authority.
GDPR requests can be sent to [email protected].
10. Limits to rights
Some requests may be refused or limited where processing is necessary for AML/KYC, accounting obligations, fraud prevention, regulatory checks, legal claims or protection of third-party rights.