Data protection notice
Privacy Policy
Effective: 21 August 2026
This notice explains how personal data is used when you create an account, select seats, make a booking, contact the Theatre Group or administer the production.
Controller and contact
The data controller is the Hellenic Society of Malta, acting through its Theatre Group. The Society is a Maltese non-profit voluntary organisation, V.O. 1432.
Address: 83 Merchants Street, Valletta VLT 1177, Malta
Privacy contact: +356 9933 7656 · WhatsApp
Data we collect
- Account data: first name, last name, telephone number, email address, account identifier and email-verification status.
- Booking data: performance date, selected seats, quantity, price, booking status, ticket QR identifier, admission timestamp, payment notes and Stripe or other payment references.
- Communications: messages, access requests, cancellation or transfer instructions and support correspondence.
- Technical and security data: necessary session identifiers, sign-in events, IP address, browser/device information and security logs handled by our hosting and authentication providers.
- Administration data: authorised administrator identity and actions taken in the ticket office.
Passwords are processed by our authentication provider. The Theatre Group cannot view your password and does not store it in the ticket database. The website does not collect card or bank-login details.
Why we use data and legal bases
- To create and secure your account, hold seats, manage the booking and provide the event: necessary to take steps at your request and perform the ticket contract.
- To record payment status, prevent fraud and double-booking, secure the service and manage disputes: our legitimate interests in operating a safe and accountable ticket service.
- To keep records or respond to public authorities: compliance with legal obligations.
- To make reasonable accessibility arrangements: at your request and, where relevant, with your explicit consent to process information you choose to provide.
We do not use booking data for unrelated marketing unless you separately opt in.
Who receives data
Access is limited to authorised Theatre Group and Society administrators who need it for the production. We also use service providers acting under their own terms or as processors:
- Supabase for verified email/password authentication and account emails;
- OpenAI Sites and Cloudflare infrastructure for hosting, databases and uploaded files;
- Brevo for transactional booking emails and Proton Mail for the organiser’s booking inbox;
- WhatsApp when you choose to contact the organiser for payment or support;
- Stripe for secure card payments; we send your email, booking reference and amount and receive payment status. Card details are entered directly on Stripe Checkout;
- Revolut when you follow the separate payment link and make payment;
- Google Maps only where the embedded venue map is loaded.
Data may also be disclosed where required by law, a court or a competent authority. We do not sell personal data.
International transfers
Some technology providers may process data outside Malta or the European Economic Area. Where required, the relevant provider must use a lawful transfer mechanism, such as an adequacy decision or approved standard contractual clauses, together with appropriate safeguards. Provider-specific information is available in each provider’s privacy documentation.
How long we keep data
- Account details are retained while the account is active and deleted or anonymised after a valid deletion request, unless needed for an unresolved booking or legal obligation.
- Booking and payment-status records are normally retained for up to five years after the performance to manage accounts, disputes and organisational records, or longer only where applicable law requires it.
- Temporary seat holds expire automatically after the checkout period.
- Security logs and session cookies are kept only for the period reasonably needed for security and authentication.
- Support correspondence is retained only while the matter is active and for a reasonable follow-up period.
Cookies and local storage
We use strictly necessary cookies to keep signed-in accounts and the admin area secure. Temporary browser storage may remember a checkout hold while you verify or sign in. These technologies are necessary for the service and are not used for advertising.
The embedded venue map is supplied by Google and may place or read its own technologies when loaded. No audience analytics or advertising cookies are currently operated by the Theatre Group on this website.
Your rights
Subject to the GDPR and any lawful limitations, you may request access, correction, deletion, restriction, portability or objection to processing. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also ask us to explain a decision or raise a concern.
Contact us by phone or WhatsApp at +356 9933 7656. We may need to verify your identity. You may complain to Malta’s Information and Data Protection Commissioner at idpc.org.mt, or to the authority where you live or work.
Security, children and changes
We use role-limited administration, verified email, dedicated password authentication, encrypted connections and seat-status controls. No online system is risk-free, so use a unique password and contact us promptly if you suspect misuse.
Customer accounts should be created and managed by an adult. A parent or guardian should manage bookings for children and avoid submitting unnecessary information about a child.
We may update this notice when the service, providers or legal requirements change. The current version and effective date will remain available from every page footer.
← Back to show