Skip to content
Passavo
Menu

Privacy statement

This statement explains which personal data is processed through Passavo, what for, on what legal basis and for how long. It is written to be read: wherever we promise something, there is a period or a name next to it.

Version of 24 September 2026

1. Who we are

Passavo is a service of Fades Management EOOD, with its registered office at Legis Center, Blvd. 6-ti Septemvri 152, Office 3-8B, 4000 Plovdiv, Bulgarije. Our communications address is Bansko, Bulgarije.

Company number: 208607050. VAT number: BG208607050.

For anything to do with personal data, write to info@fades.tech. A human answers, not a form.

We have not appointed a data protection officer: for a company of our size and with this kind of processing that is not mandatory (Art. 37 GDPR). The address above is the direct point of contact.

2. Two roles: controller and processor

Under the GDPR we wear two hats at once, and which of the two applies matters to you.

  • We are the CONTROLLER for the data of our own customers: the organisation that takes out a subscription, the people who log in on its behalf, the invoicing, the support traffic and the visits to this website. There we determine the purpose and the means ourselves. For that part, this statement is the whole story.
  • We are the PROCESSOR for the data of visitors and buyers: name, email address, orders, tickets, scans at the door and social tariff pass numbers. That data belongs to the organisation running the event; it decides why the data is collected and how long it stays. We process it solely on its instructions, under the data processing agreement.

In practice: if you buy a ticket, the organiser of that event is your point of contact for access or erasure, not us. If you find us first anyway, we pass your request on to them — we do not leave you wandering.

3. Which data we process

From a customer (the organisation and its staff):

  • name, email address, phone number and the language you work in;
  • the name, address, country and VAT number of the organisation;
  • login details: your password is stored hashed and we cannot read it;
  • billing details and the payment status of your subscription;
  • what you do in the system, in so far as it is logged: sign-ins, changes to prices and tickets, and sales at the till.

From a visitor or buyer (on behalf of the organisation):

  • name and email address, plus whatever the organisation adds to the order form itself;
  • the order: which tickets, which time slot, the amount and the payment status;
  • the ticket itself and the moment it was scanned at the door;
  • the number of a social tariff pass where one is used.

Technical:

  • the IP address and the time of a request, in the server logs;
  • error reports, with the data needed to be able to fix the error.

We do NOT process payment details. Card numbers, account numbers and everything else that belongs to a payment go straight to the payment provider the organisation connected itself. We only see whether a payment succeeded and what amount was involved.

4. What we process it for, and on what basis

Every processing operation has a purpose and a legal basis from Article 6 GDPR. They are set out side by side below.

  • Delivering your subscription, managing your account and answering your questions: necessary for the performance of the contract (Art. 6(1)(b)).
  • Processing orders, tickets and scans for an organisation: necessary for the performance of the contract between that organisation and its visitor; we do that as a processor, on its instructions.
  • Invoicing and keeping our accounts: legal obligation (Art. 6(1)(c)).
  • Keeping the till journal signed for German customers: legal obligation under the German Kassensicherungsverordnung.
  • Securing the platform, stopping abuse and fraud, keeping logs and investigating faults: legitimate interest (Art. 6(1)(f)). Our interest is a system that keeps running and does not get broken into; we weigh that against your privacy by logging no more than is needed and keeping logs briefly.
  • Putting your ticket in Apple Wallet or Google Wallet as a pass: only when you press that button yourself (Art. 6(1)(a), consent).
  • Keeping you informed about changes to the service itself: legitimate interest. We only send commercial email with consent, and every email has an unsubscribe link.

We sell your data to no one, and we do not use it to build profiles or to take automated decisions about you.

5. How long we keep it

A retention period ought to have a reason. There is one next to each of them below.

  • Invoices and accounting records: 10 years. That is the period from the Bulgarian Accountancy Act, which applies to us. For an organisation with accounting obligations in Belgium, 7 years applies to its own records.
  • Orders, tickets and scans of an organisation: for as long as that organisation is a customer, plus the period it states in its own privacy statement. It decides that, not us. If it cancels, the rule below applies.
  • Data of an organisation after the end of the subscription: 30 days to export, after which we delete it. What we are legally required to keep (the invoices) stays until the accounting period runs out.
  • An account that is closed: 30 days, so that a mistake can still be put right.
  • Server logs and error reports: 90 days.
  • Support messages: 2 years, so that we can still look up an old case when the same question comes back.

Afterwards data is deleted or made unrecognisable. Making it unrecognisable means, with us, that what is left — the number of tickets sold per evening, for instance — can no longer be traced back to a person.

6. Who we share data with

We engage suppliers that process data on our instructions. A data processing agreement has been concluded with each of them. This is the complete list:

  • Contabo GmbH (DE) — servers and back-ups, in a data centre in Germany
  • Wattify B.V. (BE) — sending and receiving our email
  • Mollie B.V. (NL) — payments by visitors, straight into the account of the organisation (only where this applies)
  • Stripe Payments Europe Ltd. (IE) — payments by visitors, straight into the account of the organisation (only where this applies)
  • Payconiq International S.A. (LU) — payments by visitors, straight into the account of the organisation (only where this applies)
  • Apple Inc. (US) — the ticket as a pass in Apple Wallet (only where this applies)
  • Google Ireland Ltd. (IE) — the ticket as a pass in Google Wallet (only where this applies)
  • publiq vzw (BE) — the social tariff: checking the pass number and registering the sale (only where this applies)
  • fiskaly GmbH (DE) — the legally required signature under the till journal for German customers (only where this applies)
  • Apple Inc. / Google Ireland Ltd. (US/IE) — distributing and updating the scanning app (only where this applies)

Beyond that we pass on data where the law obliges us to: to a tax authority, a supervisory authority or a court. That does not happen quietly — we tell you, unless we are expressly forbidden to.

Nobody else shares in anything. We do not sell data and we do not pass it on to advertisers or data brokers.

7. Transfers outside the European Economic Area

Our servers are in the European Union, and the data stays there. In three places a transfer outside the EEA can still happen, and each time only when you or the organisation choose it.

  • Put a ticket in Apple Wallet as a pass and that goes through Apple Inc. (United States). Apple is certified under the EU-US Data Privacy Framework, the adequacy decision of the European Commission.
  • Put a ticket in Google Wallet and that runs through Google Ireland Ltd. (Ireland), which relies on the standard contractual clauses of the European Commission for part of its processing.
  • If an organisation uses Stripe as its payment provider, that runs through Stripe Payments Europe Ltd. (Ireland), with transfers to the United States under the EU-US Data Privacy Framework.

We distribute the scanning app through the App Store and Google Play. Whatever those stores keep about a download happens under their own responsibility and not on our instructions.

Would you like to see the standard contractual clauses we concluded with a processor? Write to info@fades.tech.

8. Your rights

The GDPR gives you a set of rights. They all apply, and you do not have to give a reason for using them.

  • ACCESS: find out which data we hold about you, and receive a copy of it.
  • RECTIFICATION: have something corrected that is wrong.
  • ERASURE: have your data deleted, except what we are legally required to keep.
  • RESTRICTION: have the processing put on hold temporarily, for instance while a dispute is running.
  • PORTABILITY: receive your data in a common file format, to use it elsewhere.
  • OBJECTION: object to processing that rests on our legitimate interest.
  • WITHDRAWING CONSENT: where we rely on consent, you may withdraw it at any time. What happened before that remains lawful.

Write to info@fades.tech. We answer within one month; if your request is complicated we may extend that period by two months, and we say so in advance. To avoid handing data to the wrong person, we may ask you to identify yourself — never more than is needed for that.

If it concerns data we keep as a PROCESSOR for an organisation — your ticket, your order, your scan — we forward your request to that organisation, because it is the one that decides. We let you know who.

9. Lodging a complaint

If you are not happy with how we handle your data, tell us first: most things are put right faster than a procedure takes.

You can also lodge a complaint directly with a supervisory authority, and that right stands regardless of what we think of it (Art. 77 GDPR).

  • Our lead supervisory authority, because our main establishment is in Bulgaria: Комисия за защита на личните данни (KZLD) — Commission for Personal Data Protection, https://www.cpdp.bg
  • If you live in Belgium, you can go there too: Gegevensbeschermingsautoriteit (GBA), https://www.gegevensbeschermingsautoriteit.be

If you live in another member state, you may knock on the door of the supervisory authority in your own country.

10. Cookies

We only use functional cookies. There is not a single analytics, advertising or tracking cookie on this site, and we load no third-party scripts that could follow you — even the fonts sit on our own server.

  • A session cookie, so that you stay logged in and your basket does not vanish between two pages.
  • A cookie with a CSRF token, which stops another website from submitting a form in your name.
  • If you stay logged in, there is a separate cookie for that, which disappears when you log out.

We do not keep your language choice in a cookie: it is in the address of the page itself. That way a link is always shareable in the language you copied it in.

Functional cookies need no consent, and that is why there is no cookie banner either. That is not an oversight.

11. Security

What we actually do:

  • all traffic to and from the platform runs over HTTPS;
  • passwords are stored hashed, and sensitive data such as the keys of a payment provider is stored encrypted in the database;
  • who may see what is decided per role, and every query is tied to the organisation you belong to;
  • the till journal is append-only: a booked sale can no longer be changed or removed afterwards, only corrected with a new line;
  • there are daily back-ups, and we test whether they can be restored;
  • we keep up with updates to the system and to the components it runs on.

No system is unbreakable. If something does go wrong with personal data, we inform the organisation concerned within 48 hours of establishing it, and the supervisory authority within the statutory period.

12. Changes to this statement

If the service changes, this text changes with it. The version date at the top tells you which version you are reading.

If the change matters to you — a new processor, a longer retention period, a new purpose — we let the organisations that are customers know by email in advance. Small improvements to the wording we make without announcement.

We keep older versions, so that you can check what it said at the moment you agreed. Request them at info@fades.tech.

Questions about this text? Write to us at info@passavo.eu