Personal data
In force as of 09/09/2026.
This is a courtesy translation; the French version prevails.
This privacy policy describes how Association E-Cosplay collects, uses, retains and protects the personal data of users of the ticketing platform https://ticket.e-cosplay.fr (hereinafter "the Platform"), in accordance with Regulation (EU) 2016/679 of 27 April 2016 ("GDPR") and Act no. 78-17 of 6 January 1978 as amended (the "French Data Protection Act").
1. Data controller
The controller of personal data is:
Association E-Cosplay
- Non-profit association governed by the French Act of 1901
- RNA: W022006988 — SIREN: 943 121 517
- Registered office: address provided upon written request to legal@e-cosplay.fr
- Email: contact@e-cosplay.fr
2. Data Protection Officer (DPO)
In accordance with Article 37 of the GDPR, a Data Protection Officer has been appointed and notified to the CNIL (the French data protection authority):
- CNIL identifier of the DPO: DPO-167945
- Contact: rgpd@e-cosplay.fr
The DPO is your primary point of contact for any question relating to your personal data and to the exercise of your rights.
3. Definitions
- Personal data: any information relating to an identified or identifiable natural person (name, email, IP address, etc.).
- Processing: any operation performed on personal data (collection, recording, storage, consultation, disclosure, erasure, etc.).
- Data subject: the natural person whose data is processed (you).
- Processor: the service provider that processes data on behalf of the controller.
- Organiser: the association or entity that publishes an event on the Platform and holds that event.
4. Role of the Platform and role of the organiser
E-Ticket is a technical intermediation service: Association E-Cosplay provides the ticketing tool, the organiser organises the event.
- The association is the controller for the operation of the Platform: accounts, orders, tickets, payments, emails, security.
- The organiser receives the order data for its own event (surname, first name, email of the purchaser, tickets purchased, payment status) in order to hold its event, to control admissions and to respond to complaints. For these purposes and for any communication it may send you, the organiser acts as a separate controller: its own notices and its own policy apply.
- The association discloses to the organiser only the data necessary for its event, and never data relating to other organisers' orders.
5. Data collected
The Platform collects only the data strictly necessary for its purposes (data minimisation principle, Article 5 of the GDPR).
When creating an account
- Surname and first name
- Email address
- Password (stored exclusively in hashed form — bcrypt algorithm; never in plain text)
When purchasing tickets or booking a stand
- Surname and first name of the purchaser
- Email address (sending of tickets, confirmations and information relating to the event)
- Order details: event, prices, quantities, amounts, any promotional code, order number
- Tickets issued: ticket reference, security key, date and time of the first admission check
- Payment method used, card brand and last four digits only, transmitted by the payment provider
- Bank card data (card number, security code) is collected and processed exclusively by Stripe, a PCI-DSS certified provider: it never passes through the association's servers and is never stored there
When creating an organiser account
- Company name, SIREN or SIRET number, address, telephone, website and social media
- Surname, first name and email address of the representative and of the sub-accounts created by the organiser
- Stripe payment account identifier, verification status, amounts collected, refunded and transferred. The organiser's bank details are held by Stripe, not by the association
- Content provided for its events (texts, visuals, prices)
When checking admissions
- Reference of the ticket scanned, date and time of the scan, result of the check, account that carried out the scan
When making a contact or support request
- Surname, first name, email address and content of the message
Transactional emails
- Recipient's address, template sent, technical message identifier, delivery status transmitted by the sending service (delivered, deferred, rejected, complaint), in order to ensure that tickets are properly received and to cease all sending to an invalid address
Optional drafting assistant (organisers)
- Only the event content submitted by the organiser (brief, title, description, prices, venue, dates) and the public name of its entity. Email addresses, telephone numbers and identification numbers are filtered out before transmission. No purchaser content is sent
Technical data
- IP address (anonymised in access logs)
- Connection and security logs
- Strictly necessary cookies and, with your consent, anonymised audience measurement and technical error monitoring — see the cookie policy
The Platform collects no sensitive data within the meaning of Article 9 of the GDPR (origin, opinions, health, etc.). Where an organiser offers a reduced price subject to supporting evidence, that evidence is presented at the entrance to its event and is not collected by the Platform.
6. Purposes and legal bases
Each processing operation relies on a legal basis provided for in Article 6 of the GDPR:
| Purpose | Legal basis |
|---|---|
| Management of user and organiser accounts | Performance of the contract |
| Processing of orders, issuance and sending of tickets | Performance of the contract |
| Checking of tickets at the entrance to an event | Performance of the contract |
| Communication relating to the event purchased (change, postponement, cancellation) | Performance of the contract |
| Refunds and handling of complaints | Performance of the contract |
| Monitoring of email delivery and management of invalid addresses | Performance of the contract |
| Payout of funds and financial monitoring of organisers | Performance of the contract |
| Retention of accounting records and invoices | Legal obligation (French Commercial Code, art. L.123-22) |
| Security of the Platform, fraud prevention, logs, rate limiting | Legitimate interest |
| Assistance with drafting event listings by artificial intelligence | Performance of the organiser contract, at the organiser's request |
Live chat support (chat.e-cosplay.fr) |
Legitimate interest: answering support requests |
| Anonymised audience measurement (Zen) | Consent |
| Technical error monitoring (E-Monitor) | Consent |
| Response to contact requests | Pre-contractual measures / legitimate interest |
No commercial marketing is carried out on the basis of ticket purchase data.
7. Mandatory nature of the collection
The data marked as mandatory in the forms is necessary for the provision of the service (account creation, ticket purchase, event creation). Failing this, the request cannot be processed. All other data is optional.
8. Recipients of the data and processors
Your personal data is accessible only by:
- Association E-Cosplay: administration of the Platform, restricted access based on the principle of least privilege, sensitive actions logged
- The organiser of the event concerned, for the orders relating to its event only (see point 4)
Processors (Article 28 of the GDPR):
| Provider | Role | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting of the Platform, storage of files and backups | eu-west-3 (Paris, France) |
| Amazon Web Services EMEA SARL (Amazon SES and SNS) | Sending of transactional emails and notification of delivery failures | eu-west-3 (Paris, France) |
| Cloudflare, Inc. | Security, protection against denial of service, content delivery | United States, points of presence worldwide |
| Stripe Payments Europe, Ltd. | Secure processing of payments and transfers to organisers — PCI-DSS certified | Ireland |
| Anthropic | Assistance with drafting event listings, activated at the organiser's request | United States |
E-Monitor (monitoring.e-cosplay.fr) |
Measurement of technical errors, only after consent on the visitor's side; instance self-hosted by the association | European Union |
No data is sold, rented or transferred to third parties for commercial or advertising purposes. No solely automated decision producing legal effects (Article 22 of the GDPR) is taken on the basis of your data; the drafting assistant's suggestions relate only to event content and are validated by a human.
9. Transfers outside the European Union
The data is hosted in France, in the eu-west-3 region of Amazon Web Services. Certain processors (Cloudflare, Anthropic, and depending on the instance selected the error monitoring service) may nevertheless process data outside the European Union. These transfers are governed by the appropriate safeguards provided for in Chapter V of the GDPR:
- the European Commission's Standard Contractual Clauses (decision 2021/914);
- the EU–US Data Privacy Framework for certified companies.
10. Retention periods
| Data | Period |
|---|---|
| User account | For the lifetime of the account, then 3 years after the last activity |
| Orders, tickets and accounting records | 10 years (statutory accounting obligation) |
| Tickets in PDF format stored on the Platform | 12 months after the date of the event, then deletion; the ticket reference remains retained with the order |
| History of admission checks | 12 months after the date of the event |
| Connection and security logs | 12 months |
| Log of emails sent | 12 months |
| List of invalid or suppressed addresses | Retained without time limit, so as never to write to those addresses again |
| Records of use of the drafting assistant | 12 months, with no retention of the texts submitted or of the texts proposed |
| Contact requests | 3 years after the last exchange |
| Cookies and trackers | See the cookie policy — 13 months maximum, consent choice retained for 6 months |
At the end of these periods, the data is deleted or irreversibly anonymised. Deleting an account does not erase the accounting records that the law requires to be retained: they are segregated and serve no purpose other than that obligation.
11. Data security
In accordance with Article 32 of the GDPR, Association E-Cosplay implements appropriate technical and organisational measures:
- encryption of communications (TLS/HTTPS across the entire Platform);
- hashing of passwords (bcrypt) and a security key specific to each ticket;
- no bank card data on the association's servers;
- protection against denial of service and a web application firewall via Cloudflare, rate limiting on sensitive endpoints;
- restricted access to data based on the principle of least privilege, segregation of organisers, detailed permissions for sub-accounts;
- regular, encrypted backups, hosted in France and tested;
- logging of sensitive actions and detection of anomalies.
In the event of a data breach likely to give rise to a risk to your rights and freedoms, the association will notify the CNIL within 72 hours (Article 33 of the GDPR) and, where the risk is high, the data subjects (Article 34).
12. Your rights
In accordance with Articles 15 to 21 of the GDPR and with the French Data Protection Act, you have the following rights:
- Right of access (art. 15): to obtain confirmation that your data is being processed and to receive a full copy of it (account, orders, tickets, invoices).
- Right to rectification (art. 16): to have inaccurate data corrected or incomplete data completed.
- Right to erasure (art. 17): to request the deletion of your data, subject to legal retention obligations, in particular accounting obligations.
- Right to restriction of processing (art. 18): to temporarily freeze the use of your data in the cases provided for.
- Right to portability (art. 20): to receive the data you have provided in a structured, commonly used and machine-readable format.
- Right to object (art. 21): to object to processing based on legitimate interest, as well as to any marketing, without having to give reasons for your request.
- Right to withdraw consent (art. 7): to withdraw your consent at any time (audience measurement, error monitoring), without calling into question the lawfulness of the prior processing.
- Post-mortem directives (art. 85 of the French Data Protection Act): to set out directives concerning what becomes of your data after your death.
How to exercise your rights. Send your request to the DPO: rgpd@e-cosplay.fr, specifying the right exercised and providing evidence of your identity (any document enabling you to be identified; a copy of an identity document will be requested only in the event of reasonable doubt).
A response will be provided to you within a maximum period of one month, which may be extended by two months for complex requests, of which you would then be informed. The exercise of your rights is free of charge.
Where the request concerns data processed by an organiser on its own behalf (point 4), it is forwarded to that organiser and you are informed accordingly.
13. Complaint to the CNIL
If, after having contacted us, you consider that your rights are not being respected, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (the French data protection authority):
- CNIL — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
- Telephone: 01 53 73 22 22
- Online: https://www.cnil.fr/fr/plaintes
14. Cookies and trackers
The use of cookies and trackers (trackers necessary for the service, Zen audience measurement, E-Monitor error monitoring) is detailed in the cookie policy. You may change your choices at any time via the "Manage my cookies" button in the footer or the "cookie" badge at the bottom of the screen.
15. Minors
The Platform is not aimed at minors under 15 years of age. In accordance with Article 45 of the French Data Protection Act, the processing of the data of a minor under 15 years of age requires the joint consent of the minor and of the holder of parental authority. A ticket may be purchased by an adult for a minor: in that case, only the purchaser's data is collected. If you believe that a minor's data has been collected without authorisation, contact rgpd@e-cosplay.fr: it will be deleted as soon as possible.
16. Amendments to this policy
The association may amend this policy at any time, in particular in order to comply with legal or technical developments. The version in force is the one published on the Platform, together with its update date. In the event of a substantial amendment, users holding an account will be informed of it.
17. Governing law
This policy is governed by French law. Any dispute in connection with the processing of personal data is subject, failing amicable resolution, to the competent French courts.
Last updated: 09/09/2026.