Privacy Policy
Palco is a ticketing and event management platform. This policy describes how we collect, use, share, retain and protect personal data processed through palco.cloud, the public page of each event, the organiser's dashboard and the door check-in app.
It follows the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — and applicable Portuguese law, namely Law 58/2019 of 8 August.
1. Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Data subject: anyone who visits an event page, buys or receives a ticket, organises events on the platform, or works the door.
- Controller: whoever determines the purposes and means of processing.
- Processor: whoever processes data on behalf of the controller and on its instructions.
- Organiser: the entity that creates and sells an event on Palco — an association, a company or an individual.
2. Palco's two roles
Palco is a platform an organiser uses to sell tickets to their own event. That places us in two different legal positions, depending on whose data is involved:
A. Palco as controller
We are the controller for data belonging to:
- Organisers and the people they invite to their team or to the door — account, authentication, commission invoicing, audit records.
- Affiliates who join a promotion campaign.
- Visitors to palco.cloud.
B. Palco as processor
We act strictly as a processor for buyer and attendee data collected on an event's public page: name, e-mail, answers to the registration fields defined by the organiser, and entry records.
In that case, the event organiser is the sole controller. Palco only provides the infrastructure and processes that data on the organiser's documented instructions, under the processing agreement that forms part of the Terms of Use.
In practice this means a request about your data as an attendee goes to the event organiser. If it reaches us, we forward it and help the organiser answer — but the decision is theirs.
3. Controller identity and contacts
Where Palco is the controller (see section 2.A), the contact details are:
- Legal name: [denominação social a preencher]
- Trading name: Palco (palco.cloud)
- Company number: [NIPC a preencher]
- Registered office: [sede social a preencher]
- Support: apoio@palco.cloud
- Data protection: privacidade@palco.cloud
4. What we process, why, and on what basis
Collection is limited to what each purpose strictly requires.
A. Visiting an event page
- Data: IP address and technical request data, kept on our servers for short periods.
- Purposes: serving the page, protecting the platform from abuse, diagnosing faults.
- Basis: legitimate interest in the security and operation of the service (Art. 6(1)(f)).
- We use no analytics or advertising cookies on public pages. The affiliate code that sometimes travels in the address (
?ref=) is read on the server and counted in aggregate, with no cookie and no browsing profile.
B. Buying a ticket
- Data: name, e-mail address, tickets purchased, amount, payment reference, answers to the registration fields defined by the organiser and, where applicable, the name of whoever will use each ticket.
- Purposes: issuing the ticket, e-mailing it, allowing entry to the event, handling refund requests and meeting tax obligations.
- Basis: performance of the purchase contract (Art. 6(1)(b)) and compliance with a legal obligation for invoicing (Art. 6(1)(c)). For everything else, the responsible organiser's instructions.
- Card data: never reaches our servers. It is collected and processed directly by Stripe.
C. Entering the event
- Data: ticket validation at the door — date, time and who validated it.
- Purposes: access control, preventing duplicate tickets, attendance counts for the organiser.
- Basis: the organiser's instructions, in their legitimate interest in controlling access to their own event.
D. Organising events
- Data: name, e-mail, hashed password, tax number and billing address, payout account details, team members and their roles, and audit records of sensitive operations.
- Purposes: providing the service, invoicing our commission, meeting accounting and tax obligations, and being able to reconstruct who did what when money is involved.
- Basis: performance of the contract, legal obligation, and legitimate interest in platform security.
5. Who we share with, and where the data lives
We use processors under contracts that ensure GDPR compliance:
- Hosting and database: infrastructure in the European Union, running PostgreSQL with logical isolation per organiser.
- Payments: Stripe Payments Europe, Ltd. and its affiliates, for processing payments and paying out sales to the organiser.
- Transactional e-mail: Resend, for ticket, confirmation and account recovery e-mails.
We do not sell personal data, and we do not share it for third-party marketing.
International transfers. Where a processor handles data outside the European Economic Area, the transfer relies on a European Commission adequacy decision or on Standard Contractual Clauses, with the applicable supplementary measures.
6. Security
- Isolation per organiser: every row in the database belongs to one organiser, and access is filtered inside the database engine itself (Row Level Security). The organiser's identity is always determined on the server from the session — never from a value sent by the browser.
- Signed tickets: each ticket carries a cryptographic signature specific to its event. A copied or forged barcode does not pass the door.
- Encrypted connections: all traffic between the browser, the platform and our processors uses TLS.
- Passwords: stored only as cryptographic hashes, never in the clear.
- Audit log: sensitive administrative operations are recorded with author, date and target.
7. How long we keep it
- Buyer and attendee data: the period is set by the responsible organiser. Once our contract with that organiser ends, we delete or anonymise the data within 90 days, unless the law requires otherwise.
- Invoices and accounting records: 10 years, as required by Portuguese tax law.
- Organiser accounts: for as long as the account is active. After closure, deleted or anonymised within 90 days, subject to the point above.
- Refund requests and related correspondence: until the legal complaint and chargeback periods expire.
- Server logs: 12 months at most.
8. Your rights
As a data subject you have the right to:
- Access — know whether we process your data and obtain a copy.
- Rectification — correct inaccurate or incomplete data.
- Erasure — ask for deletion when the data is no longer necessary.
- Restriction — suspend processing in certain circumstances.
- Objection — object to processing based on legitimate interest.
- Portability — receive your data in a structured, commonly used format.
- Withdraw consent — where processing relies on it, without affecting what was done before.
How to exercise them. If you are an organiser, write to privacidade@palco.cloud. If you bought a ticket, the controller is the event organiser and that is where the request belongs — their contact is on the event page and in the ticket e-mail. If you would rather write to us, we forward it and follow up.
We answer within one month, extendable by two further months for complex requests, with notice.
Complaints. You always have the right to lodge a complaint with the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD).
9. Cookies
Public event pages use only what is strictly necessary to work, which is why you are not shown a consent request that would have nothing to authorise. The details, cookie by cookie, are in the Cookie Policy.
10. Changes to this policy
We may update this policy to reflect changes to the service or to the law. The date of the last revision is at the top of the page. Where a change is substantial, we notify organisers by e-mail and in the dashboard before it takes effect.