GDPR PRIVACY NOTICE AND TERMS OF USE

GDPR PRIVACY NOTICE AND TERMS OF USE

Our website sukhishvili.net provides a secure and convenient way to purchase electronic tickets for SUKHISHVILI concerts in various countries.

We are fully committed to protecting your privacy and respecting your choices. We make every effort to comply with our obligations under the EU General Data Protection Regulation (GDPR).

We place the highest priority on protecting the rights of individuals, including in cases involving automated processing of personal data, and strive to ensure maximum transparency in our relationship with customers. Accordingly, we have adopted this policy, which describes our data processing activities, their purposes, and the tools available to users to exercise their rights.

Additional information on the protection of personal data can be found on the website of the CNIL and on the website of the Estonian data protection supervisory authority (see the “Your Rights” section below).

By continuing to use this website, you unconditionally accept the terms of use set out below. The version published on the website is the only valid version throughout the period of use of the website and remains in force until it is replaced by an updated version.

The contact details of our company (Ticket Seller/Platform) are provided at the end of this document.


PRIVACY NOTICE AND PROCESSING OF PERSONAL DATA IN ACCORDANCE WITH THE GDPR

By visiting https://sukhishvili.net/, you agree that we collect, process and use the personal data specified below. This Privacy Notice describes how personal data collected through the website and its content module (the “Widget”) is processed. Your access to the website and our interaction with you are governed by this Privacy Notice.

You may use the website without disclosing personal data; however, the provision of most of our services requires certain data to be provided. By providing us with personal data, you consent to its collection, use, disclosure and storage in accordance with the terms of this Privacy Notice.

Scope

This Privacy Notice applies to all users, customers and visitors of the website.

Applicable Law and Jurisdiction

These Terms and any disputes arising from or in connection with them shall be governed by and construed in accordance with the laws of the Republic of Estonia. Mandatory provisions of European Union law, including consumer protection and personal data processing rules (in particular, the GDPR), shall also apply.

The courts of Estonia shall have exclusive jurisdiction over all disputes, except where mandatory consumer protection laws provide otherwise.

The current list of bodies for the out-of-court settlement of consumer disputes in the EU Member States, Norway and Iceland is available at:

https://consumer-redress.ec.europa.eu/dispute-resolution-bodies


KEY DEFINITIONS AND ROLES OF THE PARTIES

As tickets are sold under different models — sometimes directly through our Widget and sometimes by redirecting customers to third-party ticketing systems — the roles and responsibilities of each party are clearly distinguished below.

  • “Platform” / “Ticket Seller” — RSO Production by Voloshyn OÜ. Responsible for the operation of the website and Widget, order processing, payment processing, issuing electronic tickets and communicating with the Customer regarding ticket purchases. The Platform is not responsible for the organisation, content, date, venue or cancellation of the Event.

  • “Event Organiser” — the legal entity (tour organiser, production company or local promoter in the country where the Event takes place) directly responsible for the Event, including its programme, date, venue, postponement or cancellation, and on-site safety. The Platform is not the Event Organiser unless expressly stated otherwise on the page of the relevant Event.

  • “Third-Party Ticket Operator” — an independent ticketing system or platform (such as Fnac Spectacles, Fimalac Entertainment, Ticketmaster, etc.) to which the Platform may direct the Customer via a link or embedded widget. In this case, the ticket purchase agreement is concluded directly between the Customer and the relevant operator, while the Platform acts solely as an intermediary/information aggregator and is not a party to the agreement and bears no responsibility for its performance.

  • “Ticket” — an electronic document sent to the Customer by email (by the Platform or the Third-Party Ticket Operator, depending on the method of purchase) confirming the right to attend the Event. It contains a unique identifier (barcode or QR code), order number, Event name, date and venue, seat, price, service fee and other legal/technical information.

  • “Booking” — an order created in the System and awaiting payment by the Customer.

  • “Booking Period” — the period displayed in the Widget during the ordering process during which the Customer may pay for the order before it is automatically cancelled.

  • “Order” — one or more tickets for the same Event selected by the Customer and combined by the System under a single identification number.

  • “Event” — a concert or cultural/entertainment event that may only be attended with a valid ticket.

  • “Customer” / “You” — an individual or legal entity using the Platform’s services to book and purchase tickets.

  • “Service Fee” — a fee charged to the Customer when tickets are sold for booking and order processing services.

  • “System” — the Platform’s hardware and software infrastructure supporting the website and Widget, including booking, registration, ticket sales and generation of unique ticket numbers, identification and storage of transactions, and sending purchase confirmations by email.

  • “Website” — the Platform’s web pages, including subdomains, available at https://sukhishvili.net/.

  • “Widget” — the Platform’s content module through which the Customer purchases a ticket directly or is redirected to a Third-Party Ticket Operator to make the purchase.


PERSONAL DATA WE MAY COLLECT

  • Identification Data — first name, last name, date of birth, citizenship.

  • Contact Data — email address, telephone number, postal/billing address.

  • Payment Data — information required to process payments (card details, IBAN, transaction details).

  • Ticket Data — tickets purchased, attendance information, seat numbers.

  • Technical Data — IP address, browser type, operating system, device identifiers, access logs.

  • Communication Data — correspondence with customer support, enquiries, complaints and feedback.

  • Marketing Data — newsletter subscriptions, marketing preferences, participation in promotional campaigns or surveys.

As a rule, we receive personal data directly from you through the Website/Widget. In some cases, we receive a limited amount of information from the payment provider — for example, a token/transaction identifier, anti-fraud verification status and the last four digits of a card — for payment processing and fraud prevention.

We may also receive data from Event Organisers/venues — for example, an order number, seating information or attendance status — solely for the performance of the contract and to ensure access to the Event.

If the purchase is made through a Third-Party Ticket Operator, the processing of the relevant data is carried out by that operator as an independent data controller in accordance with its own privacy policy.

We knowingly do not collect data from persons under 13 years of age without parental consent (the legal age for independent consent to data processing in Estonia under the national Personal Data Protection Act implementing Article 8 of the GDPR). For children under 13, we rely on the consent of their parents or legal guardians.


PURPOSES OF DATA PROCESSING

  • Performance of the Contract — processing ticket purchases, confirming orders, issuing electronic tickets and providing access to the Event.

  • Customer Support — responding to enquiries, complaints and requests submitted to customer support.

  • Compliance with Legal Obligations — complying with tax, accounting and other legal requirements.

  • Security — preventing fraud, ensuring transaction security and controlling access at the venue.

  • Event Information — sending communications related to the purchased Event, such as changes to the date or cancellation.

  • Marketing (with consent) — sending newsletters, offers and personalised advertising only where the Customer has provided explicit consent.

  • Legitimate Interests — improving our services, analysing user behaviour, ensuring the proper operation of the Website and ticketing system.

Automated Decision-Making / Profiling

We use anti-fraud mechanisms to automatically assess transactions based on technical signals and payment patterns. This may result in a temporary suspension or refusal to process an order pending additional verification.

For marketing purposes (only where consent to the use of cookies/advertising has been provided), we use basic segmentation based on purchase/interaction history and cookie identifiers. Such processing does not have legal consequences for you.

You have the right to challenge an automated decision, request human intervention in the decision-making process and present your position by contacting us using the contact details provided in the “Contacts” section.

Mandatory Data

For the conclusion of the contract and ticket purchase, the following must be provided:

  • first name;

  • last name;

  • email address for ticket delivery and notifications;

  • payment details processed by the payment provider.

If mandatory data is not provided, we will not be able to process the order, issue the electronic ticket, send notifications and/or provide access to the Event.

We do not process personal data for purposes incompatible with those stated above.


LEGAL BASES FOR DATA PROCESSING

  • Performance of the Contract (Article 6(1)(b) GDPR) — processing necessary for the performance of the contract, such as purchasing a ticket, confirming an order and providing access to the Event.

  • Legal Obligation (Article 6(1)(c) GDPR) — processing necessary to comply with EU and Estonian legal requirements, including tax and accounting obligations and data retention periods.

  • Legitimate Interests (Article 6(1)(f) GDPR) — processing necessary to protect our legitimate interests, such as website security, fraud prevention and service improvement, provided that these interests do not override the rights and freedoms of the data subject.

  • Consent (Article 6(1)(a) GDPR) — processing based on explicit consent, for example for marketing communications or surveys. Consent may be withdrawn at any time; however, the lawfulness of processing carried out before withdrawal remains unaffected.


DISCLOSURE OF PERSONAL DATA

We disclose personal data to third parties only where permitted by law and where necessary:

  • IT Providers — hosting, technical support and email delivery; processing is carried out on our instructions under a data processing agreement.

  • Third-Party Ticket Operators — Fnac Spectacles, Fimalac Entertainment, Ticketmaster and others — for ticket booking and processing where the purchase is made through a redirect. Depending on their role, they may act as our data processor or as an independent data controller.

  • Payment Systems through which payments are processed. We currently use Stripe. Personal data provided to Stripe is processed by that company as an independent data controller in accordance with its own privacy policy.

  • Email and Marketing Services — processing is carried out on our behalf and in accordance with our instructions pursuant to Article 28 GDPR.

  • Event Organisers — to the extent necessary for the performance of the contract, for example for access control or seating arrangements.

  • Government Authorities and Courts — where required by law.

  • Professional Advisers — auditors, accountants and lawyers subject to confidentiality obligations.

We may also disclose personal data where required by law.

International Data Transfers

We may transfer personal data to recipients outside the European Economic Area (EEA) where the relevant processor, joint controller or other recipient is located in a third country.

Such transfers are carried out strictly in accordance with Chapter V of the GDPR and only where appropriate safeguards are in place, including:

  • an adequacy decision of the European Commission;

  • appropriate safeguards, including Standard Contractual Clauses (SCCs) and/or Binding Corporate Rules (BCRs), as well as necessary technical and organisational measures;

  • exceptions provided for under Article 49 GDPR, such as explicit consent or the necessity of the transfer for the performance of a contract, solely to the extent necessary.

For analytics and advertising, we may use Google Analytics, Meta (Facebook) Pixel and TikTok Pixel. Processing may take place in the EU and/or the United States. Transfers of data outside the EEA are carried out using Standard Contractual Clauses and additional safeguards.

We do not sell or rent personal data to third parties.


RETENTION PERIODS

  • Ticket and contractual data — for the duration of the contractual relationship and up to 3 years after its termination to protect against potential legal claims.

  • Accounting and tax data — 7 years in accordance with Estonian law.

  • Customer support correspondence — up to 2 years after the enquiry has been closed.

  • Marketing data — until consent is withdrawn or for a maximum of 2 years after the last interaction with us.

  • Technical data (IP addresses, access logs) — up to 12 months from collection, except where a longer retention period is required for the investigation of security incidents or by law.

After the applicable retention period expires, personal data is securely deleted or anonymised.


YOUR RIGHTS UNDER THE GDPR

You have the right to:

  • access your personal data;

  • correct inaccurate or incomplete data;

  • request the deletion of personal data, except where we are legally required to retain it;

  • request restriction of processing;

  • receive your data in a structured, commonly used and machine-readable format and transmit it to another controller;

  • object to processing, in particular for direct marketing purposes;

  • withdraw your consent at any time;

  • lodge a complaint with a data protection supervisory authority.

To exercise your rights, please contact us using the email address provided in the “Contacts” section. We will respond within one month. Where necessary, this period may be extended by an additional two months, taking into account the complexity and number of requests.

Supervisory Authority

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with:

Andmekaitse Inspektsioon (Data Protection Inspectorate, Estonia)
Väike-Ameerika 19, 10129 Tallinn, Estonia
Website: https://www.aki.ee
Email: info@aki.ee

You may also contact the data protection supervisory authority in your country of habitual residence or in the country where the alleged infringement occurred.

Data Breach Notification

In the event of an incident affecting the security of your personal data and creating a high risk to your rights and freedoms, we will notify you without undue delay in accordance with Article 34 GDPR and, where necessary, notify the supervisory authority in accordance with Article 33 GDPR.


COOKIES

Our Website uses cookies and similar technologies to ensure proper operation, improve the user experience, perform analytics and support marketing activities.

Categories of cookies:

  • Strictly Necessary — necessary for the operation of the Website, for example for purchasing tickets and secure login; consent is not required.

  • Analytics — allow us to analyse traffic and improve the Website; used only with your consent.

  • Functional — store user preferences, such as language or region; used only with your consent.

  • Advertising and Tracking — used for marketing, personalised advertising and retargeting; used only with your explicit consent.

Upon your first visit to the Website, you will be offered the options “Accept All” / “Reject All” / “Settings”.

You may withdraw your consent at any time by changing your cookie settings on the Website.


TERMS OF USE

These Terms of Use (the “Agreement”) apply to all purchases made through the Platform Widget and are intended to explain the purchase process, the role of the Platform in providing services, and the specifics of purchasing tickets both directly and through redirection to Third-Party Ticket Operators.

The Agreement enters into force upon its publication on https://sukhishvili.net/ and remains in force until cancelled or replaced by a new version.

Main Terms

When tickets are purchased directly through the Widget, we process the necessary personal data in accordance with this Policy and applicable law.

Where a purchase is made by redirecting the Customer to a Third-Party Ticket Operator, the terms and privacy policy of that operator apply, and the Platform is not responsible for the content, processing or performance of such agreement.

The ticket purchase agreement through the Platform Widget is concluded once the Customer has completed the ordering process and received an electronic order confirmation. From that moment, the order becomes binding and the Customer is obliged to pay the ticket price.

Under Estonian law, the right of withdrawal does not apply to leisure services where the contract provides for a specific date or period of performance. Accordingly, tickets purchased through the Widget are non-refundable, except in cases of Event cancellation or postponement.

All ticket prices are stated in euros by default unless otherwise indicated. When purchasing from other countries, payment may be made in the local currency depending on the Customer’s location, selected payment method and the ticket operator’s system.

Tickets are delivered electronically. After the purchase has been confirmed and payment successfully processed, the Customer receives the tickets by email.

The Customer is responsible for providing the correct email address and for having access to the electronic tickets received.


PAYMENT AND VAT

Ticket payments must be made directly when the order is placed. The ticket purchase agreement is concluded after the payment service confirms the payment.

Ticket prices include the applicable VAT in accordance with the location of the Event and the requirements of EU law. Pursuant to Article 53 of EU Directive 2006/112/EC, VAT on admission tickets to cultural and entertainment events is charged in the place where the Event actually takes place.

The Platform is registered under the One-Stop Shop (OSS) scheme pursuant to Articles 369a–369k of EU Directive 2006/112/EC.

This means that VAT on ticket sales for Events taking place in different EU countries is declared and paid centrally by the Platform through its registration in Estonia, without separate local VAT registration in each country where an Event takes place.

The applicable VAT rate is determined by the country where the Event actually takes place and is indicated in the order confirmation/invoice.


REFUNDS

Tickets purchased through the Platform Widget are non-refundable and cannot be cancelled by the Customer after completion of the purchase.

Refunds are available only in the following cases:

  • Event Cancellation. The ticket price will be refunded within a maximum of 30 calendar days after cancellation has been confirmed, unless mandatory laws of the country where the Event takes place provide for a different period. Service and transaction fees will be refunded to the extent required by law.

  • Event Postponement. Purchased tickets remain valid for the new date. If the Customer is unable to attend the Event, the Customer may request a refund under the same conditions as in the case of cancellation.

If a ticket was purchased through a Third-Party Ticket Operator, the refund rules are determined by that operator’s terms and the refund request must be submitted directly to that operator.

Refund and exchange rules apply subject to the mandatory requirements of the laws of the country where the Event takes place and, in B2C relationships, the mandatory laws of the consumer’s country of residence where those laws provide a higher level of consumer protection.


RIGHTS AND OBLIGATIONS OF THE PARTIES

Customer Rights

The Customer has the right to:

  • receive information about sales rules, prices, ticket categories and other Event conditions;

  • choose an available payment method;

  • submit feedback and enquiries concerning the Platform and the Event Organiser;

  • cancel the ticket purchase before payment of the order.

Customer Obligations

When using the Website, Widget and Services, the following is prohibited:

  • engaging in insulting, threatening or otherwise inappropriate behaviour;

  • using the Platform’s trademarks or other intellectual property without prior written permission;

  • copying, reproducing, decompiling, modifying, distributing or publicly displaying Website/Widget content or software without appropriate authorisation;

  • interfering with the normal operation of the Website, Widget or Services, including through bots and scripts or by circumventing technical restrictions.

Platform Rights

The Platform has the right to:

  • require the Customer to complete the full order and payment procedure;

  • cancel a booking/order where the Customer has more than two unpaid bookings/orders within a period of 5 days;

  • modify the Website, System and Widget software;

  • temporarily suspend operation to remedy serious malfunctions, perform maintenance or prevent unauthorised access;

  • establish and unilaterally change the amount of Service Fees;

  • require full payment of the ticket;

  • cancel an unpaid order after the Booking Period has expired;

  • refuse to provide further services or restrict access to the Widget where the Customer violates these Terms.


LIABILITY

We are liable only for damage caused intentionally or through gross negligence in connection with obligations for which the Platform, as Ticket Seller, is responsible, including order processing, payment processing and ticket issuance.

In cases of ordinary negligence, our liability is limited to breaches of material contractual obligations and only to foreseeable and typical damage.

The Platform is not liable for:

  • the content, programme, date, venue, quality, postponement or cancellation of the Event — responsibility for these matters lies with the Event Organiser;

  • the performance of the agreement concluded between the Customer and a Third-Party Ticket Operator where the purchase was made through a redirect — responsibility lies with the relevant operator;

  • indirect damage, consequential damage or loss of profit unless caused intentionally;

  • technical failures of internet services or third-party platforms, including ticketing systems and payment providers, which are beyond the Platform’s reasonable control.

Liability for damage to life, health or physical integrity remains fully applicable in accordance with applicable law.

Force Majeure

The parties shall not be liable for the total or partial failure to perform their obligations due to circumstances beyond their control, including natural disasters, acts of war, strikes, mass disturbances/protests, actions of governmental authorities, prolonged interruptions of telecommunications and energy networks, and other extraordinary and unavoidable circumstances.

If such circumstances continue for more than 60 consecutive calendar days, either party may terminate the agreement by notifying the other party. In such case, amounts already paid shall be refunded to the Customer, less actually incurred and documented expenses, unless mandatory consumer protection laws provide otherwise.


DISPUTE RESOLUTION

Disputes shall be subject to prior out-of-court settlement.

A written complaint accompanied by supporting documents must be submitted to the Platform within 10 calendar days from the occurrence of the dispute.

These Terms and the relationship between the parties shall be governed by the substantive laws of Estonia, excluding conflict-of-law rules that would result in the application of the law of another country.

Regardless of the applicable law chosen, mandatory provisions of the law of the country where the Event takes place shall apply where they cannot be modified by agreement between the parties, including rules concerning venue access, safety and mandatory refunds.

In B2C relationships, mandatory provisions of the law of the consumer’s country of habitual residence shall also apply where they provide a higher level of protection and cannot be modified by agreement.

The current list of bodies for the out-of-court settlement of consumer disputes in EU Member States is available at:

https://consumer-redress.ec.europa.eu/dispute-resolution-bodies


OTHER PROVISIONS

We are technically unable to restrict minors’ access to the Website/Widget and rely on parents/guardians to assess whether content and purchases are age-appropriate.

You undertake to comply with all applicable rules, policies and terms of the Platform, the Event Organiser and the venue administration.

Entry may be refused and a visitor may be removed without a refund for behaviour that violates public order, the use of offensive/obscene language or any other violation of the applicable attendance rules.

The Event is public. Please note that your presence and activities at or near the venue may be visible to other persons and may be recorded by means of photography, video or audio recording.

By attending the Event, you acknowledge and agree that the Platform, Event Organisers, their partners or licensees may record, use and distribute your image, appearance, voice and movements live or in recorded form.

Such recordings may be broadcast, published or reproduced on any existing or future media without the need for additional consent or payment of compensation.

Upon entry, security checks and bag inspections may be carried out. Certain venues prohibit specific items, including but not limited to firearms, alcohol, drugs, cameras/recording devices, laser pointers, strobe lights, etc.

Illegal resale or attempted resale of tickets, as well as the use of counterfeit or duplicate tickets, shall constitute grounds for confiscation and cancellation without compensation.

Tickets may not be used in advertising, promotional activities, competitions or prize draws without prior written permission.

We reserve the right to modify, suspend or discontinue the operation of the Website, Widget, Services or any part thereof at any time, temporarily or permanently, with or without notice.

If the Website is available in several languages, in the event of discrepancies between the language versions of this document, the English-language version shall prevail, unless expressly stated otherwise on the Website.


SECURITY AND DATA PROTECTION

We use secure SSL/TLS technology, one of the most reliable methods for protecting online payments.

All transmitted personal data is encrypted to prevent unauthorised access.

Our systems are protected by a multi-layer firewall infrastructure and internal information security policies.

Employees’ access to Customer data is granted strictly on a need-to-know basis and only to authorised personnel in the course of performing their duties.

All data operations are logged and monitored by responsible personnel.


CONTACT DETAILS

RSO Production by Voloshyn OÜ
Private limited company

Registered address:
Harju maakond, Tallinn, Kesklinna linnaosa, Karu tn 14-8, 10120, Estonia

Commercial Register No.: 17018174
VAT No. (OSS registration, Estonia): EE102806827

Managing Director: Igor Voloshyn
Contact: voloshynigor@gmail.com

Data Controller:
RSO Production by Voloshyn OÜ, Private limited company
Harju maakond, Tallinn, Kesklinna linnaosa, Karu tn 14-8, 10120, Estonia
Commercial Register No.: 17018174
VAT No. (OSS): EE102806827

Data Protection Contact:
support@sukhishvili.net

Data subject requests pursuant to Articles 15–22 GDPR should be sent to:

support@sukhishvili.net

We will respond within 1 month. Where necessary, this period may be extended by an additional 2 months in cases involving complex requests, with the relevant notification.

Data Protection Supervisory Authority:
Andmekaitse Inspektsioon (Data Protection Inspectorate, Estonia)
Väike-Ameerika 19
10129 Tallinn
Estonia
https://www.aki.ee
info@aki.ee