Skip to main content

GDPR Compliance

Last updated: July 15, 2026

1. Overview

VylioPass Systems LLC ("VylioPass", "we", "us", "our") is committed to protecting the privacy and security of personal data for users in the European Economic Area (EEA) in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").

This page explains how we comply with GDPR requirements, your rights as a data subject, and how to exercise those rights.

2. Data Controller & Representative

Data Controller: VylioPass Systems LLC, Dubai Internet City, Dubai, United Arab Emirates

EU Representative: For users in the EEA, our representative under Article 27 of the GDPR is:

Data Protection Officer (DPO): You can contact our DPO at dpo@vyliopass.com.

3. Lawful Basis for Processing

We process personal data under the following lawful bases as defined in Article 6 of the GDPR:

3.1 Performance of a Contract

We process data necessary to perform our contract with you, including:

  • Creating and managing your account
  • Processing ticket purchases and payments
  • Providing customer support
  • Delivering event tickets and access

3.2 Legitimate Interests

We process data based on our legitimate interests, provided those interests are not overridden by your rights, including:

  • Fraud prevention and security
  • Platform improvement and feature development
  • Marketing communications (with opt-out)
  • Analytics and performance optimization

3.3 Consent

We process data based on your explicit consent for:

  • Marketing Cookies and tracking technologies
  • Optional data collection (e.g., survey responses)
  • International data transfers (where required)

3.4 Legal Obligation

We process data to comply with legal obligations, including:

  • Tax and accounting requirements
  • Anti-money laundering (AML) regulations
  • Law enforcement requests (where legally required)

4. Your Rights as a Data Subject

Under the GDPR, you have the following rights regarding your personal data:

4.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with certain information about the processing.

How to exercise: Use the "Download My Data" feature in your account settings or contact us at privacy@vyliopass.com.

4.2 Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected or completed if it is incomplete.

How to exercise: Update your information directly in your account settings or contact us.

4.3 Right to Erasure ("Right to Be Forgotten") (Article 17)

You have the right to request deletion of your personal data in certain circumstances, including:

  • The data is no longer necessary for the purposes it was collected
  • You withdraw consent (where processing is based on consent)
  • You object to processing based on legitimate interests
  • The data has been unlawfully processed

Limitations: We may retain certain data where required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).

How to exercise:Use the "Delete My Account" feature in your account settings or contact us.

4.4 Right to Restrict Processing (Article 18)

You have the right to request that we restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

How to exercise: Contact us at privacy@vyliopass.com.

4.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

How to exercise:Use the "Export My Data" feature in your account settings (available in JSON and CSV formats).

4.6 Right to Object (Article 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

How to exercise: Unsubscribe from marketing emails using the link in each email, or contact us to object to other processing.

4.7 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

How to exercise: Adjust your Cookie preferences or contact us.

5. International Data Transfers

VylioPass is based in the United Arab Emirates. When we transfer personal data from the EEA to countries outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): We use EU-approved SCCs for transfers to countries without adequate protection
  • Adequacy Decisions: We rely on European Commission adequacy decisions where available
  • Binding Corporate Rules: For intra-group transfers (if applicable)
  • Explicit Consent: Where other safeguards are not available, we seek your explicit consent

Our data processing infrastructure is hosted in the following regions:

  • Primary: United Arab Emirates (Dubai)
  • Backup: European Union (Frankfurt, Ireland)
  • CDN: Global (Cloudflare)

For EEA users, we store and process data primarily in our EU data centers to minimize cross-border transfers.

6. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account Data: Retained for the duration of your account + 30 days after deletion request
  • Transaction Data: Retained for 7 years (legal/tax requirements)
  • Event Data: Retained for 3 years after event completion
  • Analytics Data: Retained for 26 months
  • Marketing Data: Retained until you unsubscribe or request deletion

After the retention period, data is securely deleted or anonymized.

7. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  • Document all breaches, including the facts, effects, and remedial actions taken

You can report a suspected data breach to us at security@vyliopass.com.

8. Supervisory Authority

If you are in the EEA and believe that we have not complied with GDPR, you have the right to lodge a complaint with a supervisory authority. The supervisory authority in your member state of residence, place of work, or the place of the alleged infringement can be contacted.

We encourage you to contact us first at dpo@vyliopass.com so we can address your concerns directly.

9. Automated Decision-Making & Profiling

VylioPass uses automated decision-making in limited circumstances:

  • Fraud Detection: Automated systems analyze transactions to detect and prevent fraud
  • Risk Scoring: Automated systems assess organizer risk based on transaction history and behavior

These automated decisions do not produce legal effects or similarly significantly affect you. If you believe an automated decision has affected you, you can request human review by contacting us.

10. Children's Privacy

VylioPass is not intended for children under 16 years of age (or the age of digital consent in your member state, if lower). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

11. Contact Us

For GDPR-related inquiries or to exercise your rights:

We will respond to your request within 30 days. For complex requests, we may extend this period by up to 60 days, in which case we will inform you of the extension and the reasons for it.