Your data.
Your relationship.
Your trust.
Privacy Policy
Artix provides the technology that helps organisations manage customer and audience relationships responsibly, securely, and transparently.
Effective starting: December 1, 2025
Last updated: 24 August 2026
Your privacy is important to Artix. We are committed to protecting personal data and being transparent about how we collect, use and protect information.
Artix Unipessoal, Lda. (“Artix”, “we”, “us” or “our”) provides cloud-based ticketing, booking, membership, CRM, audience management and related software services to cultural, entertainment, sporting and other organisations.
This Privacy Policy explains how Artix processes personal data when you visit our websites, use our services, purchase tickets or otherwise interact with Artix.
It also explains how Artix processes personal data belonging to customers, visitors, members, donors and other individuals who interact with organisations using Artix’s technology.
1. What This Policy Covers
This Privacy Policy applies to personal data processed by Artix through:
* Our websites and online services;
* Our ticketing and booking technology;
* Event registration and attendance services;
* Membership and subscription services;
* Donation and fundraising services;
* Customer relationship management and audience-management services;
* Merchandise and other transaction-related services;
* Customer support and communications; and
* Our business and commercial relationships.
Depending on how you interact with Artix, we may act as either a Data Controller or a Data Processor under the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
The distinction is important and is explained below.
2. Who We Are
The entity responsible for Artix’s own processing of personal data is:
Artix Unipessoal, Lda.
Rua das Gáveas 41, 2
Lisboa, 1200-206, Portugal
NIPC: 519088484
Email: privacy@artix.pt
Artix is a technology company providing software and services to organisations that sell tickets, manage events, operate memberships, receive donations and manage relationships with their audiences.
3. Our Role in Processing Personal Data
Artix as Data Controller
Artix acts as a Data Controller when we determine why and how personal data is processed for our own purposes.
This includes situations such as:
* Managing our business relationships with customers and suppliers;
* Responding to enquiries and requests for information;
* Managing prospective customer relationships;
* Providing demonstrations of our products and services;
* Managing contracts, billing and payments;
* Providing customer and technical support;
* Maintaining the security of our websites and systems;
* Communicating with customers and business contacts;
* Marketing Artix’s own products and services where permitted by law; and
* Complying with legal and regulatory obligations.
When Artix is the Data Controller, we are responsible for determining the applicable purposes and legal basis for processing your personal data.
Artix as Data Processor
Artix also provides its technology under contract to organisations such as museums, theatres, cultural institutions, event organisers, sporting organisations and other venues.
When you purchase a ticket, register for an event, become a member, make a donation, attend an event, or otherwise interact with an organisation using Artix’s technology, that organisation generally determines why your personal data is collected and how it is used.
In these circumstances, the organisation is generally the Data Controller, while Artix acts as its Data Processor.
Artix processes this information on behalf of the organisation and in accordance with its documented instructions and applicable data protection law.
The organisation’s own privacy policy will generally provide more information about how it uses your personal data.
Client-Controlled Patron Data
Artix recognises that the organisations using our technology maintain the relationship with their customers, visitors, members, donors and audiences.
Where Artix processes personal data on behalf of a client, that client remains responsible for determining:
* The purposes for which personal data is collected and used;
* The legal basis for processing;
* What personal data is collected;
* How long personal data should be retained;
* Whether and how personal data is used for communications or marketing; and
* How individuals can exercise their data protection rights in relation to that organisation.
Artix does not sell client-controlled patron data.
Artix does not use client-controlled patron data for independent advertising or unrelated commercial purposes. We process this information to provide the contracted services to our clients and in accordance with their instructions.
4. Information We Collect
The type of personal data we process depends on how you interact with Artix and the organisation using our technology.
Information You Provide Directly to Artix
When you communicate directly with Artix, we may collect information such as:
* Name;
* Company or organisation;
* Job title or professional role;
* Email address;
* Telephone number;
* Business address;
* Account and login information;
* Billing and invoicing information;
* Communications and correspondence;
* Information provided when requesting a demonstration or contacting support; and
* Other information you voluntarily provide to us.
Information Processed Through Artix-Powered Services
When an organisation uses Artix to sell tickets, manage events, memberships, donations or other customer interactions, Artix may process information provided by or collected from individuals using those services.
Depending on the services configured by the organisation, this may include:
* Name;
* Email address;
* Telephone number;
* Postal or billing address;
* Ticket and booking information;
* Event registration information;
* Attendance and check-in information;
* Membership and subscription information;
* Donation and fundraising information;
* Merchandise or other purchase information;
* Food and beverage purchases, where applicable;
* Purchase and transaction history;
* Refund and cancellation information;
* Customer communications;
* Customer service records;
* Preferences and interests;
* Marketing and communication preferences;
* Customer notes or other information entered by the organisation;
* Seating preferences or assigned seating information;
* Information required to issue or validate tickets; and
* Other information necessary to provide the services requested by the organisation.
The organisation using Artix determines which information it collects and how that information is used.
Payment Information
When you make a payment through an Artix-powered service, payment information may be collected and processed by third-party payment service providers, including Stripe.
Artix does not generally store complete payment card numbers.
Depending on the payment method and configuration, Artix may receive or process limited payment-related information such as:
* Transaction amount;
* Transaction date and time;
* Currency;
* Payment status;
* Payment method type;
* Transaction or payment reference;
* Billing information; and
* Information required for reconciliation, refunds or invoicing.
Payment service providers may process additional information in accordance with their own privacy policies and applicable legal requirements.
Information We Collect Automatically
When you visit our websites or use our services, we may automatically collect certain technical information, including:
* IP address;
* Browser type and version;
* Operating system;
* Device type;
* Device identifiers;
* Language and regional settings;
* Referring and exit pages;
* Date and time of access;
* Pages or features accessed;
* General usage information;
* Crash and diagnostic information; and
* Other technical information necessary for security, functionality and service operation.
We use this information to operate and secure our services, understand how our services are used, diagnose technical issues and improve our products.
5. How We Use Personal Data
How we use personal data depends on whether Artix is acting as a Data Controller or Data Processor.
When Artix Is the Data Controller
We may use personal data to:
* Provide and administer our services;
* Establish and manage customer and business relationships;
* Process contracts, orders, invoices and payments;
* Respond to enquiries;
* Provide demonstrations and information about our services;
* Provide customer and technical support;
* Communicate with customers and business contacts;
* Maintain and improve our websites and services;
* Monitor and improve the performance, reliability and security of our systems;
* Detect, prevent and investigate fraud, abuse and security incidents;
* Protect our legal rights and interests;
* Conduct business administration and reporting;
* Send marketing communications where permitted by applicable law;
* Comply with legal and regulatory obligations; and
* Carry out other purposes that are compatible with the purposes for which the information was collected.
When Artix Is the Data Processor
When processing personal data on behalf of an Artix client, we use the information only to provide the contracted services and in accordance with the client’s documented instructions.
This may include:
* Processing ticket purchases and reservations;
* Issuing tickets and booking confirmations;
* Managing event registrations;
* Recording event attendance and check-ins;
* Managing memberships and subscriptions;
* Processing donations;
* Managing customer and patron records;
* Providing CRM and audience-management functionality;
* Processing merchandise and other transactions;
* Providing customer service functionality;
* Facilitating communications requested by the client;
* Processing refunds and cancellations;
* Providing reporting and analytics to the client;
* Maintaining secure access to the Artix platform; and
* Performing other processing necessary to provide the contracted services.
6. Legal Bases for Processing
Where Artix acts as a Data Controller, we process personal data only where we have an appropriate legal basis under the GDPR.
Depending on the circumstances, the legal basis may include:
Contract
We may process personal data where it is necessary to enter into or perform a contract with you.
Legal Obligation
We may process personal data where necessary to comply with a legal or regulatory obligation.
Legitimate Interests
We may process personal data where necessary for our legitimate interests, provided that those interests are not overridden by your fundamental rights and freedoms.
Our legitimate interests may include operating and improving our business and services, maintaining system security, preventing fraud, communicating with existing business contacts, and protecting our legal rights.
Consent
Where required by law, we will process personal data based on your consent.
You may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Where Artix acts as a Data Processor, the relevant client is responsible for determining the legal basis for processing its customers’ or patrons’ personal data.
7. Ticketing, Membership, Donations and Customer Data
Artix provides technology that enables organisations to manage relationships with their audiences.
When you purchase a ticket, register for an event, become a member, make a donation or otherwise interact with an organisation through Artix, the information you provide may be made available to that organisation through the Artix platform.
The organisation may use this information to:
* Fulfil your purchase or booking;
* Provide access to an event or service;
* Manage your membership;
* Process donations;
* Provide customer support;
* Communicate with you about your transaction or participation;
* Manage attendance;
* Understand and analyse audience engagement;
* Manage its customer or patron relationship;
* Conduct marketing or communications where legally permitted; and
* Perform other activities described in its own privacy policy.
Artix provides the technology that enables these activities but does not determine the purposes for which client-controlled patron data is used.
If you have questions about how an organisation uses your personal data, you should generally contact that organisation directly.
8. Payments and Stripe
Artix may use third-party payment service providers, including Stripe, to process payments.
When you make a payment, your payment information may be transmitted directly to the applicable payment service provider.
Artix does not generally store complete payment card numbers.
Payment service providers may process information necessary to:
* Authorise and process payments;
* Prevent and detect fraud;
* Maintain payment security;
* Process refunds and disputes;
* Meet legal and regulatory requirements; and
* Provide payment-related services.
Depending on the particular processing activity, a payment service provider may act as a Data Processor or Data Controller under applicable data protection law.
Payment processing is also subject to the relevant payment provider’s own privacy policy and terms.
9. How We Share Personal Data
Artix does not sell personal data.
We may share or provide access to personal data where necessary to provide our services, operate our business, comply with legal obligations, or otherwise process personal data in accordance with this Privacy Policy.
This may include sharing information with:
* Organisations using Artix’s services;
* Payment service providers;
* Cloud hosting and infrastructure providers;
* Software and technology providers;
* Email and communications providers;
* Security and fraud-prevention providers;
* Analytics and performance providers;
* Professional advisers;
* Contractors and service providers;
* Government authorities or regulators where legally required; and
* Other parties where necessary to protect our rights, users, customers or the public.
Where Artix acts as a Data Processor, third parties that process client-controlled personal data on Artix’s behalf are engaged as sub-processors where permitted by the applicable agreement and law.
Artix requires appropriate contractual and security measures from service providers that process personal data on our behalf.
10. Service Providers and Sub-processors
Artix relies on selected third-party technology and service providers to operate its platform and deliver its services.
These providers may support functions such as:
* Cloud hosting and infrastructure;
* Payment processing;
* Data storage and backup;
* Email delivery;
* Customer support;
* Security;
* Monitoring and diagnostics;
* Analytics;
* Communications; and
* Other essential technology services.
Where a service provider processes personal data on behalf of Artix or an Artix client, Artix takes appropriate steps to ensure that the provider is contractually required to protect personal data and process it only for authorised purposes.
Artix may maintain a list of relevant sub-processors and update that list when service providers are added or changed.
11. International Data Transfers
Artix is based in Portugal and operates within the European Union.
Some of our technology and service providers may process personal data outside the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, Artix will ensure that an appropriate legal mechanism is in place where required by the GDPR.
Depending on the circumstances, this may include:
* An adequacy decision adopted by the European Commission;
* The European Commission’s Standard Contractual Clauses;
* An applicable certification or recognised transfer mechanism; or
* Other lawful safeguards recognised under applicable data protection law.
Artix takes appropriate measures to protect personal data when it is transferred internationally.
12. Data Security
Artix takes appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Our security measures may include:
* Access controls;
* Authentication and authorisation mechanisms;
* Encryption where appropriate;
* Secure hosting infrastructure;
* System monitoring;
* Backups;
* Security updates;
* Restricted access to personal data;
* Procedures for responding to security incidents; and
* Internal policies and controls governing the handling of personal data.
No system or method of transmitting information over the Internet can be guaranteed to be completely secure.
Artix continually reviews and improves its technical and organisational measures in accordance with the nature of the services and risks associated with processing personal data.
13. Data Retention
Artix retains personal data only for as long as reasonably necessary for the purposes for which it was collected or processed.
Retention periods depend on the nature of the information and the reason for processing.
Where Artix acts as Data Controller, we may retain information for as long as necessary to:
* Provide our services;
* Maintain business and financial records;
* Comply with legal and regulatory obligations;
* Resolve disputes;
* Enforce agreements;
* Protect our legal rights; and
* Maintain appropriate business records.
Where Artix acts as Data Processor, client-controlled personal data is retained in accordance with the applicable agreement and the client’s documented instructions, subject to applicable legal requirements.
When personal data is no longer required, Artix will take appropriate steps to delete, anonymise or securely isolate it.
14. Your Privacy Rights
Depending on your circumstances and applicable law, you may have the following rights under the GDPR:
* Right of access: You may request a copy of personal data we hold about you.
* Right to rectification: You may request that inaccurate or incomplete personal data be corrected.
* Right to erasure: You may request deletion of your personal data in certain circumstances.
* Right to restriction: You may request that processing of your personal data be restricted in certain circumstances.
* Right to data portability: You may request your personal data in a structured, commonly used and machine-readable format where applicable.
* Right to object: You may object to certain processing, including processing based on legitimate interests and direct marketing.
* Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time.
* Rights relating to automated decision-making: You may have rights relating to certain forms of automated decision-making and profiling where applicable.
These rights are subject to conditions and exceptions established by applicable law.
15. How to Exercise Your Rights
If Artix is the Data Controller for your personal data, you may contact us using the contact details provided below.
If your personal data is being processed by Artix on behalf of an Artix client, that organisation is generally the Data Controller.
For example, if you purchased a ticket from a museum, theatre, venue, event organiser or other organisation using Artix, you should generally contact that organisation regarding your personal data and privacy rights.
Artix will provide reasonable assistance to its clients in responding to valid data-subject requests in accordance with applicable law and our contractual obligations.
If you are unsure who controls your personal data, you may contact Artix and we will help direct your request to the appropriate organisation where possible.
16. Cookies and Tracking Technologies
Our websites and services may use cookies and similar technologies.
Cookies may be used for purposes including:
* Enabling website and platform functionality;
* Maintaining security;
* Remembering preferences;
* Understanding website usage;
* Measuring performance;
* Diagnosing technical problems; and
* Improving our services.
Where required by applicable law, Artix will obtain your consent before using non-essential cookies or similar tracking technologies.
You may also manage certain cookie settings through your browser or through cookie-management tools made available on our websites.
Additional information about the cookies and tracking technologies used by Artix may be provided in our Cookie Policy.
17. Marketing Communications
Where Artix acts as Data Controller, we may use your contact information to communicate with you about Artix’s products, services, events and other relevant business information where permitted by applicable law.
Where consent is required, we will obtain consent before sending marketing communications.
You may unsubscribe from marketing communications at any time by:
* Using the unsubscribe mechanism provided in the communication; or
* Contacting us using the details provided below.
You will continue to receive essential transactional or service-related communications where necessary, even if you have opted out of marketing communications.
Where Artix acts as Data Processor, marketing communications sent through the Artix platform are carried out on behalf of the relevant Data Controller and in accordance with that organisation’s instructions and applicable law.
18. Children’s Data
Artix’s general business services are not directed specifically at children.
We do not knowingly collect personal data from children where such collection is prohibited by applicable law.
Some organisations using Artix’s technology may provide services or events intended for children or young people. In those circumstances, the relevant organisation is responsible for ensuring that appropriate legal bases, notices and safeguards are in place for the processing of children’s personal data.
19. Data Breaches
Artix maintains procedures designed to identify, investigate and respond to personal data breaches.
Where Artix acts as a Data Processor and becomes aware of a personal data breach affecting client-controlled personal data, Artix will notify the relevant Data Controller without undue delay and provide reasonable assistance as required by applicable law and the relevant agreement.
Where Artix acts as Data Controller, we will assess and respond to personal data breaches in accordance with applicable legal requirements.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to:
* Our services;
* Our data-processing practices;
* Technology;
* Applicable law; or
* Regulatory requirements.
When we make changes, we will update the “Last updated” date at the beginning of this Privacy Policy.
Where changes are material and applicable law requires notification, we will take appropriate steps to notify affected individuals.
We encourage you to review this Privacy Policy periodically to remain informed about how Artix processes personal data.
21. Contact Artix
If you have questions about this Privacy Policy or how Artix processes personal data, you can contact us at:
Artix Unipessoal, Lda.
Rua das Gáveas 41, 2
Lisboa, 1200-206, Portugal
NIPC: 519088484
Email: privacy@artix.pt
If your enquiry concerns personal data processed by Artix on behalf of one of our clients, please identify the organisation with which you interacted so that we can direct your enquiry appropriately.
22. Supervisory Authority
If you believe that your personal data has been processed in violation of applicable data protection law, you have the right to lodge a complaint with the competent data protection supervisory authority.
For Artix, the relevant Portuguese supervisory authority is:
Comissão Nacional de Proteção de Dados (CNPD)
CNPD is responsible for monitoring and enforcing compliance with data protection legislation in Portugal.
This Privacy Policy does not limit any rights you may have under the GDPR or other applicable data protection legislation.