Dahomey Series
EventsAboutFAQContactShop
Dahomey Series

find your way back

I agree to receive marketing emails under GDPR. See our Privacy Policy.

Social
InstagramFacebookTikTok
Pages
HOMESHOPABOUT USCONTACT US
Legal
COOKIE POLICYPRIVACY POLICYREFUND POLICYTERMS OF SERVICE
2026© Dahomey Series··Organizer login

Privacy Policy

Last updated: July 2026

Dahomey Series - dahomeyseries.com

Last updated: July 17, 2026

1. WHO WE ARE

Controller:

Part-time (secondary) sole entrepreneur (mellekfoglalkozasu egyeni vallalkozo), registered under the flat-rate taxation scheme (atalanyadozas)

Tax number (adoszam): 56837319-1-43

Budapest, Hungary

Email: connect@dahomeyseries.com

Full legal identity and registered address are available on request to NAIH, contractual partners, or data subjects exercising their rights, and are not published publicly on this website for privacy and safety reasons. This does not limit your rights under GDPR; see Section 8 for how to exercise them.

This Privacy Policy explains how the controller identified above, operating Dahomey Series ("we", "us"), collects, uses, stores, and shares your personal data when you visit dahomeyseries.com, purchase tickets or shop items, attend our events, or sign up to our newsletter. It should be read alongside our separate Cookie Policy, which governs cookies and similar tracking technologies in detail.

We are established in Hungary. Our supervisory authority is the Nemzeti Adatvedelmi es Informacioszabadsag Hatosag (NAIH), Falk Miksa utca 9-11, 1055 Budapest, Hungary - naih.hu.

On the Data Protection Officer (DPO): We have assessed that we are not required to appoint a DPO under Article 37 GDPR. While we process special-category health data (allergy/dietary information under Section 4.3), this processing is occasional, event-specific, small in volume, and not our core activity - it therefore does not meet the "large scale" threshold that triggers mandatory DPO appointment. We will reassess this position if our processing scope changes materially.

No customer accounts: All purchases are processed as guest checkouts. We do not offer customer account creation or login, and we do not store a persistent customer profile beyond the order and contact data listed in Section 4 below.

2. LEGAL FRAMEWORK

We process personal data in accordance with:

  • Regulation (EU) 2016/679 (General Data Protection Regulation - GDPR)

  • Act CXII of 2011 on the right to informational self-determination and freedom of information (Hungarian Privacy Act)

  • Act C of 2003 on Electronic Communications, Section 155 (cookie consent)

  • Hungarian Government Decree 45/2014 (II.26.) on distance consumer contracts

3. WHO CAN USE OUR SERVICES

Our website, ticketing, and events are intended for individuals aged 18 and over. We do not knowingly collect personal data from minors. If we become aware that a minor has provided personal data without appropriate consent, we will delete it promptly. If you believe a minor has submitted data to us, contact connect@dahomeyseries.com.

4. DATA WE COLLECT, WHY, AND ON WHAT LEGAL BASIS

4.1 Ticket Purchases and Shop Orders

Data collected: Name, email address, phone number, billing address (street, city, postcode, country), payment provider transaction IDs, order totals, currency, VAT, refund records, IP address, browser user-agent string, Terms acceptance timestamp, marketing opt-in flag and timestamp.

Purpose: To process your order, issue your ticket or invoice, deliver purchased items, handle refunds, and prevent fraud or abuse.

Legal basis:

  • Article 6(1)(b) GDPR - performance of a contract - for all data necessary to fulfill your purchase.

  • Article 6(1)(c) GDPR - legal obligation - for invoice and financial records, retained under Act C of 2000 on Accounting (Section 169) and Act CL of 2017 on the Rules of Taxation.

  • Article 6(1)(f) GDPR - legitimate interest - for IP address, browser user-agent, and automated fraud/bot-detection signals (including those generated by our security processor, CHEQ AI Technologies) logged at checkout, used exclusively to enforce rate limits and detect fraudulent or abusive activity. This does not involve decisions producing legal or similarly significant effects on you within the meaning of Article 22 GDPR.

All purchases are processed as guest checkouts - we do not require or offer account creation. We do not store your full card number; payment is processed directly by Stripe on its secure, PCI-DSS-compliant infrastructure.

4.2 Event Attendance and Ticket Check-In

Data collected: Name, email address, phone number, organisation name, ticket code, check-in timestamp.

Purpose: To manage event entry, verify ticket validity, and produce attendance records. This data is tied to your order/ticket, not to a customer account, since we do not offer accounts.

Legal basis: Article 6(1)(b) GDPR - performance of a contract.

4.3 Dietary Requirements and Allergies

Data collected: Free-text allergy or dietary information provided voluntarily during ticket checkout or event application.

Purpose: To ensure your safety and comfort at events where catering is provided.

Legal basis: Article 9(2)(a) GDPR - explicit consent. This is special-category health data. You are not required to provide it. If you do, you are giving explicit consent for us to use it solely for catering and safety purposes. You may withdraw this consent at any time by contacting connect@dahomeyseries.com. We delete allergy data within 30 days after the relevant event concludes.

4.4 Event Applications (Exclusive Access and Guest Passes)

Data collected: Name, email, phone, organisation, title, answers to application form questions, review notes, opt-in flag, claim token.

Purpose: To review and process applications for exclusive access or guest passes.

Legal basis: Article 6(1)(a) GDPR - consent. Retained for six months after the outcome of your application, or until you request deletion, whichever comes first.

4.5 Newsletter and Marketing Email

Data collected: Name and email address; consent timestamp and source.

Purpose: To send you news, event announcements, and promotional content about Dahomey Series and our online shop.

Legal basis: Article 6(1)(a) GDPR - consent. Withdraw consent anytime via "Unsubscribe" in any email or by emailing connect@dahomeyseries.com. Withdrawal does not affect the lawfulness of processing before withdrawal.

4.6 Contact Form and Email Enquiries

Data collected: Name, email address, message content.

Purpose: To respond to your enquiry.

Legal basis:

  • Article 6(1)(b) GDPR where your enquiry relates to an existing or prospective contract (e.g., order or ticket questions).

  • Article 6(1)(f) GDPR - legitimate interest - for general enquiries not tied to a contract, since responding to messages you send us is a reasonable and expected activity that does not override your rights.

We retain correspondence for the duration of the matter plus any applicable limitation period.

4.7 Website Analytics

Currently no analytics cookies or tools are active on our site. If we activate analytics in future, it will only occur after you give consent via our cookie banner, and this policy and our Cookie Policy will be updated in advance. See our Cookie Policy for current status and details.

Legal basis (when activated): Article 6(1)(a) GDPR - consent.

4.8 Advertising (Meta Pixel / Conversions API)

We intend to integrate Meta advertising tools. These tools are only activated once you have given marketing consent via our cookie banner. When active:

  • Meta Pixel places the fbp (and, where applicable, fbc) cookie on your device and sends event data to Meta Platforms Ireland Ltd.

  • Meta Conversions API may transmit hashed versions of your email address and IP address to Meta from our server.

  • Joint controllership: We and Meta Platforms Ireland Ltd. act as joint controllers solely for the collection and transmission of data via the Pixel to Meta; Meta's subsequent independent use of that data (e.g., ad personalization across its own platforms) is carried out under Meta's own separate controllership. As required by Article 26(2) GDPR, a summary of the essence of this arrangement - including which party handles which categories of data subject requests - is available on request by emailing connect@dahomeyseries.com. Meta's own terms are at facebook.com/legal/terms/dataprocessing.

  • Data is transferred to the United States under the EU-US Data Privacy Framework (adequacy decision, July 2023).

Important note on this transfer mechanism: Following a June 2026 US Supreme Court ruling affecting the independence of the US Federal Trade Commission (a body central to DPF oversight), the advocacy group noyb has announced a new legal challenge and has called on the European Commission to reconsider the adequacy decision. The Framework remains legally valid as of this update, but if it is suspended or invalidated, we will transition to Standard Contractual Clauses (SCCs) or another valid transfer mechanism and will update this policy without undue delay.

Legal basis: Article 6(1)(a) GDPR - consent. Withdraw marketing consent anytime via the cookie preference link in our footer.

5. WHO WE SHARE YOUR DATA WITH

We do not sell your personal data. We share it only with the processors and joint controllers below, each bound by a Data Processing Agreement or equivalent legal instrument.

1-Recipient: Stripe Payments Europe Ltd.

  • Role: Processor

  • Purpose: Payment processing

  • Location: Ireland (EU) + US

  • Transfer safeguard: EU-US Data Privacy Framework

2-Recipient: Brevo (Sendinblue SAS)

  • Role: Processor

  • Purpose: Email delivery, CRM, newsletter

  • Location: France (EU)

  • Transfer safeguard: EU adequacy (intra-EU)

3-Recipient: Meta Platforms Ireland Ltd.

  • Role: Joint controller (when Pixel active)

  • Purpose: Advertising measurement

  • Location: Ireland (EU) + US

  • Transfer safeguard: EU-US Data Privacy Framework

3- Recipient: CHEQ AI Technologies

Role: Processor

  • Purpose: Bot and fraud detection at checkout/site level

  • Location: Hetzner Online GmbH (Germany / European Union)

  • Transfer safeguard: EU Standard Contractual Clauses (SCCs)

4- Recipient: Sentry (Functional Software Inc.)

  • Role: Processor

  • Purpose: Error monitoring (when configured)

  • Location: US

  • Transfer safeguard: EU-US Data Privacy Framework

5- Recipient: Hetzner Online GmbH

  • Role: Processor

  • Purpose: Infrastructure, data storage

  • Location: Germany (European Union)

  • Transfer safeguard: EU adequacy (intra-EU)

We may also disclose data to competent authorities (courts, law enforcement, tax authorities) where required by Hungarian or EU law.

6. INTERNATIONAL DATA TRANSFERS

Some processors are located in or transfer data to the United States. We currently rely on the EU-US Data Privacy Framework for Stripe, Meta, and Sentry. This mechanism is under active legal review as of mid-2026 following developments affecting the US Federal Trade Commission. We monitor developments and will switch to alternative safeguards (such as Standard Contractual Clauses) if the Framework is suspended, and will notify affected users via this policy and, where material, by email.

7. HOW LONG WE KEEP YOUR DATA

  • Data category: Invoices, order financial records
    Retention period: 8 years from end of the financial year (Hungarian Accounting Act, Section 169)

  • Data category: VAT records
    Retention period: 5 years from the year of the VAT return filing

  • Data category: Attendee contact and ticket data
    Retention period: 2 years after the event, unless you request earlier deletion

  • Data category: Allergy / dietary data
    Retention period: Deleted within 30 days after the relevant event

  • Data category: Newsletter subscriber data
    Retention period: Until you unsubscribe, then deleted promptly

  • Data category: Application data
    Retention period: 6 months after application outcome, or earlier on request

  • Data category: Contact / enquiry correspondence
    Retention period: Duration of matter plus applicable limitation period

  • Data category: IP / user-agent, fraud-detection signals (checkout)
    Retention period: Rolling 30-90 days

  • Data category: Error logs (Sentry)
    Retention period: 30-90 days, per project settings

  • Data category: Cookie consent records
    Retention period: 12 months (see Cookie Policy, Section 5)

Where a legal retention obligation applies (e.g., accounting records), we cannot delete that data earlier even on request. We will inform you if this is the case.

8. YOUR RIGHTS

Under GDPR, you have the following rights:

- Access (Article 15): Request a copy of the personal data we hold about you.

- Rectification (Article 16): Ask us to correct inaccurate data.

- Erasure (Article 17): Ask us to delete your data, where no legal retention obligation applies.

- Restriction of processing (Article 18): Ask us to limit processing while a dispute is resolved.

- Data portability (Article 20): Receive your data in a machine-readable format, where processing is based on contract or consent.

- Object (Article 21): Object to processing based on legitimate interest.

- Withdraw consent (Article 7(3)): Withdraw any consent at any time, without affecting the lawfulness of prior processing.

- Not be subject to solely automated decision-making with legal or similarly significant effects (Article 22): We do not currently make any such decisions about you.

How to exercise your rights: Email connect@dahomeyseries.com with your name, contact details, and a description of your request. Since we do not operate customer accounts, we may ask you to verify your identity by confirming details tied to a specific order or ticket (e.g., order number, email used at checkout) before fulfilling access, rectification, or erasure requests. We will respond within one calendar month, extendable by two further months for complex requests, in which case we will inform you of the extension and reasons.

Complaints: You may lodge a complaint with NAIH (naih.hu; Falk Miksa utca 9-11, 1055 Budapest, Hungary), or, if you reside in another EU/EEA member state, with your own national supervisory authority.

9. COOKIES

We use cookies and similar technologies on this website. Essential/strictly necessary cookies (including our fraud-detection tooling from CHEQ AI Technologies) are exempt from consent under Hungarian law and are active by default. Certain strictly necessary cookies (e.g., next-auth cookies) relate solely to our internal admin/staff dashboard login and are never set for customers, since we do not offer customer accounts. All other cookies - analytics and marketing - are only placed after you give explicit consent via our cookie banner, with "Reject non-essential" given equal visual prominence to "Accept all." Full details, including cookie names, durations, and providers, are in our Cookie Policy.

Stripe may set cookies on its own domain (stripe.com) during payment, governed by Stripe's own privacy and cookie policies.

10. SECURITY

We implement appropriate technical and organisational measures to protect your personal data, including:

- HTTPS encryption in transit

- Passwords stored as bcrypt hashes for internal admin/staff logins only - we do not offer customer accounts or passwords, and we never store plaintext passwords

- Encryption of sensitive API keys at rest

- Access controls limiting data access to authorised personnel only

- Automated bot and fraud detection at checkout via CHEQ AI Technologies

In the event of a personal data breach posing a risk to your rights and freedoms, we will notify NAIH within 72 hours and, where required, notify you directly without undue delay.

11. CHANGES TO THIS POLICY

We may update this policy from time to time, including in response to legal or regulatory developments (such as changes to the EU-US Data Privacy Framework). The "Last updated" date at the top of this page reflects the most recent revision. Material changes will be communicated to newsletter subscribers by email.

For questions or to exercise your rights: connect@dahomeyseries.com