Skip to the content

Legal

Privacy

The short version sits on top; the binding version follows it. Both are the same rules.

The short version

We collect what an order needs and keep the record of a sale for as long as Austrian law requires. Measurement and advertising only run if you say yes, nothing from Google loads before you answer, and saying no does not change what you can buy.

Who is responsible

The Vienna Evening Company GmbH is the controller of the personal data described here. Our address and how to reach us are on the imprint page; a person answers.

We have not appointed a data protection officer, because a company of our size and kind is not required to. Write to us at the same address with any question about your data.

What we collect

To take an order: your name, email address, telephone number and billing address, and a delivery address where something physical is going to you. Your card details are handled by our payment provider and never reach our systems.

To deliver it: the tickets themselves, their history, and whether the emails we sent you arrived.

If you ask us something through a form: what you write, and the name, telephone number and email address you give us. If you write a review: the review.

To keep bookings safe: when someone tries to open a booking with a code, the attempt, its internet address and its browser, so that guessing codes can be stopped.

If you consent: measurement and advertising data, described below. If you do not, none of it is collected and everything on this site still works.

Why, and on what legal basis

To sell, deliver and support what you book, including messages on the day of an event: because it is needed to perform the contract with you (Art. 6(1)(b) GDPR).

To keep the records of a sale that Austrian tax and company law require (the Federal Fiscal Code and the Commercial Code): because the law obliges us (Art. 6(1)(c)).

To keep the site and bookings secure, to find and fix errors, to count visits with our own statistics tool, which uses no cookies and keeps no identifier of you, and to stop sending email to addresses that bounced or complained: because we have a legitimate interest in running the site safely and lawfully (Art. 6(1)(f)). You may object to this at any time.

To measure the site with Google Analytics, to record which campaign or website brought you here, to measure advertising with Google Ads, and to send the newsletter: only with your consent (Art. 6(1)(a), and § 165(3) of the Austrian Telecommunications Act for anything stored in your browser). You can withdraw it at any time; that does not affect what happened before.

Cookies

Always on, because the site cannot work without them: your basket, your booking session, and the record of the answer you gave about cookies. On the payment page, our payment provider sets its own cookies to prevent fraud.

Only with your consent to measurement: our own cookie recording which campaign or website brought you here (kept ninety days), and Google Analytics cookies (kept thirteen months). The click identifier an advertisement adds to a link is only kept if you also consented to advertising, in our cookie and in Google's advertising cookie (kept ninety days).

Our own visitor statistics use no cookies at all.

Who else receives it

Our payment provider, Stripe, to take the payment; it also screens payments for fraud under its own responsibility. Amazon Web Services, which sends our emails from Frankfurt. Cloudflare, through whose network this site is delivered and protected, so every page you open passes through it.

Where a booking is fulfilled by a venue or operator, the minimum they need to admit you or to run the booking, and never your payment details. Our tax adviser, and authorities where the law requires it.

Only where you have consented: Google, for Google Analytics and Google Ads. We never send Google your name, email address, telephone number or address. Where you have not consented, Google receives nothing at all rather than a reduced signal.

Everything else runs on our own servers.

Transfers outside the EU

Google, Cloudflare, Stripe and Amazon Web Services are US companies, and data may reach their US parent companies. Each is certified under the EU–US Data Privacy Framework, for which the European Commission has decided that the protection is adequate (Art. 45 GDPR). Their data protection terms also contain the European Commission’s standard contractual clauses, which apply if that certification ever stops covering a transfer.

How long we keep it

The record of a sale, including your name, email and billing address: seven years from the end of the year of the order, because Austrian tax and company law require it, and longer only while a dispute or an audit about it is open. Your consent record is kept with it, because a consent that cannot be proved was not obtained.

Your telephone number and any delivery address: until ninety days after your last event or delivery. Ticket files and booking codes: until twelve months after your last event. Records of the emails we sent you: thirteen months. Attempts to open a booking with a code: ninety days. Messages sent through our forms: twelve months after they are dealt with, unless they became an order.

Google Analytics data: fourteen months. Where your order was linked to a campaign or an advertisement: those details for fourteen months after the order; after that, only the kind of channel remains.

Addresses that bounced or complained, so that we never write to them again: for as long as we send email.

What you have to give us

Your name, email address, telephone number and billing address are needed to take and deliver an order; without them we cannot sell to you. Everything else is optional.

We make no decision about you by purely automated means.

Your rights

You can ask us for a copy of what we hold about you, and have it corrected, deleted, restricted or handed to you in a portable form. You can object to anything we do on the basis of our legitimate interests, and withdraw any consent. Where the law obliges us to keep a record, we keep it, restrict it to that obligation, and delete everything else. Write to the address on the imprint page and a person answers, within one month.

You can also complain to the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at), and you do not have to come to us first.

Changes

This notice was last changed on 29 September 2026.

Terms version in force today: 0.1-provisional · Questions go to the desk — a person answers.