Last updated: September 2026
1. Introduction
This Privacy Policy describes how Rīgas Mūzikas biedrība (the “Company”, “we”, “us”, or “our”) collects, uses, processes, stores, and protects personal data when users access or use the website biletes.okoncerts.lv, purchase tickets, register for events, or otherwise interact with our services.
The Company is committed to protecting personal data and ensuring that it is processed in accordance with applicable data protection laws, including:
- General Data Protection Regulation (EU) 2016/679 (GDPR)
- Latvian Personal Data Processing Law
- Applicable electronic communications and consumer protection legislation
This Privacy Policy applies to all users of the website, including customers, event attendees, and newsletter subscribers.
2. Data Controller
The entity responsible for processing personal data under this Privacy Policy is:
Rīgas Mūzikas biedrībaRegistration No.: 40008330326
Operating ticketing and event-related services under the OKONCERT brand
Augusta Deglava iela 1, Rīga, LV-1009, Latvia
Email: [email protected]
Phone: +371 27272735
Website: okoncerts.lv
For any inquiries related to personal data processing or data protection rights, users may contact the Company via the email address above. The Company will respond to data protection inquiries within 30 calendar days.
3. Scope of This Policy
This Privacy Policy applies to personal data collected through:
- the website biletes.okoncerts.lv
- ticket purchase and booking systems
- customer support communications
- marketing and newsletter subscriptions
- cookies and analytics technologies
- event participation and registration
It does not apply to third-party services that operate under separate privacy policies.
4. Categories of Personal Data Collected
We may collect and process the following categories of personal data.
4.1 Identity and Contact Data
Information provided directly by the user, including:
- Name and surname
- Email address
- Telephone number
- Communication preferences
4.2 Transaction and Purchase Data
Information related to ticket purchases and event participation:
- Order number and ticket details
- Event name and seat selection (if applicable)
- Payment confirmation information
- Transaction timestamps
Payment card information is not stored by the Company and is processed exclusively by certified payment providers.
4.3 Communication Data
Information contained in:
- Customer service inquiries
- Email communication
- Feedback or support requests
4.4 Technical and Usage Data
When accessing the website, certain technical information may be automatically collected:
- IP address
- Device type and operating system
- Browser type and version
- Session data and browsing behavior
- Referring pages and interaction metrics
This data helps us maintain the security, performance, and reliability of the platform.
4.5 Marketing and Subscription Data
To send information about discounts and special offers, we process:
- Email address and preferred language
- Subscription status, together with when and where it was set or changed (for example, the checkbox at checkout or an unsubscribe request)
- Campaign engagement metrics (such as email open or click statistics)
At checkout, the box “Receive information about discounts and special offers” is ticked by default. If you do not want to receive such emails, simply untick it before paying — this does not affect your purchase. You can also unsubscribe at any time, free of charge, using the link in every such email or by writing to [email protected].
5. Purposes of Processing
Personal data may be processed for the following purposes:
Service Provision
- Processing ticket purchases
- Generating and delivering electronic tickets
- Administering event registrations
Customer Support
- Responding to inquiries
- Managing ticket-related issues or requests
Platform Operation
- Maintaining website functionality
- Ensuring security and fraud prevention
Marketing and Communication
- Informing users about upcoming concerts and events
- Sending information about discounts and special offers on our own concerts to customers who have bought tickets and have not objected (see Section 6)
- Sending newsletters to subscribers who are not our customers, with their consent
Analytics and Improvement
- Analyzing website performance
- Improving user experience and services
6. Legal Basis for Processing
Personal data is processed in accordance with Article 6 of the GDPR, based on the following lawful grounds:
- Performance of a contract (Art. 6(1)(b)) — for ticket purchases and event participation
- Legitimate interest (Art. 6(1)(f)) — for customer service, fraud prevention, platform security, and service improvement
- Legitimate interest in direct marketing (Art. 6(1)(f) and Recital 47 GDPR, together with Article 13(2) of the ePrivacy Directive 2002/58/EC and Section 9(2) of the Latvian Law on Information Society Services) — for sending information about discounts and special offers on our own concerts, similar to those already purchased, to customers who have bought tickets. Customers are given a clear and simple opportunity to object, free of charge, at checkout (by unticking the box) and in every such email
- Consent (Art. 6(1)(a)) — for newsletters to people who are not our customers, and for certain cookies where required
- Legal obligation (Art. 6(1)(c)) — for accounting, tax, and other statutory compliance requirements
Where processing is based on consent, users may withdraw consent at any time. Users may object to direct marketing at any time; once we receive an objection, we stop sending marketing emails to that address.
7. Data Sharing and Processors
The Company may share personal data with trusted service providers acting as data processors, strictly for the purposes described in this Privacy Policy. These may include:
- Payment processing providers
- Cloud hosting and infrastructure providers
- Email delivery services
- Analytics providers
- Ticket distribution systems
- Messaging platforms (WhatsApp / Meta Platforms, Inc.) — where the Customer has opted in to receive tickets or notifications via WhatsApp
All processors are required to comply with GDPR and operate under Data Processing Agreements (DPA) ensuring confidentiality, security, and lawful processing.
Where tickets or notifications are delivered via WhatsApp, the Customer’s phone number and ticket information are shared with Meta Platforms, Inc., which processes this data under its own terms and privacy policy. This sharing occurs only with the Customer’s explicit opt-in consent.
The Company does not sell or rent personal data to third parties.
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards are implemented in accordance with GDPR requirements. These safeguards may include:
- Standard Contractual Clauses (SCC) approved by the European Commission
- Adequacy decisions
- Contractual, organizational, and technical security measures
Such transfers occur only where necessary for service delivery or operational continuity.
9. Data Retention
Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected. Typical retention periods include:
- Transaction and accounting data: up to 5 years or longer where required by applicable law
- Customer communications: up to 2 years
- Marketing subscription data: until the user unsubscribes, objects or withdraws consent. After that, we keep only the email address and the date of the objection, so that we do not send them marketing emails again
- Analytics data: limited retention depending on the provider and configuration used
After expiration of applicable retention periods, data is securely deleted or anonymized.
10. Cookies and Tracking Technologies
The website uses cookies and similar technologies to provide core functionality, improve user experience, and support analytics. Cookie categories may include:
- Essential Cookies — required for website operation and ticket purchasing
- Functional Cookies — remember user preferences and improve usability
- Analytics Cookies — measure traffic and user behavior
- Marketing Cookies — support campaign measurement and communication features
Non-essential cookies are only placed with the user’s prior consent, in accordance with the EU ePrivacy Directive and applicable Latvian legislation. Users may manage their cookie preferences through their browser settings. Disabling cookies may affect certain website functionality, including the ticket purchasing process.
11. Analytics and Consent
We use Umami, a privacy-focused analytics tool that we host ourselves on a server located in the European Union. Umami never shares data with third parties or advertising networks, and we do not use any third-party analytics vendor to process this data.
Before you give consent, our analytics run in a fully cookieless mode: no identifier is stored in your browser, and your IP address is not stored. We only record anonymous, aggregate statistics such as which pages were viewed.
If you accept cookies in the cookie banner, two additional cookies are set on the okoncerts.lv domain so that we can recognize repeat visits across all okoncert websites (okoncerts.lv, biletes.okoncerts.lv, and our concert galleries):
- ok_consent — records your cookie choice, kept for 12 months
- ok_uid — a random identifier with no personal information attached, kept for 13 months
When you place an order, we temporarily attach your IP address and browser (user-agent) information to the order so that the resulting purchase can be correctly matched to the visit that led to it in our statistics. This information is deleted from the order automatically as soon as the purchase has been recorded in our analytics, typically within moments of the order being confirmed.
You can decline analytics cookies at any time in the cookie banner, or withdraw your consent later by deleting cookies for the okoncerts.lv domain in your browser; our analytics will then continue to run in cookieless mode for you. Google Analytics and the Meta (Facebook) Pixel, where used, are only activated once you have given the same consent and are subject to the same choice.
12. Security Measures
The Company implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Security practices may include:
- Encrypted HTTPS communication
- Access control and authentication procedures
- Restricted administrative access
- Secure server infrastructure
- Logging, monitoring, and incident response procedures
- Internal confidentiality and access limitation measures
Access to personal data is limited to authorized personnel and service providers with a legitimate operational need.
13. Data Subject Rights
Under GDPR, individuals have the following rights regarding their personal data:
- Right of access (Art. 15)
- Right to rectification (Art. 16)
- Right to erasure — “right to be forgotten” (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object to processing (Art. 21)
- Right to object to direct marketing at any time, free of charge (Art. 21(2)–(3)) — via the unsubscribe link in any marketing email or by writing to us
- Right to withdraw consent where processing is based on consent
Requests may be submitted via email to [email protected]. We will respond to data subject requests within one (1) month of receipt, as required by GDPR Article 12(3). This period may be extended by up to two additional months where necessary, taking into account the complexity and number of requests. We may request reasonable identity verification before fulfilling such requests. Exercising these rights is free of charge, unless requests are manifestly unfounded or excessive.
14. Complaints
If a user believes that personal data has been processed unlawfully, they have the right to lodge a complaint with the competent supervisory authority. In Latvia, this authority is the Data State Inspectorate (Datu valsts inspekcija).
However, we encourage users to contact us first so that we may address any concerns promptly and professionally.
15. Third-Party Links
Our website may contain links to third-party websites or services. These services operate independently and have their own privacy policies. The Company is not responsible for the privacy practices, content, or security of such third-party services.
16. Policy Updates
The Company reserves the right to update this Privacy Policy at any time in order to reflect changes in legal requirements, technology, service providers, or operational practices. The latest version will always be available on the website together with the updated revision date.
17. Contact Information
For questions regarding this Privacy Policy or personal data processing, please contact:
Rīgas Mūzikas biedrībaRegistration No.: 40008330326
Augusta Deglava iela 1, Rīga, LV-1009, Latvia
Email: [email protected]
Phone: +371 27272735
Website: okoncerts.lv
