Privacy statement

Privacy statement

This privacy statement describes how we process personal data when you use our website, create an account, order tickets, contact us via live chat or email, or request a corporate quotation. We process data in accordance with the General Data Protection Regulation (GDPR).

Last updated: 01-08-2026

1. Data controller

Zandvoort VIP Hospitality, Burgemeester van Alphenstraat 108, 2041 KP Zandvoort, the Netherlands, is the data controller. Privacy questions can be sent to privacy@zandvoort-vip.example.

2. What data we process

Account data (name, email address, phone number, password hash), order data (customer number, order number, tickets, guest names, chosen delivery method), invoicing data (address, company registration and VAT number), payment status via our payment provider, communication (live chat, email, phone notes) and technical data (IP address, device, session data and visit statistics).

3. Purposes and legal bases

Performance of the contract (order, ticket delivery, support), legal obligations (accounting and tax retention), legitimate interest (fraud prevention, security, improving the website) and your consent (marketing emails and non-essential cookies). Consent can be withdrawn at any time.

4. Guest names and tickets

Tickets are personalised per day. We therefore process the name of each guest and share it solely with the official hospitality partner and the organiser, as far as required for access. QR codes only become visible two days before the event to prevent resale and counterfeiting.

5. Recipients and processors

We share data with payment providers, our hosting party, email and chat suppliers, courier services for physical passes, hospitality partners and our accountant. Data processing agreements are in place with all processors. We never sell your data.

6. Transfers outside the EEA

Where suppliers process data outside the European Economic Area, this takes place on the basis of the European Commission's standard contractual clauses or an adequacy decision.

7. Retention periods

Invoicing and accounting data are retained for seven years (statutory tax retention). Account data are retained while your account is active and for a maximum of two years afterwards. Chat transcripts are retained for twelve months. Marketing consent is retained until withdrawal.

8. Cookies and statistics

We use necessary cookies for the cart, session and security. Analytical and marketing cookies are only placed with your consent; they help us measure visitor numbers and advertising performance. You can change your choice at any time.

9. Security

We use transport encryption (TLS), hashed passwords, role-based access control, logging of administrative actions and periodic backups. Where required, data breaches are reported to the Dutch Data Protection Authority within 72 hours.

10. Your rights

You have the right of access, rectification, erasure, restriction, data portability and objection. Requests are handled within one month. You may also lodge a complaint with the Dutch Data Protection Authority.