skip to events
tonik. VOLUME_
tonik.partner
sign in.
my tickets saved cart
sign in.

PRIVACY POLICY

ИП Алексанян Гайк Давидович (Individual Entrepreneur Aleksanyan Gaik Davidovich)

Effective Date: 9 October 2026 Version: 1.0


1. INTRODUCTION

This Privacy Policy explains how ИП Алексанян Гайк Давидович (Individual Entrepreneur Aleksanyan Gaik Davidovich) ("Tonik," "we," "us," or "our"), an individual entrepreneur registered in the Russian Federation — INN 262413169817, OGRNIP 324861700116764 — with its registered address at ul. Razdolnaya 8, Khanty-Mansiysk, KhMAO — Yugra, Russia (INN 262413169817 · OGRNIP 324861700116764 · Registered address: ul. Razdolnaya 8, Khanty-Mansiysk, KhMAO — Yugra, Russia), collects, uses, discloses, transfers, and retains personal data in connection with the website at tonik.events and related services (the "Platform").

This Policy is issued in compliance with the Federal Law No. 152-FZ "On Personal Data" of Russia ("152-FZ") and constitutes our Personal Information Collection Statement for the purposes of Data Protection Principle 1(3). Where applicable, it also addresses our obligations under the Personal Data Protection Act B.E. 2562 (2019) of Thailand ("PDPA"), Law No. 27 of 2022 on Personal Data Protection of the Republic of Indonesia ("PDP Law"), the Privacy Act 1988 (Cth) of Australia, and Regulation (EU) 2016/679 ("GDPR") where you are located in the European Economic Area or the United Kingdom.

Data Controller. ИП Алексанян Гайк Давидович (Individual Entrepreneur Aleksanyan Gaik Davidovich) is the data controller in respect of personal data processed for the operation of the Platform. Where an Organiser separately determines the purposes for which attendee data is used — for example, when sending marketing communications to its own audience — that Organiser acts as an independent controller in respect of that processing.


2. PERSONAL DATA WE COLLECT

2.1 Data You Provide Directly

Category Data When collected
Contact Email address At checkout; when signing in
Identity Name; attendee names you assign to individual tickets At checkout; when personalising tickets
Billing Billing name and address, where required by the payment method At checkout
Order communications Contents of support enquiries and correspondence When you contact us
Refund instructions Destination wallet address for digital asset refunds When requesting a refund
Organiser account data Name, business details, contact details, team member details, payout details On Organiser registration
Organiser uploads Images, video, and event content uploaded to the Platform, including any personal data contained within them When an Organiser configures an event
Bug reports Page URL, browser details, and the reporting user's email address When a bug is reported from the Organiser console

2.2 Data Collected Automatically

Category Data Purpose
Device and connection IP address, browser type and version, operating system, device type, screen and viewport dimensions, language and locale settings Security, fraud prevention, responsive display
Usage Pages viewed, events viewed, checkout steps commenced and completed, timestamps, referring URL Service operation, analytics, conversion measurement
Authentication Session identifiers, cryptographically signed order-access authorisations stored as cookies, signed resume links Order access control and account security
Time zone Device time zone, determined in your browser Display of event times in your local time

2.3 Payment Data

We do not collect, receive, process, or store full payment card numbers, card expiry dates, or card security codes. Card data is captured directly by our payment processor within secure elements embedded in our checkout and is transmitted to that processor without passing through our systems. We receive only a payment reference, the last four digits of the card, the card brand, the transaction outcome, the amount, and the currency of charge.

Where you pay in digital assets, we process the blockchain network selected, the token selected, the deposit address generated for your transaction, the transaction hash, the amount received, and — where you connect a wallet — the public address of that wallet. Blockchain transaction data is recorded on a public, permanent, and immutable ledger which we do not control and from which data cannot be erased.

2.4 Data We Do Not Collect

We do not knowingly collect: government identification numbers from ticket buyers; biometric data; data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, or sexual orientation; or personal data of children under the age of eighteen (18).

We do not record checkout sessions. Session replay is disabled across the Platform, and specifically within payment pages.


3. HOW AND WHY WE USE PERSONAL DATA

Purpose Data used Legal basis (GDPR, where applicable)
Processing your ticket purchase and issuing tickets Contact, identity, billing, payment reference Performance of a contract
Sending transactional communications (order confirmation, tickets, receipts, invoices, refund notices, reservation reminders, material event changes) Contact, identity, order data Performance of a contract
Providing customer support Contact, order data, correspondence Performance of a contract; legitimate interests
Verifying access to orders and tickets Authentication data, contact Performance of a contract; legitimate interests in security
Processing refunds Order data, wallet address or payment reference Performance of a contract
Preventing fraud, abuse, and automated ticket purchasing Device and connection, usage, order data Legitimate interests; legal obligation
Investigating reports of unrequested authentication codes Contact, authentication data Legitimate interests in account security
Screening against sanctions and restricted-party lists Identity, contact, country data Legal obligation; legitimate interests
Measuring and improving the Platform Usage, device data Legitimate interests; consent where cookies are used
Advertising measurement and conversion attribution Usage data, hashed identifiers Consent only
Providing attendee lists to the Organiser of an event you attend Name, email, ticket quantity Legitimate interests; performance of a contract
Complying with legal, tax, accounting, and regulatory obligations All categories as required Legal obligation
Establishing, exercising, or defending legal claims All categories as required Legitimate interests; legal obligation

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your interests or fundamental rights. You may object to such processing as described in Section 8.


4. DISCLOSURE OF PERSONAL DATA

We disclose personal data only as set out below. We do not sell personal data, and we do not disclose personal data to third parties for their own independent marketing purposes.

4.1 Event Organisers

When you purchase a ticket, we disclose your name, email address, and the number and category of tickets purchased to the Organiser of that event. The Organiser requires this data to administer admission, to manage capacity, and to communicate with attendees about the event.

The Organiser is an independent data controller in respect of that data. Its use of your data — including any marketing communications it sends — is governed by its own privacy policy and by its obligations under applicable law. We require Organisers to comply with applicable data protection law, but we do not control their processing. Marketing communications sent by an Organiser through the Platform must include an unsubscribe mechanism and are subject to frequency limits.

4.2 Service Providers

The following processors receive personal data in order to provide services to us. Each is engaged under a written agreement restricting its use of that data to the provision of the relevant service.

Category of recipient Service Data disclosed Regulatory status
Card and local payment method processing Card payments and the local methods offered at checkout, including Visa, Mastercard, MIR and SBP Payment card data, which is collected directly by the processor and never reaches our systems; transaction amount and currency; email address; billing details; device and fraud signals Licensed payment institution or money transmitter in each jurisdiction in which it operates; PCI DSS Level 1 certified
Digital asset infrastructure and custody Deposit addresses, on-chain settlement and custody of stablecoin payments Deposit addresses, transaction hashes, transaction amounts, order references Licensed or registered for the custody activity it performs in its home jurisdiction
Email delivery Transactional email and Organiser messages sent through the Platform Email address, name, message content, delivery and engagement metadata Data processor under a GDPR-compliant Data Processing Agreement
Database and application hosting Storage and hosting of Platform data All stored Platform data Data processor; SOC 2 Type II
Product analytics Aggregate usage measurement Usage events, device and connection data, pseudonymous identifiers Data processor; session recording disabled
Business verification (KYB/KYC) Identity and business verification of Organisers and their directors and owners, performed by the payment providers above as required by financial regulation Legal names, dates of birth, residential addresses, phone numbers, identity document data and document images, company registration documents, ownership information Same licensed payment institutions as above; data supplied only where verification requires it
Automated document reading One-time automated extraction of form fields from a verification document (for example a passport or company registration) uploaded by the person completing verification, used solely to prefill the form that person then reviews and confirms The uploaded document image, transmitted once for extraction; the extraction output is returned to the uploader's browser and is not itself retained by us AI infrastructure provider engaged as a data processor under a Data Processing Agreement; inputs are not used to train models

We do not sell personal data and we do not disclose it to any recipient outside these categories except as set out in this Policy or where the law requires it. If you wish to know the identity of a specific processor engaged in any of these categories, contact us using the details in section 14 and we will tell you.

4.3 Advertising and Measurement Partners — Consent Only

Where, and only where, you have given consent through our cookie banner, we transmit conversion and usage events to the following platforms, using identifiers supplied by the Organiser of the relevant event:

  • Meta Platforms, Inc. (Meta Pixel)
  • TikTok Technology Limited (TikTok Pixel)
  • Google LLC (Google Analytics 4; Google Ads conversion tracking)

These platforms act as independent or joint controllers in respect of the data they receive. Their processing is governed by their own privacy policies. If you do not consent, no data is transmitted to any of them and no advertising or analytics cookie is set.

Organisers may supply only the numeric or alphanumeric identifier of their advertising account. Organisers cannot inject arbitrary script into the Platform. This restriction exists to prevent a compromised Organiser account from executing code within a buyer's checkout session.

4.4 Other Disclosures

We may disclose personal data:

(a) where required by law, court order, subpoena, or binding request of a competent regulator or law enforcement authority; (b) where necessary to establish, exercise, or defend legal claims; (c) to our professional advisers, auditors, and insurers, under obligations of confidentiality; (d) to a banking, custody, or payment partner conducting due diligence on Tonik, to the extent necessary and in aggregated or minimised form wherever possible; (e) in connection with a merger, acquisition, financing, or sale of assets, subject to the recipient being bound to treat the data in accordance with this Policy; and (f) where you have expressly consented.


5. INTERNATIONAL TRANSFERS

Tonik is established in the Russian Federation. Our service providers are located in a number of jurisdictions, including the United States, the European Union, and Singapore. Your personal data will therefore be transferred outside your country of residence.

Where personal data is transferred out of a jurisdiction that restricts such transfers, we rely on one or more of the following safeguards:

(a) Standard Contractual Clauses approved by the European Commission, incorporated into our agreements with processors; (b) your explicit consent, where obtained and where permitted as a transfer basis; (c) the necessity of the transfer for the performance of our contract with you; or (d) contractual undertakings equivalent to those recommended by the Russia Privacy Commissioner for Personal Data.

You may request further information about the safeguards applied to a particular transfer by contacting privacy@tonik.events.


6. RETENTION

Data Retention period Basis
Order and transaction records Seven (7) years from the date of the transaction Russia tax and companies legislation; accounting requirements
Ticket and admission records Two (2) years following the event Dispute resolution; chargeback windows
Contact and account data Duration of the account, plus two (2) years Contract; dispute resolution
Support correspondence and bug reports Three (3) years from closure Dispute resolution; service improvement
Marketing consent records Duration of the consent, plus three (3) years following withdrawal Evidence of consent
Analytics data Twenty-six (26) months Data minimisation
Server and security logs Twelve (12) months Security; incident investigation
Authentication codes Ten (10) minutes, or until invalidated by use, by five incorrect attempts, or by report Security; data minimisation
Signed resume links Forty-eight (48) hours after the end of the associated reservation Security; data minimisation

Data is deleted or irreversibly anonymised at the expiry of the applicable period, unless a longer period is required by law or the data is subject to a legal hold.

Blockchain records cannot be deleted. Transactions settled on a public blockchain are permanently recorded on that network. Deletion of our records does not and cannot remove data from any blockchain.


7. SECURITY

We maintain technical and organisational measures appropriate to the risk. Our security controls were last subject to a full internal review in August 2026. Current measures include:

Data in transit and at rest

  • Encryption of data in transit using industry-standard transport layer security.
  • Capture of payment card data exclusively within processor-hosted secure elements, so that card data does not traverse our systems.

Access to orders and tickets

  • Cryptographically signed, expiring authorisations for access to individual orders, such that knowledge of an order identifier alone does not permit access. A request without valid authorisation returns a "not found" response, so that order identifiers cannot be enumerated.
  • One-time-code verification of email address before disclosure of order data. A code is invalidated after five (5) incorrect attempts.
  • A reporting mechanism in every authentication email allowing a recipient to invalidate all outstanding codes for their address and alert our team.
  • Irreversible locking of the ticket delivery address once the associated email address has been verified, so that a person who obtains an order identifier cannot redirect issued tickets.
  • Time-limited signed links for resuming an order on another device, expiring forty-eight (48) hours after the associated reservation ends.

Transaction integrity

  • Server-side calculation and validation of all prices, fees, and totals, with client-supplied amounts disregarded.
  • Verification of cryptographic signatures on inbound notifications from our payment and custody providers.
  • A single live payment instruction per order, with any superseded instruction cancelled, so that a change of payment method cannot result in a duplicate charge.

Accounts

  • Password hashing using scrypt with per-user salts for Organiser accounts.
  • Two-factor authentication for Organiser and team accounts.
  • Role-based access control and least-privilege administrative access.
  • Administrative interfaces protected by separate authentication and not exposed on public routes.

Uploads

  • Restriction of uploaded files to permitted image and video formats, with enforced size limits.
  • Server-generated file names and strict path validation, preventing directory traversal.

General

  • Rate limiting and abuse detection.
  • Development and diagnostic interfaces disabled in the production environment.

No system is entirely secure. We do not warrant absolute security. You are responsible for maintaining the security of the email account through which your tickets are delivered and your orders are accessed.


8. YOUR RIGHTS

Subject to the law applicable to you, you have the following rights:

Right Description
Access To be told whether we hold personal data about you and to receive a copy
Correction To have inaccurate or incomplete data corrected
Erasure To have data deleted where it is no longer necessary, where consent is withdrawn, or where processing is unlawful
Restriction To have processing restricted while a dispute about accuracy or lawfulness is resolved
Objection To object to processing based on legitimate interests, and to object at any time to direct marketing
Portability To receive data you provided in a structured, commonly used, machine-readable format
Withdrawal of consent To withdraw consent at any time, without affecting the lawfulness of prior processing
Complaint To lodge a complaint with a supervisory authority

To exercise a right, contact privacy@tonik.events. We will respond within thirty (30) days, or within any shorter period required by other applicable law. We may require verification of your identity before acting, and may charge a fee for access requests where permitted by law.

Limitations. Certain rights are qualified. We may decline erasure where retention is required for tax, accounting, anti-money-laundering, or legal-claim purposes. We cannot erase, alter, or reverse data recorded on a public blockchain.

Supervisory Authorities

  • Russia: Office of the Privacy Commissioner for Personal Data — pcpd.org.hk
  • Thailand: Office of the Personal Data Protection Committee
  • Indonesia: Ministry of Communication and Digital Affairs
  • Australia: Office of the Australian Information Commissioner — oaic.gov.au
  • EEA / UK: the supervisory authority of your country of residence

9. COOKIES

Our use of cookies and similar technologies is described in the Cookie Policy. Non-essential cookies, including all analytics and advertising cookies, are set only where you have given consent, and consent may be withdrawn at any time through the cookie preferences control on the Platform.


10. MARKETING COMMUNICATIONS

Transactional messages — order confirmations, ticket delivery, receipts, invoices, refund notifications, reservation reminders, and notices of material change to an event you have booked — are sent as part of the performance of your purchase contract. These are not marketing and cannot be opted out of while you hold a valid ticket or an active reservation.

Organiser communications — an Organiser may send messages to attendees of its own event through the Platform, including pre-event information and promotional material. Such messages identify the Organiser, are subject to frequency limits, and include an unsubscribe mechanism. Unsubscribing from one Organiser's communications does not affect others.

Tonik marketing — we will send you marketing about Tonik only where you have opted in, or where permitted by applicable law on the basis of an existing customer relationship. Every such message includes an unsubscribe link.


11. CHILDREN

The Platform is not directed to persons under the age of eighteen (18), and we do not knowingly collect personal data from such persons. If we become aware that we have collected personal data from a person under eighteen, we will delete it promptly. If you believe we hold such data, contact privacy@tonik.events.


12. AUTOMATED DECISION-MAKING

We use automated processing for fraud detection, abuse prevention, and sanctions screening. These processes may result in an order being declined or an account being suspended. Where a decision producing legal or similarly significant effects is taken solely by automated means, you may request human review by contacting privacy@tonik.events.


13. CHANGES TO THIS POLICY

We may update this Policy from time to time. The current version and its effective date are published on the Platform. Where a change materially affects how we use your personal data, we will provide notice by email or by prominent notice on the Platform before the change takes effect, and will obtain fresh consent where consent is the applicable legal basis.


14. CONTACT

ИП Алексанян Гайк Давидович (Individual Entrepreneur Aleksanyan Gaik Davidovich) the Russian Federation INN 262413169817 · OGRNIP 324861700116764 · Registered address: ul. Razdolnaya 8, Khanty-Mansiysk, KhMAO — Yugra, Russia

Privacy and data protection: privacy@tonik.events General enquiries: /help on the Platform, or help@tonik.events

tonik.events
legal /privacy policy /help /contacts /ticket terms /for organisers /
instagram help@tonik.events
© 2026 tonik. — ИП Алексанян Гайк Давидович · ИНН 262413169817 18+

ИП Алексанян Гайк Давидович · ИНН 262413169817 · ОГРНИП 324861700116764 · ХМАО — Югра, г. Ханты-Мансийск, ул. Раздольная, д. 8 · help@tonik.events

Tonik distributes event tickets via the Ticketscloud ticketing system under a distributor agreement and is not the producer or promoter of any event listed. Tonik is not a bank, and does not provide banking, custody, investment, or money transmission services to users.

Digital assets are volatile and transfers on public blockchains are irreversible. Send only the asset and network shown at checkout, from a wallet you control.

cookies.

we need a few essential cookies so sign-in, checkout and your tickets work. optional analytics show us which shows people look for — only if you say yes. details in our privacy policy.

you can change this any time from the footer.
tonik. supportonline — replies instantly
hey — tonik. support here. ask about any event on sale, your order or a refund — we answer fast.
faq →
support chat · humans reply by email