This is an independent resale/intermediary offering and not the primary ticket provider. Package pricing may exceed the original purchase price. We are not affiliated with or endorsed by FIFA or the tournament organiser.

Legal information

Privacy Policy

Effective date: 19 June 2026

Privacy policy for VIP Tickets Access enquiries, contract records, analytics and legal rights.

1. Data Controller

The data controller is:

Põhja Konstellatsioon Hospitality OÜ

Harju maakond, Tallinn, Kesklinna linnaosa

Ahtri tn 12, 15551

Estonia

Email: info@vipticketsaccess.com

Registry code: Available upon request

VAT number: Available upon request

2. Personal Data We May Collect

Information submitted through an enquiry form

  • name;
  • email address;
  • telephone number;
  • preferred contact method;
  • country or location;
  • requested event;
  • preferred package;
  • number of guests;
  • message content;
  • other information voluntarily provided.

Contract and transaction information

  • billing details;
  • company information;
  • invoice details;
  • payment status;
  • transaction reference;
  • selected package;
  • agreed price;
  • contract records;
  • correspondence;
  • delivery information;
  • guest information where required.

Technical information

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • approximate location;
  • referral URL;
  • visited pages;
  • date and time of access;
  • cookie and analytics identifiers;
  • security and server-log information.

Communication information

We may retain emails, form submissions, telephone notes, messages, documents, and other communications exchanged in connection with an enquiry or contract.

3. How We Use Personal Data

  • respond to enquiries;
  • understand client requirements;
  • prepare an individual proposal;
  • communicate with suppliers;
  • confirm availability;
  • negotiate and conclude a contract;
  • process payments;
  • issue invoices;
  • deliver tickets or access documents;
  • provide customer support;
  • prevent fraud and misuse;
  • maintain website security;
  • comply with accounting, tax, legal, and regulatory obligations;
  • establish, exercise, or defend legal claims;
  • improve website performance;
  • measure advertising and website effectiveness where permitted.

4. Legal Bases for Processing

Steps requested before entering into a contract

We process enquiry information to respond to the user and prepare a requested proposal.

Performance of a contract

We process data required to conclude and perform an agreed transaction.

Legal obligation

We may retain transaction, accounting, tax, compliance, and contractual records where required by law.

Legitimate interests

We may process data for website security, fraud prevention, business administration, service improvement, legal claims, and communication with existing clients.

Consent

Where legally required, we rely on consent for non-essential cookies, certain analytics technologies, marketing communications, and other optional processing.

Consent may be withdrawn at any time without affecting processing carried out before withdrawal.

5. Recipients of Personal Data

We do not sell personal data.

Recipients receive only information reasonably necessary for the relevant purpose.

  • payment providers, including Stripe;
  • banks and financial institutions;
  • hosting providers;
  • email and communication providers;
  • website maintenance providers;
  • analytics and advertising providers, where permitted;
  • fraud-prevention and security providers;
  • accountants, auditors, lawyers, and professional advisers;
  • hospitality suppliers;
  • ticket or access-document providers;
  • organisers or venues where guest information is required;
  • public authorities where disclosure is legally required.

6. Payment Data

Card payments may be processed by Stripe or another authorised payment provider.

We do not normally receive or store the complete card number, security code, or full payment credentials processed directly by the payment provider.

7. International Data Transfers

Some service providers or suppliers may process data outside Estonia or the European Economic Area.

Where required, we use an appropriate transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, another legally recognised safeguard, or a permitted legal derogation.

8. Data Retention

Indicative retention periods are listed below. Data may be retained longer where required for legal proceedings, fraud investigations, regulatory compliance, or defence of legal claims.

  • unsuccessful or inactive enquiries: up to 24 months after the last meaningful communication;
  • client and contract records: for the duration of the relationship and the applicable legal limitation period;
  • invoices and accounting records: for the period required by Estonian accounting and tax law;
  • payment and fraud-prevention records: as required by the payment provider, applicable law, or legitimate security needs;
  • technical server logs: normally for a limited security and troubleshooting period;
  • consent records: for as long as necessary to demonstrate compliance.

9. Data Security

We use reasonable technical and organisational measures intended to protect personal data against unauthorised access, accidental loss, unlawful disclosure, alteration, destruction, or misuse.

No internet-based system can be guaranteed to be completely secure.

10. Individual Rights

Requests may be submitted to: info@vipticketsaccess.com

We may need to verify the requester's identity before responding.

  • request access to their personal data;
  • request correction of inaccurate data;
  • request deletion of data;
  • request restriction of processing;
  • object to certain processing;
  • request data portability;
  • withdraw consent;
  • lodge a complaint with a supervisory authority.

11. Supervisory Authority

Individuals may lodge a complaint with the Estonian Data Protection Inspectorate: Andmekaitse Inspektsioon.

12. Marketing Communications

We will not send optional direct-marketing messages without an appropriate legal basis.

Users may unsubscribe or object to marketing at any time.

13. Third-Party Links

The website may contain links to independent third-party websites.

We are not responsible for their privacy practices or content.

14. Children

Our services are intended for adults and business representatives.

We do not knowingly seek to collect personal data directly from children for the purpose of entering into hospitality transactions.

15. Changes to This Policy

We may update this Privacy Policy to reflect changes in our services, technology, legal obligations, or data-processing practices.

The current version will be published on this website with an updated effective date.