Skip to content
Sign in

Privacy policy

How we process personal data, on what legal basis, and what rights you have.

This English version is provided for convenience. The German version is legally binding. Last updated: September 2026

Controller

Hoiss GmbH, Laßnitzthal 384/5, 8200 Gleisdorf, Austria. Email: office@onyx-graz.at

No data protection officer has been appointed, as there is no legal obligation to do so.

What we process

When you buy a ticket: the first and last name of each person a ticket is bought for, the buyer's email address, the order details (event, category, price, time) and your confirmation that the minimum age is met. For a table reservation, additionally the party size and the drinks ordered in advance.

At the door: the moment your ticket is scanned.

For a promoter account: name, email address, password (stored only as a hash), your confirmation that you are of age, your links, the tickets sold through them, your coin balance and your vouchers.

When you contact us through a form or by email: your message and your sender address.

Technically: when you visit the website, the IP address, browser and time in the server logs; if an error occurs on the website, an error report with technical details about the browser and the page requested.

Payment details such as card numbers are entered directly with our payment provider. They never reach us; we only learn whether a payment succeeded.

Purposes and legal bases

Processing your order, delivering tickets, checking them at the door, issuing refunds and running the promoter programme are necessary to perform the contract with you (Art 6(1)(b) GDPR).

Retaining invoice and accounting data fulfils legal obligations (Art 6(1)(c) GDPR, § 132 of the Federal Fiscal Code, § 11 of the VAT Act).

Operating and securing the website, detecting errors and abuse, and enforcing the house rules rest on our legitimate interests (Art 6(1)(f) GDPR).

Your name is passed on to the promoter whose link you buy a ticket through only with your explicit consent (Art 6(1)(a) GDPR). Consent is voluntary, does not affect the price, and can be withdrawn at any time via the link in your order confirmation.

Recipients and processors

We share your data only as far as operating the website and processing your order requires, and only with service providers contractually bound to our instructions: for hosting the website and the database, sending ticket and system emails, storing photographs, and recording technical errors.

Payment is handled by the payment provider Stripe, where you enter your payment details directly; Stripe is independently responsible for that data.

Some service providers are based outside the EU. Transfers rest on an adequacy decision of the European Commission or on its standard contractual clauses, and data is processed in data centres in the EU wherever the provider offers it. On request we will name the providers we use.

Promoters receive the names of their guests only with those guests' explicit consent, never email addresses. Authorities receive data only where we are legally obliged to provide it.

Cookies and local storage

This website sets no advertising or analytics cookies and uses no tracking services. A cookie banner is therefore not required.

Only strictly necessary storage is used: a session cookie while you are signed in; a cookie remembering your chosen language; your basket in your browser's local storage; and, during payment, the payment provider's fraud-prevention cookies. The legal basis is § 165(3) of the Telecommunications Act 2021 together with Art 6(1)(b) and (f) GDPR.

Retention

Order, ticket and invoice data: seven years from the end of the calendar year of the booking (§ 132 of the Federal Fiscal Code). Orders are not deleted after the event; they are kept only for accounting, refunds and enquiries.

Unpaid reservations in the basket: at most 30 minutes.

Promoter accounts: until the account is deleted. Coins expire twelve months after they are credited, drink vouchers six months after they are issued; the coin ledger itself is kept as an accounting record for seven years.

Error reports: 90 days. Server logs: a few days.

Photographs: until we remove them or you ask us to.

Your consent to passing your name to a promoter: as long as the related ticket is stored, as proof.

Photography in the club

Photographs are taken in the club and published on this website and, where applicable, on our social media channels. This is signposted at the entrance.

The legal basis is our legitimate interest in documenting and promoting our events (Art 6(1)(f) GDPR), with due regard to the protection of personal images (§ 78 of the Copyright Act). We do not publish images that expose or embarrass a person.

If you are identifiable in a published photograph and want it removed, a message to office@onyx-graz.at is enough. We remove the photograph promptly, and within one month at the latest.

Your rights

You have the right of access (Art 15 GDPR), rectification (Art 16), erasure (Art 17), restriction of processing (Art 18), data portability (Art 20) and objection (Art 21), and the right to withdraw any consent you have given at any time (Art 7(3)).

Send requests to office@onyx-graz.at. We answer within one month and may ask for proof of your identity. Data we are legally required to keep can only be deleted once the retention period has ended.

Right to complain

You may lodge a complaint with the Austrian Data Protection Authority: Barichgasse 40–42, 1030 Vienna, www.dsb.gv.at.