Data Processing Addendum between the Organizer and OMA
Version 2026-10 — published: 1 October 2026
The organizer controls its buyers' data and OMA processes it only on the organizer's instructions, with security, breach notice and deletion duties.
Scope and parties
This addendum covers the personal data of the organizer's ticket buyers, attendees and invitees processed through the platform. The organizer is the "controller" and OMA is the "processor" under Personal Data Protection Law No. 151 of 2020. It forms part of the organizer agreement (annex 4-A), which prevails in case of any difference.
Details of processing
- Data: what the organizer asks its buyers for at purchase, such as name, email, phone and answers to its questions, plus order and ticket details and check-in records.
- Purpose: issuing and sending tickets, checking them at the gate, transactional messages about the event, and reports for the organizer.
- Duration: the term of the agreement, then 30 days for download, then deletion, with backups purged within a further 90 days. System, access and connection logs are kept for 180 days under Law No. 175 of 2018.
- Location: servers rented from Contabo GmbH in Germany.
OMA's obligations as processor
- Process only on the organizer's written instructions. The organizer's dashboard settings and the agreement count as such instructions.
- Not use the data for any other purpose, and not sell it.
- Not move it to OMA's back-office system or anywhere else, except as aggregated counts and technical identifiers that identify no person.
- Protect it with reasonable security measures: encrypted connections, limited access, backups and a log of administrative actions.
- Not disclose it except under a reasoned judicial order or a legal obligation, in line with Article 2 of Law No. 175 of 2018.
- Keep a record of processing, and allow the organizer and the competent authority to verify compliance.
- Help the organizer technically, as far as the platform allows, to answer data subjects' requests.
- Delete the data when the agreement ends, within the periods above.
The organizer's obligations as controller
- Have a legal basis for each processing, and a privacy notice for its buyers that covers OMA's processing and the transfer of data to servers outside Egypt.
- Obtain the necessary consents, including marketing consent through a separate, unticked box.
- Not collect payment card data, sensitive data, or data of persons under 18 without the explicit written consent of the person or their guardian.
- Receive and answer data subjects' requests.
- Make the notifications the law requires of it in case of a breach.
Sub-processors
- Contabo GmbH: server hosting, in Germany.
- An email delivery provider, if the organizer uses the platform's mail server instead of its own.
- A provider for storing encrypted backups.
OMA informs the organizer of any material change to this list, and the organizer may object. Payment providers are chosen and contracted directly by the organizer and are not OMA's sub-processors.
Security breaches
OMA informs the organizer within 24 hours of becoming aware of any breach affecting its data, with what the organizer needs to notify the competent authority within 72 hours and the people affected within three working days, under Article 7 of the Personal Data Protection Law. Each party makes the notifications required of it.
Anonymised aggregate data
OMA may use aggregated data that has been anonymised so that no one can be re-identified, and that identifies no person or organizer, to improve the service and produce statistics.
Fingerprint of this text: 299325a3db9f2342