Teeckets legal

POPIA and PAIA

Your rights over the information we hold, who to ask, and the access-to-information manual every private body must publish.

Effective 16 September 2026
This page covers the Protection of Personal Information Act, 2013 (POPIA) and the Promotion of Access to Information Act, 2000 (PAIA). For what we collect day to day and why, read the Privacy Policy.

Who you are dealing with

Teeckets is an online event ticketing and event management platform operated by Kanvas Creative Solutions in South Africa. We sell tickets on behalf of the organiser who lists an event, and we collect and settle the money for those ticket sales.

  • Trading nameTeeckets (www.teeckets.co.za)
  • Operated byKanvas Creative Solutions
  • Registration number2019/136304/07
  • Physical addressto be completed, South Africa
  • Support emailsupport@teeckets.co.za
  • Legal and privacy emaillegal@teeckets.co.za
  • Telephoneto be completed
  • Support hoursMonday to Friday, 09:00 to 17:00 (SAST), excluding public holidays
  • CurrencyAll prices and payouts are in South African Rand (ZAR)

1. Responsible party and information officer

Kanvas Creative Solutions, trading as Teeckets, is the responsible party for personal information processed on the platform. An event organiser is a responsible party for the guest and attendee information they bring into it.

  • Information officerto be completed
  • Emaillegal@teeckets.co.za
  • Telephoneto be completed
  • Postal and physical addressto be completed, South Africa
  • Registered with the RegulatorAs required by section 55(1) of POPIA

The information officer deals with POPIA requests, PAIA requests, complaints and dealings with the Information Regulator.

2. Why we are allowed to process your information

Every use of personal information on Teeckets rests on one of these grounds in section 11 of POPIA:

  • Performance of a contract - selling you a ticket, delivering it, admitting you, paying the organiser.
  • Legal obligation - tax, company and consumer-protection records; responding to lawful demands.
  • Legitimate interests - fraud prevention, platform security, debt and chargeback recovery, and keeping the service working, where these do not override your rights.
  • Consent - optional extras such as marketing, or a gallery photo you choose to submit. You may withdraw consent at any time, and we stop that processing.
  • Protection of a legitimate interest of the data subject - for example telling ticket holders that an event has been cancelled.

We do not process special personal information (health, religion, biometrics, criminal history) or children's information for our own purposes. If an organiser needs it for their event, that is their responsibility and they must have the authority POPIA requires.

3. How we meet the eight conditions

  • Accountability. The information officer is answerable for compliance.
  • Processing limitation. We collect the minimum a ticket sale needs, lawfully and from you wherever possible.
  • Purpose specification. Each category is collected for a stated purpose and kept only as long as the retention schedule allows.
  • Further processing limitation. We do not repurpose your information into something unrelated to the reason it was given.
  • Information quality. You can correct your details in your account, and we act on correction requests.
  • Openness. This page, the Privacy Policy and the PAIA manual say what we hold and why.
  • Security safeguards. Access control, encrypted transport, private directories, server-side calculation, monitoring, and operator contracts with our providers.
  • Data subject participation. The request process below.

4. Your rights

  • Ask whether we hold personal information about you, and ask for a copy.
  • Ask us to correct or delete information that is wrong, misleading, out of date, excessive or unlawfully held.
  • Object, on reasonable grounds, to processing based on legitimate interests.
  • Withdraw consent where the processing rests on consent.
  • Object to direct marketing at any time, and not receive unsolicited electronic marketing.
  • Not be subject to a decision based solely on automated processing that significantly affects you. Teeckets does not make such decisions.
  • Complain to the Information Regulator, and to go to court.

Exercising a right is free, except that a fee prescribed under PAIA may apply to a request for access to records.

5. Making a request

  1. Write to the information officer at legal@teeckets.co.za, or post to the address above.
  2. Say what you want - access, correction, deletion, objection or withdrawal of consent - and give enough detail to find the records: the email address used, order references or the event.
  3. Prove who you are. We ask for identification so that we do not hand someone's ticket history to a stranger. Do not send passwords or full card numbers.
  4. We respond. Acknowledgement within five business days. A decision within 30 days, which POPIA and PAIA allow us to extend once, with reasons.

The prescribed forms are in the PAIA manual below: Form 2 for access to a record, and the POPIA forms for objection (Form 1), correction or deletion (Form 2) and a complaint to the Regulator (Form 5).

We may refuse a request where the law requires or permits it - for example where a record must be kept for tax, where releasing it would reveal someone else's personal information, or where a request is manifestly excessive. We give reasons, and you may complain to the Regulator.

6. PAIA manual

Section 51 of the Promotion of Access to Information Act requires every private body to publish a manual explaining what records it holds and how to request them. Ours covers the company's details, the information officer, the records kept, the request procedure, the prescribed fees and the remedies if a request is refused.

↓ Download the PAIA manual PDF, 264 KB · updated 16 September 2026

A printed copy may be requested from the information officer at the address above, and one is lodged with the Information Regulator. The manual is available in English.

7. Records we hold

The categories a PAIA request can ask about:

  • Organiser records - account and contact details, verification documents, events, ticket types, payout accounts and payout history.
  • Buyer and attendee records - orders, tickets, PINs, scan and attendance records, contact details supplied at checkout.
  • Payment records - amounts, methods, gateway references, proofs of payment, refunds, chargebacks and the payout ledger.
  • Communications - transactional email and SMS, contact-form messages and support correspondence.
  • Technical records - access, security and error logs.
  • Company records - those kept under the Companies Act, the Income Tax Act, the Value-Added Tax Act, the Basic Conditions of Employment Act and similar legislation, where applicable.

8. Sending information outside South Africa

Some providers - hosting, email delivery, error monitoring - process information outside the Republic. Section 72 of POPIA allows this where the recipient is bound by rules giving comparable protection, where you consent, or where the transfer is necessary to perform our contract with you. We rely on contract terms with those providers, and pass on no more than the service needs.

9. Security compromises

If personal information is accessed or acquired by an unauthorised person, section 22 of POPIA requires us to notify the Information Regulator and the people affected as soon as reasonably possible. Our notice will describe what happened, the likely consequences and what we and you can do about it.

10. The Information Regulator

You may complain to the Regulator at any time, whether or not you have complained to us first. We would rather hear from you first, but that is your choice.

Questions about this document?

Email or