Who operates viaqui.com
- Company name
- TIXELLO S.R.L.
- Tax identification number (CUI)
- 54166771 · not registered for VAT
- Trade Register number
- J2026014682005
- Registered office
- Str. Mihai Eminescu nr. 22, Camera 1, Ploiești, jud. Prahova, 100329
- contact@viaqui.com
- Phone
- 0750 292 962 · Monday to Friday, 09:00 - 18:00
1.Who we are and what this policy covers
The viaqui.com platform is operated by TIXELLO S.R.L., with the identification details above. For the data processed through the platform (accounts, orders, tickets, the points programme, support, operator signup), TIXELLO S.R.L. is the data controller within the meaning of Regulation (EU) 2016/679 (GDPR).
The activities listed on viaqui.com are offered by their operators (venues, organisers, guides). When you buy a ticket, the operator of the activity receives the data it needs in order to welcome you and becomes, for that data, an independent data controller (see the section "Who we share data with").
For any question about your data, write to us at contact@viaqui.com, with the subject "Personal data".
2.What data we collect
- The customer account: your name, email address, phone number, password (kept only in encrypted, irreversible form), communication preferences and, if you add it, your date of birth (for the birthday bonus).
- Orders: the activities, the date and time booked, the type and number of tickets, the names of the ticket holders (if you fill them in), the billing details (name or company, tax identification number, address), the amounts, the payment method and the payment status. You enter your card details directly with the payment processor: we do not see them and do not keep them. For saved cards we receive from the processor only the card type, the last digits and the expiry date.
- Access to the activity: the status of the ticket and the moment it was scanned at the entrance.
- Points, invitations and gift cards: your points balance and history, your invitation code and the accounts created through it, the balance and use of gift cards.
- Reviews: the rating, the text and the photos you publish.
- Support: the messages sent through the contact form, by email or through the support tickets in your account.
- Newsletter: your email address, preferences and the date you subscribed.
- Operators (partners): the data in the signup form (name, email, phone, the name and city of the venue, the website, what you need, your message), the tax identification number (CUI) and the company data taken from the public register of the Romanian National Agency for Fiscal Administration (ANAF), the operator account data (representative, bank details, uploaded documents, the contract) and the partner pages visited before signup (through a session identifier and the parameters of the campaign you came from).
- Technical data: IP address, browser and device type, pages visited, security and error logs, cookies and similar technologies, described in the Cookie policy.
The data comes from you, from your use of the platform, from the payment processor (payment confirmation), from the operator of the activity (ticket scanning) and, for companies, from the public ANAF register.
3.Why we use the data and on what legal basis
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| The account, sign-in and its settings | Performance of the contract (para. 1 letter b) |
| Orders, payment, issuing and sending tickets, access to the activity | Performance of the contract (letter b) |
| Tax documents and accounting records | Legal obligation (letter c) |
| Support, complaints, cancellations and refunds | Performance of the contract (letter b) and legal obligation (letter c) |
| The points programme, invitations and gift cards | Performance of the contract (letter b) |
| Newsletter and commercial messages | Consent (letter a), which you can withdraw at any time |
| Personalised recommendations on the site | Consent to personalisation cookies (letter a) |
| Analytics (Google Analytics) and campaigns (Meta, Google Ads and TikTok pixels) | Consent to analytics and marketing cookies (letter a) |
| Security, prevention of fraud and abuse, aggregate audience measurement, improving the platform | Legitimate interest (letter f) |
| Operator signup, the operator account and the partnership contract | Steps prior to entering into the contract and its performance (letter b) |
| Checking the company in the public ANAF register | Legitimate interest (letter f): we work only with real, active companies |
| Establishing, exercising or defending legal claims in court | Legitimate interest (letter f) |
We do not make decisions based solely on automated processing that produce legal effects concerning you. Activity recommendations are simple suggestions.
4.Who we share data with
We do not sell your data. We share it only as far as needed, as follows:
- The operator of the activity you bought for: your name and the names of the ticket holders, the contact details in the order, the tickets, the date and time of the booking and the check-in status. The operator uses them to organise the activity and for its legal obligations.
- The payment processor (currently Stripe) and, for cultural cards, the card issuer, for collecting the payment and keeping it secure.
- Infrastructure providers: hosting and servers, Cloudflare (page delivery and protection against attacks), transactional email providers (for example Brevo), map services (CARTO and OpenStreetMap receive the IP address when a map loads).
- Analytics and advertising (Google, Meta, TikTok), only if you have accepted analytics or marketing cookies. If the operator of the activity uses the Meta Conversions API, the confirmation of a purchase may reach Meta with the contact details irreversibly encrypted (hashed), for measuring the operator's campaigns.
- GetYourGuide, a partner whose offers appear on some pages: when you open a GetYourGuide offer, their privacy policy applies.
- Advisers (accounting, legal), bound by confidentiality.
- Authorities (for example ANAF, courts, investigative bodies), when the law requires us to.
The providers that process data on our behalf do so under a contract, only on our instructions and with appropriate security measures.
5.Transfers outside the European Economic Area
Some providers (for example Stripe, Google, Meta, Cloudflare) may also process data outside the European Economic Area, including in the United States. Transfers are made only with the safeguards required by the GDPR: the adequacy decision of the European Commission (the EU-U.S. Data Privacy Framework, for certified companies) or standard contractual clauses approved by the Commission.
6.How long we keep the data
- The customer account: for as long as it is active. If you delete it, the profile data is deleted or anonymised, and the orders stay in the accounting records.
- Orders, tax and accounting documents: up to 10 years, as required by financial and accounting legislation.
- Tickets and scans: for as long as we keep the order they belong to.
- Support and complaints: up to 3 years after the request is closed.
- Newsletter: until you unsubscribe (the link is in every email).
- Points: until they expire, under the rules of the programme.
- Operator signups without an active account: up to 2 years after the last interaction.
- Technical and security logs: up to 12 months.
- Cookies: as set out in the Cookie policy.
At the end, the data is deleted or anonymised, except for data that the law requires us to keep longer or data needed in an ongoing dispute.
7.Your rights
Under the GDPR, you have the right:
- to find out what data we hold about you and to receive a copy of it (access);
- to correct data that is wrong or incomplete (rectification);
- to ask for it to be deleted, when there is no longer a legal reason for us to keep it (erasure);
- to ask for processing to be restricted, in the cases provided for by law;
- to receive the data in a structured format and to pass it on to another controller (portability);
- to object to processing based on legitimate interest and, at any time, to direct marketing;
- to withdraw your consent, without affecting the processing carried out until then;
- to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, Bucharest, www.dataprotection.ro.
You can do much of this directly from your account: under Settings you change your details, download your data and delete your account. For the rest, write to us at contact@viaqui.com. We reply within one month at most; for complex requests the deadline can be extended by a further two months, in which case we let you know. We may ask for additional information to confirm that the request comes from you.
8.How we protect the data
We use encrypted connections (HTTPS), passwords kept only in encrypted form, role-based access to data, two-step sign-in (optional, from Settings), payments through PCI DSS certified processors, backups and access monitoring. If an incident that may affect your data does occur, we notify the ANSPDCP within 72 hours and we also notify you when the risk is high.
You help us too: keep your password to yourself and do not publish your tickets or QR codes, because anyone who has them can get in instead of you.
9.Minors
A customer account can be created from the age of 16. For younger children, tickets are bought by a parent or guardian, who fills in only the necessary details about the child (for example the name on the ticket or the age category).
10.Cookies and similar technologies
We use cookies that are necessary for the platform to work and, only with your consent, analytics, personalisation and marketing cookies. The details and the settings are in the Cookie policy. You can change your choice at any time, from the Cookie settings link at the bottom of any page.
11.Changes to this policy
We update the policy when what we do with the data, or the law, changes. The date of the last update appears at the top of the page. We tell you about important changes by email or through a message on the platform.































































