Legal Agreements
Privacy Policy
Last Updated: 10 August 2026
1. INTRODUCTION AND SCOPE
Welcome to Salaamtix Pty Ltd ("Salaamtix", "we", "us", or "our"), ABN 12 684 007 592. We operate an online event ticketing and management platform built to serve values-led communities and organisers worldwide (the "Platform"), accessible at www.salaamtix.com and via our mobile application.
This Privacy Policy explains how we collect, use, disclose, store, and protect your personal information when you use our services. It applies to all users of the Platform globally, including event organisers, attendees, and website visitors, and covers personal data processed through our website and mobile application in all operational contexts.
This Policy is designed to comply with the following laws, among others:
- Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), as amended by the Privacy and Other Legislation Amendment Act 2024
- EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)
- UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018
- California Consumer Privacy Act 2018 (CCPA), as amended by the California Privacy Rights Act 2020 (CPRA)
- US state privacy laws including the Virginia Consumer Data Protection Act (CDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Texas Data Privacy and Security Act (TDPSA), Oregon Consumer Privacy Act (OCPA), and other applicable state privacy laws
- Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial legislation, including Quebec's Act respecting the Protection of Personal Information in the Private Sector (Law 25)
By using the Platform, you agree to the collection and use of your information as described in this Policy. If you do not agree, please do not use our services.
2. WHO WE ARE
Legal Entity: Salaamtix Pty Ltd
ABN: 12 684 007 592
Headquarters: Sydney, New South Wales, Australia
Privacy Contact: admin@salaamtix.com
Website: www.salaamtix.com
Data Controller (GDPR / UK GDPR): Salaamtix Pty Ltd is the data controller in respect of personal data processed through the Platform.
Privacy Officer (Australia and Canada, PIPEDA): Salaamtix has designated a Privacy Contact accountable for privacy compliance, including under the Australian Privacy Act and PIPEDA. All privacy enquiries should be directed to our Privacy Contact at admin@salaamtix.com.
3. PERSONAL INFORMATION WE COLLECT
3.1 Information You Provide Directly
We collect the minimum personal information necessary to provide our services. This includes:
- Account registration: first name, last name, and email address. We verify your email address (double entry) before activating your account.
- Ticket purchases: name and email address. Payment card details are handled exclusively by third-party processors (see Section 3.2).
- Additional profile information: phone number, gender and age group. These fields are used to personalise your experience on the Platform and to match you with events suited to your profile. On Salaamtix, some events are organised around age-specific or gender-specific participation, for example women-only or men-only sessions, in accordance with the format set by the relevant event organiser.
- Organiser-requested attendee information: responses to optional custom questions set by event organisers (see Section 3.3).
3.2 Payment Information
Payment data (including credit and debit card details) is processed exclusively by compliant third-party payment processors. Salaamtix does not store your full payment card number on its servers.
3.3 Organiser-Requested Attendee Information
Event organisers may include optional custom questions in the ticket registration flow (for example, dietary requirements, accessibility needs, t-shirt size, affiliation). Any information you provide in response to these questions is:
- Entirely optional unless the organiser specifies that it is required for the event
- Collected on behalf of and shared with the relevant event organiser
- Used only for the purpose for which you provided it (for example, catering arrangements)
3.4 Automatically Collected Information
When you use our website or mobile app, we may automatically collect technical and usage data, including:
- IP address, browser type and version, device type, operating system
- Pages or screens viewed, features used, access times, referring URLs
- For organisers: in-app actions including ticket scans, check-ins, attendee lookups, and data exports
We use this data to operate and improve the Platform, detect security threats, and for analytics. Where this data constitutes personal information or personal data under applicable law (for example, IP addresses are personal data under GDPR), we apply the same protections as directly-provided data.
3.5 Children's Data
The Platform permits users aged 12 and over with parental or guardian consent (see our Terms and Conditions, Section 3.1). For privacy law purposes:
- We do not knowingly collect personal information from anyone under 13 without verified parental or guardian consent.
- For EU and EEA users, the age of digital consent under GDPR Article 8 is 16 (or a lower member state threshold if established). We apply the GDPR default of 16 for EU users and seek parental consent for users below this age.
- For UK users, the age of digital consent is 13 under the Children's Code (UK Age Appropriate Design Code).
- We apply data minimisation and heightened security measures to all personal data relating to minor users.
If we become aware that a child has provided personal data without the requisite consent, we will promptly delete that data. Parents or guardians who believe their child has registered without appropriate consent should contact us at admin@salaamtix.com immediately.
3.6 Cookies and Similar Technologies
We and our service providers use cookies and similar technologies (such as local storage, software development kits and pixels) when you use the Platform. We use them in the following categories:
- Strictly necessary technologies: required to operate the Platform, keep you signed in, maintain your basket and checkout session, and protect against fraud and security threats. These cannot be switched off without preventing the Platform from working.
- Analytics and performance technologies: used to understand how the Platform is used so we can improve it.
- Organiser-configured technologies: where an event organiser has connected their own tracking or advertising tool to their event listing, that tool may set cookies or similar identifiers when you view or purchase a ticket for that event. See Section 6.7.
You can control cookies through your browser settings, including by blocking or deleting them, although disabling strictly necessary cookies may prevent parts of the Platform from functioning. Where your browser or device sends a Global Privacy Control signal, we treat it as a valid opt-out request in the jurisdictions in which that signal is recognised.
4. HOW WE USE YOUR INFORMATION
We use personal information strictly for the following purposes, consistent with the purpose limitation principle under all applicable laws. For each purpose, we identify the applicable legal basis under the key privacy frameworks that govern our processing.
4.1 Providing the Service
Creating and managing your user account; processing ticket purchases and issuing tickets (including QR codes delivered by email); enabling organisers to create, manage, and run events; and operating the mobile app for on-site ticket scanning, attendee check-in, and real-time sales management.
Legal basis (GDPR and UK GDPR): performance of a contract with you (Article 6(1)(b)). Legal basis (Privacy Act): collection is reasonably necessary for our functions and activities (APP 3).
4.2 Communications
Sending booking confirmations, e-tickets, purchase receipts, event updates and notifications (on behalf of organisers), and responses to customer support enquiries. Salaamtix does not add you to any general marketing mailing list and does not send you promotional emails about third-party products or services unless you select the marketing checkbox offered while creating an account and purchasing a ticket.
Event organisers may send broadcast communications to attendees via our platform. For example, event-day reminders, venue updates, or logistics notices. Organiser broadcasts are permitted only to attendees of that specific event. Organisers are not permitted to use our platform event broadcast feature to send marketing, promotional, or cross-event communications to attendees. If an organiser misuses this feature for unsolicited marketing, please reach out to us via admin@salaamtix.com as the organiser in breach will face account restrictions and may be removed from the platform.
Legal basis (GDPR and UK GDPR): performance of a contract with you for transactional and event-related communications (Article 6(1)(b)); your consent for optional marketing communications (Article 6(1)(a)), which you may withdraw at any time. Legal basis (Privacy Act): APP 6, and APP 7 for direct marketing, from which you may opt out at any time.
4.3 Payment Processing and Financial Records
Processing transactions, maintaining accurate financial records, computing and collecting service fees, paying out event organisers, and complying with tax, financial reporting, and accounting obligations in all jurisdictions where we operate.
Legal basis (GDPR and UK GDPR): performance of a contract (Article 6(1)(b)) and compliance with a legal obligation (Article 6(1)(c)). Legal basis (Privacy Act): APP 3 and APP 6, including where required or authorised by law.
4.4 Security, Fraud Prevention, and Legal Compliance
Monitoring for fraudulent activity, security incidents, and platform misuse; investigating suspected illegal activity; enforcing our Terms and Conditions; complying with legal obligations; and responding to lawful government or regulatory requests.
Legal basis (GDPR and UK GDPR): our legitimate interests in protecting the Platform, our users and our business (Article 6(1)(f)), and compliance with a legal obligation (Article 6(1)(c)). Legal basis (Privacy Act): APP 6, including use or disclosure required or authorised by law or reasonably necessary for enforcement-related activities.
4.5 Platform Improvement and Analytics
Analysing aggregated, de-identified usage data to improve platform features, performance, and user experience. We do not use personally identifiable information for analytics beyond what is necessary for security monitoring and incident investigation.
Legal basis (GDPR and UK GDPR): our legitimate interests in improving and securing our services (Article 6(1)(f)), and your consent where analytics technologies require consent under Section 3.6. Legal basis (Privacy Act): APP 6.
We will not use your personal information for purposes beyond those described above without your prior consent or unless required or permitted by applicable law.
5. SPECIAL CATEGORIES OF PERSONAL DATA
Certain information collected through the Platform may constitute "special category" personal data under GDPR Article 9, "sensitive information" under the Australian Privacy Act (s. 6), or similarly elevated categories under other applicable laws. In particular:
Dietary and health-related information: Information about dietary requirements (for example halal, kosher, vegan, gluten-free, nut allergies) may reveal health conditions or religious beliefs. Under GDPR Article 9, this is special category data (health data and/or data concerning religious or philosophical beliefs). Under the Privacy Act, this is sensitive information. Under the CPRA, dietary information revealing health or religious belief may constitute sensitive personal information.
Gender information: Gender is collected as a standard platform field and is used to match users with events whose format involves gender-specific attendance, for example women-only or men-only sessions. Gender is not, of itself, a special category of data under GDPR. However, because gender information on the Platform is linked to event participation and may in some circumstances allow inferences to be drawn about a user, we apply the same heightened safeguards to it as we apply to other sensitive data.
Where organisers collect sensitive information via custom questions:
- Legal basis (GDPR): We rely on your explicit consent under Article 9(2)(a). Consent is freely given, specific, informed, and unambiguous. You may withdraw it at any time without detriment.
- Legal basis (Privacy Act): Collection is with your consent and for a purpose directly related to attending the event.
- Salaamtix does not use such sensitive data for any purpose other than delivering the organiser's stated event service.
- We apply heightened technical and organisational safeguards to sensitive data: restricted access (authorised organiser team only), purpose limitation, and deletion within 12 months of the event (see Section 8).
6. HOW WE SHARE AND DISCLOSE INFORMATION
6.1 We Do Not Sell Your Personal Information
Salaamtix does not sell personal information to any third party and has never done so. Under the CCPA and CPRA, "sell" means transferring personal information for monetary or other valuable consideration, and "share" means disclosing personal information for cross-context behavioural advertising. Salaamtix does not receive monetary or other valuable consideration for personal information, and does not use personal information for Salaamtix's own cross-context behavioural advertising, retargeting, or profiling.
Where an event organiser has connected their own tracking or advertising tool to their event listing, that tool transmits data to the third-party provider the organiser has chosen. That transmission is configured by the organiser and is described in Section 6.7.
6.2 Sharing with Event Organisers
When you purchase a ticket or register for an event, we share your registration information (name, email, ticket type, purchase details, and responses to any custom questions you answered) with the relevant event organiser. Organiser teams access this data via our web platform and mobile app to verify tickets, manage check-ins, prepare attendee lists, act on optional preferences (for example, meal arrangements), and send event communications.
Event organisers determine for themselves how they use attendee information for their own purposes. In relation to that use, an organiser acts as an independent controller (or the equivalent concept under the applicable privacy law) and not as a processor acting on our behalf, and Salaamtix and the organiser are not joint controllers.
Organisers may export attendee data from our platform. Once exported, that data is in the organiser's custody. Our Terms and Conditions require organisers to handle attendee data in compliance with applicable privacy laws; however, Salaamtix cannot control the organiser's data practices outside our platform. If you have concerns about an organiser's handling of your personal information, please contact the organiser directly.
6.3 Service Providers
We engage trusted third-party service providers who process personal data in connection with our services. These include payment processors, cloud infrastructure and hosting providers, email delivery services, and customer support platforms. These providers are selected for their established privacy and security standards, and we use them only to the extent necessary to deliver our services to you.
Major third-party providers in our ecosystem, including payment processors and infrastructure providers, operate their own comprehensive privacy and data protection programs by virtue of their scale and the regulatory environments they operate in. We also ensure, through the terms of our engagement, that such providers process your data only in ways consistent with this Policy.
6.4 Business Transfers
If Salaamtix is involved in a merger, acquisition, restructuring, or asset sale, personal data may be transferred to the successor entity. We will notify you via email and/or a prominent notice on our website before any such transfer, as required by applicable law, and ensure the successor entity is bound by the privacy commitments in this Policy.
6.5 Legal Disclosure
We may disclose personal information to courts, law enforcement agencies, regulatory bodies, or other authorities where we reasonably believe disclosure is required to: comply with a legal obligation, valid court order, or lawful government request; enforce our Terms and Conditions; investigate or prevent fraud, illegal activity, or serious security threats; or protect the rights, property, or safety of Salaamtix, our users, or the public.
6.6 Aggregated and Anonymised Data
We may share data that has been fully aggregated or anonymised so that it cannot reasonably be used to identify any individual. Such data is no longer personal information. It may be shared publicly or with partners for research, industry reporting, or marketing insights.
6.7 Organiser-Configured Tracking and Advertising Tools
Event organisers may connect their own third-party tracking, analytics, or advertising tool to their event listing, for example by supplying their own Meta Pixel identifier. Where an organiser has done so, and you view or purchase a ticket for that organiser's event, information about that interaction may be transmitted to the third-party provider the organiser has selected.
In relation to those tools:
- The organiser chooses the tool, supplies their own account or pixel identifier, and determines the purposes for which the resulting data is used.
- The third-party provider processes the data it receives under its own terms and privacy policy, as an independent controller or business in its own right.
- Salaamtix does not configure these tools, does not receive their output, and does not use the resulting data for Salaamtix's own advertising, retargeting, or profiling purposes.
- Our Terms and Conditions require organisers to establish a lawful basis for this processing and to make the disclosures and obtain any consents required by applicable law.
If you wish to exercise privacy rights in relation to data collected by an organiser's tracking tool, you should contact that organiser and the relevant third-party provider directly. You may also contact us at admin@salaamtix.com and we will assist where we are able to. You can additionally limit this collection through your browser settings and, where recognised, through a Global Privacy Control signal.
7. INTERNATIONAL DATA TRANSFERS
Salaamtix is based in Australia but serves a global audience. Personal information may be transferred to and processed in countries other than your own, including Australia, the United States, the United Kingdom and the European Union, where our cloud infrastructure and service providers are located. We ensure appropriate safeguards are in place for all international transfers.
EU and EEA transfers: Australia is not the subject of a European Commission adequacy decision. Where we transfer personal data from the EU or EEA to Australia or to another country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical, contractual and organisational measures following an assessment of the destination country.
UK transfers: Where we transfer personal data from the United Kingdom to a country not covered by UK adequacy regulations, we rely on the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses, together with any additional measures identified by a transfer risk assessment.
Australian transfers: Where we disclose personal information to an overseas recipient, we take reasonable steps under Australian Privacy Principle 8 to ensure the recipient does not breach the Australian Privacy Principles, or we rely on another basis permitted under APP 8.2.
Canadian transfers: Where personal information is transferred outside Canada or Quebec for processing, we use contractual and other means to provide a comparable level of protection, consistent with PIPEDA and Quebec Law 25.
You may request further information about the safeguards applied to a specific transfer by contacting admin@salaamtix.com.
8. DATA RETENTION
We retain personal information only as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, and regulatory requirements. Our specific retention periods are:
- Account information: Retained for the duration of your active account. If you delete your account or it is inactive for 3 years, we initiate deletion from active systems within 30 days, subject to legal retention obligations below.
- Event and ticketing records (attendee lists, ticket purchase records, transaction data): Retained for 7 years from the date of the event to comply with tax and financial record-keeping obligations.
- Special category and sensitive data: Deleted or anonymised within 12 months of the relevant event, or earlier upon request, subject to no overriding legal obligation to retain.
- Payment confirmation records (transaction IDs, payment status): Retained for 7 years for financial and tax compliance.
- System logs and technical data (IP addresses, access logs): Retained for 12 months, unless required longer for security incident investigation or legal proceedings.
- Customer support communications: Retained for 2 years from the date of the last communication, unless the matter is subject to ongoing legal proceedings.
- Privacy incident records: Where privacy or data security incidents occur, records of those incidents must be maintained for a minimum of 5 years from the date of the incident, as required under Quebec Law 25 and consistent with best practice under other applicable laws.
When retention periods expire, personal information is securely deleted from our systems. In practice, this is managed through automated data lifecycle processes, being scheduled routines that identify and purge records that have passed their applicable retention period. If you request deletion before the applicable retention period has ended and we are not required by law to retain the data, we will accommodate your request. See Section 10 (Your Rights).
9. DATA SECURITY
Salaamtix implements appropriate technical and organisational measures to protect your personal information from unauthorised access, use, alteration, disclosure, or destruction. These measures include:
Encryption: All communications to and from the Platform are protected by HTTPS/TLS. Sensitive information (including passwords and payment tokens) is encrypted according to industry standards.
Access Controls: Access to personal data is restricted to authorised personnel with a documented need, subject to role-based access controls. All authorised personnel are bound by confidentiality obligations.
Security Monitoring and Assessments: We conduct regular security assessments and proactive log monitoring, and maintain security detection systems to identify and respond to threats and anomalous activity.
Payment Security: We use PCI-DSS-compliant payment processors. We do not store full payment card numbers on our systems.
Organiser and Team Access Controls: Organisers manage team member access through our platform. All team accounts require secure authentication. Access is logged for audit purposes and revoked when a team member's authorisation ends.
Privacy by Design: We embed data protection principles into all product development and operational processes, including data minimisation, purpose limitation, and privacy-protective default settings.
9.1 Data Breach Notification
We will notify relevant regulators and affected individuals of personal data breaches within the following timeframes:
- Australia (NDB Scheme): Notify the OAIC and affected individuals as soon as practicable after a data breach that is likely to result in serious harm.
- EU and EEA: Notify the relevant national supervisory authority within 72 hours of becoming aware of a notifiable breach. Notify affected individuals without undue delay where there is a high risk to their rights and freedoms.
- UK: Notify the ICO within 72 hours of becoming aware of a notifiable breach. Notify affected individuals without undue delay where there is a high risk to their rights.
- Canada (PIPEDA): Notify the Office of the Privacy Commissioner of Canada (OPC) and affected individuals as soon as feasible where a breach creates a real risk of significant harm.
- Canada (Quebec Law 25): Notify the Commission d'accès à l'information (CAI) and affected individuals promptly, and in any event within 72 hours of becoming aware of any confidentiality incident that presents a risk of serious injury.
10. YOUR RIGHTS AND CHOICES
You have rights in relation to your personal information depending on where you are located. We are committed to honouring these rights. See Section 10.7 for how to exercise them.
10.1 Australian Users (Privacy Act 1988 / APPs)
- Right of Access (APP 12): Request access to the personal information Salaamtix holds about you. We will respond free of charge within 30 days, subject to limited exceptions permitted by law.
- Right to Correction (APP 13): Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. We will take reasonable steps to correct the information and, where applicable, notify third parties to whom we disclosed it.
- Right to Opt Out of Direct Marketing (APP 7): You may opt out of direct marketing at any time by contacting us or using the unsubscribe link in any marketing communications.
- Right to Complain: Lodge a privacy complaint with us, and if you are not satisfied with our response, with the Office of the Australian Information Commissioner (see Section 10.8).
10.2 EU and EEA Users (GDPR)
- Right of Access (Article 15): Request a copy of your personal data and information about how we process it.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure (Article 17): Request deletion of your personal data where it is no longer necessary, consent is withdrawn, or processing was unlawful.
- Right to Restriction (Article 18): Request that we limit processing in certain circumstances (for example, while we verify accuracy).
- Right to Data Portability (Article 20): Receive personal data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Right to Object (Article 21): Object to processing based on legitimate interests (including profiling) at any time. The right to object to direct marketing is absolute.
- Right to Withdraw Consent (Article 7(3)): Where we rely on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Rights in Relation to Automated Decision-Making (Article 22): Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not engage in such automated decision-making (see Section 11).
- Right to Lodge a Complaint (Article 77): Lodge a complaint with a supervisory authority (see Section 10.8).
10.3 UK Users (UK GDPR / Data Protection Act 2018)
UK users have the same rights as described in Section 10.2, and may lodge a complaint with the Information Commissioner's Office (see Section 10.8).
10.4 US Users, California (CCPA / CPRA)
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the third parties with whom we share it.
- Right to Delete: Request deletion of personal information we have collected from you, subject to legal exceptions.
- Right to Correct: Request correction of inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale or Sharing: Salaamtix does not sell personal information, and does not share personal information for its own cross-context behavioural advertising. Where an event organiser has connected their own advertising tool to their event listing (see Section 6.7), you may direct an opt-out request to that organiser, and you may also contact us at admin@salaamtix.com. We honour Global Privacy Control (GPC) signals as a valid opt-out request.
- Right to Limit Use of Sensitive Personal Information: Request that we limit our use of sensitive personal information to that which is necessary to provide the services you requested. We do not use sensitive personal information for any purpose beyond necessary service delivery.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
10.5 US Users, Other States
Residents of Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Florida, and other US states with enacted privacy laws have rights substantially similar to those described in Section 10.4, including rights to access, correct, delete, opt out of targeted advertising and profiling for decisions producing legal or similarly significant effects, and appeal rights.
We honour these rights to the extent required by applicable state law. To exercise your rights under any US state law, please contact admin@salaamtix.com.
10.6 Canadian Users (PIPEDA / Quebec Law 25)
- Right of Access: Request confirmation of whether we hold personal information about you and a copy of that information. We respond within 30 days (extendable to 60 days in limited circumstances).
- Right to Correction: Request correction of inaccurate or incomplete personal information. We will notify any third party that received the incorrect information where required and practicable.
- Right to Withdraw Consent: Withdraw consent to our collection, use, or disclosure of your personal information at any time, subject to legal and contractual restrictions. We will inform you of the implications before withdrawal.
Under Quebec Law 25 (Act respecting the Protection of Personal Information in the Private Sector, as amended), Quebec residents have additional rights:
- Right to Data Portability (s. 27): Request that personal information collected from you by automated means be provided in a structured, commonly used technological format. Where technically feasible, you may request direct transmission to another organisation.
- Right to De-indexing / Cessation of Dissemination (s. 28.1): Where your personal information is being disseminated online and you believe it poses a risk of serious injury, you may request that we cease disseminating it and that any hyperlink enabling access to it be de-indexed. We will assess and respond to such requests in accordance with our obligations under Law 25.
10.7 How to Exercise Your Rights
To exercise any of the rights described above, contact us at:
Email: admin@salaamtix.com
Please clearly describe your request. We may ask you to verify your identity to ensure we do not disclose or delete data for the wrong person. Identity verification may involve confirming details we already hold (for example, the email address associated with your account, or a recent ticket reference). We will not use verification information for any other purpose.
Response timeframes:
- GDPR / UK GDPR: 30 days (extendable by 2 months for complex requests, with notice)
- CCPA/CPRA: 45 days (extendable by 45 days, with notice)
- Other US states: As required by applicable state law
- PIPEDA: 30 days (extendable to 60 days, with notice)
- Australia (Privacy Act): 30 days
We do not charge fees for most privacy rights requests. If a fee applies in limited circumstances as permitted by applicable law, we will advise you in advance. If we are unable to fulfil a request due to a legal exception, we will provide a clear written explanation.
10.8 Right to Complain to a Regulator
We would prefer to resolve your concern directly, so we ask that you contact us first at admin@salaamtix.com. You always retain the right to complain to the privacy regulator in your jurisdiction, including:
- Australia: the Office of the Australian Information Commissioner (OAIC)
- United Kingdom: the Information Commissioner's Office (ICO)
- EU and EEA: the data protection supervisory authority of the member state in which you are habitually resident, in which you work, or in which the alleged infringement took place
- Canada: the Office of the Privacy Commissioner of Canada, and for Quebec residents, the Commission d'accès à l'information
- United States: your state Attorney General, and for California residents, the California Privacy Protection Agency
11. NO AUTOMATED DECISION-MAKING OR PROFILING
Salaamtix does not engage in any automated decision-making that produces legal or similarly significant effects on individuals.
- We do not use algorithms or artificial intelligence to make decisions about access to the Platform, pricing, or service eligibility without human oversight.
- We do not build personal profiles to analyse or predict behaviour, preferences, or characteristics in ways that significantly affect users.
- All significant decisions affecting users or organisers (for example, account suspension, content removal) involve human review.
12. CHILDREN'S PRIVACY
Our Platform permits users aged 12 and over with parental or guardian consent (see our Terms and Conditions, Section 3.1). Our privacy standards for children's data are:
- We do not knowingly collect personal information from anyone under 13 without verified parental or guardian consent.
- For EU and EEA users, we apply the GDPR default age of digital consent of 16 (or a lower member state threshold where established) and seek parental consent for users below this threshold.
- For UK users, the age of digital consent is 13 under the Children's Code.
If we become aware that a child has provided personal data without the requisite consent, we will promptly delete that data. Parents or guardians should contact admin@salaamtix.com if they believe their child has registered without appropriate consent.
13. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our data practices, operational activities, technology, or legal requirements. When we make changes, we will:
- Update the "Last Updated" date at the top of this Policy
- Post the updated Policy at https://salaamtix.com/agreements?key=Privacy_Policy
- For significant changes: provide prominent notice (for example, email notification to registered users)
- Where required by applicable law: seek your fresh consent before implementing changes that affect how we process your existing personal data in a materially different way
We encourage you to review this Policy periodically. Your continued use of the Platform after we post changes constitutes acceptance of the updated Policy to the extent permitted by applicable law.
14. CONTACT US
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact our Privacy Contact:
Email: admin@salaamtix.com
(Please include "Privacy Inquiry" or "Privacy Rights Request" in the subject line)
We will acknowledge your enquiry promptly and aim to respond fully within the applicable timeframe for your jurisdiction.