Last updated: 08 August 2026
1. Data Controller
This Privacy Policy describes how Foreningen Rock' In House processes personal data in connection with our products, services, websites, ticket sales, events and other activities.
The data controller for the processing of personal data covered by this Privacy Policy is:
Foreningen Rock' In House
CVR no.: 25879295
Jens Holms Vej 5
6000 Kolding
Denmark
Email: godsetnet@kolding.dk
Foreningen Rock' In House is the data controller for the processing of personal data described in this Privacy Policy.
We use data processors to assist with the provision and operation of our products and services, including ticketing systems, payment solutions, IT systems and other technical services. Where a supplier processes personal data on our behalf, this is done solely on our instructions and pursuant to a data processing agreement where required under applicable data protection legislation.
Where an external organiser is an independent data controller for the processing of personal data, that organiser is responsible for its own processing of personal data.
If you have any questions about our processing of personal data or wish to exercise your rights under data protection legislation, you are welcome to contact us using the contact details above.
2. Purposes of Processing Personal Data
We process personal data only for the purposes described in this Privacy Policy, where necessary to provide our products and services, comply with our legal obligations, or develop and improve our activities.
Depending on your interaction with us, we may process personal data for the following purposes:
We do not process personal data for purposes that are incompatible with the purposes for which the data was originally collected, unless permitted by applicable law or you have given your consent.
3. Personal Data We Process
The personal data we process depends on how you use our products, services and Digital Services.
We may process the following categories of personal data:
We process only the personal data necessary for the purposes described in this Privacy Policy.
4. How We Collect Personal Data
We collect personal data in different ways depending on how you use our products, services and Digital Services or otherwise interact with us.
We may collect personal data:
Where possible, we endeavour to collect personal data directly from you. If we receive personal data from sources other than you, we ensure that the processing is carried out in accordance with applicable data protection legislation.
5. Personal Data from Customer Accounts and Digital Services
If you create a Customer Profile or use our Digital Services, we may process additional personal data beyond the information necessary for an ordinary ticket purchase.
This may include:
We process this information only to the extent necessary to provide, administer, maintain, develop and protect our Digital Services.
6. Legal Basis for Processing
We process personal data only where there is a valid legal basis under the General Data Protection Regulation (GDPR).
Depending on the purpose of the processing, we rely on the following legal bases:
Performance of a contract (Article 6(1)(b) GDPR)
Where processing is necessary to complete ticket purchases, deliver tickets, administer your Customer Profile, administer your membership or otherwise perform a contract with you.
Legal obligation (Article 6(1)(c) GDPR)
Where we are required to process or retain personal data under applicable law, for example under accounting and bookkeeping legislation.
Legitimate interests (Article 6(1)(f) GDPR)
Where processing is necessary to administer, operate, develop, protect and improve our products, services and Digital Services, provide customer service, administer memberships and member communications, prevent misuse or pursue other legitimate interests, provided that your interests or fundamental rights do not override those interests.
**7. Newsletters in Connection with Ticket Purchases
**
If, in connection with a ticket purchase, you choose to subscribe to a newsletter, it will be clearly stated which newsletter you are subscribing to and who the data controller for that newsletter is.
If you subscribe to Godset's newsletter, Kolding Municipality is the data controller for the processing of your personal data in connection with the newsletter.
You may withdraw your consent to a newsletter at any time, for example by using the unsubscribe link in the newsletter you receive.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Further information about the processing of your personal data is provided in the Privacy Policy applicable to the newsletter to which you have subscribed. For Godset's newsletter, this information is provided in Godset's Privacy Policy.
Withdrawal of consent to a newsletter does not mean that you will cease to receive necessary service communications concerning events for which you have purchased tickets, or invitations to evaluations and customer surveys relating to those events.
8. Use of Third-Party Systems and Digital Integrations
In order to provide, administer, develop and protect our products and services, we use a number of third-party systems and digital integrations.
These systems may be used for:
Where a supplier processes personal data on our behalf, this is done solely on our instructions and pursuant to a data processing agreement in accordance with applicable data protection legislation.
We endeavour to use suppliers and partners that we consider to meet applicable information security and data protection requirements.
9. Recipients of Personal Data
We disclose personal data to others only where necessary to provide our products and services, comply with a legal obligation or where we otherwise have a lawful basis for the disclosure.
Access to personal data is limited to persons authorised to process the data and to relevant suppliers, partners and advisers where necessary to provide, administer or develop our products and services.
Where a supplier processes personal data on our behalf, this is done solely on our instructions and pursuant to a data processing agreement in accordance with applicable data protection legislation.
Personal data may also be disclosed:
to payment providers in connection with the processing of payments
to public authorities where required by law or pursuant to a valid request from a public authority
to auditors, lawyers or other professional advisers where necessary for our operations or to comply with legal obligations
to other recipients where there is a lawful basis for the disclosure
We may also process or disclose personal data where necessary to comply with applicable law, comply with a court decision or an order from a public authority, or protect our rights.
10. Data Processors
We use data processors to assist with the provision, administration, operation, development and maintenance of our products and services.
A data processor processes personal data solely on our behalf and in accordance with our instructions. The data processor may not use personal data for its own purposes.
We enter into data processing agreements with data processors where required under applicable data protection legislation. These agreements include requirements concerning confidentiality, information security and the protection of personal data processed on our behalf.
We require our data processors to process personal data securely and in accordance with applicable data protection legislation.
11. Transfers to Third Countries
If personal data is transferred to a country outside the EU/EEA (a third country), this will only take place in accordance with applicable data protection legislation and on the basis of a lawful transfer mechanism.
Where required, we ensure that the transfer is protected by, for example, the European Commission's Standard Contractual Clauses, an adequacy decision or another lawful transfer mechanism under data protection legislation.
12. Retention Periods
We do not retain your personal data for longer than necessary for the purposes for which it was collected and processed.
If you have purchased a ticket or used our products or services, your personal data will be retained for as long as your Customer Profile remains active.
A Customer Profile is considered active where activity is recorded on an ongoing basis, for example through:
purchases of tickets or other products and services
logging into your Customer Profile
updating your Customer Profile information
If no activity is recorded on your Customer Profile for a continuous period of 3 years, your personal data will be anonymised in accordance with our agreement with the ticketing system's data processor.
Information processed as part of a membership will be retained for as long as the membership continues and thereafter only for as long as necessary for documentation or other lawful purposes.
Certain personal data may be retained for a longer period where required by applicable law. Information concerning payments and accounting transactions is retained for 5 years in accordance with applicable bookkeeping legislation.
13. Your Rights
Under data protection legislation, you have a number of rights in relation to our processing of your personal data. These include the right to:
access the personal data we process about you
rectification of inaccurate or incomplete personal data
erasure of your personal data where the applicable conditions are met
restriction of processing of your personal data where provided for by data protection legislation
object to our processing of your personal data where the processing is based on our legitimate interests
receive or have transferred personal data that you have provided to us where the conditions for data portability are met
If you wish to exercise one or more of your rights, you are welcome to contact us. We will deal with your request as soon as possible and in accordance with applicable data protection legislation.
If we are unable to comply with your request, we will inform you of the reasons and of your options for lodging a complaint.
Not all rights apply in every situation. The extent of your rights depends on the specific processing and applicable data protection legislation.
14. Automated Decision-Making and Personal Recommendations
We do not make automated decisions about you that have legal or similarly significant consequences for you.
In connection with ticket sales and the use of our Digital Services, we may use information about previous purchases or activities to provide relevant recommendations about our own events and activities.
Such recommendations are used solely to improve the user experience and make it easier to find events that may be of interest to you.
15. Security
We process personal data confidentially and continuously work to ensure that it is processed securely and responsibly.
We have implemented appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised access, disclosure or other processing contrary to applicable data protection legislation.
Access to personal data is limited to persons authorised to process the data as part of their role and only to the extent necessary.
We impose corresponding requirements on data processors that process personal data on our behalf, including through data processing agreements where required under applicable data protection legislation.
We continuously assess whether our security measures are appropriate in relation to the personal data we process and the risks associated with the processing.
16. Changes to the Privacy Policy
We reserve the right to update this Privacy Policy from time to time where necessary as a result of changes in legislation, our processing of personal data or our products and services.
In the event of material changes, we will make the updated Privacy Policy available on our website.
The date on which the Privacy Policy was last updated will always be stated at the top of the Privacy Policy.
17. Complaints to the Danish Data Protection Agency
If you are dissatisfied with the way in which we process your personal data, you are always welcome to contact us. We will do our best to respond to your enquiry and address any questions or concerns.
If you continue to believe that our processing of your personal data does not comply with data protection legislation, you have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet).
Information on how to lodge a complaint and the contact details of the Danish Data Protection Agency are available on the Danish Data Protection Agency's website.
18. Contact Details
If you have any questions about this Privacy Policy or our processing of your personal data, you are welcome to contact us.
Data Controller
Foreningen Rock' In House
Jens Holms Vej 5
6000 Kolding
Denmark
CVR no.: 25879295
Email: godsetnet@kolding.dk
We recommend that enquiries concerning personal data are made in writing so that we can handle and document your enquiry as effectively as possible.
We will respond to your enquiry as soon as possible and in accordance with applicable data protection legislation.