01Who we are
Tokyyy is a product of Music Reactions d.o.o., Croatia. This policy covers the consumer app and website: creating an account, linking cards, topping up, making payments, transferring tokens and contacting support.
Privacy contact: support@tokyyy.com. An event organiser may also be responsible for the data it uses to operate its event and fulfil your purchases.
02Information we process
Account and profile details. These include your email, username, full name and the details you submit in your profile. The current profile flow also asks for a phone number, date of birth, gender, country and city; a profile photo is optional.
Cards and activity. We process linked physical or virtual card identifiers, the related event or organiser, token balances, top-ups, purchases, transfers, payment references and transaction status.
Support and technical data. We process messages you send us and the device, connection, error and security information needed to run and protect the service. Information comes from you, your use of Tokyyy, participating organisers and payment providers.
03Why we use your information
To provide the service you request: account access, card linking, balance displays, top-ups, payments, transfers and related support. Where this processing is necessary for our agreement with you, the legal basis is performance of a contract.
To prevent fraud and protect service reliability: our legitimate interests in securing accounts and transactions, balanced against your rights. Records may also be retained to meet applicable accounting, tax or other legal duties.
Where we rely on consent for an optional purpose, we explain that purpose separately. You can withdraw consent without affecting earlier lawful processing. Accepting the Terms of Use is not consent to optional marketing or tracking.
04Payments and event organisers
The current consumer payment flow uses Stripe. Payment processing may involve the payment provider receiving billing and payment-card details. Tokyyy receives the information needed to reconcile the transaction, such as status, amount, currency and reference.
Organisers receive the card and transaction information needed for event services, purchases and support. Their own privacy notice applies where they decide independently how to use information.
05Sharing and international transfers
We share relevant information with providers that help deliver the service, including payment, hosting and support providers. Access is limited to the purpose of the service they perform. We may disclose information where required by law or necessary to establish or defend legal claims.
Transfers outside the European Economic Area require an applicable legal transfer mechanism, such as an adequacy decision or appropriate contractual safeguards. Contact us for information about safeguards applicable to your data.
06Retention and security
We keep information for the purposes described here and for applicable legal, accounting, dispute-resolution and security requirements. Closing an account does not necessarily erase transaction records that must be retained by law.
Retention periods depend on the data category, account status, legal duties and unresolved claims. Information should be deleted or anonymised when it is no longer needed. We use appropriate technical and organisational safeguards; no service can guarantee absolute security.
07Cookies, permissions and optional tools
The app may request device access needed for a feature you choose, such as NFC to link a supported card or photo access to upload a profile picture. You can manage device permissions in your operating-system settings; disabling a permission may limit the related feature.
Website cookies and app SDKs must be disclosed according to their actual use. Where consent is required for optional analytics or marketing, it must be obtained before those tools operate and must be withdrawable.
08Your rights and choices
Depending on the applicable law and circumstances, you may request access, correction, erasure, restriction or portability of your information, and object to certain processing. You may also withdraw consent where consent is the legal basis.
Send a request to support@tokyyy.com or use in-app Support. We may need proportionate information to verify your identity. Under the GDPR, we respond without undue delay and normally within one month; we will explain any permitted extension.
You may complain to your competent data protection authority. In Croatia, this is AZOP: azop.hr, azop@azop.hr. You do not have to contact us before contacting an authority.
09Age requirements
Eligibility to use Tokyyy and age restrictions at an event are separate. If you believe an account has been created by someone who does not meet applicable age requirements, contact support@tokyyy.com.
10Changes and contact
We will update this notice when the service or our data practices change. The published version will show its effective date, and material changes will be communicated where required.
For privacy questions or requests, contact support@tokyyy.com. If your request concerns an organiser’s separate processing, we can help identify the relevant contact.