Skip to content

Your data

Privacy policy

This policy explains which personal data may be processed when you visit the website, send an enquiry or deliberately activate third-party content.

Editorial status: 8 September 2026

Controller

The controller responsible for data processing is DJ Robinho, proprietor Robin Kolb, Carrer de S’Illot 13, 07400 Alcúdia, Spain.

Email: info@dj-robinho.com

Booking and contact enquiries

We use the information in your enquiry to check availability, understand your event, prepare a proposal and communicate with you. As a rule you receive an automatic confirmation email at the address you provided shortly after submitting; it repeats your name, the event type, date and location of your enquiry.

The first contact includes event type, date or flexibility, location, guest count, name and email address. We also collect the preferred contact method and a phone number that is optional for email but required when phone or WhatsApp is selected. Planned start and end timings, music styles, technical areas and requirements, and a message are optional details used for quote and event planning.

The legal basis is Article 6(1)(b) GDPR for pre-contractual steps and contract performance. Where a statutory retention obligation applies, Article 6(1)(c) GDPR also applies.

Technical delivery and server data

When the site is opened, the IP address, time, requested URL, referrer, browser and device information may be processed technically. This supports secure delivery, stability and abuse detection. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the secure and reliable operation of the website. The website is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA; server functions currently run in the Washington, D.C. (USA) region, static content is delivered through a global network. Transfers to the USA rely on EU standard contractual clauses (Article 46 GDPR) and, where the certification is in place, on the EU-US Data Privacy Framework. According to its documentation, Vercel keeps access logs only briefly for troubleshooting and abuse prevention.

Optional analytics and performance data

After your consent we additionally count how often the pages of this website are opened. Only the following are processed: the page path without its query string, the language version, the country derived at the network entry point, a traffic-source group (search engine, social network, direct visit or referring domain — never the full referring address), a coarse device category (phone, tablet, computer) and the time during which the page was visible, plus whether the enquiry button was pressed, a service was selected, the enquiry form was started or submitted, or an external video was approved — only the category, never form contents. Your IP address and your browser identification are not stored; they only feed a visitor key built with a random value that is generated fresh each day. That random value is deleted the following day, which makes recognising you beyond a single day technically impossible. No cookies are set and no individual visit histories are shown; the evaluation consists solely of daily totals. Countries are named individually, even when only a single view came from a country on a given day. Views inside the admin area are not counted, and the data is not passed on to third parties.

After your explicit consent, we enable Vercel Web Analytics and Speed Insights. Page views, referrers, approximate region, device and browser information, technical Web Vitals and only the following interaction categories may then be processed: an enquiry-action click, the selected event format, moving to the second form step, the submission result and approval of an external video. Names, email addresses, phone numbers, event locations, dates, messages and internal enquiry IDs are never sent as analytics events. According to Vercel, Web Analytics uses no cookies and stores anonymised data; your choice is stored locally in your browser.

The legal basis is Article 6(1)(a) GDPR. You can withdraw consent at any time through the privacy settings with effect for the future. Web Analytics and Speed Insights remain disabled until you make a choice. Our own visitor count sets no cookies and stores nothing on your device; only your choice itself is stored there so that it still applies on your next visit.

External content and communication services

Embedded videos, maps, social or scheduling content loads only after your consent or a deliberate action. Approved Google reviews are instead delivered from our own system, so viewing them creates no direct connection to Google. Only the link to the original opens Google.

Depending on the content you activate, this may include YouTube and Google services, Instagram and WhatsApp from Meta, Spotify, Vimeo and Calendly. External links open the relevant provider’s website, where that provider is independently responsible for further processing.

Where consent is required, the legal basis is Article 6(1)(a) GDPR. You can withdraw consent at any time with future effect. Editorially approved Google reviews are published on the basis of Article 6(1)(f) GDPR; our legitimate interest is to provide a verifiable account of genuine customer experience. You may object to this processing on grounds relating to your particular situation.

Recipients and processors

Data is shared only with service providers needed for hosting, email, communication or the specific event delivery, and with participating partners when this is necessary for your enquiry or contract. Processors are bound under Article 28 GDPR where required. We use Resend as the email processor for the private notification sent to the website owner. Resend receives the configured business recipient address and the form details you submit about the event, date, location, guest count, contact details, music, production requirements and message; your email address is also set as Reply-To so the owner can respond directly to your enquiry. The technical delivery outbox stores no form-content fields. It does store the private recipient address, the internal inquiry reference, delivery status, lock and retry data, and the provider message ID. The static subject, application URLs, technical logs and provider receipt contain no form values; the internal inquiry reference does not appear in the subject. For automatic translation in the protected CMS, only deliberately approved public marketing copy is sent to Anthropic Ireland Limited as a processor. Booking, contact, email, telephone, legal and admin content is technically excluded. Processing supports consistent multilingual publishing on the basis of legitimate interests under Article 6(1)(f) GDPR. According to the provider, API content is not used for training by default and is deleted within 30 days; this is not a Zero Data Retention commitment. If the provider's automated abuse systems flag content, it may be retained for up to 2 years and the related classification scores for up to 7 years. For users in the EEA, Anthropic Ireland Limited is the contracting entity; for transfers outside the EEA, the Anthropic DPA refers to adequacy decisions or EU Standard Contractual Clauses, as applicable. The feature remains disabled without a server-side API key. The enquiry inbox, the admin area and the website media are hosted by Supabase Inc. (USA) as a processor; data is stored in the eu-central-1 (Frankfurt, EU) region, and transfers to the USA rely on EU standard contractual clauses under the Supabase DPA. Your confirmation email is also sent through Resend; it contains your name, the event type, date and location of your enquiry.

Transfers outside the EEA

Deliberately activated services may process data outside the European Economic Area. Such a transfer takes place only on the basis of a valid adequacy decision or appropriate safeguards under Chapter V GDPR. The specific provider information is displayed with the relevant service or in that provider’s privacy notice.

Retention

New and active enquiries are stored in the enquiry inbox for no longer than 180 days. Enquiries marked as closed or spam are deleted within 30 days. If an enquiry becomes a contract, the inbox record is deleted no later than 30 days after the required contract data has been transferred; contract and billing data remains only for statutory retention periods. The notification status and technical delivery metadata are linked to the enquiry through the outbox and are deleted with it; the recipient-change audit is stored for no longer than 365 days. According to Resend's current provider documentation, Resend retains email data for 30 days across all plans; production backups are also retained for 30 days. These periods are separate from our local enquiry inbox and the owner's email mailbox. Local deletion does not automatically remove an already-sent notification from the email mailbox and does not mean immediate deletion from Resend backups. Messages in the email mailbox are not deleted automatically; they are deleted manually once enquiry handling is complete and no required contractual or legal retention reason remains. Because Resend keeps backups for 30 days, we do not promise immediate deletion from all provider backups. For imported Google reviews, we remove the reviewer name, star rating and review text no later than 30 days after the last successful sync. Technical abuse-prevention keys expire after no more than 24 hours.

The individual events of our own visitor count are deleted after 90 days at the latest; only daily figures without any personal reference remain. The daily random value behind the visitor key is deleted the following day.

Your rights

Subject to the statutory conditions, you may exercise the following rights:

  • Access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent for the future.

Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement. The authority responsible for the controller is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.

Cookies and consent

Technically necessary storage may be used to provide the website securely. Non-essential cookies or comparable technologies are activated only after consent. Consent can be withdrawn for the future at any time through the privacy settings offered on the website.

Privacy contact

A message is sufficient for privacy questions or to exercise your rights. Please do not send sensitive information that is not required to handle your request.

Email: info@dj-robinho.com