Your data
Privacy policy
This policy explains which personal data may be processed when you visit the website, send an enquiry or deliberately activate third-party content.
Editorial status: 3 August 2026
Controller
The controller responsible for data processing is DJ Robinho, proprietor Robin Kolb, Carrer de S’Illot 13, 07400 Alcúdia, Spain.
Email: info@dj-robinho.com
Booking and contact enquiries
We use the information in your enquiry to check availability, understand your event, prepare a proposal and communicate with you.
The first contact includes event type, date or flexibility, location, guest count, name and email address. We also collect the preferred contact method and a phone number that is optional for email but required when phone or WhatsApp is selected. Planned start and end timings, music styles, technical areas and requirements, and a message are optional details used for quote and event planning.
The legal basis is Article 6(1)(b) GDPR for pre-contractual steps and contract performance. Where a statutory retention obligation applies, Article 6(1)(c) GDPR also applies.
Technical delivery and server data
When the site is opened, the IP address, time, requested URL, referrer, browser and device information may be processed technically. This supports secure delivery, stability and abuse detection. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the secure and reliable operation of the website.
Optional analytics and performance data
After your explicit consent, we enable Vercel Web Analytics and Speed Insights. Page views, referrers, approximate region, device and browser information, technical Web Vitals and only the following interaction categories may then be processed: an enquiry-action click, the selected event format, moving to the second form step, the submission result and approval of an external video. Names, email addresses, phone numbers, event locations, dates, messages and internal enquiry IDs are never sent as analytics events. According to Vercel, Web Analytics uses no cookies and stores anonymised data; your choice is stored locally in your browser.
The legal basis is Article 6(1)(a) GDPR. You can withdraw consent at any time through the privacy settings with effect for the future. Web Analytics and Speed Insights remain disabled until you make a choice.
External content and communication services
Embedded videos, maps, social or scheduling content loads only after your consent or a deliberate action. Approved Google reviews are instead delivered from our own system, so viewing them creates no direct connection to Google. Only the link to the original opens Google.
Depending on the content you activate, this may include YouTube and Google services, Instagram and WhatsApp from Meta, Spotify and Calendly. External links open the relevant provider’s website, where that provider is independently responsible for further processing.
Where consent is required, the legal basis is Article 6(1)(a) GDPR. You can withdraw consent at any time with future effect. Editorially approved Google reviews are published on the basis of Article 6(1)(f) GDPR; our legitimate interest is to provide a verifiable account of genuine customer experience. You may object to this processing on grounds relating to your particular situation.
Recipients and processors
Data is shared only with service providers needed for hosting, email, communication or the specific event delivery, and with participating partners when this is necessary for your enquiry or contract. Processors are bound under Article 28 GDPR where required. We use Resend as the email processor for the private notification sent to the website owner. Resend receives the configured business recipient address and the form details you submit about the event, date, location, guest count, contact details, music, production requirements and message; your email address is also set as Reply-To so the owner can respond directly to your enquiry. The technical delivery outbox stores no form-content fields. It does store the private recipient address, the internal inquiry reference, delivery status, lock and retry data, and the provider message ID. The static subject, application URLs, technical logs and provider receipt contain no form values; the internal inquiry reference does not appear in the subject. For automatic translation in the protected CMS, only deliberately approved public marketing copy is sent to OpenAI Ireland Ltd. as a processor. Booking, contact, email, telephone, legal and admin content is technically excluded. Processing supports consistent multilingual publishing on the basis of legitimate interests under Article 6(1)(f) GDPR. According to the provider, API content is not used for training by default. The store: false setting prevents persistence as Responses application state but is not a Zero Data Retention commitment; safety and abuse-monitoring logs may be retained for up to 30 days by default, unless longer retention is required by law or reasonably necessary to protect the services or third parties. For transfers outside the EEA, the OpenAI DPA refers to adequacy decisions or EU Standard Contractual Clauses, as applicable. The feature remains disabled without a server-side API key.
Transfers outside the EEA
Deliberately activated services may process data outside the European Economic Area. Such a transfer takes place only on the basis of a valid adequacy decision or appropriate safeguards under Chapter V GDPR. The specific provider information is displayed with the relevant service or in that provider’s privacy notice.
Retention
New and active enquiries are stored in the enquiry inbox for no longer than 180 days. Enquiries marked as closed or spam are deleted within 30 days. If an enquiry becomes a contract, the inbox record is deleted no later than 30 days after the required contract data has been transferred; contract and billing data remains only for statutory retention periods. The notification status and technical delivery metadata are linked to the enquiry through the outbox and are deleted with it; the recipient-change audit is stored for no longer than 365 days. According to Resend's current provider documentation, Resend retains email data for 30 days across all plans; production backups are also retained for 30 days. These periods are separate from our local enquiry inbox and the owner's email mailbox. Local deletion does not automatically remove an already-sent notification from the email mailbox and does not mean immediate deletion from Resend backups. Messages in the email mailbox are not deleted automatically; they are deleted manually once enquiry handling is complete and no required contractual or legal retention reason remains. Because Resend keeps backups for 30 days, we do not promise immediate deletion from all provider backups. For imported Google reviews, we remove the reviewer name, star rating and review text no later than 30 days after the last successful sync. Technical abuse-prevention keys expire after no more than 24 hours.
Your rights
Subject to the statutory conditions, you may exercise the following rights:
- Access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent for the future.
Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority, in particular in the member state of your habitual residence, place of work or the place of the alleged infringement.
Privacy contact
A message is sufficient for privacy questions or to exercise your rights. Please do not send sensitive information that is not required to handle your request.
Email: info@dj-robinho.com