Legal · GDPR + LOPDGDD

Privacy policy.

How we collect, use, and protect your personal data. In compliance with the EU General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).

Effective version Last updated: June 2026

At Lenz Music Lab we take your privacy seriously. This document explains, in plain language, what personal data we collect when you interact with our website and services, why we collect it, who has access to it, how long we keep it, and what rights you have over it.

01Data controller

The entity responsible for the processing of your personal data is:

Controller details

Lenz Music Lab (commercial name)
Legal name: [Pending — to be updated upon SL incorporation]
Tax ID (NIF/CIF): [Pending]
Registered address: Barcelona, Spain
Contact email: hello@lenzmusiclab.com
Website: lenzmusiclab.com

For matters specifically related to data protection, you can also reach us directly at privacy@lenzmusiclab.com.

02Data we collect

We only collect data that is necessary for the purposes described below. Specifically:

Contact form

When you submit our contact form (/contact), we collect:

  • Identification: name (or artist name) and email address
  • Inquiry details: inquiry type, genre, timeline, and message content
  • Consent records: timestamp of privacy policy acceptance and marketing opt-in preference

Client information form

If you are an existing client and complete the data form we send you, we collect:

  • Identification: full name or business name, stage name, email, phone
  • Billing information: tax ID (NIF/CIF/VAT), billing address
  • Social profiles: Instagram, Facebook, SoundCloud, Spotify, Beatport (optional)
  • Additional notes: any comments you provide

Service-related data

When you contract our mastering, mixing, or production services, we additionally process:

  • Audio files you upload for processing
  • Project metadata: service tier selected, references, special instructions
  • Payment information — note that payments are processed by Stripe; we do not store card details on our servers
  • Invoicing data required by tax law

Technical data

When you browse the site, our servers automatically receive standard technical information (IP address, browser type, pages visited, timestamps) for security, troubleshooting, and basic analytics purposes.

04Retention periods

We keep your data only as long as necessary for the purposes for which it was collected:

  • Contact form inquiries (no service contracted): up to 1 year from last contact, unless you request earlier deletion
  • Client records (active relationship): for the duration of the commercial relationship plus the legally required retention periods
  • Invoicing and tax data: 6 years minimum, as required by Spanish tax law
  • Audio project files: delivered files are kept on our servers for 90 days after delivery for re-download, then archived for an additional 12 months and deleted
  • Marketing data: until you withdraw consent or unsubscribe
  • Technical logs: typically 30 days

05Sharing with third parties

We never sell your personal data. We share it only with the following categories of recipients, and only when strictly necessary:

Service providers (data processors)

We work with carefully selected providers who process data on our behalf under data processing agreements (DPA):

  • Hosting: OVH (France/EU) — website and CRM infrastructure
  • Email delivery: our SMTP server hosted in the EU
  • Payment processing: Stripe (Ireland/EU) — handles all payment-related data directly under their own privacy policy
  • File transfer: Google Drive, Dropbox, WeTransfer or similar (only the cloud link you choose to share; we don't grant them access to your account)

Legal obligations

We may share data with public authorities (tax authority, judicial bodies) when required by law.

What we do NOT do

  • We do not sell your data to anyone
  • We do not share your data with advertisers
  • We do not transfer your data to marketing companies
  • We do not publish artist names, releases, or details without explicit permission

06International transfers

Our primary data processing happens within the European Union, where GDPR applies directly. In specific cases, some processors may transfer data outside the EU (for example, certain cloud services). In all such cases, we ensure that adequate safeguards are in place, such as:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules where applicable

07Cookies

Our website uses minimal cookies, only those strictly necessary for it to function. Specifically:

Strictly necessary cookies

  • Session cookies: to maintain your shopping cart and language preference
  • Security cookies: to protect against CSRF and other attacks

These cookies do not require consent as they are essential for the site to work.

Analytics cookies

We may use privacy-friendly analytics (such as anonymized server-side analytics) to understand site usage patterns. These do not track individual users and do not require consent under GDPR.

What we do NOT use

  • We do not use third-party advertising cookies
  • We do not use cross-site tracking technologies
  • We do not use fingerprinting techniques

You can control or delete cookies through your browser settings. Disabling essential cookies may affect site functionality.

08Security measures

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit: all communications use HTTPS/TLS
  • Encryption at rest: sensitive data stored in encrypted databases
  • Access control: strict role-based access to the CRM and project files
  • Backups: regular encrypted backups stored separately
  • Audit trails: logs of significant data access and modifications
  • Email authentication: SPF, DKIM and DMARC configured for outgoing emails

Despite these measures, no system is 100% secure. In the unlikely event of a data breach affecting your personal data, we will notify the Spanish Data Protection Agency (AEPD) within 72 hours and inform you directly if there is a high risk to your rights.

09Your rights

Under GDPR you have the following rights regarding your personal data:

Access
Obtain confirmation of whether we process your data and receive a copy of it.
Rectification
Correct inaccurate or incomplete data we hold about you.
Erasure
Request deletion of your data ("right to be forgotten") when no longer needed or when consent is withdrawn.
Restriction
Limit how we process your data in specific circumstances.
Portability
Receive your data in a structured, machine-readable format and transmit it to another controller.
Objection
Object to processing based on legitimate interest or for direct marketing purposes.
Withdraw consent
Revoke any consent previously given, at any time, without affecting prior lawful processing.
Lodge a complaint
File a complaint with the Spanish Data Protection Agency (AEPD) at aepd.es.

How to exercise your rights

To exercise any of these rights, send a request to privacy@lenzmusiclab.com with:

  • Your full name and a copy of an ID document (to verify your identity)
  • A clear description of the right you wish to exercise
  • Your contact details for our response

We will respond within 30 days of receiving your request. In complex cases this period may be extended by an additional 60 days, in which case we will inform you of the extension and its reasons.

Exercising your rights is free of charge. We may only charge a reasonable fee for manifestly unfounded or excessive requests.

10Minors

Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from minors. If you are under 18, please do not submit any personal information to us. If we become aware that we have inadvertently collected data from a minor, we will delete it as soon as possible.

Parents or guardians who believe a minor has provided us with personal data can contact us at privacy@lenzmusiclab.com and we will promptly delete it.

11Changes to this policy

We may update this privacy policy from time to time to reflect changes in our practices or for legal reasons. The "Last updated" date at the top of this document indicates when it was last revised.

For significant changes that affect how we process your personal data, we will notify you directly (by email if you have given us your contact details) or through a prominent notice on the website. We encourage you to review this policy periodically.

12Contact us

For any question, concern, or request related to this privacy policy or your personal data:

Email (privacy matters): privacy@lenzmusiclab.com
Email (general): hello@lenzmusiclab.com
Postal address: Lenz Music Lab — Barcelona, Spain
Website: lenzmusiclab.com

If you believe your data protection rights have been violated and we have not addressed your complaint satisfactorily, you can lodge a complaint with the Spanish supervisory authority:

Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6 · 28001 Madrid · Spain
Phone: +34 901 100 099
Web: www.aepd.es