Privacy Policy — MVA Music

Privacy Policy

Effective date: 22 May 2026 · Version 1.0

In short: MVA Music does not collect special categories of sensitive data (e.g. health, biometric, or payment card data) through this website by default. We only process personal data you choose to provide or that is necessary to run the site and optional services. You control what you share.

1. Data controller

The data controller responsible for personal data processed in connection with mva-music.com and related MVA Music services is:

Mark Andersen (trading as MVA Music)
Hedensted, Denmark
Email: contact@mva-music.com
Support: Support@mva-music.com

2. Scope

This Privacy Policy applies to visitors and users of mva-music.com, including portfolio pages, contact inquiries, and any linked artist or studio portal operated by MVA Music. Separate written agreements may apply to paid production work.

3. Personal data we may process

Depending on how you use our services, we may process:

  • Contact data: name, email address, and message content you send voluntarily (e.g. contact forms or email).
  • Account data (optional portal): login identifier, password (stored in hashed form where applicable), profile information, and project-related metadata you enter.
  • Uploaded content: audio files, stems, lyrics, images, or other materials you choose to upload to studio tools or vaults.
  • Calendar data (optional): if you connect Google Calendar or Apple/iCloud, we process OAuth tokens and booking information needed to sync sessions you create.
  • Technical data: IP address, browser type, device information, timestamps, and server logs generated when you access the website.
  • Cookies and similar technologies: as described in Section 10.

4. Data we do not seek to collect

We do not require you to provide government identification numbers, passport data, full payment card numbers, bank account details, precise geolocation for advertising, health information, or other special categories of data under Article 9 GDPR for ordinary use of this website.

5. Purposes and legal bases (GDPR)

We process personal data only where we have a valid legal basis, including:

  • Contract (Art. 6(1)(b)): to provide services you request, manage accounts, and deliver studio-related functionality.
  • Legitimate interests (Art. 6(1)(f)): to operate, secure, and improve the website; prevent abuse; and communicate with you about your inquiries, balanced against your rights.
  • Consent (Art. 6(1)(a)): where required for non-essential cookies or optional integrations—you may withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)): where we must retain or disclose data under applicable law.

6. How long we keep data

We retain personal data only as long as necessary for the purposes above, including:

  • Account and project data: while your account is active and for a reasonable period thereafter unless you request deletion.
  • Contact inquiries: typically up to 24 months unless a longer period is needed for ongoing business or legal reasons.
  • Server logs: for a limited period for security and troubleshooting.

7. Recipients and processors

We may share data with trusted third parties who process data on our behalf or under their own policies when you use their features, such as:

  • Website hosting and infrastructure providers
  • Email service providers
  • Google (OAuth / Calendar API) or Apple (iCloud calendar), if you enable those features

We do not sell your personal data. We require processors to handle data securely and only for specified purposes where contractually required.

8. International transfers

Some providers may process data outside the EU/EEA. Where applicable, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions, or your explicit consent for certain transfers.

9. Your rights

If you are in the EU/EEA (including Denmark), you may have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Erase data (“right to be forgotten”) in certain circumstances
  • Restrict or object to processing in certain circumstances
  • Data portability where processing is based on consent or contract and carried out by automated means
  • Withdraw consent at any time (without affecting prior lawful processing)
  • Lodge a complaint with a supervisory authority

To exercise your rights, contact contact@mva-music.com. We will respond within the timeframes required by applicable law (generally within one month under GDPR).

You may complain to the Danish Data Protection Agency (Datatilsynet): www.datatilsynet.dk.

10. Cookies

We may use essential cookies necessary for site operation and security. Non-essential cookies (e.g. analytics or preferences) will only be used where permitted by law and, where required, after you have consented. You can control cookies through your browser settings.

11. Security

We implement appropriate technical and organisational measures (such as HTTPS, access controls, and limited access to data). No method of transmission over the Internet is 100% secure; we cannot guarantee absolute security.

12. Children

Our services are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us and we will delete it promptly.

13. Changes to this policy

We may update this Privacy Policy from time to time. The effective date at the top will change. Material changes will be indicated on this page. Continued use after changes constitutes acceptance where permitted by law.

14. Contact

Questions about this Privacy Policy: contact@mva-music.com

This document is provided for general information. It is not legal advice. For specific legal questions, consult a qualified attorney in Denmark or your jurisdiction.

← Back to MVA Music