01Who we are
This site is run by DJ Cy (“we”, “us”), a DJ and producer based in North London. We are the controller of the personal data collected through it, which means we decide how and why it’s used and we’re responsible for looking after it under the UK GDPR and the Data Protection Act 2018.
For anything in this policy, including using any of your rights, through the contact form. Start your message with “Privacy request” so it reaches the right place.
02What we collect
We only collect what the site needs to do the thing you asked for:
- Messages and booking requests. Your name, email address and message. Booking requests also include the event date and venue. If you’re signed in when you send one, it’s linked to your member account.
- Member accounts. Your name, email address and password, plus when you joined and when you last signed in. Passwords are stored only as a one-way bcrypt hash, so nobody can read them, us included.
- Vault activity. When a member plays a full-length track or downloads one from the vault, we record which track, whether it was a play or a download, and when.
- Your cookie choice. An anonymous record of what you chose, the policy version and the time. It holds a random identifier, not your IP address or anything else that identifies you.
- Usage statistics. Cookieless page-view counts from Vercel Web Analytics and, only if you opt in, Google Analytics. See the cookie policy for the detail.
- Technical data. Like any website, our host receives your IP address and browser details with each request. We use the IP address briefly, in memory, to stop the contact and sign-in forms being flooded. We don’t save it to our database.
- Failed sign-ins. If a sign-in attempt fails, we note the email address that was typed and the time, so we can stop anyone guessing passwords. These notes are deleted after 15 minutes, or sooner when that account next signs in.
We don’t collect special category data, we don’t buy data about you from anyone, and we never sell yours.
03How we use it and why
The UK GDPR requires a lawful basis for each use of your data. Ours are:
| Purpose | Data | Lawful basis |
|---|---|---|
| Replying to messages and handling bookings | Enquiry details | Legitimate interests, or steps before a contract when you ask to book a set |
| Running your member account and the vault | Account details | Contract: providing the membership you signed up for |
| Understanding which vault tracks members value | Vault activity | Legitimate interests |
| Keeping the site secure and free of spam | Technical data, failed sign-ins | Legitimate interests |
| Cookieless page-view counts | Usage statistics | Legitimate interests |
| Google Analytics | Usage statistics | Consent, which you can withdraw at any time |
| Proving we asked before setting optional cookies | Cookie choice record | Legal obligation |
Where we rely on legitimate interests, we’ve checked that the use is expected, limited and doesn’t override your rights. We don’t send marketing email and we don’t make automated decisions about you.
05International transfers
Vercel and Google may process data outside the UK, including in the United States. Where they do, the transfer is protected by UK adequacy regulations (such as the UK Extension to the EU–US Data Privacy Framework) or by the ICO’s International Data Transfer Agreement or Addendum.
06How long we keep it
- Messages and booking requests: up to two years after our last contact, so we can follow up on a conversation or a booking. Anything tied to a paid booking may be kept for six years for tax records.
- Member accounts: until you ask us to close your account.
- Vault activity: while your account is open. When an account is deleted, its plays and downloads stay only as anonymous totals, no longer linked to anyone.
- Cookie choice records: kept as evidence of consent. They don’t identify you.
- Google Analytics: no longer than 14 months, under the retention setting in Google Analytics.
- Failed sign-ins: 15 minutes, or until that account next signs in.
- IP addresses: held only in server memory for rate limiting, never written to our database, and gone when the server restarts.
07Your rights
Under the UK GDPR you can ask us to:
- Give you a copy of the personal data we hold about you.
- Correct anything that’s wrong or incomplete.
- Delete your data, including closing your account.
- Restrict or object to how we use it, including anything based on legitimate interests.
- Send it to you or another service in a machine-readable format.
- Withdraw consent for analytics at any time, using “Cookie settings” in the footer.
It’s free, and we’ll reply within one month. To ask, . We may need to check it’s really you before acting on a request.
If you’re unhappy with how we’ve handled your data, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113.
08Keeping it secure
The site is served only over HTTPS. Passwords are hashed with bcrypt, sign-in sessions are held in signed and encrypted cookies, and the sign-in, sign-up and contact forms are rate-limited. Only site admins can see enquiries and member details. No system is perfectly secure, but if a breach ever puts your data at risk we’ll tell you and the ICO as the law requires.
09Children
The site isn’t aimed at children. You must be 13 or over to create a member account. If you think a child has given us their details, and we’ll delete them.
10Changes to this policy
We’ll update this page when what we collect or how we use it changes, and the date at the top will move with it. If a change affects your cookie choices, the cookie prompt will ask you again.