Privacy notice
EFFECTIVE 2 SEPTEMBER 2026 · VERSION 1.1
Crimson Creative Group AB is responsible for the personal data described here. We collect only what we need to run the studio, the website and the partner portal. Website analytics is optional and stays off until you actively accept it.
1. Who controls your data
Crimson Creative Group AB (brand: Crimson Creative Studio), organisation number 559586-8083. Our business address and VAT information are on the legal and contact page.
Privacy contact: [email protected].
2. What this notice covers
This notice covers our public website, meeting bookings reached from the website, direct enquiries, and the password-protected band partner portal. It does not replace a signed band partnership agreement or the separate information that applies to a specific merch sale.
3. What we process and why
| Purpose | Data | Legal basis | Typical retention |
|---|---|---|---|
| Serve and secure the website | Request time, IP address and basic device/request information in short-lived infrastructure and security logs | Legitimate interests in operating a secure, reliable service | Rotated or deleted when no longer needed for security and troubleshooting |
| Optional first-party analytics | Pseudonymous analytics ID, session ID, page path, referrer origin, campaign tags and booking/Instagram clicks. We do not store raw IP addresses in the analytics tables. | Your consent | Analytics events: 13 months |
| Remember your cookie choice | Pseudonymous consent receipt, policy version, choice and time | Necessary storage plus legitimate interests in demonstrating and respecting your choice | Consent evidence: up to 3 years; preference cookie: 180 days |
| Arrange a call | Name, contact details, availability and answers you submit to Cal.eu | Steps you request before a possible agreement; legitimate interests in scheduling | For the booking and reasonable follow-up, then deleted or retained with the business relationship |
| Manage leads and partners | Contact details, band profile, conversation history, approvals, project status and relationship notes | Steps before an agreement, performance of an agreement and legitimate interests in managing business relationships | While the relationship is active and normally up to 24 months after the last meaningful contact, unless a longer period is required |
| Run the partner portal | Account details, password hash, two-factor secret, messages, linked file metadata, products, order items, totals, statuses and timestamps | Performance of the partnership agreement and legitimate interests in security and operations | Account/project data while active and normally up to 24 months afterwards; accounting material for the statutory period |
| Handle data-rights requests | Email, requested scope, verification state, deadline, source checks and response; a minimal reference/status audit | Legal obligation to handle GDPR rights | Unverified email: 7 days. Detailed completed request: 90 days after closure and successful SMTP submission; minimal accountability history retained separately. Open requests remain until resolved. |
| Prevent restoration of erased analytics | One-way hash of the high-entropy browser receipt and erasure time | Legal obligation to respect erasure | While a backup capable of restoring those records remains available |
4. Who receives data
We use service providers only where needed to operate the business. These may include Hostinger and infrastructure providers for hosting, Cloudflare for DNS and edge security, Cal.eu for bookings, Fibery for CRM and project records, n8n for controlled automation, Google Drive for partner files, Discord for internal approvals and alerts, GitHub for encrypted offsite backups, and OpenAI tools for limited human-reviewed research and drafting. Access is restricted by role and purpose.
Some providers may process data outside the EEA. Applicable transfer safeguards and provider arrangements depend on the service and account; contact us for information about the safeguards applicable to your data. Cal.eu is the EU-hosted booking service selected for this website. Opening its booking link takes you to that service.
Backups are encrypted and access-restricted. Current backup files are pruned after 14 days, but earlier encrypted versions can remain in private Git history; that is not a guaranteed 14-day erasure period. Erased browser analytics is excluded when restoring a database using the separate live erasure ledger. Broader requests require checking backup restrictions and restore exclusions as part of the review.
5. AI and automated decisions
AI may help prepare research or drafts. A person reviews customer-facing business communications before they are sent. Identity-verification and status emails for data-removal requests are automated when the mail service is available; they are not AI decisions about entitlement to erasure. Shared or legally retained records receive human review. We do not make solely automated decisions that produce legal or similarly significant effects about website visitors, leads or partners.
6. Your rights
Depending on the situation, you can ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You can withdraw consent at any time without affecting earlier lawful processing. Use for analytics consent, or email us for other requests.
Use the data-rights page to remove this browser’s analytics or request other removal. We verify email control and, where needed, your authority over a shared account. We normally respond within one calendar month of receipt; any permitted extension must be explained within that month. Deletion is not absolute: accounting duties, legal claims and others’ rights may require limited retention, which we explain.
You may complain to the Swedish Authority for Privacy Protection (IMY) at imy.se. We may need to verify your identity before acting on a request.
7. Security
We use encrypted transport, access controls, signed secure cookies, rate limits, two-factor authentication options, encrypted backups and monitoring. No online system is risk-free; if a personal-data incident creates a legal notification duty, we will follow the applicable GDPR process.
8. Changes and questions
We will update the effective date and version when this notice changes materially. Questions or rights requests can be sent to [email protected].