1. Data Controller
The data controller is the operator of Audiogarden Studio (“Controller”). Contact email: info@audiogarden.cz.
2. Data We Collect
In connection with providing audio mastering and related services, we process:
- Identity data: name, username
- Contact data: email address, phone number
- Billing data: address, city, postal code, country
- Business data (for companies): company name, registration number, VAT ID
- Project data: service type, project status, deadlines, order history
- Audio files: recordings submitted for processing and delivered masters
- Technical data: IP address, browser type (for access security only)
3. Purpose of Processing
- Contract performance: delivering ordered services, project communication, file delivery
- Invoicing and accounting: issuing invoices, maintaining accounting records
- Internal records: client management, project history, quality assurance
- Security: portal access protection, abuse prevention
4. Legal Basis
- Contract performance (Art. 6(1)(b) GDPR)
- Legal obligation (Art. 6(1)(c) GDPR) — accounting, tax records
- Legitimate interest (Art. 6(1)(f) GDPR) — client records, service improvement
5. Data Retention
- Billing data: 10 years (accounting law)
- Contact and project data: duration of relationship + 3 years
- Final audio files: retained long-term in the portal for repeated download
- Source audio files: retained for the duration needed to complete the project
6. Data Access
- Administrator: full access to client cards and projects
- Collaborator (audio engineer): limited access — name, email, phone, and project notes only. No access to billing data.
- Processors: payment provider (Stripe), invoicing (Fakturoid), cloud storage (Dropbox)
We do not share data with third parties for marketing purposes.
7. Your Rights
Under GDPR, you have the right to: access, rectification, erasure, restriction of processing, data portability, and the right to lodge a complaint with a supervisory authority.
Contact us at info@audiogarden.cz to exercise your rights.
8. Security
We implement appropriate technical and organizational measures: encrypted transport (HTTPS/TLS), secure cloud storage, role-based access, time-limited audio streaming tokens.
9. Changes
We may update this policy. Material changes will be communicated via email or portal notification.
Effective from: March 2026