★ Legal

Privacy Policy

Last updated: 17 Aug 2026

At GRE2JAZZ S.L. we take your privacy seriously. This policy explains what personal data we collect, for what purpose, on what legal basis, for how long, with whom we share it and what rights you have over it. It complies with the UK GDPR and the Data Protection Act 2018.

1. Data controller

We have not appointed a Data Protection Officer (DPO) for now, as it is not required given the volume and type of data we process. For any privacy query, please write to the email address above.

2. What data do we collect and why?

2.1 If you subscribe to the newsletter

2.2 If you add yourself as a musician to the directory

2.3 If you make an enquiry as a client / promoter

2.4 If you email us (the "Enquiry" CTA)

We process the data you send us in order to reply to your enquiry. Legal basis: the implied consent of anyone who sends an email asking for a reply. Retention: 24 months after the last interaction or until you request deletion.

2.5 Automatic technical data (analytics)

If you accepted analytics cookies, Google Analytics 4 collects: anonymised IP, page views, duration, device, browser, city-level location. It is not cross-referenced with any personal identity. More detail in theCookie Policy.

2.6 If you create a Jazz Live UK account

2.7 If you enable personalised event alerts

3. Who do we share your data with?

Your data is NEVER sold to third parties. We work with data processors bound by GDPR contracts:

If in the future we sign a booking contract for an event, we will share the essential data (name, artistic and financial terms) between the musician and the contracting client in order to perform the contract. Never with third parties outside the transaction.

4. International transfers

Some processors (Google, Meta, Anthropic, Stay22 and the Adsterra advertising network) may process data outside the UK, including in the USA. These transfers are covered by theUK Extension to the EU-U.S. Data Privacy Framework or by the UK's International Data Transfer Agreement (IDTA) and standard contractual clauses.

5. Your rights (access, rectification, erasure, portability & restriction)

The UK GDPR grants you the following rights:

To exercise any of these rights:

  1. Send an email toinfo@clubgre2jazz.com stating which right you are exercising and attaching a copy of your ID or equivalent document (identity verification).
  2. We will respond within a maximum of 30 calendar days (extendable to 60 if the request is complex, in which case we would let you know).

If you believe we have not handled your right properly, you can complain to the Information Commissioner's Office (ICO):ico.org.uk— Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF — helpline 0303 123 1113.

6. How do we protect your data?

We apply proportionate technical and organisational measures: TLS encryption across the whole site, strong passwords on internal systems, encrypted backups, role-based access control, minimal staff with visibility. Continuous auditing of our data processors.

If a security breach were to occur that could affect your data, we would notify the ICO within 72 hours and notify you if the breach involves a high risk, in accordance with articles 33-34 of the UK GDPR.

7. Children

This site is not directed at children under 14. If we discover that we have collected a child's data by mistake, we will delete it.

8. Changes to this policy

If we substantially change this policy we will notify you by email (if you gave us one) or via a banner. The "Last updated" date always reflects the current version.

9. Contact

For any query:info@clubgre2jazz.com.