★ Legal

Privacy Policy

Last updated: 17 Aug 2026

At GRE2JAZZ S.L. we take your privacy seriously. This policy explains what personal data we collect, for what purpose, on what legal basis, for how long, with whom we share it and what rights you have over it.

Two sets of rules apply to us at once. We are a Spanish company publishing a US listings site. Because the controller is established in the European Union, the GDPR applies to this processing wherever you read from — that is also why the data is held in the EU. And if you are a resident of California, the CCPA as amended by the CPRA gives you its own rights, which are set out in section 5. Where the two differ, we apply whichever gives you more.

1. Data controller

We have not appointed a Data Protection Officer (DPO) for now, as it is not required given the volume and type of data we process. For any privacy query, please write to the email address above.

2. What data do we collect and why?

2.1 If you subscribe to the newsletter

2.2 If you send us a musician profile or a correction

We do not run a booking service here: we do not ask for your fee, we do not broker engagements and we do not charge you any commission.

2.3 If you make an enquiry as a client / promoter

2.4 If you email us (the "Enquiry" CTA)

We process the data you send us in order to reply to your enquiry. Legal basis: the implied consent of anyone who sends an email asking for a reply. Retention: 24 months after the last interaction or until you request deletion.

2.5 Automatic technical data (analytics)

If you accepted analytics cookies, Google Analytics 4 collects: anonymised IP, page views, duration, device, browser, city-level location. It is not cross-referenced with any personal identity. More detail in the Cookie Policy.

2.6 If you create a Jazz Live US account

2.7 If you enable personalised event alerts

3. Who do we share your data with?

Your data is NEVER sold to third parties. We work with data processors bound by GDPR contracts:

Not processors, but they still see you. Some pages pull photographs, album artwork, a player or a map straight from Deezer, Apple Music, Wikimedia Commons, TheAudioDB, YouTube, Spotify and CARTO / OpenStreetMap. They do not act on our instructions, so they are not our processors: your browser simply contacts them, and they see your IP address and the page you are on. This happens whatever you choose in the cookie banner, because it is how the page is put together. The Cookie Policy lists each one and links its policy.

If in the future we sign a booking contract for an event, we will share the essential data (name, artistic and financial terms) between the musician and the contracting client in order to perform the contract. Never with third parties outside the transaction.

4. International transfers

Your data is held in the European Union. Some processors (Google, Anthropic and Stay22) may process it outside the EU, including in the United States: under the GDPR that is an international transfer, and those transfers are covered by the EU-U.S. Data Privacy Framework or by the standard contractual clauses approved by the European Commission. Stay22 is Canadian, covered by the European Commission's adequacy decision for Canada.

The direction is worth stating plainly, because it is the opposite of what you might assume from a US site: your data does not sit in the United States and get sent to Europe. It sits in Europe.

5. Your rights (access, rectification, erasure, portability & restriction)

The GDPR grants you the following rights:

To exercise any of these rights:

  1. Send an email to info@clubgre2jazz.com stating which right you are exercising and attaching a copy of your ID or equivalent document (identity verification).
  2. We will respond within a maximum of 30 calendar days (extendable to 60 if the request is complex, in which case we would let you know).

If you believe we have not handled your request properly, write to us first — it is usually the fastest way to fix it. If that does not settle it, you have two routes, depending on where you are:

What California adds. You may ask what categories of personal information we collect and why, ask us to delete it, and ask us to correct it. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of on that front — and we will never treat you worse for exercising any of this.

6. How do we protect your data?

We apply proportionate technical and organisational measures: TLS encryption across the whole site, strong passwords on internal systems, encrypted backups, role-based access control, minimal staff with visibility. Continuous auditing of our data processors.

If a security breach were to occur that could affect your data, we would notify the AEPD within 72 hours and notify you if the breach involves a high risk, in accordance with articles 33-34 of the GDPR. Where a breach reaches California residents we would also follow California's own notification rules.

7. Children

This site is not directed at children under 14. If we discover that we have collected a child's data by mistake, we will delete it.

8. Changes to this policy

If we substantially change this policy we will notify you by email (if you gave us one) or via a banner. The "Last updated" date always reflects the current version.

9. Contact

For any query: info@clubgre2jazz.com.