Mallorca DJs
Privacy
How Mallorca DJs handles data during visits, enquiries and use of the protected administration area.
Pre-release status: the dedicated Supabase database, authentication and media library are configured. This information describes the current technical implementation. Hosting, email delivery, provider agreements and binding erasure procedures still require final decisions and verification.
Controller and contact
Robin Kolb
Carrer de S’Illot 13
07400 Alcúdia, Spain
info@dj-robinho.com
+34 657 847 794
Enquiries and contact
The form requires the occasion, date, venue, first and last name, email, street, postal code, city and country. Phone, guest count, preferred DJ and message are optional. The language, an enquiry reference, acknowledgement of the privacy notice, processing status and delivery status are also processed. The form cannot be submitted without required information.
The purpose is to handle your enquiry and prepare a possible booking (Art. 6(1)(b) GDPR). The required checkbox acknowledges this notice; it is not consent to advertising or analytics. Requiring a full postal address at the initial enquiry stage must be justified before release or the form must be changed.
Stored enquiries and general contact messages are accessible to authorised staff in the protected inbox. General contact requires first name, last name, email and a message, but no event date; a phone number is optional. Event enquiries also offer optional service, timing, contact preference, music, equipment and referral details. No automated booking decision is made.
Optional email notification
Resend is planned for notifications initiated by authorised staff. The message contains an administration link and enquiry reference, not the form details. Sender, configured internal recipient and delivery metadata are also processed. This is not an automatic confirmation email to you. The recipient, mailbox provider and mailbox erasure rules must still be defined; alternatively this delivery remains disabled.
Delivery of the website and abuse prevention
Network requests technically process IP addresses and connection data, among other information. Hosting, logs and their retention depend on the operation still to be confirmed. The purpose is secure website delivery and preventing abusive enquiries (Art. 6(1)(f) GDPR).
Enquiry protection uses a secret key to derive values from the email address and, in the planned Vercel deployment, the IP address. These values, counters and time windows are stored separately from enquiries. This is not full anonymisation. Expiry of a counting window alone does not trigger erasure. Successfully storing a new enquiry removes keys whose stored counting window started more than two hours earlier. A new window may first begin for reused keys. Without such a new enquiry, no fixed erasure time is guaranteed.
Optional analytics and your choice
Optional page analytics starts only after “Allow analytics” (Art. 6(1)(a) GDPR). You can decline or choose “Revoke analytics” at the bottom of the page; enquiries do not depend on this choice. Withdrawal stops further analytics transmissions and attempts to abort pending ones. It does not individually delete events already received.
Each event contains a random event ID, page category, language, an optional DJ, service or editorial page ID, and a server timestamp. The analytics record contains no names, form details, IP address, full URL or persistent visitor ID. This does not eliminate technical processing of connection data during transport. Counts measure views, not uniquely identified people.
The mallorca-analytics cookie stores only your choice for up to 180 days; a new choice renews that period. Analytics settings remain available at the bottom of public pages. Stored enquiries are also counted independently for operational enquiry totals; these are not visitor conversion rates. This relies on the legitimate interest in an operational overview (Art. 6(1)(f) GDPR).
Protected administration
Staff sign in with email and password through Supabase Auth. An optional second factor uses time-based TOTP codes; once activated, protected administration actions require both factors. Session cookies named mallorca-djs-auth, including possible cookie chunks, support login and session renewal. Roles control access; publications record the user ID and time. This supports secure administration and accountability (Art. 6(1)(f) GDPR). Session duration, account erasure and history retention must be defined for operation.
Images and external links
Images are served from website files or the dedicated Supabase media library through this website. Unpublished uploads are accessible only to authorised staff. No automatically embedded video or social media players are used. External links are subject to the destination provider’s information. The editor permits external HTTPS images, which would send connection data to their provider on page visits. Providers and legal bases must be checked before publishing these images.
Planned providers and transfers
A dedicated Supabase project in Ireland (eu-west-1) provides the database, authentication and media library. Vercel is planned for hosting; Resend is prepared for internal notifications but is not yet configured as a functioning delivery channel. Hosting regions, processing agreements, subprocessors, logs, backups and international transfers require final verification before public release.
The provider agreements contain international transfer provisions and standard contractual clauses. Resend identifies the USA as its primary processing location. This establishes neither a confirmed agreement for this project nor exclusively European processing. The applicable transfer mechanism and access to its safeguards must be established for the final operation.
Storage and erasure
Automatic deletion is not yet implemented for enquiries, their delivery metadata, staff accounts or publication history. The operator must define justified periods or erasure criteria, responsibilities and an executable procedure. Records needed for contracts or taxes must be distinguished from mere enquiries; no blanket retention periods are specified here.
The prepared analytics cleanup removes events older than 30 days on the next collection, owner report or explicitly requested maintenance. Without such a call there is no cleanup; guaranteed daily deletion has not been established. Provider logs, backups, exports and mailbox copies require separate rules. Actual execution must be verified before publication.
Your rights
Subject to statutory conditions you can request access, rectification, erasure, restriction and portability. You may object to processing based on legitimate interests for reasons relating to your particular situation. You may withdraw consent for the future without affecting the lawfulness of earlier processing. Use the contact above. You may complain to a data protection authority, in particular the Spanish AEPD.
DJ applications
The separate application form processes your name or DJ name, email, business registration status and, where applicable, business name, business location and tax identifier (NIE/NIF/CIF in Spain or VAT ID abroad), Mallorca residence, equipment skills, self-reported driving licence, Instagram address, reported genuine followers, website, fluent languages and an optional message. No identity document or driving licence photos are requested. This information is used to assess a possible collaboration; the form requests your consent for this purpose (Art. 6(1)(a) GDPR).
Answers are compared against criteria configured by the operator. Meeting them does not verify the information. Unmet criteria produce a rejection draft for human handling; the system does not send automatic rejections or make a binding collaboration decision. The owner can review and process applications. Qualifying applications have an internal notification prepared for info@mallorca-djs.com, containing a protected administration link and reference, not the tax identifier. Delivery remains pending without a configured email channel.
Changing languages can preserve entries in application memory while the application remains open. Application data is not written to Local Storage or Session Storage. The draft is cleared after confirmed submission and discarded on access after 30 minutes without changes; reloading loses it. Event enquiry and general contact drafts, in contrast, use the current tab’s Session Storage and are removed after confirmed submission. Closing the tab ends its session.
Automatic application retention is currently disabled. The owner can configure a period: closed or spam-marked applications are then removed when the inbox opens after that period expires. Open cases, backups and previously exported or emailed copies are not automatically erased by this process. Binding retention rules must be defined before release.