PRIVACY POLICY
(pursuant to Articles 13 and 14 of EU Regulation 2016/679 – GDPR)
Last updated: 26 June 2026
This policy describes how the personal data of users who visit the monoloco.live website, submit a demo through the /demo page, or subscribe to the newsletter of the MONOLOCO / MONOLOCO SOUND project are processed. This policy does not concern the third-party sites or platforms reachable through the links present on the site (Instagram, TikTok, WhatsApp, SoundCloud, Facebook, Nightify, Google Maps), which have their own independent privacy policies.
1. DATA CONTROLLER
The Data Controller is:
European Broadcasting Company S.r.l.
Registered office: Via Berta 10, 86170 Isernia (IS) – Italy
VAT no. 01647060704
Contacts for privacy matters and for the exercise of rights:
- General e-mail: events@monoloco.live
- E-mail for demos (MONOLOCO SOUND): demos@monoloco.live
- Booking e-mail: bookings@monoloco.live
- Events office (telephone): +39 335 736 7638
The Controller has not appointed a Data Protection Officer (DPO), there being no legal obligation to do so; any request concerning data protection may be sent to the contact details indicated above.
2. TYPES OF DATA PROCESSED, PURPOSES AND LEGAL BASES
2.1 Submission of a demo (/demo page – "MONOLOCO SOUND")
When you submit a demo by filling in the relevant form, we collect the data you voluntarily provide:
- stage name (mandatory);
- e-mail address (mandatory);
- private/streaming link to the track (mandatory – no audio files are uploaded or stored: we process only the link you provide);
- genre/style of the track and, optionally, the title of the track and its publication status (unreleased/already released);
- Instagram profile or other social media (mandatory);
- city/country of origin (optional);
- a short message (mandatory);
- the consent checkbox for the privacy policy and the optional checkbox for newsletter subscription.
Submissions are saved in a protected technical register, hosted on the hosting provider's servers (Aruba), in a structured format with restricted access.
Purpose: to evaluate the demo you have sent us and, in case of interest, to contact you to follow up on the artistic proposal.
Legal basis: performance of pre-contractual measures taken at your request and/or the Controller's legitimate interest in evaluating the artistic proposals received (Art. 6(1)(b) and (f) GDPR). The consent you give concerns the review and acceptance of this policy for the specific purpose of evaluating the demo.
2.2 Newsletter and e-mail marketing (double opt-in)
If you subscribe to the newsletter (from the site or by checking the relevant box in the demo form), we process your e-mail address – and possibly your name – to send you updates on events, dates, line-ups and new releases from the label.
Subscription takes place through a double opt-in procedure: after the request, you will receive a confirmation e-mail and the subscription is completed only after you have clicked the verification link. We retain proof of consent (date, time and method of subscription) for accountability purposes.
Purpose: sending promotional and informational communications by e-mail.
Legal basis: free, specific and revocable consent of the data subject (Art. 6(1)(a) GDPR). You may withdraw your consent at any time, without affecting the lawfulness of the processing based on the consent given before its withdrawal, by using the unsubscribe link present in every e-mail or by writing to events@monoloco.live.
2.3 Browsing data and server logs
The computer systems and software procedures used to operate the site acquire, in the course of their normal operation, certain data whose transmission is implicit in the use of Internet communication protocols (e.g. IP address, browser type/user agent, operating system, date and time of the request, pages visited). Such data are processed by the hosting provider (Aruba) in log files for exclusively technical purposes, for statistics in aggregate form and for security.
Purpose: to ensure the correct functioning, security and diagnostics of the site, as well as to ascertain any liability in the event of computer crimes against the site.
Legal basis: the Controller's legitimate interest in the security and continuity of the service (Art. 6(1)(f) GDPR) and any legal obligation (Art. 6(1)(c) GDPR).
2.4 Anti-abuse measures for the demo form
To prevent automated submissions and abuse of the demo form, we apply a limit on submissions per IP address. For this purpose the IP address is not stored in clear text: it is transformed into a non-reversible encrypted code (SHA-256 hash) and used only for the temporary counting of submissions. In addition, the integration of the Cloudflare Turnstile anti-bot system is in place – but currently DEACTIVATED – which may be activated solely for the security of the form.
Purpose: prevention of spam, fraud and abuse; security of the site.
Legal basis: the Controller's legitimate interest (Art. 6(1)(f) GDPR); for the possible activation of Cloudflare Turnstile, where required, consent through the banner.
2.5 Cookies and similar technologies
The site does NOT use profiling cookies, does NOT install Google Analytics, does NOT use the Meta/Facebook pixel or any other third-party tracking or marketing tools.
The only ones present are:
- a first-party technical cookie (e.g. "monoloco_consent") that stores the choice you expressed on the banner relating to this policy, so as not to present it again at every visit;
- possibly, if activated, the Cloudflare Turnstile technical security tool on the demo form (currently deactivated).
The typographic fonts used by the site are hosted directly on our servers (self-hosting): NO call is therefore made to Google Fonts and no IP address is communicated to Google for loading the fonts.
The site contains exclusively outbound links (and not embedded content/"embeds") to third-party platforms (Instagram, TikTok, WhatsApp, SoundCloud, Facebook, Nightify) and a link to Google Maps for locating the venues: such links do not install cookies on our site; any processing takes place only after you have clicked and been redirected to the respective platforms, according to their independent policies.
Legal basis of the technical cookie: legitimate interest and/or technical necessity connected to the use of the service requested by the user (Art. 6(1)(f) GDPR); for the technical cookie storing the choice, no prior consent is required under the applicable legislation.
3. NATURE OF THE PROVISION OF DATA
The provision of the data marked as mandatory in the demo form is necessary in order to evaluate your proposal: in its absence, it will not be possible to follow up on the submission. The provision of the e-mail for the newsletter is optional, but necessary to receive communications: failure to provide it only results in the impossibility of subscribing. Browsing data are collected automatically for technical reasons.
4. RECIPIENTS AND DATA PROCESSORS
The data are processed by the Controller's authorized personnel and may be communicated, within the limits of their respective purposes, to the following parties, appointed as Data Processors pursuant to Art. 28 GDPR where they act on behalf of the Controller:
- Aruba S.p.A. (Italy – EU) – Data Processor. Provides the hosting of the site, the storage of the demo register and the e-mail mailbox used, primarily, for sending confirmation/notification e-mails and for receiving communications.
- SMTP2GO (SMTP2GO Inc. / SMTP2GO Ltd – United States, with an EU data center available) – Data Processor. Used as a backup (fallback) delivery channel for transactional e-mails (demo confirmations and notifications) when the primary Aruba channel is unavailable, and as a delivery service for the newsletter.
- Hetzner Online GmbH (Germany – EU) – Data Processor/sub-processor. Provides the server (VPS) on which the newsletter management software "listmonk" is self-hosted.
- Brevo (Sendinblue SAS – France – EU) – former Data Processor. E-mail marketing platform used in the past for the management of the newsletter; mentioned for transparency with reference to past processing.
- Cloudflare, Inc. (United States) – possible Data Processor, limited to the Turnstile anti-bot service on the demo form, currently DEACTIVATED; it will be involved only in the event of its future activation.
With reference to brand advertising: MONOLOCO runs advertising campaigns (ads) on Meta's Facebook and Instagram platforms. Such activities take place entirely within the Meta platforms. NO Meta pixel, SDK or tracking tool is installed ON THE monoloco.live SITE: the site does not transmit users' browsing data to Meta. Meta Platforms Ireland Ltd (Ireland – EU) and Meta Platforms, Inc. (United States) act as independent controllers/joint controllers for the processing carried out on their own platforms, according to their respective policies.
The data may also be communicated to competent authorities, consultants and professionals, where necessary to comply with legal obligations or for the ascertainment and defence of a right. The data are not disseminated nor sold to third parties for marketing purposes.
5. DATA TRANSFERS TO NON-EU COUNTRIES
Processing takes place primarily within the European Union (Aruba hosting in Italy; Hetzner listmonk server in Germany).
Some providers may involve a transfer of personal data to the United States:
- SMTP2GO (USA): the transfer, where it takes place through the provider's US infrastructure, is carried out on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission pursuant to Art. 46 GDPR and/or, where the provider is certified, the EU-US Data Privacy Framework (European Commission adequacy decision of 10 July 2023), with adequate supplementary measures. SMTP2GO also makes available a data center located in the EU (Amsterdam).
- Cloudflare (USA) – only in the event of future activation of Turnstile: transfers are covered by the Standard Contractual Clauses (SCC) and/or by certification under the EU-US Data Privacy Framework.
- Meta (USA) – limited to the ads managed on the Meta platforms, and therefore outside the site: Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework and adopts the Standard Contractual Clauses as additional safeguards.
In all cases, transfers take place in compliance with Articles 44 et seq. of the GDPR. You may request a copy of the safeguards adopted by writing to the contacts indicated in section 1.
6. DATA RETENTION PERIOD
- Non-selected demos and related contacts: retained for a maximum of 24 months from submission, after which they are deleted. In case of interest and the start of a relationship, the data are retained for the time necessary to manage the collaboration and the related obligations.
- Newsletter and e-mail marketing: the data are retained until consent is withdrawn or the subscription is cancelled; proof of consent is retained for the time necessary to demonstrate its lawfulness.
- Server logs: retained for the technically necessary time according to the hosting provider's policies, for security and diagnostic purposes, and in any case for a limited period.
- Hash of the IP address for form rate limiting: retained only for the time window necessary for the anti-abuse check (in the order of hours).
- "monoloco_consent" technical cookie: limited duration (generally up to 6-12 months), unless deleted earlier by the user.
At the end of the indicated periods, the data are deleted or irreversibly anonymized.
7. RIGHTS OF THE DATA SUBJECT
In relation to the data processed, you have the right, within the limits and under the conditions provided for by Articles 15-22 of the GDPR, to:
- obtain confirmation of the existence of the processing and access to your personal data (Art. 15);
- obtain the rectification of inaccurate data or the integration of incomplete data (Art. 16);
- obtain the erasure of the data ("right to be forgotten"), in the cases provided for (Art. 17);
- obtain the restriction of processing (Art. 18);
- receive the data concerning you in a structured, commonly used and machine-readable format, and transmit it to another controller (portability, Art. 20);
- object at any time, for reasons connected to your particular situation, to processing based on legitimate interest, as well as object at any time to processing for direct marketing purposes (Art. 21);
- not be subject to automated decisions producing legal effects (Art. 22): the Controller does not carry out automated decision-making processes or profiling;
- withdraw at any time the consent given, without affecting the lawfulness of the processing carried out before the withdrawal (Art. 7(3)).
To exercise your rights you may write to events@monoloco.live or, for demos only, to demos@monoloco.live. The request is free of charge and we will respond without undue delay and in any case within one month, extendable by a further two months in cases of particular complexity. To unsubscribe from the newsletter you may also use the link at the bottom of every e-mail.
8. COMPLAINT TO THE SUPERVISORY AUTHORITY
If you believe that the processing of your data takes place in violation of the GDPR, you have the right to lodge a complaint with the Italian Data Protection Authority:
Garante per la protezione dei dati personali – Piazza Venezia 11, 00187 Rome – website www.gpdp.it / www.garanteprivacy.it – switchboard +39 06 696771.
Without prejudice to any other administrative or judicial action.
9. CHANGES TO THIS POLICY
The Controller reserves the right to modify or update this policy, including as a result of changes in the applicable legislation or in the services and providers used. The updated version will be published on this page with an indication of the date of last update. We invite you to consult it periodically.
European Broadcasting Company S.r.l. – monoloco.live