Privacy Policy

1. Introduction

At Sandrock Recordings (“Company”, “we”, “our”, or “us”), accessible via sandrockrecordings.com (“Website”), we are committed to safeguarding your personal data and respecting your privacy. We recognize the importance of protecting personal information in accordance with applicable privacy and data protection legislation, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the California Consumer Privacy Act of 2018 (“CCPA”). This Privacy Policy outlines how we collect, use, disclose, and protect your personal data when you interact with our Website and services.

2. Scope of Policy and Data Controller Role

This Privacy Policy applies to all users who visit or interact with sandrockrecordings.com. Sandrock Recordings is the data controller for personal data collected via the Website. As the data controller, we determine the purposes and means of the processing of your personal data, in accordance with applicable laws.

If you are located in the European Union, or if you are a California resident, specific rights and obligations outlined below will apply to your personal data in accordance with GDPR and CCPA, respectively.

3. Categories of Data Processed

We may collect and process the following categories of personal data about you, depending on how you use our Website and services:

3.1 Usage Data
Includes information about how you use the Website, such as your IP address, browser type, operating system, referring URLs, page views, duration of visit, and other diagnostic data generated from your interactions with our Website.

3.2 Account Data
Includes information you provide when you create an account, subscribe to services, or correspond with us. This may include your name, physical address, email address, phone number, and user credentials.

3.3 Profile Data
Includes preferences, product and artist interests, purchase history, playlists, saved songs, and account behavior, which help tailor your user experience and suggestions.

3.4 Communication Data
Includes records of communications with us, including inquiries submitted via contact forms, support tickets, email exchanges, or other modes of customer support.

3.5 Technical Data
Includes device identifiers, system configuration information, browser plug-in types and versions, time zone settings, and platform identifiers collected automatically via your use of the Website.

3.6 Transaction Data
Includes information relating to product purchases and services obtained through the Website, such as payment details, transaction IDs, billing address, delivery address, and order history.

3.7 Preference Data
Includes preferences regarding marketing consents, newsletter subscriptions, your music interests, and preferred content formats.

4. Legal Bases for Processing

We rely on the following legal bases for the collection and processing of your personal data:

– Performance of a Contract: Where data processing is necessary for the performance of a purchase, service agreement, or other contractual relationship with you.

– Consent: Where we rely on your freely given, specific, informed, and unambiguous consent, such as for sending marketing communications or placing cookies (non-essential).

– Legitimate Interests: Where processing is necessary for our legitimate interests and those interests are not overridden by your fundamental rights and freedoms, such as improving services or detecting fraud.

– Legal Obligation: Where we are required to process your personal data to comply with legal or regulatory obligations.

5. Your Rights

Subject to applicable law, you have the following rights in relation to your personal data:

– Right of Access: To request access to your personal data and receive a copy of the information we hold about you.

– Right to Rectification: To request correction of inaccurate or incomplete information.

– Right to Erasure: To request the deletion of your personal data, under specified conditions.

– Right to Restriction: To request that we temporarily restrict how we use your data under certain circumstances.

– Right to Data Portability: To request to receive your data in a structured, commonly used and machine-readable format and/or have it transferred to another controller.

– Right to Object: Where applicable, to object to data processing based on our legitimate interests.

– Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw consent at any time.

To exercise any of these rights, please contact us at [email protected].

If you are a California resident, you are entitled to additional rights under the CCPA, including:

– Right to Know: You may request to know what personal data we have collected, used, disclosed, and sold about you over the past 12 months.

– Right to Delete: You may request deletion of your personal data, subject to certain exceptions.

– Right to Opt-Out: You have the right to direct us not to sell your personal data. We do not sell personal data without your explicit consent.

6. Security Measures

We employ industry-standard technical and organizational security measures to protect your personal data. These include:

– Encrypted transmission of sensitive data (e.g., via SSL/TLS)
– Access controls on secure systems and data storage
– Regular system security reviews and audits
– Data backups and disaster recovery protocols
– Ongoing employee training in data privacy best practices

Despite these measures, no method of transmission over the Internet or electronic storage is fully secure, and we cannot guarantee absolute data security.

7. International Transfers

Your personal data may be transferred and processed outside your country of residence, including to countries that may not provide the same level of data protection. When such transfers occur, we implement appropriate safeguards, such as Standard Contractual Clauses, to ensure your personal data remains protected in accordance with GDPR and other applicable legislation.

8. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, including to comply with legal, contractual, or regulatory requirements. The duration of data retention depends on the category:

– Usage and Technical Data: up to 12 months
– Account and Profile Data: for the duration of your active relationship with us, and for up to 3 years after account termination
– Transaction and Communication Data: retained for up to 7 years to comply with financial and legal obligations
– Preference and Marketing Data: until consent is withdrawn or up to 2 years of inactivity

9. Cookie Policy

We use digital tracking technologies, including cookies, to improve user experience, personalize content and analyze Website traffic. These include:

– Essential Cookies: Required for the Website to function properly, such as those used for authentication and secure shopping.

– Functional Cookies: Enhance the Website’s functionality and remember your preferences.

– Performance/Analytics Cookies: Collect anonymized data to help us understand how users interact with the Website and improve overall performance.

– Marketing Cookies: Used to deliver relevant advertisements and content based on your browsing behavior and preferences.

10. Cookie Management and Compliance

By law, we are required to obtain your consent before placing non-essential cookies on your device. Upon visiting sandrockrecordings.com, you will be presented with a cookie consent notice allowing you to manage your preferences. You may withdraw or modify your cookie preferences at any time via our Cookie Management Tool or by adjusting your browser settings to disable or delete cookies.

California residents may exercise their opt-out rights concerning targeted advertising or sale of personal data by utilizing any “Do Not Sell My Info” link provided on our Website, where applicable.

11. Special Protections for Children Under 13

We do not knowingly collect personal data from children under the age of 13. If we become aware that such data has been collected without verified parental consent, we will take appropriate steps to delete the information. If you believe a child has provided personal data through sandrockrecordings.com, please contact us at [email protected].

12. Policy Updates and User Notifications

We reserve the right to modify or update this Privacy Policy from time to time, to reflect changes in legal requirements, technology, or our practices. Where material changes are made, we will take appropriate measures to inform you, which may include posting a prominent notice on the Website or contacting you directly.

13. Contact

If you have any questions, complaints, or privacy-related concerns about this Privacy Policy or our handling of your personal data, please contact us at:

Email: [email protected]
Website: https://sandrockrecordings.com

We are committed to ensuring full compliance with applicable data protection laws and strive to provide transparency and control regarding the use of your personal data. Please feel free to reach out to us at any time with inquiries or requests related to your privacy.