1. Who is responsible:
The data controller for this site is [legal name of the business], [address], [VAT / company number], trading as Sound Weekends. For anything to do with your data, write to [privacy e‑mail] — it comes to me directly, there is no support department in between.
2. What is collected:
Nothing is asked of you just for reading the site. Data appears in three situations only: when you buy, when you subscribe, and when you write to me.
| When |
What |
| You open a page |
Technical data your browser sends: IP address, browser and version, operating system, referring page, time of the request, and the pages viewed. Stored in the web server log. |
| You buy a library |
Name, e‑mail address, billing address and country, company name and VAT number if you buy as a business, the order itself (libraries, price, currency, tax rate and amount), and the payment reference returned by the payment provider. |
| You join the mailing list |
E‑mail address, the date and IP of the sign‑up as proof of consent, and whether the mails are opened. |
| You use the contact form |
Name, e‑mail address and whatever you write in the message. |
Card numbers never reach this site. Payment details are entered on the payment provider’s own page or in their hosted field, and I only ever see the last four digits, the card brand and whether the payment went through.
3. Why, and on what legal basis:
Under the GDPR each purpose needs a legal basis. Mine are:
- Performance of a contract — to take the order, deliver the download links, re‑issue them, answer support questions and handle refunds.
- Legal obligation — to issue invoices and keep accounting and VAT records for as long as the tax law requires.
- Consent — for the mailing list and for any non‑essential cookie. You can withdraw it at any time; that does not affect what was done before.
- Legitimate interest — to keep the site online and secure, to prevent fraud and abuse, and to understand in aggregate which pages people use. This never involves profiling you as an individual.
4. Who else sees the data:
Only the companies that are needed to run the shop, and only the part of the data each of them needs. Nothing is sold, rented or passed on for anyone else’s advertising.
| Processor |
What it handles |
| [hosting provider] |
Runs the server, holds the site files, the database and the access logs. |
| [payment provider] |
Takes the payment, holds the card data, returns the result and the payout reports. |
| [e‑mail / newsletter provider] |
Sends order and download e‑mails and the mailing list. |
| [analytics] |
Aggregated visit statistics. |
| [accountant] |
Invoices, bookkeeping and tax filings. |
Data may also be disclosed where the law requires it — a lawful request from an authority, or defending a legal claim.
5. Payments and VAT records:
Selling digital goods inside the EU means tax is charged according to where the buyer is, so the law requires me to record and keep two independent pieces of evidence of your location — usually your billing address and the country of your IP address or of your payment method.
If you buy as a business with a valid EU VAT number, the number is checked against the VIES database and the result of that check is stored with the order. Invoices, evidence of location and VAT returns are kept for the retention period set by tax law and cannot be deleted on request before it expires.
6. Mailing list:
The list is opt‑in and it is used for one thing: telling you when a new library is out and sending a few free sounds from it. No partner offers, no rented lists, no selling of addresses.
Every mail has an unsubscribe link, and one click is enough. After you unsubscribe your address is removed from the active list; a minimal record of the unsubscribe is kept so you are not accidentally added again.
7. Cookies and analytics:
Cookies are small files a site stores in your browser. This site uses as few as it can:
| Type |
What for |
Consent |
| Essential |
Keeping the cart, the session and the checkout working, and remembering your cookie choice. |
Not required |
| Analytics |
Counting visits and seeing which pages are read, in aggregate. |
Required |
| Marketing |
Not used at the moment. |
Required if introduced |
You can refuse or delete cookies in your browser settings at any time. Blocking essential cookies will break the cart and the checkout. Because there is no agreed industry standard for it, Do Not Track browser signals are not acted upon.
8. How long it is kept:
| Data |
Kept for |
| Server access logs |
[N] days, then deleted automatically |
| Orders, invoices, VAT evidence |
[N] years — the period required by tax law |
| Customer account and licence record |
As long as the account exists, so download links can be re‑issued |
| Mailing list |
Until you unsubscribe |
| Contact form correspondence |
[N] months after the conversation ends |
9. Transfers outside the EEA:
Some of the services above are run by companies based outside the European Economic Area, mainly in the United States. Where that happens the transfer is covered by the European Commission’s Standard Contractual Clauses or by an adequacy decision, and the processor is bound by a data processing agreement. The current list of processors and their locations is in section 4.
10. Your rights:
Wherever you live, you can ask me for any of the following, and I will answer within one month:
- Access — a copy of the data held about you;
- Rectification — correcting anything wrong or out of date;
- Erasure — deleting it, except where tax law requires me to keep the invoice;
- Restriction and objection — pausing or objecting to processing based on legitimate interest;
- Portability — receiving your data in a machine‑readable file;
- Withdrawing consent — at any moment, for the mailing list and for cookies.
Residents of California have equivalent rights under the CCPA, including the right to know what is collected and to ask for deletion. I do not sell personal information, in the CCPA sense or any other.
To use any of these rights, write to [privacy e‑mail] from the address the data is connected to.
11. Children:
The shop is not aimed at children and I do not knowingly collect data from anyone under 16. If you are a parent or guardian and think your child has given me their data, write to me and I will delete it.
12. Security:
The site runs over HTTPS, administrative access is limited to me, backups are encrypted, and payment data is handled entirely by the payment provider. No system is perfectly secure, but if a breach ever affects your data I will notify you and the supervisory authority as the GDPR requires.
13. Automated decision‑making:
There is no profiling and no automated decision that has a legal or similarly significant effect on you. The payment provider runs automated fraud checks on transactions — for example temporarily blocking a card or an IP address after repeated failed attempts — and those checks are part of their own service.
14. Changes and complaints:
This policy will be updated when the shop changes — a new payment provider, a new tool, a new legal requirement. The date at the top always shows the current version.
If you are unhappy with how your data is handled, tell me first — it is usually a misunderstanding I can fix. You also have the right to complain to the data protection authority in the country you live in, or to [the supervisory authority of the country of establishment].