LEGAL / 01

Privacy notice

EFFECTIVE 2 SEPTEMBER 2026 · VERSION 1.1

1. Who controls your data

Crimson Creative Group AB (brand: Crimson Creative Studio), organisation number 559586-8083. Our business address and VAT information are on the legal and contact page.

Privacy contact: [email protected].

2. What this notice covers

This notice covers our public website, meeting bookings reached from the website, direct enquiries, and the password-protected band partner portal. It does not replace a signed band partnership agreement or the separate information that applies to a specific merch sale.

3. What we process and why

4. Who receives data

We use service providers only where needed to operate the business. These may include Hostinger and infrastructure providers for hosting, Cloudflare for DNS and edge security, Cal.eu for bookings, Fibery for CRM and project records, n8n for controlled automation, Google Drive for partner files, Discord for internal approvals and alerts, GitHub for encrypted offsite backups, and OpenAI tools for limited human-reviewed research and drafting. Access is restricted by role and purpose.

Some providers may process data outside the EEA. Applicable transfer safeguards and provider arrangements depend on the service and account; contact us for information about the safeguards applicable to your data. Cal.eu is the EU-hosted booking service selected for this website. Opening its booking link takes you to that service.

Backups are encrypted and access-restricted. Current backup files are pruned after 14 days, but earlier encrypted versions can remain in private Git history; that is not a guaranteed 14-day erasure period. Erased browser analytics is excluded when restoring a database using the separate live erasure ledger. Broader requests require checking backup restrictions and restore exclusions as part of the review.

5. AI and automated decisions

AI may help prepare research or drafts. A person reviews customer-facing business communications before they are sent. Identity-verification and status emails for data-removal requests are automated when the mail service is available; they are not AI decisions about entitlement to erasure. Shared or legally retained records receive human review. We do not make solely automated decisions that produce legal or similarly significant effects about website visitors, leads or partners.

6. Your rights

Depending on the situation, you can ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You can withdraw consent at any time without affecting earlier lawful processing. Use for analytics consent, or email us for other requests.

Use the data-rights page to remove this browser’s analytics or request other removal. We verify email control and, where needed, your authority over a shared account. We normally respond within one calendar month of receipt; any permitted extension must be explained within that month. Deletion is not absolute: accounting duties, legal claims and others’ rights may require limited retention, which we explain.

You may complain to the Swedish Authority for Privacy Protection (IMY) at imy.se. We may need to verify your identity before acting on a request.

7. Security

We use encrypted transport, access controls, signed secure cookies, rate limits, two-factor authentication options, encrypted backups and monitoring. No online system is risk-free; if a personal-data incident creates a legal notification duty, we will follow the applicable GDPR process.

8. Changes and questions

We will update the effective date and version when this notice changes materially. Questions or rights requests can be sent to [email protected].