epk.show

Privacy policy

Last updated: [DATE]

Draft. This document describes how the epk.show platform processes data. Before publishing, review it with legal counsel and fill in the entity details marked in brackets.

1. Controller

[LEGAL ENTITY], tax ID [TAX ID], registered at [ADDRESS] (“epk.show”, “we”) is the controller of the data described here. Privacy contact: privacidad@epk.show.

When a customer (agency or artist) uses epk.show to manage their own contacts’ data (promoters, send recipients), the customer is the controller of that data and epk.show acts as a processor. That relationship is governed by the Data Processing Agreement (DPA).

2. What we process and on what basis

DataPurposeLegal basis (GDPR art. 6)
Account and users: email, name, password (encrypted), language, role. Create and operate the account; authentication. Performance of a contract (6.1.b).
Artist content: stage name, bio, images, riders and documents uploaded by the customer. Publish and share the EPK. Performance of a contract (6.1.b).
Recipients: name, organization and email entered by the customer to autocomplete sends. Send proposals and attribute engagement. Customer’s legitimate interest (6.1.f), governed via the DPA.
Link (Smart Link) tracking events: event type (open, section view, rider download, booking click), timestamp, IP always hashed (never stored in the clear), user agent, approximate country/city, and dwell time. B2B contracting intelligence: know which proposal was opened and with what interest. Legitimate interest (6.1.f). B2B, proportionate, only on tracked links.
Booking requests: name, email, event info and message submitted by the promoter via the form. Connect the promoter with the artist/agency. Pre-contractual measures at the data subject’s request (6.1.b).
Billing: Stripe customer ID, subscription status, tax status, tax ID and business name. We do not store card data. Charge the subscription and meet tax obligations. Performance of a contract (6.1.b) and legal obligation (6.1.c).
Public metrics: subscribers and views of the linked YouTube channel. Keep the EPK automatically up to date. Legitimate interest (6.1.f); public data.

3. Tracking, plainly

4. Processors and transfers

To deliver the service we rely on providers that process data on epk.show’s behalf:

ProviderFunctionLocation
SupabaseDatabase and authenticationEuropean Union
CloudflareCDN, edge compute, file storage (R2) and cache (KV)Global (edge)
StripePayments and billingEU / US (with adequate safeguards)
ResendTransactional emailUS (with adequate safeguards)
Google (YouTube Data API)Public channel metricsGlobal

Personal data at rest is hosted in the European Union (Supabase). Where a provider processes data outside the EEA, the transfer relies on Standard Contractual Clauses or other adequate GDPR safeguards.

5. Retention

6. Your rights

You may exercise the rights of access, rectification, erasure, portability, objection and restriction. From Settings → Privacy & data the account owner can export all their data (readable JSON) and request deletion of the account at any time. You can also write to privacidad@epk.show. You have the right to lodge a complaint with your competent supervisory authority.

7. Account deletion

When you request deletion, the account is marked for removal and is permanently and irreversibly deleted after 30 days, including stored files, users and all events. During that window you can cancel the request or export your data. Links you already shared stop working after deletion.

8. Minors

epk.show is a professional (B2B) product and is not directed at minors.

9. Changes

We may update this policy. The current version will be posted on this page with its update date.