Privacy Policy
Last updated: 9 July 2026
1. Privacy Policy
Last updated: 08 July 2026 | Compliant with UK GDPR and the Data Protection Act 2018
1.1 Introduction and Data Controller
Music Concierge Worldwide Ltd ("Music Concierge", "we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you visit www.musicconcierge.co.uk or use our services, and sets out your rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
For the purposes of applicable data protection legislation, the data controller is Music Concierge Worldwide Ltd, Hertford, Hertfordshire, UK.
Our Information Commissioner's Office (ICO) registration number is: [ICO Registration Number – ZB689105].
For any data protection queries, please contact us at: info@musicconcierge.co.uk.
1.2 What Personal Data We Collect
Identity and Contact Data
- Full name
- Email address
- Postal / billing address
- Business telephone number
- Company name (where applicable)
Technical and Usage Data
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time spent on those pages
- Referring URLs
- Cookie identifiers (see Cookie Policy, Section 3)
Financial Data
- Payment card details (processed securely via our PCI-DSS-compliant payment provider; we do not store full card details on our systems)
Communications Data
- Any correspondence you send us, including support enquiries
We do not intentionally collect special category data (e.g. health, religious beliefs, biometric data). Please do not submit such data to us.
1.3 How We Collect Your Data
- Directly from you: when you register on our site, purchase a service, fill in a form, or contact us.
- Automatically: via cookies and similar technologies as you interact with our website.
- From third parties: such as analytics providers (e.g. Google Analytics) and payment processors.
1.4 Legal Basis for Processing
Under UK GDPR, we must have a valid legal basis for processing your personal data. The bases we rely on are:
- Contract performance: to provide the services you have requested or purchased from us.
- Legal obligation: to comply with applicable law, including copyright reporting obligations to collecting societies such as PRS for Music and PPL.
- Legitimate interests: to improve our website and services, prevent fraud, and send relevant marketing communications (where you have not objected). We carry out legitimate-interest assessments to ensure our interests are not overridden by your rights.
- Consent: for non-essential cookies and certain direct marketing activities. You may withdraw consent at any time without detriment.
1.5 How We Use Your Data
- To deliver and manage the services and products you request.
- To process payments and prevent fraudulent transactions.
- To comply with copyright licensing obligations (e.g. reporting usage data to PRS for Music, PPL, and other relevant bodies).
- To send service-related communications (e.g. invoices, account updates).
- To send marketing communications where you have opted in or we have a legitimate interest and you have not opted out.
- To analyse and improve website performance using aggregated, anonymised analytics data.
- To comply with legal and regulatory requirements.
1.6 Data Sharing and Third Parties
We do not sell your personal data. We may share your data with:
- Service providers acting as data processors on our behalf (e.g. payment processors, email delivery providers, IT/hosting providers). These parties are bound by data processing agreements and may only use your data on our instructions.
- Collecting societies (PRS for Music, PPL, and others) as required to fulfil our licensing obligations.
- Professional advisers (solicitors, accountants, auditors) under obligations of confidentiality.
- Regulatory or law-enforcement bodies where required or permitted by law.
Where we transfer data outside the UK, we ensure appropriate safeguards are in place (e.g. UK adequacy decisions or standard contractual clauses).
1.7 Data Retention
We retain personal data for no longer than is necessary for the purposes for which it was collected. Typical retention periods are:
- Customer account and transaction data: 7 years (for tax and accounting compliance).
- Marketing opt-in records: until you withdraw consent or opt out.
- Website analytics data: up to 26 months in aggregated / anonymised form.
- Communications: 3 years from the date of the last correspondence.
1.8 Your Rights Under UK GDPR
You have the following rights in relation to your personal data:
- Right of access: to request a copy of the personal data we hold about you (Subject Access Request).
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure ('right to be forgotten'): to request deletion of your data where there is no compelling reason for us to continue processing it.
- Right to restriction: to request that we limit how we use your data.
- Right to data portability: to receive your data in a structured, machine-readable format where processing is based on consent or contract.
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making: we do not currently use solely automated decision-making that has a legal or similarly significant effect on you.
To exercise any of these rights, please contact us at info@musicconcierge.co.uk. We will respond within one calendar month (or three months for complex requests, with notification). You will not normally need to pay a fee.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113, if you are unhappy with how we handle your data.
1.9 Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration, or disclosure. These include TLS encryption, access controls, and regular security reviews. We maintain PCI-DSS compliance for payment card data. However, no internet transmission is completely secure; you transmit data at your own risk.
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the ICO without undue delay and within 72 hours of becoming aware of the breach (where required by law).
1.10 Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The effective date at the top of this document indicates when it was last revised. We will notify you of material changes by posting a notice on our website or by email where appropriate.
1.11 Contact us
If you have any questions about this Privacy Policy, please email us at info@musicconcierge.co.uk.