LEGAL

Privacy Policy

Last updated: May 2026

1. Data Controller

Music Hub Transilvania S.R.L.
Calea Baciului nr. 99, Cluj-Napoca, România
Email: [email protected]
Phone: 0770 271 051

2. What data we collect

When you use our contact form, booking system or purchase a voucher, we collect:

  • Identity data: first and last name
  • Contact data: email address, phone number
  • Booking data: preferred room, date and time, session duration, chosen extras
  • Payment data: transaction status (processed securely by Stripe — we never store card details)
  • Communication data: messages sent through the contact form

3. Why we collect it (legal basis)

  • Contract execution (Art. 6(1)(b) GDPR): to process your room booking or voucher purchase and send confirmation emails
  • Legitimate interest (Art. 6(1)(f) GDPR): to manage our schedule, prevent fraud and improve our services
  • Consent (Art. 6(1)(a) GDPR): to send marketing communications — only if you have explicitly opted in

4. How long we keep your data

  • Booking data: 3 years from the date of the booking (accounting obligations)
  • Contact messages: 12 months from receipt
  • Voucher data: 3 years from the date of issue

5. Who we share your data with

We only share your data with trusted third-party processors:

  • Stripe Inc. — payment processing (PCI-DSS compliant)
  • Resend Inc. — transactional email delivery
  • Google LLC — calendar management (internal scheduling)

We do not sell, rent or share your personal data with any other third party for marketing purposes.

6. Your rights

Under GDPR you have the right to:

  • Access — request a copy of the data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — request deletion of your data (subject to legal obligations)
  • Restriction — ask us to limit processing of your data
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interest
  • Withdraw consent — at any time, without affecting prior processing

To exercise any of these rights, email us at [email protected]. We will respond within 30 days.

7. Cookies

Our website uses only essential cookies required for the site to function (session management, security). We do not use tracking or advertising cookies.

8. Security

All data is transmitted over HTTPS. Payment data is handled exclusively by Stripe and is never stored on our servers. We apply appropriate technical and organisational measures to protect your personal data.

9. Complaints

If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the Romanian national supervisory authority: ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, Bulevardul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, www.dataprotection.ro.