Last updated: 9 August 2026
1. Controller
Roberto Marín Muñoz
RoMaMu Records
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
Email: webmaster@romamurecords.com
No data protection officer has been appointed because the statutory requirements for an appointment do not apply.
2. General information
We process personal data only where this is necessary to provide this website, respond to enquiries, review music submissions, operate our newsletter or protect the website against abuse. The principal legal bases are Article 6(1)(a), (b), (c) and (f) GDPR.
3. Website hosting and server logs
This website and its email service are hosted by STRATO GmbH, Otto-Ostrowski-Straße 7, 10249 Berlin, Germany. STRATO operates data centres in Germany.
When the website is accessed, the hosting infrastructure may process technical data such as the requested resource, date and time, transferred data volume, referrer, browser and operating-system information, and an IP address or anonymised host identifier. STRATO states that host names and IP addresses in hosting statistics are anonymised and that an anonymised IP remains valid for no more than 24 hours. Hosting log files are generally available for up to six weeks and error logs for a shorter period.
The processing is necessary to deliver the website, maintain security and diagnose faults. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are secure, stable and efficient website operation. STRATO acts as our processor where applicable.
4. Contact form and email
If you contact us, we process your name, email address, subject, message and the associated technical delivery data in order to respond. The legal basis is Article 6(1)(b) GDPR where the enquiry relates to a contract or pre-contractual measures, and otherwise Article 6(1)(f) GDPR. Our legitimate interest is responding to genuine enquiries.
Messages are delivered to our STRATO-hosted mailbox. WordPress does not retain a separate database copy of form submissions. General enquiries are normally deleted no later than 12 months after completion unless statutory retention duties or the establishment, exercise or defence of legal claims require longer storage.
5. Demo submissions
For demo submissions we process artist name, email address, the private listening link, an optional note and technical delivery data. The purpose is the editorial review of the submitted music and any related communication. The legal basis is Article 6(1)(b) GDPR where the submission seeks a potential contractual relationship, and otherwise Article 6(1)(f) GDPR.
Rejected or inactive submissions are normally deleted within six months. If discussions continue, the data is retained for the duration of the relationship and any applicable legal retention or limitation periods. Please submit links only and do not send sensitive personal data or confidential unreleased files through the form.
6. Playlist submissions
For playlist consideration we process artist name, email address, the Spotify URL, selected playlist, an optional note and technical delivery data. Submission is voluntary and following a playlist is not required. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the editorial curation of our playlists and communication with submitting artists. Inactive submissions are normally deleted within six months.
7. Newsletter and Sendy
If you subscribe to the newsletter, we process your email address, optional name, subscription status, confirmation and unsubscribe records, timestamps and technical information generated during registration. The legal basis is your consent under Article 6(1)(a) GDPR. We use double opt-in: the subscription becomes active only after confirmation by email.
The newsletter is managed with our own Sendy installation at newsletter.romamurecords.com. Its database is hosted in the AWS Europe (Ireland) Region. Amazon Web Services EMEA SARL acts as a processor under the AWS GDPR Data Processing Addendum. Subscription data is kept until you unsubscribe or withdraw consent. Minimal suppression and consent records may then be retained where necessary to respect the unsubscribe request and demonstrate compliance.
You may withdraw your consent at any time by using the unsubscribe link in any newsletter or by contacting us. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
8. hCaptcha
Forms are protected by hCaptcha, a service of Intuition Machines, Inc., to distinguish legitimate submissions from automated abuse. hCaptcha may process technical and interaction data, including IP address, browser and device information, page context, challenge responses and timing information.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are preventing spam, fraud and attacks and maintaining the availability of our forms. hCaptcha may process data in the United States and other countries. It states that it uses the EU Standard Contractual Clauses and participates in the EU–US Data Privacy Framework. Further information is available in the hCaptcha Privacy Policy and its GDPR information.
9. External links and social networks
The website contains ordinary links to Spotify, Apple Music, Instagram, Facebook, YouTube and other external services. No social-media or streaming embed is loaded automatically. Data is transferred to those providers only when you choose to follow an external link. The destination provider is independently responsible for its processing.
10. Cookies and similar technologies
We do not use analytics, advertising pixels, behavioural profiling, remote web fonts or non-essential third-party embeds. The public website does not intentionally set non-essential cookies. Technically necessary session or security storage may be used by WordPress administration, Sendy or hCaptcha where required for the requested service or abuse prevention. Because no consent-requiring service is currently enabled, the website does not display a consent banner.
11. Recipients and transfers
Personal data is disclosed only where necessary to the processors described above, where required by law, or where necessary to establish, exercise or defend legal claims. We do not sell personal data. Where processing outside the EEA occurs, we rely on an adequacy decision, the EU Standard Contractual Clauses or another safeguard permitted by Chapter V GDPR.
12. Your rights
Subject to the statutory requirements, you have the right to access, rectification, erasure, restriction of processing, data portability and objection. Where processing is based on consent, you may withdraw it at any time with future effect. Where processing is based on Article 6(1)(f) GDPR, you may object on grounds relating to your particular situation.
You also have the right to lodge a complaint with a supervisory authority. The authority generally responsible for private organisations established in Bavaria is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
www.lda.bayern.de
13. Security and changes
We use appropriate technical and organisational measures, including encrypted HTTPS transmission, access controls, data minimisation and anti-abuse protection. We may update this policy when services or legal requirements change. The current version is published on this page.