Legal
Privacy Policy
1. Name and Address of the Controller
The controller within the meaning of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU GDPR) is:
2112 Studios Ltd
Private Limited Company
11 Broadway West
York YO10 4JN
England, United Kingdom
Company No.: 12091600
Registered in England and Wales
Director: Dominik Kirkman-Seitz
E-Mail: info@2112.studio
2. EU Representative pursuant to Art. 27 EU GDPR
As our company is established in the United Kingdom and offers services to individuals in the European Union, we have designated a representative in the European Union in accordance with Art. 27 EU GDPR. This representative serves as the point of contact for all matters relating to the processing of personal data of EU data subjects.
Our EU representative is:
MACK One France SAS1 Chemin de l'Amitie
67115 Plobsheim
France
Phone: +49 7822 77-18000
E-Mail: dpo@2112.studio
Data subjects in the European Union may contact our EU representative directly, in addition to the controller, to exercise their rights under the EU GDPR or to submit data protection enquiries.
The designation of the EU representative does not affect the liability of the company as controller under the EU GDPR.
3. General Information on Data Processing
3.1 Applicable Legal Frameworks
Our company is established in the United Kingdom and offers services worldwide. The following legal frameworks therefore apply:
- UK GDPR in conjunction with the Data Protection Act 2018 for all personal data we process
- EU GDPR additionally for personal data of individuals located in the European Union (Art. 3(2) EU GDPR - market location principle)
3.2 Scope of Processing
We process personal data of our users only to the extent necessary for the provision of a functional website and our content and services.
3.3 Legal Bases for Processing
The processing of your personal data is based on one of the following legal bases:
- Performance of a contract or pre-contractual measures (Art. 6(1)(b) UK GDPR / EU GDPR), e.g. when commissioning music productions
- Legitimate interests (Art. 6(1)(f) UK GDPR / EU GDPR), e.g. when collecting server log data or responding to contact enquiries
- Consent (Art. 6(1)(a) UK GDPR / EU GDPR), e.g. for embedded media services such as the Spotify Music Player
- Legal obligation (Art. 6(1)(c) UK GDPR / EU GDPR), e.g. statutory retention obligations under tax and commercial law
3.4 Deletion and Retention Periods
Personal data is deleted as soon as the purpose of processing has ceased and no statutory retention obligations apply. Where such obligations exist, processing is restricted, meaning the data is blocked and not used for any other purpose.
3.5 Security
We use SSL/TLS encryption to protect the transmission of personal data. An encrypted connection is indicated by "https://" and the padlock symbol in your browser's address bar.
3.6 Disclosure to Third Parties
Personal data is only disclosed to third parties where this is necessary for the performance of a contract, required by law, or covered by your consent. Disclosure generally takes place within the framework of a contractually regulated data processing agreement.
4. International Data Transfers
As we offer services worldwide, personal data may be transferred to countries outside the United Kingdom or the EU.
Transfers from the UK to third countries are based on:
- Adequacy regulations made by the UK Secretary of State, or
- International Data Transfer Agreements (IDTAs)
Transfers from the EU to the United Kingdom: The EU Commission's adequacy decision for the UK is currently in force. Should this lapse, we will implement EU Standard Contractual Clauses (SCCs).
5. Hosting, Log Files and Content Delivery (Cloudflare)
Our website is hosted and delivered via Cloudflare. The provider is:
Cloudflare, Inc.101 Townsend St
San Francisco, CA 94107
USA
Cloudflare acts as a Content Delivery Network (CDN) and hosting provider. All access to our website is routed through Cloudflare's network. Our system automatically collects the following technical data (so-called traffic data):
- IP address of the accessing device
- Browser type and version
- Operating system
- Internet service provider
- Referrer URL (the page from which access was made)
- Pages visited
- Date and time of access
The IP address is stored for the duration of the session to enable delivery of the website. In the log files, it is anonymised or deleted after a maximum of 7 days, so that it can no longer be attributed to individual persons.
Cloudflare also sets technically necessary cookies to ensure the security and performance of the website (e.g. to defend against DDoS attacks and bot traffic). A complete overview of the cookies used can be found in Section 8.
Legal basis: Art. 6(1)(f) UK GDPR / EU GDPR. Our legitimate interest lies in the secure, performant and technically error-free provision of our website.
Data transfer to the USA: Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (DPF), so data transfers to the USA are carried out on this basis. For transfers from the UK, we rely on the relevant UK adequacy regulations and/or IDTAs. We have concluded a Data Processing Agreement (DPA) with Cloudflare.
Right to object: The collection of this data is technically essential for the operation of the website. An objection pursuant to Art. 21 UK GDPR / EU GDPR is possible to the extent that you can demonstrate particular circumstances that argue against the processing.
Further information on data protection at Cloudflare: https://www.cloudflare.com/privacypolicy/
6. Analytics and Tracking
We do not use any tracking or analytics tools, nor any analytics cookies. No user profiles are created and no browsing behaviour is analysed.
7. Consent Management (OneTrust)
We use the consent management tool OneTrust to obtain, manage and document your consent to the use of cookies and embedded services.
The provider is:
OneTrust LLC1200 Abernathy Road NE, Building 600
Atlanta, GA 30328
USA
When you visit our website, a cookie banner appears through which you can manage your consents. OneTrust stores your preferences and a timestamp of your consent in order to document proof of consent.
Legal basis: Art. 6(1)(c) UK GDPR / EU GDPR (legal obligation to document consents) and Art. 6(1)(f) UK GDPR / EU GDPR (legitimate interest in legally compliant record-keeping).
Data transfer to the USA: OneTrust LLC is certified under the EU-U.S. Data Privacy Framework (DPF). For transfers from the UK, we rely on IDTAs. We have concluded a Data Processing Agreement (DPA) with OneTrust.
You can adjust your cookie settings at any time via the cookie settings link in the footer of our website.
Further information: https://www.onetrust.com/privacy-notice/
8. Cookies - Complete Overview
Below you will find an overview of all cookies used on our website, broken down by provider and category.
8.1 Technically Necessary Cookies
These cookies are strictly required for the operation of the website and are set without your consent.
OneTrust (Consent Management)
- OptanonConsent: Stores your cookie consent preferences; 1 year
- OptanonAlertBoxClosed: Stores whether the cookie banner has been closed; 1 year
8.2 Spotify Music Player (Opt-in)
Our website embeds the Spotify Music Player.
Provider: Spotify AB, Regeringsgatan 19, SE-111 53 Stockholm, Sweden
To protect your privacy, the Spotify Player is not loaded automatically. Instead, a placeholder is displayed first. The connection to Spotify's servers is only established after you have actively given your consent by clicking on the placeholder.
After your consent, the following data is transmitted to Spotify:
- Technical connection data (IP address, date, time, browser)
- Page visited
- Possible association with your Spotify account if you are logged in
Legal basis: Art. 6(1)(a) UK GDPR / EU GDPR (consent).
Cookies set by Spotify (after consent):
- sp_t: Tracking cookie for usage statistics; 1 year
- sp_landing: Stores the user's entry page; Session
Note: Cookies set by Spotify may vary. For further information, please refer to Spotify's privacy policy: https://www.spotify.com/en/legal/privacy-policy/
Withdrawal of consent: You can withdraw your consent at any time with effect for the future via the cookie settings in the footer of our website. After withdrawal, please reload or refresh the page - the placeholder will then be displayed again and the player will no longer load.
8.3 Managing Cookie Settings
You can adjust or withdraw your consents for the OneTrust banner at any time via the cookie settings link in the footer of our website. Technically necessary cookies cannot be disabled as they are essential for the operation of the website.
9. Social Media Buttons
Our website includes buttons linking to the following platforms: Facebook, Instagram, LinkedIn, X (formerly Twitter), YouTube and Spotify.
These buttons are implemented as simple hyperlinks to our respective social media pages. They are not embedded plugins that automatically transmit data to the providers when the page loads.
Please note: When you visit our profile pages (fan pages) on these platforms, we are jointly responsible with the respective platform provider for the data processing taking place there. Please refer to the privacy notices of the respective providers for further information:
- Facebook/Instagram: https://www.facebook.com/privacy/policy/
- LinkedIn: https://www.linkedin.com/legal/privacy-policy
- X: https://x.com/en/privacy
- YouTube/Google: https://policies.google.com/privacy
- Spotify: https://www.spotify.com/en/legal/privacy-policy/
If you do not want platform providers to associate your visit with your user account, please log out before clicking.
10. Contact Form (provided by Anexia)
10.1 Description and Scope
The contact form embedded on our website is technically provided and operated by Anexia Holding GmbH:
Anexia Holding GmbHFeldkirchner Strasse 140
9020 Klagenfurt
Austria
When you use the contact form, the following data is processed:
- First name and last name
- E-mail address
- Message content
- IP address, date and time of submission (for abuse prevention; deleted after 7 days)
The transmitted data is stored on Anexia's servers and used by us solely to process your enquiry. Alternatively, you may contact us at any time by e-mail at info@2112studios.com.
10.2 Data Processing Agreement
We have concluded a Data Processing Agreement (DPA) with Anexia in accordance with Art. 28 UK GDPR / EU GDPR. Anexia processes your data exclusively on our instructions and not for its own purposes.
10.3 Legal Basis
- For general enquiries: Art. 6(1)(f) UK GDPR / EU GDPR (legitimate interest in responding to your enquiry)
- For contract-related enquiries: Art. 6(1)(b) UK GDPR / EU GDPR (pre-contractual measures)
10.4 Retention Period
Data is deleted once the conversation has been concluded and no statutory retention obligations apply. Technical metadata (IP address, timestamp) is deleted after a maximum of 14 days.
10.5 Right to Object
You have the right to object to the processing of your personal data at any time (Art. 21 UK GDPR / EU GDPR). In such a case, we will be unable to continue processing your enquiry. Please contact us at: info@2112.studio
11. Rights of the Data Subject
To the extent that your personal data is processed by us, you have the following rights:
Right of Access (Art. 15 UK GDPR / EU GDPR)
You may request information about the data we process about you. For identification purposes, we may request proof of your identity.
Right to Rectification (Art. 16 UK GDPR / EU GDPR)
You may request the correction of inaccurate or incomplete data.
Right to Erasure (Art. 17 UK GDPR / EU GDPR)
You may request the deletion of your data under certain conditions.
Right to Restriction of Processing (Art. 18 UK GDPR / EU GDPR)
You may request the restriction of processing, e.g. if you contest the accuracy of the data.
Obligation to Notify (Art. 19 UK GDPR / EU GDPR)
We are obliged to inform any recipients of your data of any rectification, erasure or restriction of processing.
Right to Data Portability (Art. 20 UK GDPR / EU GDPR)
You may request that your data be provided in a commonly used, machine-readable format.
Right to Object (Art. 21 UK GDPR / EU GDPR)
You have the right to object at any time to the processing of your data on the basis of legitimate interests, in particular in the case of direct marketing.
Right to Withdraw Consent
Any consent you have given may be withdrawn at any time with effect for the future. The lawfulness of processing carried out prior to withdrawal is not affected.
To exercise your rights, please contact: info@2112.studio or dpo@2112.studio
12. Right to Lodge a Complaint with a Supervisory Authority
For data subjects in the United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Website: https://ico.org.uk. Phone: +44 303 123 1113
For data subjects in the European Union: You have the right to lodge a complaint with the data protection authority of your place of residence, workplace or the place of the alleged infringement. An overview of all EU data protection authorities can be found at: https://edpb.europa.eu/about-edpb/about-edpb/members_en
We kindly ask you to contact us directly before lodging a complaint so that we can address your concern.
13. Automated Decision-Making and Profiling
We do not carry out any automated decision-making within the meaning of Art. 22 UK GDPR / EU GDPR. No profiling takes place.
14. Changes to this Privacy Policy
We reserve the right to update this privacy policy as necessary to reflect changes in our data processing practices or legal requirements. The current version is available on our website at all times.
Last updated: August 2026