Privacy Policy

1. Name and Address of the Controller

The controller within the meaning of the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU GDPR) is:

2112 Studios Ltd
Private Limited Company
11 Broadway West
York YO10 4JN
England, United Kingdom

Company No.: 12091600
Registered in England and Wales
Director: Dominik Kirkman-Seitz
E-Mail: info@2112.studio

2. EU Representative pursuant to Art. 27 EU GDPR

As our company is established in the United Kingdom and offers services to individuals in the European Union, we have designated a representative in the European Union in accordance with Art. 27 EU GDPR. This representative serves as the point of contact for all matters relating to the processing of personal data of EU data subjects.

Our EU representative is:

MACK One France SAS
1 Chemin de l'Amitie
67115 Plobsheim
France
Phone: +49 7822 77-18000
E-Mail: dpo@2112.studio

Data subjects in the European Union may contact our EU representative directly, in addition to the controller, to exercise their rights under the EU GDPR or to submit data protection enquiries.

The designation of the EU representative does not affect the liability of the company as controller under the EU GDPR.

3. General Information on Data Processing

3.1 Applicable Legal Frameworks

Our company is established in the United Kingdom and offers services worldwide. The following legal frameworks therefore apply:

3.2 Scope of Processing

We process personal data of our users only to the extent necessary for the provision of a functional website and our content and services.

3.3 Legal Bases for Processing

The processing of your personal data is based on one of the following legal bases:

3.4 Deletion and Retention Periods

Personal data is deleted as soon as the purpose of processing has ceased and no statutory retention obligations apply. Where such obligations exist, processing is restricted, meaning the data is blocked and not used for any other purpose.

3.5 Security

We use SSL/TLS encryption to protect the transmission of personal data. An encrypted connection is indicated by "https://" and the padlock symbol in your browser's address bar.

3.6 Disclosure to Third Parties

Personal data is only disclosed to third parties where this is necessary for the performance of a contract, required by law, or covered by your consent. Disclosure generally takes place within the framework of a contractually regulated data processing agreement.

4. International Data Transfers

As we offer services worldwide, personal data may be transferred to countries outside the United Kingdom or the EU.

Transfers from the UK to third countries are based on:

Transfers from the EU to the United Kingdom: The EU Commission's adequacy decision for the UK is currently in force. Should this lapse, we will implement EU Standard Contractual Clauses (SCCs).

5. Hosting, Log Files and Content Delivery (Cloudflare)

Our website is hosted and delivered via Cloudflare. The provider is:

Cloudflare, Inc.
101 Townsend St
San Francisco, CA 94107
USA

Cloudflare acts as a Content Delivery Network (CDN) and hosting provider. All access to our website is routed through Cloudflare's network. Our system automatically collects the following technical data (so-called traffic data):

The IP address is stored for the duration of the session to enable delivery of the website. In the log files, it is anonymised or deleted after a maximum of 7 days, so that it can no longer be attributed to individual persons.

Cloudflare also sets technically necessary cookies to ensure the security and performance of the website (e.g. to defend against DDoS attacks and bot traffic). A complete overview of the cookies used can be found in Section 8.

Legal basis: Art. 6(1)(f) UK GDPR / EU GDPR. Our legitimate interest lies in the secure, performant and technically error-free provision of our website.

Data transfer to the USA: Cloudflare, Inc. is certified under the EU-U.S. Data Privacy Framework (DPF), so data transfers to the USA are carried out on this basis. For transfers from the UK, we rely on the relevant UK adequacy regulations and/or IDTAs. We have concluded a Data Processing Agreement (DPA) with Cloudflare.

Right to object: The collection of this data is technically essential for the operation of the website. An objection pursuant to Art. 21 UK GDPR / EU GDPR is possible to the extent that you can demonstrate particular circumstances that argue against the processing.

Further information on data protection at Cloudflare: https://www.cloudflare.com/privacypolicy/

6. Analytics and Tracking

We do not use any tracking or analytics tools, nor any analytics cookies. No user profiles are created and no browsing behaviour is analysed.

7. Consent Management (OneTrust)

We use the consent management tool OneTrust to obtain, manage and document your consent to the use of cookies and embedded services.

The provider is:

OneTrust LLC
1200 Abernathy Road NE, Building 600
Atlanta, GA 30328
USA

When you visit our website, a cookie banner appears through which you can manage your consents. OneTrust stores your preferences and a timestamp of your consent in order to document proof of consent.

Legal basis: Art. 6(1)(c) UK GDPR / EU GDPR (legal obligation to document consents) and Art. 6(1)(f) UK GDPR / EU GDPR (legitimate interest in legally compliant record-keeping).

Data transfer to the USA: OneTrust LLC is certified under the EU-U.S. Data Privacy Framework (DPF). For transfers from the UK, we rely on IDTAs. We have concluded a Data Processing Agreement (DPA) with OneTrust.

You can adjust your cookie settings at any time via the cookie settings link in the footer of our website.

Further information: https://www.onetrust.com/privacy-notice/

8. Cookies - Complete Overview

Below you will find an overview of all cookies used on our website, broken down by provider and category.

8.1 Technically Necessary Cookies

These cookies are strictly required for the operation of the website and are set without your consent.

OneTrust (Consent Management)

8.2 Spotify Music Player (Opt-in)

Our website embeds the Spotify Music Player.

Provider: Spotify AB, Regeringsgatan 19, SE-111 53 Stockholm, Sweden

To protect your privacy, the Spotify Player is not loaded automatically. Instead, a placeholder is displayed first. The connection to Spotify's servers is only established after you have actively given your consent by clicking on the placeholder.

After your consent, the following data is transmitted to Spotify:

Legal basis: Art. 6(1)(a) UK GDPR / EU GDPR (consent).

Cookies set by Spotify (after consent):

Note: Cookies set by Spotify may vary. For further information, please refer to Spotify's privacy policy: https://www.spotify.com/en/legal/privacy-policy/

Withdrawal of consent: You can withdraw your consent at any time with effect for the future via the cookie settings in the footer of our website. After withdrawal, please reload or refresh the page - the placeholder will then be displayed again and the player will no longer load.

8.3 Managing Cookie Settings

You can adjust or withdraw your consents for the OneTrust banner at any time via the cookie settings link in the footer of our website. Technically necessary cookies cannot be disabled as they are essential for the operation of the website.

9. Social Media Buttons

Our website includes buttons linking to the following platforms: Facebook, Instagram, LinkedIn, X (formerly Twitter), YouTube and Spotify.

These buttons are implemented as simple hyperlinks to our respective social media pages. They are not embedded plugins that automatically transmit data to the providers when the page loads.

Please note: When you visit our profile pages (fan pages) on these platforms, we are jointly responsible with the respective platform provider for the data processing taking place there. Please refer to the privacy notices of the respective providers for further information:

If you do not want platform providers to associate your visit with your user account, please log out before clicking.

10. Contact Form (provided by Anexia)

10.1 Description and Scope

The contact form embedded on our website is technically provided and operated by Anexia Holding GmbH:

Anexia Holding GmbH
Feldkirchner Strasse 140
9020 Klagenfurt
Austria

When you use the contact form, the following data is processed:

The transmitted data is stored on Anexia's servers and used by us solely to process your enquiry. Alternatively, you may contact us at any time by e-mail at info@2112studios.com.

10.2 Data Processing Agreement

We have concluded a Data Processing Agreement (DPA) with Anexia in accordance with Art. 28 UK GDPR / EU GDPR. Anexia processes your data exclusively on our instructions and not for its own purposes.

10.3 Legal Basis

10.4 Retention Period

Data is deleted once the conversation has been concluded and no statutory retention obligations apply. Technical metadata (IP address, timestamp) is deleted after a maximum of 14 days.

10.5 Right to Object

You have the right to object to the processing of your personal data at any time (Art. 21 UK GDPR / EU GDPR). In such a case, we will be unable to continue processing your enquiry. Please contact us at: info@2112.studio

11. Rights of the Data Subject

To the extent that your personal data is processed by us, you have the following rights:

Right of Access (Art. 15 UK GDPR / EU GDPR)

You may request information about the data we process about you. For identification purposes, we may request proof of your identity.

Right to Rectification (Art. 16 UK GDPR / EU GDPR)

You may request the correction of inaccurate or incomplete data.

Right to Erasure (Art. 17 UK GDPR / EU GDPR)

You may request the deletion of your data under certain conditions.

Right to Restriction of Processing (Art. 18 UK GDPR / EU GDPR)

You may request the restriction of processing, e.g. if you contest the accuracy of the data.

Obligation to Notify (Art. 19 UK GDPR / EU GDPR)

We are obliged to inform any recipients of your data of any rectification, erasure or restriction of processing.

Right to Data Portability (Art. 20 UK GDPR / EU GDPR)

You may request that your data be provided in a commonly used, machine-readable format.

Right to Object (Art. 21 UK GDPR / EU GDPR)

You have the right to object at any time to the processing of your data on the basis of legitimate interests, in particular in the case of direct marketing.

Right to Withdraw Consent

Any consent you have given may be withdrawn at any time with effect for the future. The lawfulness of processing carried out prior to withdrawal is not affected.

To exercise your rights, please contact: info@2112.studio or dpo@2112.studio

12. Right to Lodge a Complaint with a Supervisory Authority

For data subjects in the United Kingdom: Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, United Kingdom. Website: https://ico.org.uk. Phone: +44 303 123 1113

For data subjects in the European Union: You have the right to lodge a complaint with the data protection authority of your place of residence, workplace or the place of the alleged infringement. An overview of all EU data protection authorities can be found at: https://edpb.europa.eu/about-edpb/about-edpb/members_en

We kindly ask you to contact us directly before lodging a complaint so that we can address your concern.

13. Automated Decision-Making and Profiling

We do not carry out any automated decision-making within the meaning of Art. 22 UK GDPR / EU GDPR. No profiling takes place.

14. Changes to this Privacy Policy

We reserve the right to update this privacy policy as necessary to reflect changes in our data processing practices or legal requirements. The current version is available on our website at all times.

Last updated: August 2026