Data controller
Privacy and data subject rights contact: booking.ecoa@gmail.com.
ECOA is the public-facing brand used by the project. At this stage, it is not a separate incorporated company.
Scope
This Privacy Policy applies to personal data processed through:
- ecoa.live and its language versions;
- the Community / Early Access form;
- the Contact form;
- the Partners form;
- the DJs form;
- the Founding Circle form;
- communications relating to requests submitted through the website;
- technical security, abuse prevention and website operation mechanisms;
- Google Analytics 4, active by default until the user rejects non-essential mechanisms.
When a user accesses an external platform, including a ticketing platform, that platform's terms and privacy information also apply. The external provider may act as an independent controller or as a processor depending on the specific service and processing activity.
Personal data we may collect
Community / Early Access
We may process name, email address, telephone number where applicable, language, signup source, UTM parameters, consent date and time, consent wording version, authorised channel and subscription status.
Contact
We may process name, email address, optional telephone number, optional company and website, reason for contacting us, message, language, source, UTM parameters, submission date and internal request status.
Partners
We may process name, company, email address, partnership type, optional website, message, language, source, date and internal request status.
DJs
We may process full name, artist name, email address, city, genres, public music links, performance video, short bio and, where provided, social profiles, website, availability, previous experience and another relevant link. We also retain the date, consent wording version, language, source and internal submission status. The IP address is not stored with the submission.
Founding Circle
We may process name, email address, telephone number, Instagram, age, city, profession, optional university, optional TikTok and website, night-out frequency, usual group size, answers about motivation and community contribution, source and optional additional links. We also retain consent dates and wording version, language, internal status, review notes, manual assessment scores and, only when assigned, a founding number from 001 to 020. The IP address is not stored with the application.
Technical and security data
Website operation may involve technical data such as date and time, requested route, browser and device information, technical headers, IP address or derived identifiers, only to the extent required for hosting, security, diagnostics and abuse prevention. The rate-limiting mechanism is designed to use HMAC-derived identifiers rather than retaining full email addresses or IP addresses within that mechanism.
Purposes and legal bases
Community / Early Access
We use the data to manage signups, provide early access and send information about future ECOA Sessions and ECOA-related communications.
The legal basis is consent. Consent is voluntary, must not be pre-selected and may be withdrawn at any time. Different communication channels, such as email and WhatsApp, require separate choices where used.
Contact
We use the data to reply to general requests, questions, proposals and event-related contacts.
Depending on the request, the legal basis is:
- steps taken at the data subject's request before entering into a contract, where the contact concerns a potential service or business relationship;
- legitimate interests, where necessary to respond to a general request, organise correspondence, secure operations or keep a reasonable record of the contact.
Partners
We use the data to assess partnership proposals, contact potential partners, arrange meetings and prepare a possible business relationship.
The legal basis is pre-contractual steps and, where applicable, legitimate interests in managing professional opportunities and partnerships.
DJs
We use the data to assess the artistic project and include the submission in a private curation base for future ECOA Sessions. A submission does not guarantee a reply, booking, date, payment or place in a line-up. The legal basis is consent, which may be withdrawn at any time through booking.ecoa@gmail.com. The submission does not authorise marketing communications.
Access is restricted to authorised people responsible for curation and strictly necessary technical administrators. The data is not published or shared with other artists or partners for their own purposes.
Founding Circle
We use the data to review the request manually, hold a conversation where there is a potential fit, manage an invitation and, for accepted members, retain the founding number record. An application does not guarantee entry, an invitation, a ticket, payment or participation in an event. Internal scoring is assigned manually by authorised people and does not produce a solely automated decision.
The legal basis is consent to receive, review and manage the application. Email and/or phone contact strictly required for the application and, for selected applicants, participation in the Founding Circle forms part of this process and may cover the outcome, onboarding, wristband, founding number, access, benefits and operational information. These communications do not authorise general marketing, which depends on a separate, optional and unticked choice. Consent may be withdrawn through booking.ecoa@gmail.com without affecting processing carried out before withdrawal.
Security and abuse prevention
Technical data and derived identifiers may be processed to prevent spam, attacks, automated submissions, misuse and service disruption. The legal basis is our legitimate interest in information security, service continuity and the protection of users and systems.
Google Analytics 4
If enabled, Google Analytics 4 will be used to understand website use in aggregate, including visited pages, traffic source, devices and technical performance.
Under the current technical configuration, analytics_storage, ad_storage, ad_user_data and ad_personalization start as granted. The Google tag may create Analytics cookies and send full measurement before an explicit choice. If the user rejects non-essential mechanisms, all four signals are updated to denied and controllable Analytics cookies are removed. Google Signals and personalised advertising remain disabled in the tag configuration. This configuration requires legal review before publication.
Marketing communications
Community communications will only be sent through authorised channels. Consent may be withdrawn through an unsubscribe link where available, through the preference management mechanism, or by contacting booking.ecoa@gmail.com.
Withdrawal does not affect processing carried out before consent was withdrawn. A minimal suppression record may be retained to prevent further unwanted contact and document the opt-out.
Recipients and service providers
Personal data may be processed by service providers required to operate the website, including Vercel, Supabase, Upstash, Resend, Google / Gmail and Google Analytics. Under the current consent mode configuration, Google Analytics may create cookies and receive full measurement before an explicit choice; rejecting non-essential mechanisms changes the four consent signals to denied. Professional technical or legal advisers may also process data where strictly necessary.
Personal data is not sold. Disclosure to a commercial partner for that partner's own purposes requires a separate legal basis and additional information to the data subject.
International transfers
Even where the primary database is hosted in the European Economic Area, international providers may use support teams, subprocessors, technical logs or administrative access outside the EEA.
Where an international transfer occurs, recognised GDPR mechanisms must be used, including European Commission adequacy decisions, the EU-U.S. Data Privacy Framework where validly applicable, Standard Contractual Clauses and any necessary supplementary safeguards.
Retention
Recommended retention periods are:
- Contact: up to 24 months after closure or the last relevant interaction;
- Partners: up to 24 months after the last relevant interaction, unless negotiations or a contract remain active;
- DJs: up to 24 months after submission or the last relevant update, with earlier deletion when consent is withdrawn or deletion is requested;
- Founding Circle: unsuccessful applications for up to 24 months after the decision or last interaction; for accepted members, the minimum founding-number record while the programme and founding recognition remain active, subject to data subject rights and minimisation review;
- active Community membership: while consent remains valid, with review after 24 months of inactivity;
- cancelled Community membership: minimal suppression and consent evidence for up to 3 years after withdrawal;
- security logs: normally up to 90 days, or up to 12 months when linked to an incident or legal defence;
- rate-limiting identifiers: only for the required technical window, generally no more than 24 hours;
- data subject rights requests: up to 3 years after closure;
- contractual, accounting or tax records: for the applicable statutory period.
Data will be deleted or anonymised when retention is no longer required.
Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, objection, portability where applicable, withdrawal of consent and information about recipients and transfers.
Requests may be sent to booking.ecoa@gmail.com. Additional information may be requested where strictly necessary to verify identity.
Requests are normally answered within one month. This period may be extended in complex cases in accordance with the GDPR, with notice to the requester.
Complaint
You may lodge a complaint with the Portuguese Data Protection Authority, Comissão Nacional de Proteção de Dados, without prejudice to other administrative or judicial remedies.
Security
Technical and organisational measures appropriate to the risk are applied, including HTTPS, access controls, server-side validation, anti-automation controls, rate limiting, server-side secrets and database access rules.
No system can be guaranteed to be completely secure. Incidents will be assessed and handled in accordance with applicable legal requirements.
Children
The website and forms are not intentionally directed at children. A parent or legal guardian who believes that a minor's data has been submitted without an appropriate basis may contact us to request review and deletion.
The minimum age for each event will be stated in the relevant event and venue conditions.
External links and ticketing
The website may link to ticketing platforms, social networks, venues, artists or partners. Those services are governed by the relevant provider's own terms and privacy information.
Changes
This policy may be updated to reflect legal, technical, operational or supplier changes. The current version and update date will remain available on the website.