Privacy Policy
Last updated: 17 August 2026
This Privacy Policy describes how we process your personal data when you use Mythic Artist, in accordance with Regulation (EU) 2016/679 (GDPR) and Law no. 506/2004 on the processing of personal data in the electronic communications sector.
Access to the site is free. By browsing and using the site, you give your informed consent to the processing described here.
1. Data controller
The controller of your personal data is:
- Controller — ***
- Registered office / address — ***
- Company / registration number — ***
- Contact email — ***
- Phone — ***
2. Important information
We respond to your requests within 30 days at the latest. This period may be extended where the law allows, in which case we will inform you.
We may restrict access to certain data where the law requires it, or where we cannot reliably verify your identity.
We may process data without your explicit consent where another legal basis applies, such as performing a contract, meeting a legal obligation, or a legitimate interest.
3. Definitions
- GDPR — Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.
- Personal data — any information relating to an identified or identifiable natural person.
- Controller — the person that determines the purposes and means of the processing.
- Data subject — the natural person whose data is processed.
4. What data we collect
We collect the following categories of data:
- Provided by you — email, name, and username; and, if you become an artist: stage name, biography, avatar, contact email and phone, location (country, state, city), and artist type, as well as the events you create.
- Collected automatically — IP address, device and browser type, approximate location, and pages visited.
- Payments — processed by Stripe; we store a reference to your Stripe customer and subscription, not your card details.
5. Purposes of processing
We process your data in order to:
- provide and maintain your account, profile, and events;
- process artist subscriptions through Stripe;
- respond to your inquiries and support requests;
- keep the service secure and prevent abuse;
- send marketing messages, only where you have consented;
- improve and develop the service.
6. Legal bases
We rely on the following legal bases: performance of a contract with you (providing the service); compliance with legal obligations; our legitimate interests (security, preventing abuse, improving the service); and your consent, where required (for example, marketing).
7. How long we keep your data
We keep your data for the duration of the processing, for a maximum of 5 years from your last interaction, or as required by applicable law. Payment and invoicing data is kept in line with our legal (accounting and tax) obligations.
8. Who we disclose data to
We do not disclose your data without your consent, except to:
- Service providers — who help us run the service, within a limited capacity — Supabase (database, authentication, storage), Stripe (payments), and our email provider.
- Authorities — courts, prosecutors, or public authorities, where required to comply with the law.
- Other parties — at your instruction or with your consent.
9. Transfers to third countries
Some of our providers may process data outside the European Economic Area. Where this happens, appropriate safeguards are applied. Any new transfer will be notified to you.
10. Lawfulness of processing (Article 6 GDPR)
Processing is lawful only if at least one of the following applies:
- (a) you have given consent;
- (b) processing is necessary for a contract with you;
- (c) processing is necessary to comply with a legal obligation;
- (d) processing is necessary to protect vital interests;
- (e) processing is necessary for a task carried out in the public interest;
- (f) processing is necessary for our legitimate interests, except where overridden by your rights (this does not apply to public authorities).
11. Your rights
Under the GDPR, you have the right to:
- withdraw your consent at any time;
- access the data we hold about you;
- rectify inaccurate data;
- erase your data (the “right to be forgotten”);
- restrict processing;
- data portability, under the conditions set by law;
- object to processing;
- not be subject to a decision based solely on automated processing, with the exceptions provided by law;
- lodge a complaint with the supervisory authority — in Romania, the ANSPDCP (National Supervisory Authority for Personal Data Processing) — and to seek justice.
12. Cookies
We use cookies and local storage to operate the site. For full details, see our Cookie Policy.
13. Confidentiality of information
We are committed to safeguarding the confidentiality of your information. We apply measures such as row-level access controls, encrypted connections, and authentication safeguards to prevent unauthorized access, in line with the GDPR and national law.
14. Third-party links
The site may include links to external websites. We do not control and are not responsible for their data collection or content. We recommend reviewing the privacy policies of those websites.
15. Changes to this policy
We may update this policy at any time. Changes take effect once published; the last updated date above shows the latest revision.
16. Exercising your rights
To exercise any of your rights, contact the controller at the email above, or reach us through our Support page.