Privacy and cookies
This notice describes how www.mixxea.com handles personal data. It covers the public site, the booking form, demo submissions, the newsletter, the artist portal, the DJ pool, and staff sign-in.
Who we are
The controller is Freq Grup SRL, CUI 52133484, Trade Reg. No. J2025050803009, EUID ROONRC.J2025050803009, Intr. Gheorghe Simionescu 19, Ap. B26, 014155 București (Sector 1), România.
No data protection officer is appointed. Privacy requests go to hello@mixxea.com.
Contact messages
The booking page at /booking-agency posts to /api/contact. The fields sent are your name, email, inquiry type, and message. If you fill them in, the message also includes the artist, venue, city, and date. The link field is sent empty. Inquiry types on that form are Booking Request, A&R / Demo Submission, Artist Management, Brand / Partnership, Press / Media, and General.
The admin site at /admin has a separate contact form that posts the same endpoint with name, email, message, inquiry type, an optional link, and a newsletter opt-in checkbox. The public homepage does not have its own contact form.
Each message is stored with an id and the time it was sent. If the inquiry type contains the word “booking” (the booking page’s “Booking Request” does), a second record is stored as a booking. On that record the venue and contact are set to your name, the notes are the message, and artist, date, city, country, and fee are left empty. The artist, venue, city, and date you typed stay inside the message text.
The site then emails an admin notification and a confirmation to the address you entered, through Resend.
Purpose: to read and reply to the message, and to keep a booking record when the inquiry is a booking request.
Lawful basis: legitimate interests in answering a general message and running the site. A booking enquiry is steps before a contract, or the contract once a booking is signed.
Retention: contact messages are kept for 24 months. A booking enquiry that did not become a booking is kept for 24 months. A signed booking is kept for as long as Romanian accounting and tax law requires.
Demo submissions
/submit.html posts JSON to /api/demos/submit. The stored fields are artist name, legal name, email, country, performing-rights organisation (PRO), a profile or SoundCloud link, track title, version, genre, BPM, musical key, file format, a download link, a description, whether the track was released before and where, whether you are the sole writer or a co-writer, co-writer details, whether publishing would sit with Mixxea or your own publisher, your publisher’s name if you have one, and whether the track uses samples (none, cleared, or uncleared). The record also stores an id, the time it was sent, and a status that starts as “new”.
That page sends a download link. It does not upload a file. The same endpoint accepts a multipart upload (the admin demo form does this) with a track file of up to 200 MB. Demo audio is stored privately. It is not given a public link. Only authorised staff can open it, through an admin sign-in.
An admin can also email a submission invite (/api/demos/send-link) using an email address and an artist name. That is started by staff, not by the public form.
The site emails an admin notification and, when an email was provided, a confirmation to the submitter, through Resend.
Purpose: A&R review of a demo you chose to send.
Lawful basis: steps before a contract, or the contract once it is signed.
Retention: a demo record, its audio, and its links are kept for 24 months when they do not lead to a signing. A signed deal is kept for as long as Romanian accounting and tax law requires.
Newsletter
The footer form posts your email to /api/newsletter/subscribe with source “footer”. The admin site’s newsletter box uses source “homepage”. If you tick the newsletter box on the admin contact form, the same email is added with source “contact-form”. The address is stored in lower case with the time you joined, that source, and the consent wording version (currently 2026-10-02). That time and source are the record of your consent. A welcome email is sent. Signing up again does not create a second row.
Staff can send a campaign to the stored addresses. Each newsletter email, including the welcome, contains an unsubscribe link. The link carries a signed token for that address, not the address itself. The message also includes a one-click unsubscribe header for mail clients. The campaign record keeps the subject, intro, from-name, time, how many recipients were attempted, whether it succeeded, and the provider. It does not keep a separate copy of every address.
Opening the link shows a confirm button. The address is removed only when that button is used, or when a mail client sends the one-click request. A mail client that only previews the link does not unsubscribe you.
Purpose: to send the newsletter you asked for.
Lawful basis: consent. You can withdraw it with the unsubscribe link. Withdrawing consent does not affect a message already sent.
Retention: the address stays on the list until you unsubscribe, and it is then deleted. A minimal suppression record (the address and the time) is kept so a bulk import does not add you again. Subscribing yourself later is a new consent and clears that record.
Booking enquiries
Booking requests use the contact form described above. Admins can still read the booking records that form creates, and any booking records already on file.
Purpose: to handle a booking request.
Lawful basis: steps before a contract, or the contract once a booking is signed.
Retention: an enquiry that did not become a booking is kept for 24 months. A signed booking is kept for as long as Romanian accounting and tax law requires.
Artist portal
/portal is a login form. It sends email and password to /api/auth/artist/login. The password is checked against a bcrypt hash. It is not stored in plain text. A successful login puts the artist id and artist name on the session cookie mixxea.sid. There is no separate artist cookie.
Artist accounts are by invitation only. An admin creates the account. Public self-registration is not available. The stored fields are artist name, legal name, email, country, genre, a SoundCloud URL, and a password stored as a bcrypt hash. Status starts as “unsigned”.
A signed-in artist can load /api/royalties/my. Royalty rows are entered by an admin and can include the payee name, amounts, the statement period, and payment details if those were entered. A signed-in artist can also open a contract file stored in their name. Other people cannot.
Purpose: to give an artist access to the portal, their royalty rows, and their own contract.
Lawful basis: steps before a contract, or the contract once it is signed. Contracts and royalties are also kept where Romanian accounting and tax law requires it.
Retention: the account is kept for 12 months after it is closed. Contracts and royalties are kept for as long as Romanian accounting and tax law requires.
DJ pool
The DJ pool is an invitation-only service for approved DJs. It is not offered to the public, and nobody pays for it. The site does not collect a card number or any other payment detail for the DJ pool.
Hearts store a visitor id and a track id. Crates store a visitor id, a crate name, and track ids. A download stores a visitor id, the track id, and the time. A subscription record, when one exists, stores a tier name, status, start time, download limit, and downloads used. That record is not a payment.
Purpose: to provide the DJ-pool service to an approved DJ.
Lawful basis: contract.
Retention: these rows are kept until the account is closed, then for 12 months. The session cookie itself expires after 24 hours.
Admin and staff sign-in
POST /api/auth/admin/login takes an email and a password. The environment admin is checked against the configured admin email and password. Staff are checked by email against a bcrypt password hash. A successful staff login stores the time of that login. The session cookie records the role, staff id, name, and email. A second cookie, mixxea_auth, is set for admin and staff sign-in. Both cookies are httpOnly, SameSite Lax, Secure in production, and last 24 hours. Passwords are not stored in the cookies.
Staff accounts are created by an admin with a name, email, role, and password. The password is stored only as a bcrypt hash. An admin can also create an API token. The token secret is shown once. Only a hash, a label, the created time, and the last-used time are stored.
Purpose: to let staff open the admin tools and to keep those accounts secure.
Lawful basis: legitimate interests in running the site.
Retention: the cookies last 24 hours. The account is kept for 6 months after it is closed.
Email delivery records
Resend is the email provider. If Resend reports that a message bounced, was complained about, failed, or was suppressed, the site stores up to 100 of those events. Each one can include the event type, recipient addresses, subject, from address, bounce type, reason, Resend’s email id, and the time. An alert is emailed to hello@mixxea.com unless another alert address is configured.
Purpose: to see which messages were not delivered.
Lawful basis: legitimate interests in fixing failed email.
Retention: 12 months.
Other records staff enter
These are not public forms. Admins can store them:
- Contracts: artist, type, signed date, expiry, notes, status, and an uploaded file. The file is stored privately and is visible only to authorised staff, or to the signed-in artist named on that contract.
- Promoters: name, email, venue, city, country, a booking count, and notes.
- Royalties: payee name, amounts, statement period, and payment details if entered.
Purpose: to manage the label’s business.
Lawful basis: legitimate interests in managing the label’s business. Contracts and royalties are also kept under a legal obligation in Romanian accounting and tax law.
Retention: promoter records are kept for 24 months. Contracts, royalties, and signed bookings are kept for as long as Romanian accounting and tax law requires.
Who we share data with
The site calls these services. The code has no step that sells personal data.
- Vercel provides hosting. When Blob storage is configured, demo audio and contract files are stored there as private blobs. They are not served from a public URL.
- Upstash provides the Redis database for the records above when it is configured. If it is not, the server falls back to files on the machine running it.
- Resend is the only email provider. It sends contact, booking, demo, newsletter, and bounce-alert email. Resend can call back with the delivery events described above.
- Google Analytics 4 is provided by Google Ireland Limited. It loads only after you accept analytics. See Cookies.
- The Meta Pixel is provided by Meta Platforms Ireland Limited. It loads only after you accept marketing. See Cookies.
These providers may process data outside the European Economic Area, including in the United States. We rely on each provider’s standard data processing terms. Those terms use the EU Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework. This notice does not claim any separately signed contract.
Vercel keeps the request logs it needs to host the site. How long those logs last is Vercel’s own retention policy, described in Vercel’s privacy policy. This codebase does not set a number of days.
Cookies
We use optional cookies from two services. Both stay off until you choose, and you can change that choice at any time from Cookie settings in the footer.
Analytics uses Google Analytics 4, provided by Google Ireland Limited, property G-MEVRRCQQ5T. It tells us which pages are visited and whether the site is working. If you accept analytics, Google may store _ga (about two years, to tell browsers apart) and a _ga_* cookie for each Google Analytics measurement ID used by our Google tag (about two years, to keep a session together), including _ga_MEVRRCQQ5T and, where a linked destination is configured, _ga_BQW5PQ4Y99.
Marketing uses the Meta Pixel, provided by Meta Platforms Ireland Limited, pixel 1331927570650344. It measures visits from Meta ads. The pixel is not loaded unless you accept marketing. If you do, Meta may store _fbp (about three months, to recognise the browser) and, after an ad click, _fbc (about three months, to store that click). If you accept marketing, Google may also store _gcl_au (about 90 days), the Google Ads conversion linker cookie. It is not set unless you accept marketing.
Strictly necessary storage is not optional. It is used to keep you signed in, including when an approved DJ uses the DJ pool, and to remember the choice you already made.
| Name | What it is | How long |
|---|---|---|
mixxea.sid | Session cookie. Set when an admin signs in, an artist signs in, or an approved DJ uses the DJ pool. httpOnly, SameSite Lax, and Secure in production. It holds a session id. It does not hold your password. | 24 hours |
mixxea_auth | Admin and staff sign-in cookie. httpOnly, SameSite Lax, and Secure in production. | 24 hours |
mx-consent | Not a cookie. Your analytics and marketing choice is stored in this browser’s localStorage under this key, with the time you made it. | 12 months. After that the banner asks again. |
Optional cookies are set by Google or Meta only after the matching choice. Rejecting, or never choosing, does not load those tags.
| Name | Who sets it | How long |
|---|---|---|
_ga | Google Ireland Limited, after you accept analytics | About two years |
_ga_MEVRRCQQ5T | Google Ireland Limited, after you accept analytics | About two years |
_ga_BQW5PQ4Y99 | Google Ireland Limited, after you accept analytics. A _ga_* cookie for a Google Analytics measurement ID used by our Google tag when that ID is a linked destination. | About two years |
_fbp | Meta Platforms Ireland Limited, after you accept marketing | About three months |
_fbc | Meta Platforms Ireland Limited, after you accept marketing and only following an ad click | About three months |
_gcl_au | Google Ireland Limited, after you accept marketing. Google Ads conversion linker. Not set unless marketing is accepted. | About 90 days |
Lawful basis for analytics and marketing cookies: consent. You can withdraw it with the button above, or with Cookie settings in the footer. Withdrawing consent does not affect processing that already happened. Strictly necessary cookies are used because they are required for the sign-in or DJ-pool feature you are using.
Your rights
You can ask for access, rectification, erasure, restriction, and a portable copy of your data. You can object to processing based on legitimate interests. You can withdraw consent for the newsletter and for analytics or marketing cookies. Email hello@mixxea.com. We reply within one month, as the GDPR requires. That period can be extended where the GDPR allows it.
You can complain to the ANSPDCP, Romania’s data protection authority, at https://www.dataprotection.ro.
The minimum age is 16. That is Romania’s age of digital consent. The site’s services are not directed at children under 16.