This Privacy Policy describes how Istituto Discografico Italiano (also referred to as "we", "us", or "the Label Group") collects and processes personal data when you use the website https://www.idiscd.it (the "Website"). The policy is drafted in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable Italian data protection laws.
Data Controller
Istituto Discografico Italiano
VAT No.: 02288340132
Contact e-mail for privacy matters: dprefumo@alice.it
For any questions regarding this Privacy Policy, data protection, or the exercise of your rights, you may contact us at the above e-mail address. In Italian: per qualsiasi richiesta relativa al trattamento dei dati personali, è possibile scriverci all’indirizzo indicato.
This Privacy Policy applies to personal data collected through the Website (for example via contact forms, demo and project submissions, press requests, newsletter or similar tools if activated) and through our e-mail correspondence related to the Website and our labels (IDIS, Vermeer, Artemisia). It does not cover processing activities carried out on external platforms (such as Spotify, Apple Music, Naxos and others), which are governed by their own privacy policies.
When you interact with the Website, we may collect and process the following categories of personal data:
- Identification and contact data: name, surname, e-mail address and any other contact details that you voluntarily provide when filling in contact forms, sending demo or project proposals, or communicating with us by e-mail.
- Professional information: information about your artistic activity, ensemble, repertoire, discography or press profile that you voluntarily provide in demo, project or press requests.
- Content of messages: the text of your requests, proposals, press communications or other correspondence sent to us.
- Technical and navigation data: IP address, date and time of access, URL requested, HTTP status code, the pages visited on the Website, the type of browser and device used, and similar log data generated by the use of the Website and collected mainly through technical cookies and server logs.
- Cookie-related data: information collected through cookies and similar technologies used on the Website. Details are provided in our separate Cookie Policy.
We generally do not request or knowingly collect special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, etc.). Please avoid including such information in your communications; if you do so, the processing will be limited to what is strictly necessary for handling your request.
We process your personal data only when there is a valid legal basis under the GDPR. In particular, your data may be processed for the following purposes and on the following legal bases:
- Handling enquiries and general contact requests
To receive, manage and respond to requests for information about our labels, catalogue, services or Website, including messages sent through contact forms or directly by e-mail.
Legal basis: Article 6(1)(b) GDPR – performance of a contract or pre-contractual measures carried out at your request; in some cases Article 6(1)(f) GDPR – legitimate interest in responding to users and maintaining good relations with our audience and professional contacts. - Managing demo and project submissions
To evaluate recording projects, artistic proposals and collaborations sent by artists and ensembles, and to contact you if your proposal is of interest.
Legal basis: Article 6(1)(b) GDPR – pre-contractual measures at your request; Article 6(1)(f) GDPR – legitimate interest in evaluating artistic proposals consistent with our editorial line. - Press and professional relations
To handle requests from journalists, critics, concert organisations and other professionals, including the sending of press materials or links when appropriate.
Legal basis: Article 6(1)(b) GDPR or Article 6(1)(f) GDPR – legitimate interest in promoting our catalogue and maintaining professional relationships within the music sector. - Website operation, security and statistics
To ensure the functioning, security and integrity of the Website (for example, through logs and technical cookies), to prevent abuse or attacks, and to obtain anonymous or aggregated statistics on visits and use of the Website.
Legal basis: Article 6(1)(f) GDPR – legitimate interest in ensuring the security and proper operation of the Website and in improving the quality and relevance of our online presence. - Compliance with legal obligations
To comply with obligations imposed by laws, regulations or authorities, and to manage any disputes or legal protection.
Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation; Article 6(1)(f) GDPR – legitimate interest in defending our rights. - Optional communications and updates (if activated)
If we decide to activate newsletters or similar communications, your e-mail address may be used to send you updates about our releases, projects and activities, only with your prior consent where required.
Legal basis: Article 6(1)(a) GDPR – your consent, which you may withdraw at any time.
Data retention periods
We store personal data only for as long as necessary to achieve the purposes for which it was collected, or for the periods required by applicable law. In particular, and unless longer terms are imposed or allowed by law:
- Data related to contact requests and general correspondence are typically retained for up to 24 months from the last relevant communication.
- Data related to demo and project submissions may be retained for the time required to evaluate the proposal and, if appropriate, for the duration of any resulting collaboration or contractual relationship and the applicable limitation periods.
- Technical logs necessary for the security and functioning of the Website are generally retained for short periods (usually a few weeks or months), save for longer retention where required to investigate incidents or comply with legal obligations.
- Data processed on the basis of your consent (for example for optional communications, if activated) are retained until you withdraw your consent or request erasure, without prejudice to any longer retention necessary for legal obligations.
At the end of the retention period, personal data will be deleted, anonymised or otherwise made irreversibly unusable.
Recipients and data processors
Your personal data may be accessed only by persons authorised by the Data Controller and, where necessary, by third parties that provide services functional to the management of the Website or our activities, such as:
- hosting and infrastructure providers for the Website and related IT services;
- e-mail service providers and tools used to manage communications;
- consultants or professionals (for example legal or IT consultants) who assist us within the limits of their mandate;
- authorities and public bodies when required by law or by their legitimate requests.
Where required by Article 28 GDPR, such third parties are appointed as data processors and are bound by contractual obligations to protect personal data and process them only on our documented instructions.
Under the GDPR and applicable Italian law, you have a number of rights in relation to the processing of your personal data. In particular, you may exercise the following rights, within the limits and conditions set out in Articles 15–22 GDPR:
- Right of access – to obtain confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the data and to information about the processing.
- Right to rectification – to obtain the correction of inaccurate personal data and the completion of incomplete data.
- Right to erasure ("right to be forgotten") – to obtain the deletion of your personal data where the legal conditions are met (for example, where the data are no longer necessary in relation to the purposes for which they were collected, or if you withdraw consent where there is no other legal basis).
- Right to restriction of processing – to request that the processing of your data be limited in certain cases (for example, while the accuracy of the data is being verified or when you have objected to the processing).
- Right to data portability – where processing is based on consent or on a contract and is carried out by automated means, to receive the personal data concerning you in a structured, commonly used and machine-readable format and to transmit those data to another controller, where technically feasible.
- Right to object – to object at any time, on grounds relating to your particular situation, to the processing of personal data based on our legitimate interests, including any profiling based on such interests. In such a case we shall no longer process the data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
- Right to withdraw consent – where processing is based on your consent, you may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise your rights, you can contact the Data Controller at the e-mail address dprefumo@alice.it, specifying "Privacy – exercise of rights" in the subject line and indicating which right you wish to exercise. In Italian: è possibile esercitare i propri diritti scrivendo all’indirizzo e-mail indicato e specificando nell’oggetto "Privacy – esercizio dei diritti".
If you believe that the processing of your personal data infringes data protection legislation, you also have the right to lodge a complaint with the competent Supervisory Authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. In Italy, the competent authority is the Garante per la protezione dei dati personali (www.garanteprivacy.it).
Security measures
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction. Such measures include, for example, the use of secure servers provided by professional hosting providers, access control procedures, and the limitation of access to personal data to authorised persons who need it for their duties.
However, no transmission of data over the Internet or electronic storage system can be guaranteed to be 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security, and you share information with us at your own risk.
International data transfers
The main processing associated with this Website is carried out within the European Union. If, in specific cases, your data are transferred to entities located in countries outside the European Economic Area ("third countries"), such transfers will take place in compliance with Chapter V of the GDPR, for example:
- to countries that have been the subject of an adequacy decision by the European Commission; or
- on the basis of appropriate safeguards, such as standard contractual clauses adopted by the European Commission, and, where necessary, additional measures aimed at ensuring a level of protection essentially equivalent to that guaranteed within the EU.
Further information on the possible transfer of data to third countries and on the safeguards adopted may be requested by contacting us at the e-mail address indicated in this Privacy Policy.
This Privacy Policy should be read together with our Cookie Policy, which provides detailed information on the use of cookies and similar technologies on the Website and on how you can manage your preferences. You can access the Cookie Policy at any time from the relevant link in the Website footer or directly at the page dedicated to cookies.
The Website may contain links to third-party websites, services or platforms (for example, streaming and download services such as Spotify, Apple Music, Naxos and others). These third parties operate as independent data controllers and have their own privacy policies, which we invite you to consult carefully. We are not responsible for the processing of personal data carried out by such third parties.
We may update this Privacy Policy from time to time, for example to reflect changes in our processing activities, in the Website or in applicable legislation. The updated version will be published on this page, with an indication of the date of the last update where appropriate. We encourage you to review this Privacy Policy periodically.