Privacy Policy
Last updated: August 9, 2026
Introduction
Dionysia ("we", "us", or "our") is operated by Talent Hub ApS, which is the data controller responsible for your personal data. Dionysia is a marketplace connecting artists and musicians with event organizers and venues. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our website and services. Where consent is the legal basis for a particular activity, we ask for it separately and you may withdraw it at any time.
Data We Collect
We collect the following categories of information when you create an account, use our platform, or interact with our services:
Account Information
- Full name, display name, and email address
- Password (stored securely using bcrypt hashing)
- Phone number (optional)
- Preferred language and timezone
- Account role (artist, organizer, or both)
Profile Information
- Biography and description
- Profile avatar image
- Social media links (Instagram, Facebook, YouTube, Soundcloud)
- Musical genres and performance details
- Equipment details (sound and lighting)
- Location and allowed countries for performances
- Venue information (for organizers), including address and coordinates
Instagram Connection and EPK Photo Import
- When an artist optionally connects an Instagram professional Creator or Business account: the Instagram-scoped professional account ID, username, profile URL, verification status, connection timestamps, and an encrypted access token
- While the artist browses their own Instagram media: media IDs, media types, temporary image URLs, post links, and timestamps
- When the artist confirms an import: a managed copy of each selected image and its Instagram media ID, retained to prevent duplicate imports
- We do not retrieve captions, messages, comments, contacts, follower lists, advertising information, or insights, and we do not publish content to Instagram
We process this information to provide functionality requested by the artist and to perform our agreement with the artist under Article 6(1)(b) GDPR. The Instagram connection and photo import are optional.
Activity Data
- Bookings, bids, applications, counter-offers, and the structured terms attached to them
- Immutable agreement versions, document fingerprints, rider snapshots, amendments, and agreement lifecycle events
- Legal name, role, account snapshot, express-confirmation state, server-recorded time, locale, session version, pseudonymised network evidence, and user-agent hash recorded for agreement actions
- Artist fee billing email, billing address, optional Danish VAT ID, fee liability, invoice status, and Stripe reconciliation identifiers
- Availability slots and calendar data
- Chat messages and conversations
- Ratings and reviews
- Notification preferences and email preferences
- Event details and participation history
Technical Data
- Session data (encrypted session cookies)
- Error logs and performance data (via Sentry)
- IP address (for rate limiting and security purposes)
- For agreement evidence, the raw IP address is not stored in the agreement record; it is immediately transformed using a keyed HMAC together with the evidence-key identifier and account ID. The agreement record stores only that pseudonymised value and a SHA-256 hash of the limited user-agent string
- Usage analytics via Google Analytics - collected only with your consent (page views, approximate location, device and browser type, in anonymised and aggregated form)
How We Use Your Data
- To create and manage your account on the platform
- To facilitate connections between artists and event organizers
- To process bookings, bids, and applications
- To create tamper-evident agreement versions, prove which signed-in party took an agreement action, preserve amendments, and provide both parties with an audit history
- To enable real-time messaging between users
- To process subscriptions and separate Dionysia fee invoices through Stripe; Dionysia does not process the performance fee between artist and organiser
- To send transactional emails (booking confirmations, agreement notifications, magic links)
- To verify that an artist controls the professional Instagram account linked to their Dionysia profile
- At the artist's request, to display photos owned by their connected Instagram account for selection and copy selected photos into their EPK
- To provide analytics and insights to organizers about their events
- To monitor and improve the security and performance of our platform
- To enforce our terms of service and prevent abuse
Data Sharing & Disclosure
We take your privacy seriously and are committed to transparency about how your data is handled:
- We do not sell, rent, or trade your personal data to any third parties.
- We do not share your Google user data with third parties for their own marketing, advertising, or any unrelated purposes.
- Google user data (name, email, profile picture) obtained through Google Sign-in is used solely for account authentication and creation on our platform.
- YouTube channel data obtained through Google OAuth is used to verify your identity as an artist. If you choose to display YouTube videos on your profile, we fetch your publicly available videos to showcase your work to event organizers. This data is not shared with any third parties beyond what is visible on your public Dionysia profile.
- Instagram professional-account data obtained through Instagram Business Login is used only for ownership verification and the optional EPK photo picker. Authorized members of the artist workspace with verification or media permissions may manage the connection, browse the connected account's available photos, and import selected copies. Imported copies may be displayed on the artist's public profile and EPK.
- When you make or accept a proposal, the necessary agreement terms, recorded legal name, account display name, and decision history are shared privately with the other contracting party. They are retained as part of both parties' agreement record and where necessary to establish, exercise, or defend legal claims. Raw network evidence and user-agent hashes are not shown to the counterparty.
- Apart from disclosures to your contracting counterparty and disclosures required by law, we share personal data with the third-party service providers listed below only to the extent necessary to operate our platform.
- We may disclose your personal data if required to do so by law, regulation, or legal process, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Third-Party Services
We use the following third-party services to operate our platform. Each service has its own privacy policy governing how they handle your data:
Stripe
Payment processing for platform subscriptions and separate Dionysia fee invoices. Stripe handles card data directly, and we do not store your card details. For Dionysia fees, we share the artist legal party's billing email, billing address, legal name and optional Danish VAT ID with Stripe, and retain the customer, invoice, PaymentIntent, charge, dispute and status identifiers needed for invoicing and reconciliation. We prune normalized event details after 90 days. The Stripe event ID, type, processing outcome, error code and timestamps remain for deduplication and audit.
Google OAuth
Optional sign-in method. When you sign in with Google, we request access to your name, email address, and profile picture. This data is used solely to create and authenticate your account on Dionysia. Your Google authentication tokens are stored securely in our database. We do not share your Google account data with any other third parties, and we do not use it for advertising or marketing purposes.
Google Analytics
Consent-based website analytics provided by Google. We load it only after you opt in via our cookie banner, and use it to measure aggregated usage - such as page views and approximate region - so we can improve the platform. Google Analytics 4 does not store IP addresses, Google Signals and ad personalisation are disabled, and we do not use Google Analytics data for advertising or share it for others' marketing. Google's handling of this data is governed by its own privacy policy.
Spotify
Optional sign-in and artist verification. We may access your Spotify profile information and top tracks to verify your artist identity and display your music.
YouTube
Artist verification and optional profile display. With your consent, we request read-only access to your YouTube channel information to verify your identity as an artist by confirming channel ownership. If you choose to enable YouTube video display on your profile, we use the YouTube Data API to fetch your most popular public videos (titles, thumbnails, and links) to showcase your work to organizers. This video data is publicly available on YouTube and is not stored permanently; it is fetched on demand. YouTube channel and video data is not shared with any third parties beyond what you choose to display on your public artist profile on Dionysia.
Instagram and Meta
Optional professional-account ownership verification and EPK photo import. After the artist authorizes Instagram Business Login, Meta provides the account ID, username, profile link, and read-only access to that account's media. We store the access token encrypted. Media URLs are used temporarily while the artist browses their photos; only photos the artist selects are copied to Dionysia's managed file storage and added to the EPK. We do not publish to Instagram or request access to messages, comments, contacts, follower lists, advertising data, or insights.
Sentry
Error tracking and performance monitoring. Sentry collects technical error data, which may include your email address and name, to help us identify and fix issues on the platform. This data is used solely for debugging and platform reliability purposes.
UploadThing
Managed file storage for profile images and EPK photos, including copies of Instagram photos that an artist explicitly selects for import.
OpenStreetMap & CartoDB
Map display services for venue locations. These services may collect anonymized usage data when maps are displayed.
International Data Transfers
Some of our third-party service providers, including Meta, Stripe, Sentry, and UploadThing, may process data in the United States or other countries outside the European Economic Area (EEA). Where an international transfer requires a safeguard, we rely on an applicable adequacy decision, Standard Contractual Clauses (SCCs), or another approved transfer mechanism in accordance with applicable data-protection law.
Cookies
Cookies are small text files stored on your device when you visit a website. Dionysia keeps its own cookies to a minimum: one strictly necessary cookie that keeps you signed in, and - only if you give consent - Google Analytics cookies that help us understand how visitors use the site. Some pages also embed third-party media players (Spotify, SoundCloud, Vimeo) that may set their own cookies when you play them - these are listed in the table below. We do not use cookies for advertising, and we do not sell your data.
Session cookie
NecessaryKeeps you securely signed in and maintains your session. Encrypted, HTTP-only, and uses the SameSite "Lax" attribute. Strictly necessary, so it does not require consent.
Consent preference (dionysia_cookie_consent)
NecessaryRemembers your cookie choice so we do not ask you on every visit.
Google Analytics (_ga, _ga_*)
AnalyticsSet only after you accept. Measures page views and aggregated usage so we can improve the platform. Google Analytics 4 does not store IP addresses, Google Signals is disabled, and the data is never used for advertising.
Embedded media players
FunctionalWhen you play an embedded track or video on an artist's profile or EPK, these providers may set their own cookies or storage. They load only on pages that contain embedded media. YouTube embeds use the privacy-enhanced no-cookie mode.
Google Analytics cookies are loaded only after you click "Accept" in our cookie banner. If you decline, no analytics cookies are set and the Google Analytics script is never loaded. You can withdraw or change your consent at any time using the button below or the "Cookie settings" link in the footer.
Data Security
We take the security of your data seriously and implement the following measures to protect your information:
- Passwords are hashed using bcrypt with a high work factor
- Session data is encrypted using iron-session
- Secure, HTTP-only cookies with SameSite protection
- Rate limiting on authentication endpoints to prevent brute-force attacks
- Content Security Policy (CSP) headers to prevent cross-site scripting
- Stripe webhook signature verification for payment security
- OAuth state validation with time-limited tokens
- Instagram OAuth access tokens are encrypted at rest and are cleared when access is deauthorized, the connection is reset, the workspace is archived, or workspace ownership is transferred
Your Rights
Under the General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights regarding your personal data:
- Right of access - request a copy of the personal data we hold about you
- Right to rectification - request correction of inaccurate personal data
- Right to erasure - request deletion of your personal data
- Right to restrict processing - request that we limit how we use your data
- Right to data portability - request your data in a machine-readable format
- Right to object - object to our processing of your personal data
- Right to withdraw consent - withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us using the details provided below. We will respond to your request within 30 days.
Data Retention
We retain your personal data for as long as your account is active or as needed to provide the services. If you delete your account, we remove or anonymise account-scoped personal data within 30 days except where retention is necessary for legal, tax, regulatory, fraud-prevention, security, or legal-claims purposes. Instagram access tokens are retained only while the workspace connection is active and are cleared when Meta deauthorizes access, the connection is reset, the workspace is archived, workspace ownership is transferred, the token is detected as expired or revoked, or an applicable signed Meta deletion request is received. Instagram photos copied into an EPK and their source media IDs remain until an authorized workspace member deletes them, the workspace is removed under our retention process, or an applicable signed Meta deletion request is received. Normalized Stripe event data and identifiers are pruned after 90 days. The Stripe event ID, event type, processing outcome, error code and timestamps remain for deduplication and audit. Immutable booking-agreement documents and their acceptance or amendment evidence may be retained with the recorded legal name and action evidence where necessary to preserve the record for the other contracting party and to establish, exercise, or defend legal claims. Imported legacy records are retained as explicitly partial records and do not contain invented acceptance evidence. Other chat, booking, and transaction data may be retained in anonymised form for analytics and dispute resolution.
Account Deletion & Data Erasure
You have the right to delete your account at any time through your profile page. When you request account deletion:
- Your login identity is permanently anonymised, your password is removed, and your account-level OAuth credentials are deleted
- Your active access to every workspace is revoked. You must first transfer or archive each workspace that you own
- Workspace profiles, files, bookings, proposals, verifications, and history are not automatically deleted with one member's account; they remain with the transferred or archived workspace
- Provider access tokens are cleared when workspace ownership is transferred or the workspace is archived. Existing social-verification records and imported media can remain as workspace content until an authorized member resets or deletes them, or an applicable provider deletion request is received
- Historical records (past bookings, performances, ratings, and reviews) are retained in anonymised form as "Deleted User" to maintain platform data integrity
- Immutable agreement records may retain the legal name, agreed document, and integrity-protected action evidence where required for the counterparty's record or legal claims; they are not presented as current public profile data
- Non-personal data such as music genres, equipment preferences, and performance statistics are retained for historical context
To delete your account, open Account settings and go to the Danger Zone. You will confirm with your email address. Before deletion, transfer or archive every workspace you own. If an artist workspace has legacy billing records, its Checkout sessions and Stripe cleanup must be completed before the workspace can be archived or transferred. Upcoming confirmed performances must also be completed or cancelled. An artist can separately reset an Instagram verification and delete imported EPK photos from the workspace media tools. When Meta sends us a valid signed data-deletion request, we remove the matching Instagram verification, access token, source identifiers, and Instagram-sourced EPK copies.
Account deletion is immediate and permanent. Once deleted, your account cannot be recovered. If you need assistance, please contact us at privacy@dionysia.live.
Children's Privacy
Dionysia is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us and we will take steps to remove that information.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify registered users of significant changes via email or through a notice on our platform. We encourage you to review this policy periodically. Your continued use of Dionysia after any changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at privacy@dionysia.live.