Privacy Policy

Last updated: March 2026

1. Controller

The controller responsible for data processing on this website is:

Homm & Kasper GBR

Markus Homm

Buchäckerweg 1B, 91224 Pommelsbrunn, Germany

Email: info@stagemix.de

2. Overview of Data Processing

We collect and process personal data only to the extent necessary to provide our audio editing services, process payments, and communicate with you. We do not sell your data to third parties. We do not use your data for advertising or profiling purposes.

3. Data We Collect

Account Data

When you create an account, we store your email address and hashed password. This data is necessary to authenticate you and manage your orders.

Order Data

When you place an order, we collect your name, email address, project details, and any audio files you upload. This data is needed to provide the requested service.

Payment Data

Payment is processed by Stripe. We receive your name, email, and a confirmation of payment. We do not receive or store your credit card number, bank account details, or other sensitive payment information. This data is handled entirely by Stripe.

Communication Data

When you contact us by email, we store your message and email address to respond to your inquiry and maintain records of our communication.

Technical Data

When you visit our website, our hosting provider automatically collects technical data such as your IP address, browser type, operating system, and access timestamps. This data is used for security purposes and to ensure the technical operation of the website.

4. Legal Basis (GDPR Art. 6)

  • Contract performance (Art. 6(1)(b)): Processing your order, delivering services, invoicing, and account management.
  • Legal obligation (Art. 6(1)(c)): Retention of invoices and business records as required by German tax law.
  • Legitimate interest (Art. 6(1)(f)): Ensuring website security, fraud prevention, and improving our services.

5. Third-Party Service Providers

We use the following third-party services to operate our platform. Data processing agreements (DPA) are in place with each provider:

Supabase Inc.

Database, authentication, and file storage. Data is hosted in the EU (Frankfurt).

Stripe Inc.

Payment processing. Stripe is PCI DSS Level 1 certified. See Stripe Privacy Policy.

Resend Inc.

Transactional email delivery (invoices, order confirmations).

Vercel Inc.

Website hosting and deployment. Requests may be routed through global edge locations.

6. Cookies

Our website uses only essential cookies that are strictly necessary for the website to function. These include authentication session cookies managed by Supabase. We do not use analytics cookies, tracking cookies, or advertising cookies.

Essential cookies do not require consent under GDPR as they are necessary for the service you have requested.

7. Data Retention

  • Account data: Stored until you request deletion of your account.
  • Order data & uploaded files: Stored for the duration of the project. Completed project files may be deleted after 90 days unless otherwise agreed.
  • Invoices & billing data: Retained for 10 years as required by German tax law (§147 AO, §14b UStG).
  • Server logs: Automatically deleted after 30 days.

8. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15) — request a copy of your data
  • Right to rectification (Art. 16) — correct inaccurate data
  • Right to erasure (Art. 17) — request deletion of your data
  • Right to restriction (Art. 18) — restrict processing of your data
  • Right to data portability (Art. 20) — receive your data in a machine-readable format
  • Right to object (Art. 21) — object to processing based on legitimate interest

To exercise any of these rights, contact us at info@stagemix.de.

9. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates the GDPR. The responsible authority is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)

Promenade 18, 91522 Ansbach, Germany

www.lda.bayern.de

10. Data Security

We use SSL/TLS encryption for all data transmitted between your browser and our servers. Access to personal data is restricted to authorized personnel only. Our infrastructure providers maintain industry-standard security certifications.

11. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at stagemix.de/privacy. We will notify registered users of significant changes by email.

Homm & Kasper GBR · Buchäckerweg 1B · 91224 Pommelsbrunn · Germany
USt-IdNr.: DE295188656