- Updated
Concertainly platform privacy notice
Updated: 26 July 2026
The German version is the editorial source. If the versions differ, the German version prevails.
1. Controller
The controller for the operator's own processing described in this notice is:
Tamino Consulting UG (haftungsbeschränkt)
Sansibarstraße 4a
81827 Munich
Germany
Email: tamino.rat@gmail.com
Phone: +49 89 30 64 33 37
Privacy contact: Tamino Rat. The operator states that no data protection officer is currently appointed. The statutory appointment criteria will be reviewed again if the organisation or processing changes.
2. Scope and roles
This notice covers the public Concertainly pages, applications and registrations by music-school owners, platform accounts, and secure platform operation.
The relevant music school is generally the controller for its student, family, teacher, concert and registration data. Concertainly processes that data on behalf of the school. The school's privacy notice is linked from its school instance.
Concertainly is a separate controller where it processes data for its own lawful operational, security, contract or billing purposes. The contract and data processing agreement define the allocation in more detail.
3. Visiting the public website
Technically necessary connection data may be processed, including IP address, time, requested address, transferred volume, referrer, browser, operating system, device information, and technical error, security or abuse signals.
The purpose is delivery, stability, error analysis and protection against attacks and abuse. The legal basis is Article 6(1)(f) GDPR, reflecting the legitimate interest in secure and reliable operation. Article 6(1)(b) GDPR may also apply where processing is required to provide a specifically requested service.
Technical access and security logs are generally deleted after 30 days. Extracts retained for a specific security investigation may be kept until the investigation is complete and for no longer than twelve months, unless a longer statutory or legal-claims need applies.
4. Owner application and pre-contract steps
When a music school applies for access, we may process the applicant's name, business contact details, music school, preferred language, selected plan, invoice recipient, invoice email, invoice address, country, optional tax ID, the version and time of price and terms acceptance, and application status. The purposes are reviewing the request, contacting the applicant, taking pre-contract steps, creating and managing the billing account, issuing and matching invoices, preventing abuse, and documenting the decision and contract acceptance. Current invoice status, external invoice numbers and payment times are stored in the invoice journal. We currently process no bank account or payment-card details and trigger no automatic charges.
Legal bases are Article 6(1)(b) GDPR for pre-contract steps, Article 6(1)(f) GDPR for abuse prevention and limited process documentation, and Article 6(1)(c) GDPR where a legal obligation applies.
Unsuccessful or withdrawn applications are deleted six months after the request is closed or withdrawn, unless retention is required by law or for legal claims.
5. Platform accounts, authentication and roles
For owners, administrators, teachers and platform administrators, we may process name, email, technical account ID, school membership, role, language, login and security events, invitation, session and one-time-code metadata, support and administration events.
Authentication currently uses a one-time code sent by email and valid for 15 minutes. The code must not be disclosed.
Legal bases are Article 6(1)(b) GDPR for contractually required platform use, Article 6(1)(f) GDPR for security, role management and abuse prevention, and Article 6(1)(c) GDPR where a legal obligation applies.
Account data is used while the authorisation remains active. Access is disabled immediately when authorisation is removed. Associated personal account data is generally erased or anonymised within 30 days after contract end. Contract and evidence records remain restricted where statutory retention applies.
6. School data processed on behalf of a school
Depending on use, this may include:
- names, email addresses and roles of owners, administrators and teachers;
- student names and birth dates;
- names and contact details of parents, guardians and adult students;
- registrations, instrument, teacher, works, instrumentation, duration, companions, waiting-list status and organisational notes;
- consent evidence, including photo consent where the school uses it;
- communication, change, audit, export, deletion and retention information.
The school determines purpose, legal basis and retention. Data subjects should normally contact the school first. Concertainly supports the school under the data processing agreement.
7. Email
Email is used for one-time codes, invitations, confirmations, waiting-list and cancellation notices, reminders and necessary operational messages. Depending on the message, the email address, recipient name, school and concert context, required content and delivery metadata are sent to:
Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA.
Article 6(1)(b) GDPR is the legal basis for contractually required messages and Article 6(1)(f) GDPR for security and operational messages. Resend states a standard 30-day retention period for email data. Our own delivery metadata is generally erased or anonymised after 90 days unless a specific delivery, security or legal matter requires longer retention.
Marketing email will not be sent without a separately reviewed legal basis.
8. AI-supported features
The optional AI features support work, composer and programme text. Under the product design, only work, composer and programme information and neutral placeholders are sent. Student, family and teacher names, email addresses, birth dates or other personal data must not be sent to the AI service.
Anthropic is used for the optional AI feature. Anthropic Ireland, Limited provides the service in the EEA region; the Anthropic group includes Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA. The contract documents applicable to the specific API account remain authoritative.
An authorised person must review AI output before use. School-specific deactivation is not currently promised. The feature can be disabled centrally by the operator.
The current features use the Anthropic Messages API without intentionally enabled Files, Batch or prompt-caching features. Anthropic states a standard retention period of up to 30 days for API inputs and outputs. The API account used for the service does not have a zero-data-retention agreement. Any future personal-data transmission requires a prior update of this notice and a new legal-basis assessment.
9. Recipients and subprocessors
Providers are used only for delivery, communication, security or optional
features. The current direct-subprocessor list is available at
/en/legal/subprocessors. It currently covers Convex for backend and
database, Vercel for hosting, Resend for transactional email and Anthropic for
optional AI processing.
Within Concertainly, access is restricted to people who require it for their tasks. Statutory disclosure duties remain unaffected.
10. International transfers
Providers or their subprocessors may process data outside the EEA. Where there is no adequacy decision, appropriate safeguards such as the Standard Contractual Clauses and, where required, supplementary measures are assessed.
Convex stores the selected deployment in EU West (Ireland). Vercel serves content through a global CDN and states in its DPA that its primary processing facilities are in the United States; server-side functions may also run in the United States unless configured otherwise. Resend and Anthropic group companies may process in the United States. Their DPAs include Standard Contractual Clauses or other applicable transfer mechanisms. Support and downstream providers may involve further countries listed in the current subprocessor lists.
Copies of relevant safeguards may be requested at tamino.rat@gmail.com, subject to third-party rights and confidentiality.
11. Cookies and device storage
Concertainly operates without optional advertising or tracking. The
technically necessary sidebar_state cookie stores the navigation state for
seven days. Convex Auth uses technically necessary session and security
storage; names may change with the library version and the lifetime is limited
to the session and authentication purpose. Optional analytics, advertising
and marketing technologies are not currently enabled.
If a device access is not strictly necessary for transmission or a service explicitly requested by the user, prior consent under section 25 TDDDG will be obtained. Any future analytics or marketing service requires a new review before activation.
12. Retention
Personal data is retained only while required for the purpose, legal duties or legal claims. The following operator periods apply:
| Category | Period or criterion |
|---|---|
| access and security logs | generally 30 days; incident-specific extracts for no longer than twelve months where required |
| owner applications | six months after closure or withdrawal |
| contract, billing and business records | six years where this period applies; invoices are retained for any longer mandatory statutory period |
| platform accounts and roles | immediate access disablement; erasure or anonymisation generally within 30 days after contract end |
| support | 24 months after closure unless a legal or security matter requires longer retention |
| email delivery metadata | Resend email data generally 30 days; our own delivery metadata generally 90 days |
| school data processed on instructions | the school's instructions and configuration; current product default is 72 months after the concert and can be configured from 1 to 120 months, subject to the school's decision |
| backups | expire under provider rotation and, for offboarding, no later than 30 further days after active-data deletion; restricted and used only for recovery in the interim |
13. Data-subject rights
Subject to the statutory conditions, data subjects may request access, rectification, erasure, restriction, portability and may object. Consent may be withdrawn for the future.
School-data requests should normally be addressed to the relevant school. They may also be sent to tamino.rat@gmail.com; we will route or support the request where required. Where processing relies on Article 6(1)(f) GDPR, the data subject may object on grounds relating to their particular situation.
14. Complaint
For private organisations established in Bavaria, the competent authority is:
Bavarian State Office for Data Protection Supervision (BayLDA)
Promenade 18
91522 Ansbach
Germany
A complaint may also be submitted to another authority permitted by law.
15. Required information and automated decisions
Required fields are identified in the relevant form. Without them, the requested service may not be provided. Concertainly currently makes no solely automated decision producing legal or similarly significant effects under Article 22 GDPR. This assessment must be repeated if the platform changes.
16. Changes
This notice will be updated when processing, providers or law change. The
current notice is available at /en/legal/privacy.
Effective: 26 July 2026
Last updated: 26 July 2026