MTT Audio Solutions

audiosolutions

The one stop service provider for the 21st century producer

Privacy Policy

Last updated: September 16, 2026

1. Controller

Matteo Taberna
trading as “MTT Audio Solutions”
Marchlewskistr. 77
10243 Berlin
Germany

Email: mt@mttaudio.com

2. Scope

This policy covers the freelance audio services on mttaudio.com (Part A) and the separately operated ticket shop tickets.mttaudio.com (Part B). Matteo Taberna is the sole controller for both services; “MTT Audio Solutions” is his trading name, not a separate controller.

Part A – MTT Audio website

3. Website access and technical data

The IP address, time, requested URL or resource, browser identifier, and technical request, security and error data may be processed as necessary to provide, secure, troubleshoot and maintain the website. Hashes derived from IP addresses and, where applicable, email addresses, together with a session identifier, are also used to limit abusive order requests.

4. Audio-service enquiries and orders

Contact and order information is processed for mixing, mastering and other audio services, including selected services, quantities, prices and payment status. Depending on the order, fulfilment involves project titles, submitted file links and audio files, reference tracks, notes, revision requests and reviews. Deliverables and revisions are made available for download; status messages support order fulfilment. The relevant form and order determine which information is needed.

5. Customer accounts and guest orders

Registration requests a name, email address and password; a password hash is stored. Account status, newsletter status and information for activation and password resets are also processed. Guest orders can be placed using an email address without registration; a guest record is created for this purpose. Accounts and order identifiers associate orders with customers and enable authorised access to deliverables and available downloads.

6. Stripe payments on the website

Stripe processes payments for relevant website purchases. The application transmits payment and order information needed for checkout; for audio orders this includes customer email, order identifiers and language. Matteo Taberna receives payment status and transaction identifiers to reconcile and fulfil orders. Card details are processed through Stripe and are not stored directly in this application.

7. Contact form

The contact form processes email address, subject and message, along with form acknowledgement and anti-abuse information. The enquiry is forwarded by email for handling and response. Information voluntarily included in the message is used to address the enquiry. Contacting us does not itself subscribe you to a newsletter.

8. Newsletter and Listmonk

Newsletter signup involves processing the email address, any supplied name and subscription status to manage and deliver the newsletter. The website uses Listmonk newsletter software as part of this process. Signup may involve storage in the configured Listmonk instance and updates to subscription status in the customer account. Signup requires an explicit subscription action. You can stop delivery at any time using an available unsubscribe option or by emailing mt@mttaudio.com. Where valid consent has been given, it is the basis for newsletter delivery.

9. hCaptcha

hCaptcha is embedded on protected forms, in particular contact, registration and guest orders, to prevent automated or abusive submissions. A script is loaded from hCaptcha. Server-side verification sends the CAPTCHA response and detected IP address to hCaptcha and processes its result. Loading and running the service may involve further technical connection and browser data. Its purpose is security and abuse prevention.

10. Offen analytics

Public website pages embed Offen to analyse website use; the administration view is excluded. The script is loaded from an MTT Audio subdomain. Offen’s documented standard integration requests consent and records pageviews after agreement. The embedded Offen service manages this process. Where usage data is processed on the basis of consent, you can withdraw it using the functions offered by Offen. Technical connection data is also processed when the service loads.

Part B – Ticket shop

11. Separate ticket shop

Matteo Taberna operates tickets.mttaudio.com as a separate self-hosted Pretix installation for ticket sales and event administration. Pretix Hosted is not used.

12. Ticket orders and attendee information

Depending on the event configuration, the shop processes email addresses, requested purchaser or contact details, attendee details where requested, and order, ticket and payment-status information. Not every event collects all these details or requires them in every case. This information supports ticket purchases, order administration, ticket generation, communication and admission. The relevant forms show which information is required.

13. Stripe ticket payments

Stripe is the intended provider for online ticket payments. When this payment method is used, information required for the transaction is passed to Stripe. Through Pretix, Matteo Taberna receives payment status and transaction identifiers necessary to administer the ticket order. Full card details are not intended to be stored directly in Pretix; they are processed through Stripe.

14. Transactional ticket email

Order confirmations, payment notifications, tickets and event-related transactional messages are sent through the configured MTT Audio mail infrastructure. Email addresses and the order or event information needed for each message are processed for this purpose. A ticket purchase does not itself subscribe you to a newsletter.

15. Ticket generation and admission

Ticket identifiers and associated ticket information are processed to create and validate tickets, prevent fraud or duplicate use, and manage admission. This may include checking a QR code or barcode and recording admission status.

Part C – General information

16. Infrastructure and security

Technical infrastructure and mail services support the provision, maintenance, communication and protection of the respective services. The ticket service uses Cloudflare network and security functionality. Cloudflare may process technical network connection information to deliver and protect that service. This description of Cloudflare concerns the ticket service.

17. Recipients and service providers

Data is processed as needed by Matteo Taberna and providers used for the relevant purpose: in particular Stripe for payments, hCaptcha for protected website forms, and providers of the hosting, network and mail infrastructure actually used; for the ticket service this includes Cloudflare. Newsletter data is processed within the newsletter infrastructure, including Listmonk. Using self-hosted software such as Pretix or Listmonk does not itself transfer data to its developers. Depending on their actual role, providers act as processors or under their own data-protection responsibility. Disclosures required by law, including to competent authorities, remain possible.

18. Legal bases

Handling contract-related enquiries and fulfilling audio orders or ticket purchases, including necessary communication, relies on Article 6(1)(b) GDPR. Legal obligations, particularly retention of accounting and tax records, rely on Article 6(1)(c) GDPR. Where appropriate and balanced against your interests, Article 6(1)(f) GDPR supports secure service provision, troubleshooting, abuse prevention and handling other enquiries. Article 6(1)(a) GDPR applies only where valid consent is actually obtained, for example for newsletters or consent-based analytics. Rules governing access to devices apply in addition.

19. Required information

Where information in an order or ticket form is marked as required, it is necessary to enter into or perform the relevant contract. Without the required information, the relevant order or ticket booking cannot be processed.

Optional information is not required for contract fulfilment. Information submitted through contact enquiries or newsletter signups is processed only for the respective purpose described in this policy.

20. Retention

Personal data is retained only as long as necessary for its purpose or legal obligations. Relevant criteria include ongoing orders and revisions, necessary evidence, statutory retention duties and the establishment or defence of claims. Operational ticket data may be deleted or anonymised once event operations and legal requirements no longer require identifiable information. Website sessions are limited to seven days. Order rate-limit counters expire after ten minutes for IP-derived hashes and one hour for email-derived hashes; a lock against concurrent orders is released or expires after 30 seconds. These periods do not apply to the associated order or accounting records.

21. International processing

Where personal data is transferred outside the EU or EEA, the lawful transfer mechanism applicable to the provider and service is used. Stripe states that it participates in the EU-U.S. Data Privacy Framework and also provides EU Standard Contractual Clauses for relevant transfers. Cloudflare states that it uses the EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses for relevant transfers. hCaptcha states that it participates in the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses for relevant transfers. Further information about safeguards is available in the providers’ privacy and data-processing documentation or on request at mt@mttaudio.com.

22. Your rights

Subject to the legal conditions, you have rights of access, rectification, erasure, restriction of processing and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation, and to direct marketing at any time. You may withdraw consent at any time for the future, without affecting the lawfulness of earlier processing. To exercise your rights, contact mt@mttaudio.com.

23. Supervisory authority

You may lodge a complaint with a competent data protection authority, particularly where you habitually reside or work, or where an alleged infringement occurred. The authority responsible for the Berlin-based controller is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

24. Changes to this policy

This policy is updated when the services or processing change. Last updated: September 16, 2026.