Privacy Policy

Last updated: 27 August 2026

This policy explains what personal data Ready Release collects, why, how long we keep it, who we share it with, and what you can do about it. It covers visitors and clients in the United States, Canada, the United Kingdom and the European Union.

1. Who is responsible for your data

The data controller — in Canadian terms, the organisation accountable for your personal information — is:

CONSILIO SASU, trading as Ready Release
10 rue des Pliettes, 63400 Chamalières, France
SIREN 848 259 644

The person accountable for privacy matters, and the contact for any request under this policy, is Jean-Christophe Blondet, reachable at hello@readyrelease.net. We have not appointed a Data Protection Officer; our processing does not meet the thresholds in Article 37 GDPR that would require one.

2. What we collect

When you place an order — your first name, last name and email address; the campaign you chose; the amount, currency and date of your order; your order reference; and the two consents you give at checkout (the request for immediate performance, and, where you upload photographs, the confirmation that you hold the rights to them), each recorded with a timestamp.

What you upload — your audio file; any photographs you choose to send; and any answers you give in the optional project brief. Photographs may show identifiable people, which makes them personal data about those people as well as about you. That is why we ask you to confirm you have the right to send them.

Payment data — we do not collect it. Your card details go directly to Stripe. We receive only the outcome (paid or not), the amount, the currency and a transaction reference.

Technical data — when you visit the site, your IP address, browser type, operating system, referring page and the pages you view. Analytics data is only collected if you consent to it (see clause 5).

When you write to us — the content of your message and the address you sent it from.

We do not knowingly collect data from anyone under 18, we do not ask for special-category data, and we do not want any. Do not send us health, biometric, political, religious, trade-union or sexual-orientation data in a project brief.

3. Why we process it, and on what legal basis

PurposeLegal basis (GDPR / UK GDPR)
Taking, producing and delivering your orderPerformance of a contract, Art. 6(1)(b)
Processing your paymentPerformance of a contract, Art. 6(1)(b)
Sending order confirmations and delivery emailsPerformance of a contract, Art. 6(1)(b)
Keeping invoices and accounting recordsLegal obligation, Art. 6(1)(c) — French Commercial Code, art. L123-22
Keeping a record of the consents you gave at checkoutLegal obligation and legitimate interest, Art. 6(1)(c) and (f) — evidence that the consent was given
Site security, fraud prevention, abuse investigationLegitimate interest, Art. 6(1)(f)
Analytics (Google Analytics)Your consent, Art. 6(1)(a) — withdrawable at any time
Answering your messagesLegitimate interest, Art. 6(1)(f)

Where the basis is legitimate interest, we have weighed that interest against your rights and freedoms, and you may object at any time (see clause 8).

We do not sell your personal data. We do not share it for cross-context behavioural advertising. We do not profile you and we make no automated decision that produces a legal or similarly significant effect on you.

4. Who we share it with

We use the following processors. Each acts on our instructions under a written contract.

ProcessorWhat it doesWhere
StripePayment processing and tax calculationIreland / United States
NetlifyWebsite hosting and server functionsUnited States
Netlify BlobsPrivate storage of your track, photographs and briefUnited States
ResendSending transactional emailUnited States
Google Analytics (Google LLC / Google Ireland Ltd)Audience measurement — only with your consentUnited States / Ireland
Google Fonts (Google LLC)Serving one webfont; your IP address is transmitted to Google when the font loadsUnited States

Beyond those, we disclose personal data only where the law requires it, or to establish, exercise or defend a legal claim.

5. Cookies and analytics

The site sets a small number of cookies and browser-storage items that are strictly necessary for it to work: they remember the campaign you selected, your currency, and the identifier of your order in progress. These carry no advertising purpose and are set without consent, as the law permits.

Google Analytics is not loaded until you consent to it. You are asked when you first arrive, and you may accept, refuse, or change your mind at any time. Refusing changes nothing about how the site works for you. If you consent, Google Analytics sets cookies that measure how the site is used; IP addresses are truncated before storage and we have disabled Google Signals and advertising features.

We do not use advertising cookies and we run no advertising network on this site.

You can also block or delete cookies in your browser settings, and most browsers offer a Do Not Track or Global Privacy Control signal — we honour Global Privacy Control as an opt-out of any sale or sharing, which in our case is already none.

6. Transfers outside your country

Several of our processors are established in the United States, so your data is transferred there.

For transfers from the European Union and the United Kingdom, we rely on: the EU–US Data Privacy Framework and its UK Extension where the recipient is certified under it — Google LLC and Stripe are; and on the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where relevant, for every other recipient, together with the supplementary technical measures described in clause 7.

For clients in Canada, we transfer personal information outside Canada on the same basis and remain accountable for it under PIPEDA and, in Quebec, under the Act respecting the protection of personal information in the private sector.

You can ask us for a copy of the safeguards in place. Write to the address in clause 1.

7. Security

The site is served over HTTPS. Your uploads are held in private object storage and are never reachable from a guessable public URL; access runs through signed, short-lived links tied to your order. Uploaded files are validated on the server by binary signature, not by file extension, and anything that fails is destroyed rather than stored. Access to production data is limited to the people who need it.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent authority within 72 hours and, where the risk is high, notify you directly.

8. How long we keep it

DataRetention
Your track, photographs and project brief12 months after delivery, then deleted
Abandoned checkouts and their files48 hours, then deleted automatically
Order and customer records3 years after the last order, for contractual claims
Invoices and accounting records10 years — required by French law
Records of the consents given at checkoutAs long as needed to evidence them, and no longer than the order record
Analytics data14 months maximum
Email correspondence3 years from the last exchange

9. Your rights

If you are in the European Union or the United Kingdom, you have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, to withdraw a consent at any time without affecting what was done before, and to define directives on what happens to your data after your death.

If you are in California, you have the right to know what we collect and why, to access it, to have it deleted, to have it corrected, and to opt out of sale or sharing — we do neither. You may exercise these rights through an authorised agent, and we will not discriminate against you for exercising them. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.

If you are in another US state with a comprehensive privacy law — Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and others — you have equivalent rights of access, correction, deletion, portability and opt-out, and a right to appeal a refusal, which you may exercise by replying to our decision.

If you are in Canada, you may access your personal information, ask for it to be corrected, withdraw a consent, and, in Quebec, ask for de-indexation or receive your data in a structured format.

To exercise any of this, write to hello@readyrelease.net. We answer within one month — 30 days in Canada and 45 days in the United States — and may extend once where the request is complex, telling you why. We may ask for proof of identity where we cannot otherwise be sure who is asking; we ask for no more than we need.

10. Complaints

If you think we have handled your data badly, tell us first — we would rather fix it. You also have the right to complain to a supervisory authority:

  • France — CNIL, 3 place de Fontenoy, 75007 Paris, cnil.fr
  • United Kingdom — Information Commissioner’s Office, ico.org.uk
  • European Union — the supervisory authority of the Member State where you live
  • Canada — Office of the Privacy Commissioner of Canada, or the Commission d’accès à l’information in Quebec
  • California — California Privacy Protection Agency, or the Attorney General

11. Changes to this policy

We may update this policy. The date at the top tells you when it last changed. If a change materially affects how we use data we already hold, we will tell you by email before it takes effect.

12. Contact

Jean-Christophe Blondet — CONSILIO SASU — 10 rue des Pliettes, 63400 Chamalières, France — hello@readyrelease.net

← Back to home