1. Introduction
Creative Events Promoter ("CEP Agency", "we", "us", "our") is committed to protecting the privacy and personal data of everyone who interacts with our website and services. This Privacy Policy describes how we collect, use, store, and protect your personal information in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and the Dutch Implementation Act (UAVG).
By using our website or engaging our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use our website or services.
2. Data Controller
The data controller responsible for your personal data is:
Creative Events Promoter — CEP Agency
Amsterdam, Netherlands
3. What We Collect
3.1 Information You Provide Directly
- Name, email address, phone number, and company name when submitting a booking enquiry or contact form
- DJ/artist name, genre, city, country, social media handles, and mix links when submitting to RadioDJSound
- Event details, dates, venue information, and budget when requesting a booking quote
- Any additional information you voluntarily include in messages or correspondence
3.2 Automatically Collected Data
- IP address, browser type, and operating system
- Pages visited, time spent on site, and navigation paths
- Referring website and search terms
- Device type and screen resolution
3.3 Third-Party Data
We may receive information about you from third-party platforms such as social media networks (Instagram, Facebook), streaming platforms (Spotify, SoundCloud), or event listing services, where you have made that information publicly available or have consented to sharing.
4. How We Use Your Data
We use your personal data only for the following purposes:
- Processing and responding to booking enquiries and contact form submissions
- Communicating with you about our artists, services, and events
- Sending auto-confirmation emails following form submissions
- Reviewing RadioDJSound DJ submissions for playlist consideration
- Improving our website, services, and user experience
- Analysing website traffic and usage patterns (aggregated, anonymised)
- Complying with legal obligations under Dutch and EU law
- Protecting our legitimate business interests and preventing fraud
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Legal Basis for Processing (GDPR Art. 6)
Contractual Necessity (Art. 6(1)(b))
Processing required to respond to booking enquiries and fulfil service agreements.
Legitimate Interests (Art. 6(1)(f))
Website analytics, fraud prevention, and improving our services — balanced against your rights.
Consent (Art. 6(1)(a))
Marketing communications and non-essential cookies — only where you have given explicit consent.
Legal Obligation (Art. 6(1)(c))
Compliance with Dutch tax law, accounting obligations, and court orders.
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
After the retention period, data is securely deleted or anonymised.
8. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Right of Access
Request a copy of all personal data we hold about you (Art. 15)
Right to Rectification
Correct inaccurate or incomplete personal data (Art. 16)
Right to Erasure
Request deletion of your data ("right to be forgotten") (Art. 17)
Right to Restriction
Restrict how we process your data in certain circumstances (Art. 18)
Data Portability
Receive your data in a structured, machine-readable format (Art. 20)
Right to Object
Object to processing based on legitimate interests or direct marketing (Art. 21)
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl if you believe your rights have been violated.
10. International Data Transfers
Your personal data is primarily processed within the European Economic Area (EEA). Where data is transferred outside the EEA (for example, to third-party service providers), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission for the destination country
- Binding Corporate Rules where applicable
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures include encrypted data transmission (HTTPS/TLS), access controls, and regular security reviews.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours and inform affected individuals without undue delay, as required by GDPR Art. 33–34.
12. Children's Privacy
Our website and services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately at [email protected] and we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.
Your continued use of our website or services after changes are posted constitutes your acceptance of the updated policy.
14. Contact & Complaints
For any questions, requests to exercise your rights, or complaints about how we handle your personal data, please contact us:
Supervisory Authority
If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl

