Privacy policy
As things stand, the site collects no personal data. What that means, and what will change when the service opens.
This policy explains what personal data Mixartisan collects, for what purposes, on what legal basis, how long it is kept, who it is shared with, and how to exercise your rights. It is written under Regulation (EU) 2016/679 (GDPR) and French Act No. 78-17 of 6 January 1978 as amended.
We would rather be precise than reassuring. Three points deserve a careful read: your audio files and your conversations with the assistant will be personal data (section 2), some of that data will be processed in the United States (section 6), and you will be able to ask for it to be erased at any time (section 7).
0. Where the service stands today
🟢 As at the last update of this page, mixartisan.com is a presentation site. It collects no personal data.
That is not a promise, it is a reading, taken on 3 August 2026 in the site's source code and in the browser on the live site:
- no form — not a single input field anywhere on the site, including the "Log in" page, which shows nothing but a holding message;
- no accounts, no database, no payment;
- no cookies, no local storage (see the cookie policy);
- no audience measurement tool, and no resource loaded from a third-party domain.
🔴 No processor receives any data from this site today — not Supabase, not Anthropic, no payment provider, no email provider. Those names appear below because they are planned for the service to come. None of them processes anything today.
One exception, and we would rather say it plainly: our host Vercel produces technical logs (IP address, timestamp, page requested) simply because your browser loads a page. That is true of any website, and it is described in section 5.
⚠️ Sections 2 to 6 largely describe the service to come, not the current state. They are written in advance so that you know what you will be signing up to the day you open an account. This page will be updated BEFORE the service opens, not after: the actual recipients will be named then, with their role, their location and the transfer safeguards that apply.
1. Data controller
The data controller is:
- L&L4S, a French société par actions simplifiée with share capital of €100.00, operating the service under the trading name Mixartisan
- Registered office: 9 rue des Colonnes, 75002 Paris, France
- SIREN / SIRET: 941 794 141 / 941 794 141 00015 — RCS Paris 941 794 141
- Contact for any data protection question: contact@mixartisan.com
Data protection officer (DPO): none has been appointed. Appointing a DPO is only mandatory in the cases listed in Article 37 GDPR — public authority, large-scale systematic monitoring, large-scale processing of special category data — none of which is met: the site processes no user data at all today. This analysis will be reviewed before the service opens, and the officer's name published here should appointing one become necessary.
2. Data we collect
2.1 Today — no data collected
The site has no form. There is currently no waiting list, no pre-registration and no newsletter: no email address can reach us through this site.
The day a waiting list opens, it will ask only for:
- your email address, which you will enter voluntarily;
- the date and time of sign-up;
- your browsing language, so we write to you in the right one.
Nothing else will be asked at that stage, and this page will be updated before the form exists.
2.2 After launch — your account
None of what follows happens today: accounts are not open.
- Account credentials: email address, password (stored as a hash, never in clear text), name or alias if you provide one.
- Subscription and billing data: plan, credit balance and history, invoices. Card details will never pass through our servers: they will be handled by a payment provider, which has not yet been chosen and will be named here before the first sale.
2.3 Content you will entrust to the service
The service is not open, so no content is entrusted to us today.
- Uploaded audio files: tracks, stems, mixes, bounces, together with their technical metadata (length, sample rate, levels, file name).
- Conversations with the assistant: your messages, the assistant's replies, and the analyses produced on your tracks.
- Project material: project names, notes, session history.
🔴 We treat this content as personal data. A recording may contain your voice; a conversation may reveal your professional activity, your skill level, your work in progress or your clients. We do not treat it as mere technical payload.
An audio file may also contain the voice or performance of third parties (performers, session musicians, guests). By uploading a file you warrant that you hold the necessary permissions — see the terms of use and terms of sale.
2.4 Technical data
- Access logs: IP address, timestamp, browser type, pages viewed, errors encountered. These logs are generated automatically by the hosting provider, as of today, simply because a page is loaded. They are the only data about you that exists at this stage.
- Strictly necessary cookies: no cookie is set today. Those that will be set once the service opens are described in the cookie policy.
We collect no special category data within the meaning of Article 9 GDPR (health, opinions, sexual orientation, trade union membership, biometric identifiers). Please do not send any through the assistant.
3. Purposes and legal bases
Every processing operation rests on an identified legal basis. Today, only the last two in this list actually take place — security, and answering your requests — alongside the host's technical logs. The others will begin when the service opens:
- Notifying you when the service opens (waiting list) — legal basis: your consent (Article 6(1)(a) GDPR). You can withdraw it at any time, via the unsubscribe link or by email; withdrawing is as easy as consenting.
- Creating and managing your account, delivering the mixing and mastering guidance service, storing your projects — legal basis: performance of the contract with you (Article 6(1)(b)).
- Analysing your audio files and running the conversational assistant — legal basis: performance of the contract (Article 6(1)(b)). This processing is the service: without it, nothing can be delivered.
- Invoicing, taking payment and keeping accounting records — legal basis: legal obligation (Article 6(1)(c)), in particular Article L. 123-22 of the French Commercial Code.
- Measuring audience in aggregate and improving the service — legal basis: legitimate interests (Article 6(1)(f)), namely understanding how the product is actually used in order to fix it. Balanced against your rights: measurement is aggregated and is never used to target you individually. You may object (section 7).
- Keeping the service secure, preventing fraud and abuse — legal basis: legitimate interests (Article 6(1)(f)).
- Answering your requests (support, rights requests) — legal basis: legitimate interests (Article 6(1)(f)) or legal obligation (Article 6(1)(c)), depending on the request.
What we do not do
- We do not sell, rent or trade personal data. Ever.
- We do not use your audio files or your conversations to train an artificial intelligence model, or to build a dataset.
- We run no targeted advertising based on the content of your tracks or your conversations.
- We take no decision producing legal effects concerning you based solely on automated processing (Article 22 GDPR). The assistant's analyses are recommendations: you decide and you execute.
AI model training — what we are not yet asserting
The service to come plans to call the API of an artificial intelligence model provider (Anthropic). What becomes of content sent to such an API — whether or not it is used to train the models, and how long the provider keeps it — will only be written here once we have read the commercial terms in force, at the source, and we will cite that source.
🟢 While the service is not open, the question does not arise: no content goes to that API, or to any other. This check is part of the update planned before launch.
4. Retention periods
Today, the only data kept is the technical log produced by the host. The periods below will apply to service data from the moment it opens.
We would rather state a verified period than a plausible one: those still to be settled are flagged as such, and will be published here before the corresponding data is ever collected.
- Waiting list email address: until the service opens, then 3 years from your last contact, in line with the reference period recommended by the CNIL for prospect data. Deleted immediately if you unsubscribe.
- Account and associated data: for as long as your account is open, then a purge period to be published here before the service opens, backups included.
- Uploaded audio files: period to be published here before the service opens. It will in every case come with immediate deletion on request.
- Conversations with the assistant: period to be published here before the service opens.
- Invoices and accounting records: 10 years from the close of the financial year (Article L. 123-22 of the French Commercial Code). This period is imposed on us and cannot be shortened at your request.
- Access and security logs: period to be published here. The CNIL generally accepts 12 months for security traces, but the period the host actually applies has to be checked with them before we announce it; so we are not announcing it yet.
- Proof of consent: kept for as long as the consent has effect, then 5 years as evidence.
5. Recipients and processors
Your data is accessible only to the publisher and to the technical providers strictly required to run the service. Each acts as a processor within the meaning of Article 28 GDPR, on documented instructions, and is not permitted to use your data for its own purposes.
🟢 Today, Vercel is the only recipient, in respect of technical hosting logs. The other providers named below — Supabase, Anthropic, a payment provider, an email provider — are planned for the service to come and receive no data today. We list them in advance, along with what remains to be confirmed, rather than have you discover them at launch.
Vercel Inc. — site hosting and code execution
The only processor actually in operation today.
- Role: application hosting, page delivery, technical logs.
- Address: 340 S Lemon Ave #4133, Walnut, CA 91789, United States.
- Where processing happens: United States and a global network of edge locations.
- Transfer safeguard: Vercel states that it is certified under the EU-U.S. Data Privacy Framework, which provides an adequacy basis for transfers from the European Union, the United Kingdom and Switzerland; this is backed by the European Commission standard contractual clauses included in its data processing agreement. The certification can be checked on the official Data Privacy Framework list.
⚠️ We have to be exact here: this certification is stated by Vercel, and we were unable to confirm it ourselves on the official list on 3 August 2026, that list being searchable only interactively. It has to be renewed annually. We will verify it and date that verification here; you can also check it yourself on the list.
Supabase — database and authentication (planned — not in service)
🔴 Supabase processes no data today: no database is connected to the site. What follows describes the service to come.
- Planned role: database storage, account and authentication management, file storage.
- Planned data location: the Frankfurt region (Germany, European Union). Data at rest would not leave the European Union.
- Transfer safeguard: administrative or support access from the United States would remain possible and would be covered by the standard contractual clauses in the data processing agreement. The exact legal name and address of the contracting entity will be taken from the signed DPA and published here before the service opens.
Anthropic — artificial intelligence models (API) (planned — not in service)
🔴 No content is sent to this API today, the service not being open. What follows describes the service to come.
- Planned role: processing the messages you will send to the assistant and the project context attached to them, in order to produce replies and analyses.
- Planned processing location: United States.
- Transfer safeguard: European Commission standard contractual clauses (SCCs). The exact legal name, the address of the contracting entity and the reference of the signed DPA will be published here before the service opens.
🔴 In plain terms, once the service opens: the content of your conversations with the assistant will be sent to Anthropic's API and processed in the United States. That is a technical condition of the service. If you would rather it were not, do not use the assistant.
Other recipients
- Payment provider: none today — no sales are open. Its name, role and location will be published here before the first sale.
- Email delivery provider: none today — the site sends no email. Its name, role and location will be published here before the first send.
- Administrative or judicial authorities, upon a valid legal request and within its limits.
6. Transfers outside the European Union
🟢 Today, the only transfer outside the European Union is that of the technical logs Vercel produces because of your visit. The other two will only happen when the service opens.
- Vercel Inc. (United States) — hosting and technical logs; EU-U.S. Data Privacy Framework certification as stated by Vercel (see the caveat in section 5). In operation today.
- Anthropic (United States) — processing of conversations and analyses through the API. Planned, not in service.
- Supabase — data stored in the European Union (Frankfurt), with possible administrative access from the United States. Planned, not in service.
These transfers are covered by the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), supplemented where relevant by additional technical measures (encryption in transit and at rest, access segregation).
We owe you an honest statement: despite those safeguards, US law allows certain authorities to access data held by providers under their jurisdiction. You can obtain a copy of the applicable safeguards by writing to the contact address in section 1.
7. Your rights
You have the following rights over your personal data:
- Access (Article 15): confirm that processing exists and obtain a copy of your data.
- Rectification (Article 16): correct inaccurate or incomplete data.
- Erasure (Article 17): have your data deleted, including your audio files and conversations. This right does not extend to data we are legally required to keep, such as invoices.
- Portability (Article 20): receive your data in a structured, machine-readable format, or have it sent directly to another controller where technically feasible.
- Objection (Article 21): object to processing based on our legitimate interests, in particular audience measurement.
- Restriction (Article 18): have processing frozen while a dispute is resolved.
- Withdrawal of consent (Article 7(3)): at any time, for the waiting list. Withdrawal does not affect the lawfulness of processing carried out beforehand.
- Post-mortem instructions (Article 85 of the French Data Protection Act): set instructions on what happens to your data after your death.
How to exercise these rights: write to contact@mixartisan.com. We reply within one month of receipt, extendable by two months for complex requests, in which case you will be told. Proof of identity may be requested only where there is reasonable doubt about the identity of the person making the request.
8. Complaint to the supervisory authority
If, after contacting us, you consider that your rights have not been respected, you may lodge a complaint with the French data protection authority:
- Commission nationale de l'informatique et des libertés (CNIL) — 3 Place de Fontenoy, 75007 Paris, France
- Online complaint: www.cnil.fr/fr/plaintes
If you live in another EU member state, you may also complain to your own national supervisory authority.
9. Security
Today, the site being a presentation site with no accounts and no database, the only measure that has anything to apply to is encrypted communications (HTTPS/TLS), active across the whole site.
The following will apply to the service from the moment it opens: encryption at rest, passwords stored as hashes, segregated database access, logging of administrative access, and regular backups.
No system is infallible. In the event of a breach likely to result in a high risk to your rights and freedoms, you will be informed without undue delay in accordance with Article 34 GDPR, and the CNIL will be notified within 72 hours.
10. Minors
The service is not intended for anyone under 15. If you are between 15 and 18, use of the service requires your legal guardian's agreement. If we learn that an account was created by a child under 15 without the consent of the holder of parental responsibility, it will be deleted.
11. Changes to this policy
This policy may be updated, in particular when the service evolves or a processor changes. The last update date is shown at the foot of this page. Any substantial change — a new purpose, a new recipient, a new transfer outside the European Union — will be notified to you by email before it takes effect.
Last updated: