Privacy Policy & Terms
This page contains our Privacy Policy, Cookie Policy and Terms & Conditions. It explains how personal data is handled on this website, how cookies are used and the rules for using this site. By browsing or using this site you agree to these terms.
Privacy Policy
This Privacy Policy describes how we collect, use and protect personal data when you visit our website or interact with us. We comply with the European Union’s General Data Protection Regulation (GDPR) and other applicable data protection laws. This policy covers data collected through our website, newsletter sign-ups, analytics, cookies and embedded multimedia.
1. Data controller
This website is operated by Martin Karu. For GDPR purposes, Martin Karu is the data controller. For privacy‑related requests please use our Contact page. We will respond without undue delay and in any case within one month, as required by the GDPR.
2. What data we collect
We collect only the information necessary to provide our services and respond to your enquiries. Depending on how you use the site, we may collect:
- Name and email address if you provide them via our contact form or newsletter subscription.
- Message content you send via the contact form.
- Newsletter subscription details (e.g., subscription date/time, IP address, consent records).
- Aggregated website analytics data such as device type, session duration, traffic source and events. These metrics are collected via Google Analytics 4 only after you consent (see “Analytics” below).
- Technical data needed for security and operation (e.g., IP address, browser/device data in server logs).
- Cookie consent preferences.
Please avoid sending sensitive personal information via forms. If you do, we will treat it with care but we do not request or require such information.
3. Contact messages
If you send a message via the contact form, we process the information you provide (such as name, email address and message content) to respond to your enquiry. Our legal basis for processing is legitimate interests (GDPR Art. 6(1)(f)) and/or steps prior to entering a contract. We keep correspondence only as long as necessary to respond and maintain reasonable records.
Your contact message is not added to the newsletter unless you separately subscribe.
4. Newsletter subscription
If you subscribe to our newsletter, we process your email address to send occasional updates about performances, releases and announcements. You can unsubscribe at any time using the unsubscribe link in every email.
We use MailerLite to manage our email marketing subscriber list and to send newsletters. MailerLite acts as a data processor on our behalf. MailerLite’s privacy policy is available at mailerlite.com/legal/privacy-policy .
We operate a double opt-in process. After submitting your email address, you will receive a confirmation email and will only be subscribed after clicking the confirmation link. MailerLite records the date and time of subscription, IP address, approximate location, source of subscription and confirmation status in order to demonstrate that valid consent was obtained.
To measure and improve newsletter performance, we collect engagement statistics, including whether emails are opened and which links are clicked. This is done using standard email technologies such as tracking pixels (web beacons) and personalised links. The data may include information such as IP address, device or email client type. Engagement data is used only for aggregated reporting and is not used for profiling or targeted advertising.
Legal basis: your consent (GDPR Art. 6(1)(a)). You may withdraw your consent at any time by unsubscribing from the newsletter or by contacting us to adjust your preferences.
5. Analytics
We use Google Analytics 4 (GA4) to understand how visitors use our site so we can
improve it. GA4 uses first‑party cookies to distinguish users and unique sessions
. The cookies set include _ga (used to distinguish
users, default expiration 2 years) and _ga<container‑id> (used to
persist session state). These cookies are not strictly necessary
for the site to work, so they are only activated after you provide consent via our
cookie banner.
Google Analytics 4 does not log or store individual IP addresses. For EU users, IP address data is used solely to derive coarse location metadata (city, country, etc.) on EU‑based servers before being immediately discarded. GA4 provides controls to disable collection of Google signals and granular location/device data on a per‑region basis. We have configured GA4 to disable Google signals and granular location and device data for EU traffic. We also set the retention period for user‑level and event‑level data to 14 months, after which Google automatically deletes the data.
Legal basis: your consent (GDPR Art. 6(1)(a)). Analytics cookies are only set after you opt in via our cookie banner. You can change or withdraw your preferences at any time.
6. Embedded videos
Occasionally we embed videos from YouTube to share media content. We use YouTube’s privacy‑enhanced mode whenever possible. When privacy‑enhanced mode is enabled, YouTube does not store information about visitors until they play the video. However, once you click play, YouTube may receive your IP address and set cookies or similar technologies to deliver and personalise content. If you are logged into your Google or YouTube account, YouTube may link your viewing behaviour to your account.
We do not load embedded videos or associated cookies until you consent via our cookie banner or by explicitly clicking on the video. Our privacy policy explains that the recipient of this data is YouTube/Google; the purpose is to display video content; the data processed may include your IP address and local storage/cookies; the legal basis is your consent; you can withdraw consent at any time; and data may be transferred to the United States, where the level of data protection may be lower.
7. Data storage and international transfers
We use service providers such as website hosting, MailerLite and Google to operate this site and deliver newsletters and analytics. Personal data may be processed on servers located within or outside the European Economic Area (EEA). For example, MailerLite hosts its services in ISO 27001‑certified data centres in the EU and ensures that any transfer of personal data outside the EEA is done in accordance with applicable laws and appropriate safeguards, including adherence to the EU‑U.S. Data Privacy Framework and the use of Standard Contractual Clauses. Google Analytics 4 collects EU data via EU domains and servers before forwarding traffic to other servers and does not log IP addresses.
8. How long we keep data
- Contact messages: kept only as long as necessary to respond and maintain reasonable correspondence records.
- Newsletter subscribers: kept until you unsubscribe or we delete inactive lists as part of periodic maintenance.
- Analytics data: user‑level and event‑level analytics data are retained for 14 months then automatically deleted.
- Cookie preferences: stored for up to 12 months unless reset earlier.
9. Your rights under GDPR
You have the right to:
- Request access to your personal data and receive a copy.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data where it is no longer needed or processing is unlawful.
- Request restriction of processing while we assess a contested issue.
- Object to processing based on legitimate interests.
- Withdraw consent at any time (for consent‑based processing).
- Request portability of your data in a commonly used, machine‑readable format .
- Not be subject to automated decision‑making without human intervention.
To exercise any of these rights, please contact us via the Contact page. Requests are handled free of charge and we will respond within one month. You also have the right to lodge a complaint with a supervisory authority. In Estonia, this is the Estonian Data Protection Inspectorate (AKI): aki.ee.
10. Sharing of data
We only share personal data with service providers necessary to operate the website and newsletter (e.g., hosting providers, MailerLite and Google). These providers act as data processors under our instructions and only process personal data to deliver their services. We do not sell personal data.
11. Security
We use reasonable technical and organisational measures to protect personal data, including encrypted connections (HTTPS), secure hosting and restricted access. MailerLite’s data centres and sub‑processors maintain ISO 27001 certification. No method of transmission or storage is 100 % secure; if you believe your data has been compromised, please contact us immediately.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, systems or legal requirements. The latest version will always be published on this page.
13. Contact
For privacy‑related questions or requests, please use our Contact page.
Cookie Policy
Cookies and similar technologies help us remember your preferences, provide essential functionality, analyse how the site is used and embed third‑party media. Under EU law you must be informed about the cookies we use and choose which ones to allow. We categorise cookies as follows and obtain your consent before setting any that are not strictly necessary:
- Essential cookies: these are required to operate the site and cannot be disabled. They include cookies that remember your cookie choice and keep essential features working.
- Analytics cookies: we use Google Analytics 4 to collect anonymous
statistics about how visitors use our site. GA4 sets first‑party cookies such as
_gaand_ga<container‑id>for this purpose. These cookies are only placed after you opt‑in. They are used to distinguish unique users and sessions, and to understand traffic sources and interactions. You can decline analytics cookies without affecting the basic functioning of the site. - Video player cookies: when you consent to view an embedded YouTube video, YouTube may set cookies or local storage items and receive your IP address. We embed videos in privacy‑enhanced mode and only load them after you opt in; if you decline, we show a placeholder or link instead.
If you decline optional cookies, essential cookies may still be used to record your choice and ensure the banner does not repeatedly appear. You can change your preference at any time using the controls below.
Terms & Conditions
These Terms & Conditions govern your use of this website. By accessing or using the site you agree to be bound by these terms.
1. Operator
This website is operated by Martin Karu.
2. Acceptable use
You may use this website only for lawful, personal and non‑commercial purposes unless otherwise agreed in writing. You must not:
- Attempt to gain unauthorised access to systems.
- Interfere with normal operation of the site.
- Upload malicious code.
- Scrape or reuse content for commercial purposes.
- Use the site in violation of applicable laws.
3. Intellectual property
Unless stated otherwise, all content on this site-including text, images, audio, video, branding and design-is owned by or licensed to Martin Karu and protected by copyright and related laws.
You may not reproduce, distribute or commercially exploit materials without prior written permission.
4. Accuracy & availability
We aim to keep information current and accurate, but content may be incomplete, outdated or subject to change, including performance dates and announcements. We do not guarantee uninterrupted availability of the website and may suspend access for maintenance or technical reasons.
5. External links
This website may link to third‑party platforms or services (such as social media or ticketing services). We are not responsible for their content or privacy practices. When following a link to an external site you should read their own legal notices and policies.
6. Newsletter
Newsletter subscriptions and related data processing are governed by our Privacy Policy (see the Privacy Policy section above). You may unsubscribe at any time via the link in each email.
7. Limitation of liability
To the extent permitted by law, we are not liable for losses or damages arising from use of this website. Nothing in these Terms limits liability for intent, gross negligence or mandatory consumer rights under EU law.
8. Governing law
These Terms are governed by the laws of the Republic of Estonia, unless mandatory consumer protection laws provide otherwise.
9. Changes to these Terms
We may update these Terms & Conditions from time to time. The latest version will always be published on this page.
10. Severability
If any part of these Terms is found invalid or unenforceable, the remaining provisions remain in effect.
11. Contact
For questions about these Terms, please use our Contact page.