Privacy information
Privacy
This page explains how the My Evil Twin website handles personal data. It is intentionally excluded from search indexing until the hosting details are approved.
Last updated: 16 July 2026
Data controller
The website is operated for the My Evil Twin music project by its members — Riccardo Battimelli, Mario Russo, Matteo Zangrandi and Daniele Serra — acting as data controllers. Privacy enquiries can be sent to info@myeviltwinmusic.com.
Data you choose to provide
The contact form collects name, email address, subject and message. The newsletter form collects name, email address and explicit subscription consent. Do not include sensitive personal information unless it is necessary for your request.
Why data is used
- To answer booking, press, professional and general enquiries.
- To send band updates only after newsletter double opt-in is completed.
- To protect forms and infrastructure from spam, abuse and fraud.
- To maintain essential technical and security logs.
The final legal bases must be reviewed against the band's real operating arrangements before launch.
Service providers
Newsletter sign-up is handled through Brevo, connected via API: the form submits data to the site backend, which forwards it to Brevo to trigger the double opt-in flow. Form abuse protection uses Google reCAPTCHA v2 Enterprise (checkbox variant). Its script and widget load only after the visitor accepts the security category in the cookie settings. YouTube uses the privacy-enhanced domain and loads only after both external-media consent and a deliberate press of the play button. The production hosting provider must be added here before publication.
Cookies and external media
Analytics: the site uses Google Analytics 4 only after the visitor accepts the Analytics category in the cookie settings. Google Analytics measures page views, scrolling, outbound clicks, file downloads, approximate technical/geographic information and referral sources. Advertising storage, advertising user data, Google Signals and advertising personalisation are disabled in the site configuration. Visitors who reject Analytics send no Analytics data because the Google tag is not loaded.
YouTube players are not requested during normal page load; they load only once you press play.
reCAPTCHA (Google reCAPTCHA v2 Enterprise, checkbox variant): because the visible checkbox widget is rendered as soon as a page containing a protected form loads, Google's reCAPTCHA script and cookies (e.g. _GRECAPTCHA) are set on page load for any page displaying that form — not only after the user checks the box or submits the form. reCAPTCHA also processes technical/behavioural signals (e.g. mouse movement, browser and device data) to assess whether the visitor is human; this data is sent to Google, which acts as an independent controller for its own reCAPTCHA/fraud-prevention purposes. This cookie is listed in the site's cookie banner, and the reCAPTCHA checkbox and form submission are only made available once the corresponding banner category has been accepted; visitors who decline it will see the contact/newsletter form indicate that this category must be accepted in order to submit.
External streaming, social and official-merch links take you to services governed by their own privacy policies.
Newsletter
Newsletter signup uses double opt-in: submitting the form does not complete subscription until the confirmation link sent by Brevo is used. Every marketing email must provide an unsubscribe mechanism.
Security and retention
Form requests are validated, rate-limited and protected by a honeypot and reCAPTCHA. Secrets are stored outside the public web root. Data is retained only for as long as necessary for the stated purpose, in line with the storage-limitation principle (GDPR Art. 5(1)(e)):
Contact form data: retained for the time needed to handle the enquiry, and in any case no longer than needed to address any related claim under the applicable statute of limitations.
Technical/security logs: retained in line with the retention periods indicated by the competent data protection authority for this type of log (in Italy, generally up to 6 months, extendable up to 24 months where needed for crime prevention or investigation, per the Garante's guidance on system administrator logs).
Newsletter data: retained until the user withdraws consent (unsubscribes).
Your rights
Depending on applicable law, you may request access, correction, deletion, restriction or portability, or object to certain processing. You may also withdraw newsletter consent at any time. Contact info@myeviltwinmusic.com to make a request.
You also have the right to lodge a complaint with your national data protection authority (in Italy, the Garante per la Protezione dei Dati Personali, www.garanteprivacy.it) if you believe processing violates applicable law.
