Privacy Policy
**1. Controller / Who We Are**
The controller responsible for the processing of your personal data is:
Christophe Dhoker
Stereo Express
Dubai Media City, Building 8
Dubai, United Arab Emirates
Email: academy@stereo-express.com
**2. Data We Collect and Purposes**
We collect and process personal data only to the extent necessary to provide our services, including the sale of digital products (wallpapers, sample packs, DJ course) and our free exclusive track lead magnet.
**Types of data collected:**
- Name (first and last, if provided)
- Email address
- **Phone number** (if provided during sign-up or purchase)
- IP address
- Date and time of registration, sign-up or purchase
- Technical data (browser type, device, approximate location via IP)
- Payment-related data (processed by third-party providers – we do not store full card details)
- Order details (products purchased, license information for digital downloads)
- Account data (for DJ course member area/login via Payhip)
**Purposes:**
- Processing and fulfilling orders (digital downloads, course access)
- Providing customer support and account management
- Sending order confirmations, download links, and transaction receipts
- Delivering the free exclusive track upon sign-up
- Sending newsletters, tips, updates, and promotional content (music, DJing, equipment) via email and/or SMS – only with your consent
- Communicating with you via phone (e.g. support, order issues, exclusive offers) – only with your consent
- Ensuring website security, fraud prevention, and system integrity
- Complying with legal obligations (e.g. tax, accounting)
**3. Legal Basis**
We process your data based on the following legal grounds:
- **Performance of a contract** (Art. 6(1)(b) GDPR / equivalent under UAE PDPL): for order fulfillment, digital downloads, course access, and delivering the free track
- **Consent** (Art. 6(1)(a) GDPR / Art. 5 UAE PDPL): for marketing emails/newsletters/SMS, phone communication, and certain cookies/tracking (given via checkbox + double opt-in confirmation)
- **Legitimate interests** (Art. 6(1)(f) GDPR): for technical logs, security, fraud prevention, and direct marketing of similar products (you can object at any time)
**4. Double Opt-in Procedure**
For newsletter sign-ups, free exclusive track, and any SMS/phone marketing, we use **double opt-in** where technically possible. After entering your email (and phone number if provided), you receive a confirmation email with a link. Your subscription only becomes active after clicking this link. This ensures we can prove your consent.
**5. Storage Period**
- Order data (including invoices): 10 years (tax/legal retention requirements)
- Newsletter/SMS subscribers + phone numbers: until you withdraw consent
- Proof of consent (double opt-in records): 6 years (statutory limitation period)
- Technical logs / IP addresses: 7–30 days (security purposes)
- Account data (DJ course): until account deletion or inactivity (as per Payhip terms)
**6. Recipients / Processors**
We share data only with trusted service providers (processors under Art. 28 GDPR):
- **Payhip** (UK/USA) – shop platform, digital delivery, member area/login, payments
- **PayPal**, **Stripe**, **Apple Pay** – payment processing (we do not store full payment details)
- **GoHighLevel** (USA) – lead magnet, email & SMS collection, double opt-in, newsletters/SMS
- Meta (Facebook/Instagram), Google (YouTube/Google Ads) – advertising and conversion tracking (Pixel/Analytics)
All processors are bound by contracts ensuring GDPR/UAE PDPL compliance.
This website is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., Facebook, or Instagram. We are an independent business and have no affiliation with Meta Platforms, Inc.
**7. International Data Transfers**
Our company is based in the UAE (no EU adequacy decision). We use processors in the USA/UK.
- Transfers are based on **EU Standard Contractual Clauses (SCCs)** (2021 version) or equivalent safeguards.
- GoHighLevel and Payhip provide SCCs or similar mechanisms (as per their DPAs).
- For Meta/Google: Transfers under their respective SCCs or Data Privacy Framework (if certified – check their current status).
We have assessed risks and implemented supplementary measures where needed.
**8. Your Rights**
You have the following rights (where applicable under GDPR/UAE PDPL/CCPA):
- Access to your data
- Rectification of inaccurate data
- Erasure (“right to be forgotten”)
- Restriction of processing
- Objection to processing (especially marketing via email/SMS/phone)
- Withdrawal of consent (future effect)
- Data portability
To exercise any right: email academy@stereo-express.com or use the unsubscribe link in newsletters/SMS.
You may lodge a complaint with:
- UAE Data Office
- Your local EU supervisory authority (if GDPR applies)
**9. CCPA/CPRA (California Residents – Additional Notice)**
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights, including:
- Right to know what personal information we collect/use/share
- Right to delete
- Right to opt-out of sale/sharing of personal information
- Right to limit use of sensitive personal information (e.g. phone number, precise geolocation)
We **do not sell** your personal information as defined under CCPA/CPRA (no monetary exchange for data). However, certain advertising tools (Meta Pixel, Google Ads) may constitute “sharing” for cross-context behavioral advertising.
To opt-out of sale/sharing: Click “Do Not Sell or Share My Personal Information” in the footer (link leads to opt-out form). We honor Global Privacy Control (GPC) signals.
For CCPA requests: email academy@stereo-express.com. We verify identity before processing.
**10. SSL Encryption**
This website uses HTTPS (SSL/TLS) to protect data in transit.
**11. Changes to this Privacy Policy**
We may update this policy. Changes will be posted here with the updated date. Continued use after changes constitutes acceptance.
**Last updated: February 17, 2026**