Privacy Policy
Last Updated: March 12, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how DM HOLDING Piano Studio (“we”, “us”, or “our”) collects, uses, and protects personal data when you visit this website, contact us, or request lesson availability for piano lessons in Paris or online sessions. We take privacy seriously and aim to describe our practices in plain language, including how consent-based cookies work, what information is necessary to respond to inquiries, and what choices you have.
Data Controller (GDPR): DM HOLDING SAS, 5 Rue Elzévir, 75003 Paris, France. Contact email: [email protected].
We do not appoint a Data Protection Officer (DPO) as our processing activities do not require one under applicable law. If you have any privacy questions, you can contact us using the email above and we will respond within a reasonable timeframe.
Effective date: March 12, 2026.
2. Personal Data We Collect
We collect personal data that you provide directly, data created during your interactions with the website, and limited technical identifiers required for basic site operation. The categories below describe what we may collect depending on how you use the site:
- Identity and contact information: name, email address, phone number (if provided).
- Form content: the message you send, lesson format preference, availability, goals, level notes, and any contextual details you include in your inquiry.
- Technical data: IP address, browser type and version, device identifiers, operating system, language settings, approximate location derived from IP (city/region-level), and connection information.
- Usage data: pages visited, time spent on pages, referrer URL, interactions such as link clicks, and navigation paths.
- Cookies and identifiers: cookie IDs and consent choices as described in Section 4, including essential cookies that keep the site functional and optional cookies that support analytics and marketing measurement.
- Conversion events: signals that a form was successfully submitted (for measurement and service improvement). These events may be used in aggregated reporting.
We do not intentionally collect special-category data (such as health data, religious beliefs, political opinions), financial account details, or government-issued identification numbers through this website. Please do not include that type of information in the message field.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data only when we have a lawful basis. The lawful basis depends on the purpose and the context of your interaction with us:
- Responding to inquiries and coordinating lessons (contact form, email, phone): GDPR Art. 6(1)(b) (steps prior to entering into a contract) and, where required, Art. 6(1)(a) (consent) for specific contact preferences.
- Analytics (under consent): GDPR Art. 6(1)(a) (consent). Analytics cookies activate only after you accept them.
- Marketing and remarketing (under consent): GDPR Art. 6(1)(a) (consent). Marketing cookies activate only after you accept them.
- Security and fraud prevention (protecting the site, detecting abusive traffic): GDPR Art. 6(1)(f) (legitimate interests). This includes basic logging and protective controls to keep the website stable.
- Legal compliance (if applicable): GDPR Art. 6(1)(c) (legal obligation), for example when retaining certain business records required by law.
Automated decision-making (GDPR Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects. Any lesson availability response is handled by people and depends on scheduling and instructor capacity, not automated eligibility scoring.
4. Cookies & Tracking (Essential, Analytics, Marketing)
Cookies are small text files stored on your device. We also use similar technologies, such as pixel tags and server-side event calls, depending on your consent choices. We use three categories of cookies that match the options in our cookie banner and preferences panel:
Essential cookies (always active)
Essential cookies are required for the website to function reliably and securely. They support basic operations such as maintaining continuity during a browsing session and storing your cookie consent choices. These cookies do not require consent under EU rules when they are strictly necessary. Typical retention: session-based to up to 12 months depending on the cookie.
- _site_session: supports basic session continuity (session).
- cookie_consent: stores your preferences (12 months).
Analytics cookies (consent required)
If you enable analytics cookies, we may use Google Analytics 4 (GA4) to understand website usage at an aggregate level, such as which pages are most visited, how visitors navigate the site, and whether the site performs well on different devices. We configure analytics to reduce unnecessary data and to support privacy-friendly settings (such as IP anonymization where applicable). Data retention in analytics reporting is typically 14 months.
- _ga (typical retention: 2 years)
- _ga_XXXXXXXXXX (typical retention: 2 years; GA4 property identifier varies)
Marketing cookies (consent required)
If you enable marketing cookies, we may measure advertising performance and run remarketing campaigns (for example, showing an ad to people who visited the site but did not contact us). Marketing cookies can also help build audiences such as custom audiences or lookalike audiences. These features are only activated after explicit consent through the cookie banner or preferences panel.
- _gcl_au (Google Ads conversion linker; typical retention: 90 days)
- _fbp (Meta Pixel browser identifier; typical retention: 90 days)
- _fbc (Meta Pixel click identifier; typical retention: 90 days when present)
Beyond cookies, measurement may involve pixel tags (for example, Google tag or Meta Pixel) and may include server-side transmission of events in a privacy-preserving manner (for example, using hashed identifiers). Any such processing is consent-dependent for analytics and marketing and is described in our Cookie Policy as well.
5. Consent (EEA/UK) and How to Withdraw It
Users in the EEA and UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (GDPR Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie for up to 12 months.
You may withdraw consent at any time by selecting “Manage cookie preferences” in the footer, or by clearing cookies in your browser settings. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
6. Sharing With Advertising & Service Partners
We may share limited information with service providers that help us operate the website and measure marketing performance, depending on your consent choices. We do not sell personal data. We expect our providers to process data only for the purposes we specify and in accordance with their contractual obligations.
- Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): cookie IDs, usage data, conversions, and remarketing list membership where enabled. Reference: https://policies.google.com/privacy.
- Meta Platforms (Meta Pixel, Custom/Lookalike Audiences, Conversion API): page views, conversions, audience membership, and hashed identifiers where enabled. Reference: https://www.facebook.com/privacy/policy.
- Cloudflare (CDN and security): IP-based threat detection and performance optimization. Reference: https://www.cloudflare.com/privacypolicy/.
We do not permit these providers to use site data for their own independent commercial purposes outside of providing services to us, subject to the provider’s platform terms and settings we apply.
7. International Data Transfers
Some of our service providers may process data outside the EEA/UK, including in the United States. Where applicable, transfers may rely on the EU–US Data Privacy Framework (DPF) and the UK Extension to the DPF, with Standard Contractual Clauses (EU 2021/914) or the UK International Data Transfer Addendum/IDTA used as a fallback mechanism when needed.
We take reasonable steps to ensure appropriate safeguards are in place for international transfers, consistent with GDPR requirements.
8. Data Retention
We keep personal data only for as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law. Typical retention periods are:
- Contact submissions: up to 2 years from the last interaction, to manage follow-ups and scheduling context.
- Analytics data: 14 months in standard reporting settings (where enabled).
- Marketing cookies: retained per cookie lifetime (typically 90 days for common marketing cookies) where enabled.
- Email correspondence: duration of the relationship plus up to 1 year for continuity and dispute handling.
- Server logs and security records: typically up to 90 days unless needed longer for investigating abusive traffic or security incidents.
- Cookie consent record: up to 3 years to support compliance auditing, where necessary.
- Legal and tax records: retained as required by applicable law (often 6–10 years for certain business records).
9. Your Rights (GDPR & UK GDPR)
If you are in the EEA/UK (and in many other jurisdictions with similar laws), you may have the following rights with respect to your personal data:
- Right of access (GDPR Art. 15)
- Right to rectification (Art. 16)
- Right to erasure (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Right to withdraw consent at any time (Art. 7(3))
- Right to lodge a complaint with a supervisory authority (Art. 77)
To exercise your rights, email [email protected]. We typically respond within 30 days, and may extend by up to 60 days for complex requests, as permitted by law.
Supervisory authority (France): CNIL — https://www.cnil.fr. General EU information: https://edpb.europa.eu.
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If we learn that personal data from a child under 16 has been collected without verifiable parental consent, we will delete it promptly.
11. Do Not Track
This website does not respond to Do Not Track (DNT) browser signals. Third-party providers may have their own handling of similar signals, which is described in their policies.
12. Data Deletion Requests
To request deletion of personal data, email us with the subject line “Data Deletion Request” at [email protected]. We may request additional information to verify identity before processing the request. We aim to complete valid deletion requests within 30 days, unless we must retain certain information for legal obligations or legitimate interests (for example, security incident records).
13. Business Transfers
If DM HOLDING SAS is involved in a merger, acquisition, asset sale, financing, reorganization, or insolvency, personal data may be transferred as part of that transaction. If such a transfer materially changes how personal data is used, we will provide notice on the site.
14. California (CCPA/CPRA) Notice
This section applies to California residents to the extent the California Consumer Privacy Act (CCPA), as amended by the CPRA, applies. In the past 12 months, we may have collected the categories of personal information described in Section 2 (identifiers such as name, email, IP address; internet/network activity such as site interactions; and inferences such as general interests based on pages viewed) and disclosed them to service providers and advertising partners for the purposes described in Sections 3–6.
We do not sell personal information as defined by CCPA. We may share information for cross-context behavioral advertising if marketing cookies are enabled, and California residents may opt out by using our cookie preferences panel (Manage cookie preferences in the footer) and disabling Marketing Cookies.
California rights may include the right to know, delete, correct, and opt out of sale/sharing, as well as non-discrimination. To submit a request, email [email protected] with the subject line “California Privacy Request”. We will take reasonable steps to verify your identity before responding. Authorized agents may submit requests with appropriate written proof of authorization.
15. Virginia (VCDPA) Notice
If the Virginia Consumer Data Protection Act (VCDPA) applies, Virginia residents may have rights to access, correct, delete, obtain a copy of personal data, and opt out of targeted advertising. We do not sell personal data and we do not engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject line “Virginia Privacy Request”. If we decline a request, you may appeal by emailing with the subject “Appeal of Refusal — Privacy Request”. We aim to respond to appeals within 60 days. If an appeal is denied, you may contact the Virginia Attorney General.
16. Nevada Notice
Nevada residents may submit a verified opt-out request by emailing us with the subject line “Nevada Do Not Sell Request”. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the website, our services, or legal requirements. If changes are material, we will provide a notice on the homepage at least 14 days before the updated policy takes effect where practical. The “Last Updated” date at the top of this page shows when the policy was last revised.
18. Contact
For privacy questions or requests, contact:
DM HOLDING SAS
5 Rue Elzévir
75003 Paris, France
Email: [email protected]
Phone: +33 1 42 72 18 64