1. Who is responsible
The website operator identified in the document details is the controller of personal data processed through this site. Privacy and data-rights requests can be sent to the contact address shown there.
2. Data received
- Contact enquiries: name, email address, optional organisation, enquiry category, optional reference link and message.
- Technical records: requested URL, date and time, browser or user-agent information, referring page and IP address may appear in ordinary web-server and security logs.
- Language preference and a short-lived contact-session identifier, as described in the Cookie Notice.
3. Purposes and legal bases
Contact details are used to read, route and answer an enquiry, take requested pre-contractual steps where relevant, and keep an appropriate record of professional correspondence. Technical records are used to deliver and secure the site, prevent abuse, troubleshoot faults and maintain reliability. These uses rely on the requested communication, contractual steps where applicable, and the legitimate interests of operating a secure official website.
4. No advertising or sale
The site has no advertising pixels, behavioural profiling or mailing list. Personal data submitted through the site is not sold. It is not used for unrelated marketing.
5. Recipients, international processing and external connections
Alone New Yorker is based in New York, United States, so information submitted through the site may be processed in the United States. Data may also be handled by the hosting and email providers needed to operate the site, subject to their service and security arrangements. Where applicable law requires safeguards for international processing, appropriate measures will be used. Apple-hosted artwork and previews and the externally hosted display font may cause the visitor’s browser to make a technical request to those providers. Spotify, YouTube and other platform links are not embedded and are contacted only when a visitor chooses to open them.
6. Retention
Enquiries and related correspondence are retained only for as long as reasonably necessary to answer the request, manage the professional relationship, establish rights or meet legal obligations. Routine technical logs are retained according to security and hosting rotation needs and are deleted or overwritten when no longer necessary.
7. Your rights
Depending on the applicable law, you may request access, correction, deletion or restriction of your personal data, object to certain processing, or ask for portability where relevant. You may also lodge a complaint with the competent privacy or data-protection authority in your jurisdiction. Visitors in the European Economic Area may contact the authority where they live or work, or where they believe an infringement occurred. Identity may need to be verified before a request is fulfilled.
8. Security and updates
The site uses HTTPS, access controls, input validation and other proportionate safeguards. No internet transmission can be guaranteed absolutely secure. This notice may be updated to reflect a material change in processing or law; the effective date identifies the current version.