Last updated: 2026-05-27
1. Who we are
cubansalsa.nl is an independent calendar for Cuban salsa events in the Netherlands. Within the meaning of the General Data Protection Regulation (GDPR), the data controller is:
Cubansalsa.nl
Contact: the contact form
There is (as yet) no legal obligation to appoint a Data Protection Officer. Privacy questions reach us directly at the email address above.
2. What data we collect
We collect as little as possible. Below is what comes in per channel:
2.1 Contact and report form
When you submit an event, report an error or otherwise send us a message via the form at /contact, we process:
- Name
- Email address
- Organisation (optional)
- The content of your message
- Possibly a reference to the event the report relates to
2.2 Website usage & statistics
We use Google Analytics 4 (loaded via Google Tag Manager) with Google Consent Mode v2. This works in two modes:
- With consent(you accept ‘analytics cookies’ in the cookie banner): we place analytics cookies and collect data about page visits, click behaviour, session duration and technical characteristics (browser type, screen size). IP addresses are anonymised by GA4 by default before they are stored.
- Without consent (the default, and when you decline analytics cookies): no cookies are placedand no personal data is stored. Google does receive so-called ‘cookieless pings’: fully anonymous signals with the page path, time and event type, without any identifier that could link you or your visit to another session. Google uses these aggregated signals for statistical modelling of total visitor volume.
Because no cookies are placed and no personal data is processed in the ‘without consent’ mode, no consent is required for it (see section 3 for the legal bases). See the cookie statement for details on which cookies are and are not placed.
2.3 Newsletter
If you sign up via /newsletter or the footer form, we process:
- Your email address
- The moment of signing up, confirming and, where applicable, unsubscribing
- A hash of your IP address (SHA-256 with a server salt — never stored in unencrypted form), and the user agent of your browser at the moment of subscribing (for fraud/abuse analysis)
- Language preference (NL / EN)
We use double opt-in: your subscription is only active after you click the confirmation link in the email you receive. You can unsubscribe at any time with a single click via the link at the bottom of every email — without logging in.
2.4 Account & login
For the admin section we use session cookies (NextAuth). These are strictly necessary and are placed without consent as soon as someone attempts to log in. Regular visitors do not have an account.
2.5 Log files
Our hosting provider (Vercel) records technical logs (IP address, timestamp, path, status code) that are needed for security, fraud prevention and error handling. These logs are automatically retained for a limited time by Vercel.
3. Purposes and legal bases (art. 6 GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Handling event submissions and error reports | Name, email, organisation, message | Legitimate interest (art. 6(1)(f) GDPR) — maintaining a correct, complete calendar |
| Contacting you about your report | Name, email | Legitimate interest (art. 6(1)(f) GDPR) |
| Sending the weekly newsletter (opt-in) | Email address, consent metadata (hashed IP, user agent), tokens for confirmation and unsubscription | Consent (art. 6(1)(a) GDPR) — double opt-in, always revocable with a single click |
| Website usage statistics with cookies (GA4 via GTM, after opt-in) | Anonymised visit data, device and browser data, GA4 client-id cookie | Consent (art. 6(1)(a) GDPR) |
| Statistical modelling without cookies (Consent Mode v2 cookieless pings) | Aggregated, non-identifiable signals (path, time, event type — no client-id, no cookies) | Legitimate interest (art. 6(1)(f) GDPR) — no processing of personal data, only aggregated visitor measurement |
| Operation of login sessions (admin) | Session cookie, linked to email | Performance of a contract / legitimate interest (art. 6(1)(b) / (f)) |
| Security and error handling | IP, user agent, request logs | Legitimate interest (art. 6(1)(f) GDPR) |
4. Retention periods
- Event reports: a maximum of 24 months after the report has been handled, unless there is ongoing contact.
- Email correspondence: a maximum of 24 months.
- Analytics (GA4): the default setting of 14 months; aggregated, anonymised reports remain available longer.
- Newsletter subscription: for as long as you are subscribed. After unsubscribing we keep the registration for a further maximum of 12 months in a closed status (proof of opt-out), after which it is permanently deleted. You can unsubscribe at any time with a single click via the link in every email.
- Hosting log files: in accordance with Vercel’s retention policy (typically ≤ 30 days).
- Cookie preference: 12 months in your browser (localStorage).
5. Processors
We engage a limited number of service providers that process personal data on our behalf. We have a data processing agreement with each of them. Overview:
| Processor | Role | Location |
|---|---|---|
| Vercel Inc. | Hosting of the website, edge CDN, logs | EU region |
| Supabase | Database (Postgres) for events and reports | EU region |
| Resend | Sending transactional emails | EU/US — with appropriate safeguards |
| Google (Tag Manager + Analytics 4) | Website usage statistics (only after consent) | EU region with data transfers under the EU-US Data Privacy Framework |
6. Your rights as a data subject
Under the GDPR you have the right to:
- Access the personal data we process about you;
- Rectification if it is inaccurate or incomplete;
- Erasure(the “right to be forgotten”);
- Restriction of the processing;
- Object to processing based on legitimate interest;
- Port your data (data portability) where applicable;
- Withdraw consent you previously gave. This does not affect the lawfulness of processing carried out before the withdrawal.
Submit your request via the contact form. We respond within four weeks.
8. Contact
Do you have a question, complaint or request? Reach us via the contact form.
9. Complaint to the Dutch Data Protection Authority
You always have the right to lodge a complaint with the Dutch supervisory authority: the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). We would appreciate it if you give us the chance to resolve any issues ourselves first.