D3LTA HQ Privacy Policy

Updated 18 September 2026

This policy explains how D3LTA HQ, including the Meta app D3lta HQ Integration, uses information. HQ is an internal workspace for D3LTA’s authorised team, with a public mailing-list signup.

Who is responsible

D3LTA’s team operates HQ and manages the information described here. For privacy questions or requests, contact d3lta.officialmusic@gmail.com with the subject “D3LTA HQ privacy”.

Information we use

  • Team access: login and session records, authentication attempts and security information. If enabled, a configured phone number is used for WhatsApp verification.
  • Meta: authorised ad account, Facebook Page and Instagram identities; campaign, ad set and creative settings; delivery status; and reporting such as spend, impressions and clicks. Depending on granted access, HQ also reads aggregate follower and content statistics and available audience identifiers. Aggregate reports are not lists of individual ad viewers.
  • Google Drive and creative assets: the connected account identity, selected folder and file metadata, approved media and ticket-update files. HQ retains creative references and may store imported media for campaign preparation. Selected media is sent to Meta when an authorised team member prepares an ad.
  • Mailing-list signup: email, first name, city, country and consent; optional surname, phone number and birth date where supplied. Signup information and consent evidence, including submission time and network address, are sent to Openstage. HQ retains mailing-list reports, including aggregate counts and limited location, source, tag and signup-date information. Security controls also use hashed network and email identifiers.
  • Other connected services: ticket counts and histories from Eventbrite and authorised ticket files, and artist/audience metrics from Chartmetric when connected. Optional AI campaign planning sends selected planning inputs to the configured AI service when used.

Why we use it

We use this information to secure team access, report artist and tour performance, manage authorised campaigns and creative assets, maintain reporting histories and provide updates requested by fans. Where applicable, the legal bases are consent for marketing subscriptions and optional permissions, legitimate interests in secure artist operations and reporting, and compliance with legal obligations. You can withdraw marketing consent without affecting earlier lawful processing.

Access and sharing

Access is limited to authorised team members and services needed to operate HQ. These include Sites/OpenAI and Cloudflare infrastructure, and the integrations you authorise, such as Meta, Google Drive, Openstage, Eventbrite and Chartmetric. Information is sent to the relevant provider to perform the requested feature. Providers also process information under their own policies. HQ does not sell personal information.

Service providers may process information outside your country. Applicable protections depend on the provider and service; contact us for information about the arrangements relevant to your data.

Security and cookies

HQ uses essential login/session cookies and server-side access controls. Integration credentials are encrypted on the server and are not returned in page data. HQ does not ask for your Facebook or Instagram password. No system can guarantee absolute security.

How long information is kept

Account settings, selected assets and reporting histories are retained while needed for authorised operations, historical reporting, security or applicable legal obligations. Historical campaign and ticket records do not have an automatic fixed deletion period. Session and security records are subject to expiry and cleanup; current report snapshots may be replaced on refresh. Removing a provider permission does not automatically erase previously stored HQ records. Contact us to request deletion; any necessary exceptions will be explained. Minimal consent or suppression records may be retained to respect an unsubscribe request.

Your choices and rights

You can revoke provider access in the provider’s settings, unsubscribe using the link in mailing-list emails, or contact d3lta.officialmusic@gmail.com. Depending on applicable law, you may request access, correction, deletion, restriction or portability, object to processing, or withdraw consent. We may ask for proportionate information to verify a request. You may also complain to your local data-protection authority. See our data-deletion instructions.

Updates

Changes to this policy will appear here with an updated date. Contact us if you need help understanding how a particular integration uses your information.