JEVNU privacy
Privacy notice
Effective 13 August 2026 · last updated 19 August 2026 · launch-governance draft
Overview
JEVNU is a free, members-only professional musician discovery network based in Switzerland. It processes account, profile, professional, location, interaction, trust, support, and technical information to provide, operate, secure, and improve the services requested by members. Privacy questions can be sent to support@jevnu.com.
Data controller
- Name
- Lennox Ferguson, acting as an individual controller
- Country
- Switzerland
- Privacy contact
- support@jevnu.com
No separate business postal address is currently available. A private residential address is not published here.
Information JEVNU processes
- Account authentication, membership status, account lifecycle information, 18+ self-attestation, and versioned Terms and Community Guidelines acceptance evidence.
- Musician profile information, including name or stage name, biography, profile image, instruments and roles, genres, languages, member-declared availability, optional professional work types and note, travel preferences, and recent activity.
- City, region, country, country code, and governed coordinates used for city-level discovery; JEVNU does not ask for a residential address in the musician profile.
- Music ID, its status, and the minimum linkage needed to prevent reassignment. When a member uses exact Music ID resolution, JEVNU keeps private count-only rate-limit buckets linked to that member; attempted Music IDs are not logged.
- Social links, handles, confirmation state, temporary verification records, and optional performance evidence submitted by members. At least one confirmed social account supports Music ID activation; performance links remain optional professional context.
- Saved musicians; private discovery-watch criteria and baselines; new ACTIVE-match, read, and minimal duplicate-prevention records; member-only opportunity tags with role, date, canonical city, compensation, short context and lifecycle; contact preferences; professional introduction requests and their lifecycle; confirmed professional collaborations, structured positive recommendations and recipient visibility choices; released contact details after acceptance; blocks; reports; and notifications.
- Moderation, governance, security, and audit records, including bounded operator notes.
- Notification preferences, privacy and account-management requests, support correspondence, and transactional-email delivery metadata.
JEVNU’s email outbox does not store introduction message bodies. Resend necessarily receives the content of transactional messages it sends.
Why JEVNU processes it
- Account creation and authentication.
- Membership administration, 18+ eligibility enforcement, policy acceptance, and account lifecycle.
- Profile creation and maintenance.
- Music ID issuance, integrity, lifecycle, and owner-requested portability through a generic member-gated link and locally generated QR/card.
- Professional member discovery, including geographic search.
- Member-to-member introductions, mutually confirmed professional-collaboration records, positive professional recommendations, time-bounded member-only opportunity discovery, optional factual availability/work-type matching, private saved discovery watches, optional generic new-match alerts, and notifications.
- Security, abuse prevention, reporting, blocking, and accountable moderation.
- Member support and privacy, export, deactivation, and closure requests.
- Service reliability, operational security, and compliance with applicable obligations.
Processing position and draft legal bases
Swiss-law posture
JEVNU describes its processing purposes, recipients, transfers, retention, and member rights so that processing is transparent. It does not present Swiss FADP transparency duties as a copy of the GDPR Article 6 framework.
GDPR-aware posture
| Purpose | Candidate GDPR basis | Status |
|---|---|---|
| Creating and operating membership and requested features | Article 6(1)(b), only where objectively necessary | Legal review |
| Security and abuse prevention | Article 6(1)(f), where a balancing assessment supports it | Legal review |
| Compliance and privacy obligations | Article 6(1)(c), where an applicable obligation exists | Legal review |
| Processing specifically requiring consent | Article 6(1)(a) | Legal review |
Owner / legal review required. JEVNU does not use blanket consent for all processing and does not perform behavioral advertising.
Providers and recipients
- Supabase provides authentication, a PostgreSQL database, and private profile-image storage. The production project’s primary region is Stockholm, Sweden.
- Vercel provides application hosting, deployments, server execution, and operational logging. Current server functions execute in North Virginia, United States.
- Cloudflare provides authoritative DNS and routes messages sent to JEVNU’s support address to a controlled inbox.
- OpenCage geocodes member-entered location searches on servers in Germany and Finland. JEVNU sends
no_record=1, which instructs OpenCage not to retain the query contents in its logs. - Resend sends application and transactional email using recipient addresses, necessary message content, and delivery metadata. Its account data is stored in the United States. JEVNU does not enable open or link tracking in its sending code.
International transfers
Some providers or their subprocessors may process information outside Switzerland or the EEA, including in the United States and Singapore. Provider processing terms include contractual transfer mechanisms such as standard contractual clauses and Swiss adaptations where applicable. The final provider and transfer assessment remains subject to owner or legal review.
Retention
The certified operational schedule uses record-specific defaults, subject to legal review and any applicable hold or validated erasure decision:
- Account and profile information generally follows the account lifetime; profiles are hidden immediately on deactivation or closure, with approved deletion or anonymisation reviewed within 30 days of validated erasure processing.
- Pending introductions expire after 30 days. Accepted connections, terminal requests, removed-block audits, and ordinary interaction audit events are generally scheduled for up to 24 months.
- Pending collaboration requests withdraw when an applicable membership becomes inactive. Confirmed collaboration history and its audit provenance are retained for up to 24 months after the relationship becomes terminal or the account closes; they are hidden immediately when lifecycle or blocking rules require it. Withdrawn or removed recommendations follow the same ordinary interaction schedule, while reports follow the moderation schedule.
- Open opportunities expire automatically after their final displayed date. Closed, expired, and removed opportunities leave discovery immediately; creator-visible history remains for 90 days, while ordinary opportunity and audit evidence is generally scheduled for up to 24 months. Reported or moderated records follow the report schedule.
- Terminal membership, moderation, and report records are generally scheduled for up to 36 months after closure. Completed privacy-handling audit records are scheduled for three years.
- In-product notifications are scheduled for 90 days. Sent email-delivery metadata is scheduled for 30 days; failed or permanent-failure metadata for 90 days.
- Visible new-match history for discovery watches is retained for 90 days. Minimal activation-event deduplication keys remain for the life of the watch so the same activation event cannot alert twice; deleting the watch removes its criteria, visible matches, and watch-level deduplication keys.
- Historical age and policy-acceptance evidence is retained as an auditable membership-governance record; its final legal retention treatment remains under review.
- Exact Music ID lookup rate-limit buckets contain only the member, time window, bucket type, and count. They are removed opportunistically after 24 hours.
- A CLOSED Music ID code, terminal status, and minimum linkage needed to prevent reassignment are retained indefinitely and never recycled.
The five-minute worker expires overdue opportunities and removes visible watch-match history after 90 days. Other deletion execution remains governed and manual; it is not an automatic hard-delete promise.
Your choices and rights
Depending on the applicable law and circumstances, you may request information or access, correction, deletion, restriction, objection, portability, or withdrawal of consent where processing depends on consent. Members can also update profile and notification settings, export account data, deactivate or reactivate membership, begin account closure, or request a deletion review from the account page.
Requests may require proportionate identity verification and are reviewed against safety, legal-retention, audit-integrity, and Music ID non-recycling obligations. To exercise a right, use the in-product tools or email support@jevnu.com.
Security
JEVNU uses technical and organisational safeguards designed to protect personal data. These include members-only discovery, access controls, private profile-image delivery, governed administration, audit records, and protected server secrets. Anonymous Music ID links do not resolve an ID or query profile data; resolution occurs only after the current authentication, compliance, and membership gates. Hidden, invalid, blocked, and unavailable IDs produce the same result. No internet service can promise absolute security.
Cookies, browser storage, and tracking
JEVNU uses technically necessary Supabase authentication cookies to maintain and refresh member sessions. Music ID copy, native share, QR, and card-download actions run locally and do not create share history, referral records, or analytics. The current application does not intentionally use local storage or session storage, advertising cookies, behavioral tracking, Google Analytics, Cloudflare Web Analytics, Meta Pixel, TikTok Pixel, Microsoft Clarity, Hotjar, or similar analytics beacons. No non-essential cookie banner is deployed because no non-essential tracker is intentionally active.
Children and minimum age
JEVNU membership is intended only for adults aged 18 or older. Members confirm the requirement through self-attestation; JEVNU does not independently verify every member’s age or collect a birth date or government ID for signup. JEVNU does not knowingly permit persons under 18 to create member accounts. If JEVNU becomes aware of an under-18 account, it may take appropriate account and privacy action. Questions can be sent to support@jevnu.com.
Changes to this notice
This notice is effective from 13 August 2026 and was last updated on 19 August 2026. JEVNU will update this page when processing changes and will use an appropriate in-product or direct notice for material changes where required. Minor wording or formatting changes may be made without individual email notice.