This Privacy Policy explains in clear terms how Mythic Harmonies collects, uses, stores, and protects your personal data when you visit our website, subscribe to our newsletter, or interact with our content. We take your privacy seriously and comply with the European General Data Protection Regulation (GDPR — Regulation EU 2016/679) and Belgian data protection law.
Last updated: May 2026
1. Who we are (Data Controller)
This website (mythic-harmonies.com, hereinafter “the Site”) is operated by Mythic Harmonies, a creative project based in Belgium dedicated to original Old Norse music, Viking culture, and Norse mythology research.
For the purposes of the GDPR, Mythic Harmonies acts as the Data Controller for the personal data collected through this Site.
Contact for privacy matters:
Email: [email protected]
Website: mythic-harmonies.com/contact
Country of establishment: Belgium
2. Scope of this Policy
This Privacy Policy applies to all personal data processed by Mythic Harmonies in connection with:
- Visits to our website and its subpages
- Subscription to our newsletter
- Comments posted on articles
- Contact requests submitted via email or contact form
- Interactions with embedded third-party content (YouTube, Spotify, Apple Music)
- Automated analytics gathered through Google Analytics
This policy does not apply to third-party websites or services linked from our Site. We encourage you to read the privacy policies of those services independently.
3. What personal data we collect
3.1 Data you provide actively
- Newsletter subscription: your email address (mandatory) and optionally your first name if you choose to provide it
- Comments: name (or pseudonym), email address (kept private, not displayed), comment content, and the IP address from which the comment was submitted (for anti-spam purposes only)
- Contact form / direct email: name, email address, subject, and message content
3.2 Data collected automatically
- Technical data: anonymized IP address (last octet truncated), browser type and version, operating system, device type (desktop, mobile, tablet), screen resolution
- Browsing data: pages visited, time spent per page, referring website, exit page, language preference
- Approximate geolocation: country and city derived from anonymized IP (used for analytics only, not for tracking)
- Cookies and similar technologies: see Section 9 below for full details
3.3 Data we do NOT collect
We want to be transparent about what we never collect:
- Payment information (we don’t sell anything directly through this Site)
- Government-issued IDs or sensitive identifiers
- Health data, religious beliefs, political opinions, sexual orientation, or other sensitive categories under Article 9 GDPR
- Data from children under 16 (see Section 13)
4. Why we collect data — Purposes and Legal Bases
Under GDPR Article 6, every data processing activity requires a legal basis. Here is a complete breakdown:
4.1 Newsletter
- Purpose: to send you periodic emails about new music releases, new articles, exclusive Norse content, and announcements
- Legal basis: your explicit consent (Art. 6(1)(a) GDPR), given when you submit the subscription form and confirm via double opt-in email
- Data used: email address, first name (optional), subscription date
4.2 Comments and discussions
- Purpose: to allow community discussion under articles and to moderate inappropriate content
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — fostering meaningful exchange around our content, plus your consent given when you submit the comment
- Data used: name/pseudonym, email (private), comment content, IP for anti-spam
4.3 Contact requests
- Purpose: to respond to your questions, licensing requests, partnership proposals, or feedback
- Legal basis: pre-contractual measures or legitimate interest in responding to inquiries (Art. 6(1)(b) and (f) GDPR)
- Data used: name, email, message content
4.4 Analytics and audience measurement
- Purpose: to understand how visitors find and use our Site, which articles are most read, and how we can improve the user experience
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — improving our content and Site performance. We use IP anonymization and do not engage in cross-site tracking
- Data used: anonymized IP, page views, session duration, device info
4.5 Security and abuse prevention
- Purpose: protecting the Site from spam, brute-force attacks, and malicious bots
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in securing the Site and its users
- Data used: IP address, request patterns, user-agent strings
4.6 Legal compliance
- Purpose: meeting legal obligations (responding to lawful requests from authorities, tax records, etc.)
- Legal basis: legal obligation (Art. 6(1)(c) GDPR)
5. Who has access to your data — Third-party processors
We use carefully selected third-party services to operate the Site. Each is bound by a data processing agreement (DPA) compliant with Art. 28 GDPR, where applicable. We never sell, rent, or share your personal data for marketing purposes outside of these necessary services.
5.1 Hosting and infrastructure
- PlanetHoster (web hosting) — servers located in Canada/France
Privacy Policy: planethoster.com/privacy-policy - Cloudflare (CDN, DDoS protection, performance) — servers worldwide
Privacy Policy: cloudflare.com/privacypolicy - WP Rocket (caching plugin) — processes data locally on the server, no external transfer
Privacy Policy: wp-rocket.me/privacy-policy
5.2 Email and newsletter
- MailerLite (newsletter management) — Lithuanian company, GDPR-compliant
Privacy Policy: mailerlite.com/legal/privacy-policy
Data handled: email address, name, subscription metadata
5.3 Analytics
- Google Analytics (anonymized traffic analysis) — Google Ireland Ltd.
Privacy Policy: policies.google.com/privacy
We have enabled IP anonymization and disabled Google Signals to maximize privacy. - Google Tag Manager — used to manage tracking tags
Privacy Policy: policies.google.com/privacy
5.4 Embedded content
When you interact with embedded media on our Site, those platforms may collect data independently:
- YouTube (video embeds) — see Google Privacy Policy
- Spotify (music player embeds) — see Spotify Privacy Policy
- Apple Music (artist page links) — see Apple Privacy Policy
- Amazon Music (artist page links) — see Amazon Privacy Notice
6. International data transfers
Some of our processors operate servers outside the European Economic Area (EEA), notably in the United States (Google) and Canada (PlanetHoster). When such transfers occur, they are protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- EU-US Data Privacy Framework certification, where applicable (Google is certified)
- Additional safeguards: IP anonymization, encryption in transit (HTTPS/TLS), and encryption at rest
We continuously monitor regulatory developments (notably regarding US data transfers) and update our practices accordingly.
7. How long we keep your data — Retention periods
| Data category | Retention period |
|---|---|
| Newsletter subscribers | Until you unsubscribe |
| Unsubscribed newsletter records | 3 months (suppression list), then anonymized |
| Comments on articles | Indefinitely (deletable upon request) |
| Contact form messages | 12 months after last contact |
| Server access logs | 30 days (security purposes) |
| Google Analytics data | 14 months (anonymized) |
| Anti-spam IP records | 6 months |
After these retention periods, your data is either permanently deleted or irreversibly anonymized (in which case it is no longer personal data under GDPR).
8. Your rights under GDPR
You have extensive rights regarding your personal data. We are committed to facilitating their exercise.
8.1 Right of access (Art. 15 GDPR)
You can request a copy of all personal data we hold about you, including: what data, why we process it, who has access, how long we keep it.
8.2 Right to rectification (Art. 16 GDPR)
You can correct inaccurate or incomplete data we hold about you.
8.3 Right to erasure / “right to be forgotten” (Art. 17 GDPR)
You can request the deletion of your personal data when:
- It is no longer necessary for the original purpose
- You withdraw consent and no other legal basis applies
- You object to processing
- The data was processed unlawfully
8.4 Right to restriction of processing (Art. 18 GDPR)
You can request that we limit how we use your data in specific circumstances.
8.5 Right to data portability (Art. 20 GDPR)
You can receive your data in a structured, commonly used, machine-readable format (e.g. JSON, CSV) and transmit it to another controller.
8.6 Right to object (Art. 21 GDPR)
You can object to processing based on legitimate interest (Art. 6(1)(f)) at any time. For direct marketing (newsletter), your objection will be respected unconditionally.
8.7 Right to withdraw consent (Art. 7(3) GDPR)
Where processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. The unsubscribe link in every newsletter is the fastest way.
8.8 Right not to be subject to automated decisions (Art. 22 GDPR)
We do not engage in automated decision-making or profiling that would produce legal effects concerning you.
8.9 Right to lodge a complaint (Art. 77 GDPR)
If you believe we have violated your data protection rights, you can lodge a complaint with the Belgian Data Protection Authority (Autorité de Protection des Données / Gegevensbeschermingsautoriteit):
Rue de la Presse 35, 1000 Bruxelles
Website: dataprotectionauthority.be
8.10 How to exercise your rights
Simply email us at [email protected]. We will respond within one month as required by GDPR (extendable by two months for complex requests). The service is free unless requests are manifestly unfounded or excessive.
To protect against fraudulent requests, we may ask you to verify your identity.
9. Cookies and similar technologies
9.1 What are cookies?
Cookies are small text files stored on your device when you visit a website. They allow the site to remember your actions and preferences over time.
9.2 Cookies we use
Essential cookies (no consent required — strictly necessary for the Site to function):
wordpress_*— WordPress session and securitywp-settings-*— admin preferences (only for logged-in users)cf_*— Cloudflare security and DDoS protection
Performance cookies (improving Site speed):
wp_rocket_*— WP Rocket caching
Analytics cookies (require consent):
_ga,_gid,_gat— Google Analytics (anonymized IP, 2-year max retention)
Third-party cookies set by embedded content (only when you interact with the embed):
- YouTube cookies (when you play a video)
- Spotify cookies (when you play a track)
9.3 Managing cookies
You can manage cookies through:
- Our cookie banner (when first visiting the Site)
- Your browser settings (Chrome, Firefox, Safari, Edge all allow per-site or global cookie control)
- Specialized tools like Google Analytics Opt-out
Disabling cookies will not prevent you from accessing the Site, but some features (like remembered preferences or embedded media) may not function optimally.
10. Data security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption in transit: HTTPS/TLS 1.3 on all pages (free SSL certificate via Let’s Encrypt and Cloudflare)
- Encryption at rest: data stored on our servers is encrypted at the database level where supported
- Access controls: only authorized personnel (currently the site owner) have access to personal data
- Strong authentication: WordPress admin protected by complex passwords and 2FA
- Regular updates: WordPress core, themes, and plugins kept up to date
- Backups: daily encrypted backups via UpdraftPlus
- Security plugins: anti-malware and brute-force protection
- Cloudflare WAF: web application firewall blocking malicious requests
In the unlikely event of a personal data breach affecting your rights and freedoms, we will notify you and the Belgian Data Protection Authority within 72 hours as required by Art. 33 and 34 GDPR.
11. Newsletter — Specific notes
Our newsletter is opt-in only. When you subscribe:
- You receive a confirmation email (double opt-in) to verify ownership of the email address
- You must click the confirmation link before any newsletter is sent
- Every newsletter contains an unsubscribe link in the footer
- Unsubscribe is immediate and unconditional — no questions asked
We process your subscription through MailerLite, which is GDPR-compliant and has a Data Processing Agreement in place.
12. Comments — Specific notes
When you post a comment:
- Your name/pseudonym is displayed publicly with the comment
- Your email is never displayed publicly — only used for moderation and reply notifications
- Your IP address is logged for anti-spam purposes only (Akismet plugin)
- Comments are moderated before publication
You can request deletion of your comments at any time by contacting us.
13. Children’s privacy
This Site is not directed at children under 16 years old (the age of digital consent in Belgium under Art. 8 GDPR). We do not knowingly collect personal data from children. If you are under 16, please do not subscribe to the newsletter or submit any personal data.
If you are a parent or guardian and believe we have collected data from your child, contact us immediately and we will delete it.
14. Links to external sites
Our Site contains links to external websites (streaming platforms, sources, partners). We are not responsible for the privacy practices of these sites. We encourage you to read their privacy policies before submitting any personal data.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in legislation (GDPR updates, new Belgian laws)
- New services or third-party processors
- Improvements to our practices
The “Last updated” date at the top of this page reflects any changes. For material changes affecting your rights, we will notify newsletter subscribers via email at least 30 days in advance.
16. Specific provisions for non-EU residents
UK residents: this Policy also serves as our UK GDPR notice. The Information Commissioner’s Office (ICO) is the supervisory authority for UK residents.
Swiss residents: the Swiss Federal Act on Data Protection (FADP) provides similar rights. The Federal Data Protection and Information Commissioner (FDPIC) is the relevant authority.
California residents (CCPA): you have specific rights including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.
17. Contact and complaints
For any question, concern, or to exercise your rights:
Email: [email protected]
Subject line suggestion: “GDPR request — [your request type]”
For complaints unresolved through direct contact, you may reach the Belgian Data Protection Authority at dataprotectionauthority.be.
By using this Site, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please refrain from using the Site or providing personal data.
This Privacy Policy was last reviewed and updated in May 2026 to reflect current data processing practices and regulatory developments.
