Controller
- Name
- Mahlwerk Kollektiv für Musik & Kultur
- ZVR number
- 1263062876
- Address
- Hackengasse 7/9
1150 Wien
Austria - Privacy contact
- [email protected]
- General contact
- [email protected]

This page explains how MAHLWERK processes personal data through this website, MAHLWERK Signal and the services used to operate them.
Visitors can voluntarily subscribe to MAHLWERK Signal on the Join page. MAHLWERK processes the submitted email address to send updates about releases, artists, events, MAHLWERK activities and occasional paid collaborations with partners in music and culture. The legal basis is consent under Article 6(1)(a) GDPR and the applicable Austrian rules for electronic communications.
The subscription uses a double opt-in process. After submitting the form, the subscriber must confirm the address through the email sent by Brevo. MAHLWERK and Brevo retain the subscription status and the records needed to demonstrate that consent was given. The subscription does not become active without confirmation.
MAHLWERK uses Brevo as a processor to manage subscribers and send the emails under a data processing agreement. Brevo and its subprocessors process the data as described in Brevo's privacy policy and its contractual data protection terms. Where processing involves a transfer outside the EEA, the safeguards described in those terms apply.
Campaign open and click measurement is configured anonymously. MAHLWERK does not give subscriber addresses, individual activity or identifiable reports to sponsors or collaboration partners. A partner may receive only aggregated, non-personal campaign results. Sponsor content will be identified in the email where required.
Consent can be withdrawn at any time through the unsubscribe link in every email or by contacting [email protected]. Withdrawal does not affect processing carried out before withdrawal. After unsubscribing, the address may remain on a suppression list and the consent record may be retained where necessary to prevent further sends and to demonstrate compliance with legal obligations.
The MAHLWERK Signal form loads Cloudflare Turnstile to prevent automated abuse. Turnstile can process technical signals such as IP address, user agent, TLS information, the website origin and the Turnstile site key to determine whether a form submission is legitimate. This processing is based on MAHLWERK's legitimate interest under Article 6(1)(f) GDPR in protecting the form and mailing list from abuse.
Turnstile is configured without pre-clearance. The form therefore does not request a cf_clearance cookie. Further information is available in Cloudflare's Turnstile privacy notice.
The website is a static Astro site served through Cloudflare Pages. When a page is opened, Cloudflare receives the normal technical request data needed to deliver the site, such as IP address, request URL, time, browser request headers and security-related metadata.
The site loads a first-party script from /scripts/analytics.js. It sends selected page and click events to the first-party endpoint /api/analytics-event. The stored event data is limited to timestamp, event type, release slug, artist slug, event slug, platform or destination where relevant.
The custom analytics event table does not store IP addresses, user IDs, cookies, fingerprints, full user agents or profiles. The site code does not set cookies and does not use localStorage or sessionStorage.
The homepage can load release data from the MAHLWERK release-sync Worker at mahlwerk-release-sync.mahlwerkmoves.workers.dev. That request returns release metadata and platform links.
Cloudflare Web Analytics is documented in the repository as responsible for normal page views and performance, and it is enabled in the Cloudflare dashboard. Cloudflare describes Web Analytics as privacy-first analytics that does not use cookies and does not collect or use visitors' personal data.
The analyzer page decodes and measures selected audio files locally in the visitor's browser. The audio file is not uploaded to MAHLWERK by the analyzer code.
If a visitor uses the copy-report button, the generated text is written to the visitor's clipboard through the browser's clipboard API.
MAHLWERK uses a scheduled Cloudflare Worker to prepare the public release feed. That Worker can request the MAHLWERK SoundCloud RSS feed, search Deezer, check the MAHLWERK Bandcamp page and call the MusicLink API when an API key is configured.
These release-sync requests happen server-side. Visitors do not contact SoundCloud, Deezer, Bandcamp or MusicLink directly because of the sync process. The public result is stored as release metadata in Cloudflare KV and as a static fallback cache in the repository.
Custom click and page events are stored in Cloudflare D1 through the first-party Pages Function at /api/analytics-event, when the analytics database binding is available. The current table stores the event time, event type and short slugs for releases, artists, events, platforms or destinations. It does not store IP addresses, user IDs, cookies, fingerprints or full user agents.
Custom MAHLWERK analytics events in Cloudflare D1 do not currently have an automatic deletion rule in the website code. They remain in the D1 table until MAHLWERK deletes them or adds a retention job. Access is limited to people who have the needed MAHLWERK Cloudflare account, D1 database or Wrangler access.
Cloudflare D1 product metrics are separate from the custom event table. Cloudflare documents D1 metrics as available for the past 31 days.
Cloudflare Pages Function logs are not stored by Cloudflare Pages. They can be viewed as a live stream through the Cloudflare dashboard or Wrangler while a logging session is active. The release-sync Worker does not enable Workers Logs in its Wrangler config. If Workers Logs are enabled in Cloudflare, Cloudflare documents a maximum retention of 7 days, with 3 days on the Free Workers plan and 7 days on the Paid Workers plan.
Cloudflare Web Analytics can be viewed for the previous six months. Cloudflare documents unsampled beacon data for the past 7 days before longer-term aggregation.
Release metadata stored in Cloudflare KV is public website content: release titles, artwork URLs, dates and platform links. It stays in KV until the release-sync Worker overwrites it or MAHLWERK removes it.
Release, streaming, shop and ticket links can lead to external services, including SoundCloud, Bandcamp, Spotify, Apple Music, YouTube Music, Deezer, TIDAL and Amazon Music. Event ticket links currently use the friends and booking platform already configured for MAHLWERK events: the 808Factory Stager shop. These services receive data once a visitor follows the link. Their own privacy terms then apply.
The MAHLWERK site code does not set cookies and does not create visitor identifiers in browser storage. Turnstile is configured without pre-clearance, and the newsletter form does not request a Turnstile clearance cookie. Cloudflare may still process technical request data for hosting, security, delivery and enabled analytics features.
Subject to the conditions in the GDPR, data subjects have rights of access, rectification, erasure, restriction, data portability and objection. Where processing is based on consent, consent can be withdrawn at any time. To exercise a right or ask a privacy question, contact MAHLWERK at [email protected].
Data subjects also have the right to lodge a complaint with the Austrian Data Protection Authority, Barichgasse 40-42, 1030 Vienna, dsb.gv.at.
Releases, events and news from MAHLWERK. Sent occasionally