Privacy Policy

Last updated: 6 September 2026

Who we are

SongGenie is a music production business run by Max Honsinger in London, United Kingdom. When you send us information through this website, we are the "data controller" for it, which means we decide what happens to it and we are responsible for looking after it.

Maxima Music Group Ltd, a company registered in England and Wales, company number 12843015, registered office 20-22 Wenlock Road, London N1 7GU. SongGenie and MixGenie are trading names of that company.

[email protected]. SongGenie and MixGenie are both trading names of Maxima Music Group Ltd, so that address reaches the same person either way.

We are registered with the Information Commissioner's Office and pay the annual data protection fee, as required of UK organisations that handle personal information.

What this policy covers

This policy covers the information we collect through song-genie.com. It does not cover what happens once you become a client and we are working together on your music, which is dealt with in our Terms of Service and in whatever we agree between us.

What we collect, and why

There are two forms on this site, and everything else on this page follows from them.

The contact form (on the homepage and on the contact page) asks for your name, your email address, an optional subject line, and your message.

The application form asks for your name and your email address, plus your answers to a set of questions: what stage your song is at, what you need help with, whether you are ready to invest in production, what recording setup you have, and your timeline. There are also three free text boxes where you can tell us about the song, what you want out of it, and links to any demos.

We use all of that for one purpose: to read your enquiry and reply to it, and to work out whether we are the right people to help you. We do not sell it to anyone.

We only add you to our mailing list if you actively tick the box asking us to. It is never ticked for you and it is never required. If you do not tick it, we use your details to reply to you and for nothing else.

Alongside your form answers we also receive:

  • The country you are in. Cloudflare, who host this site, tell us which country a visitor is connecting from. It gets added to the bottom of the email we receive. This applies to both forms.
  • Advertising click IDs. If you arrived here by clicking a Google or Meta advert, the advert adds a code to the web address (gclid or fbclid). The site stores that code in your browser for the length of your visit, and sends it to us with your application so we know which advert brought you here. This is only ever sent to us with an application, though the code that remembers it runs on every page, so if you arrive anywhere on the site from an advert it is held for the rest of your visit. See the section on cookies below, because this is the part of the site with the weakest legal footing.
  • Your IP address, seen by Cloudflare. When you complete the anti-spam check, your IP address is sent to Cloudflare so they can verify it. We do not store your IP address ourselves and it does not appear in the email we receive.

We do not use analytics. There is no Google Analytics, no Meta pixel, no Plausible, nothing. Nobody is counting your clicks.

We do not take payments on this site. There is no checkout and no card details are ever entered here.

Where your information actually goes

This is the honest version. It is short, because the system is short.

Your form submission is turned into an email and sent to us by Resend, an email delivery service. It is not saved to a database, it is not put into a CRM, and it is not stored anywhere on this website. It exists as an email in our inbox and nowhere else.

The three companies involved are:

WhoWhat they doWhere
Cloudflare, Inc.Hosts the site, runs the anti-spam check, delivers pagesUnited States (global network)
Plus Five Five, Inc. (trading as Resend)Turns your form submission into an email and delivers it to usUnited States
BunnyWay d.o.o. (Bunny Fonts)Serves the fonts the site is set inEuropean Union

Bunny Fonts was chosen on purpose instead of Google Fonts. Bunny publish a zero-tracking and no-logging policy and state that they cannot track or monitor end users in any way. That is their claim, linked in the sources below, and it is why they are here.

If you send us your music. Once you are working with us, you upload your audio through a Dropbox file request. Dropbox is only the delivery route, not where your music lives: once the files arrive we move them onto our own storage, so they do not sit in Dropbox afterwards.

We keep client audio indefinitely, and that is deliberate. It is kept as a backup, so that if you come back in three years having lost your own copy, we still have it. That has saved people before. If you would rather we did not keep it, say so and we will delete it. You can ask at any point, during a project or long after.

Using your work as an example. Once your song is released, we may use it in our portfolio, on this website, or on social media. If you would prefer we did not, tell us and we will not. You can say so at any time and it comes down.

We do not post work in progress. Nothing from your project goes anywhere before you have released it, and if we ever wanted to share something early we would ask first.

Our lawful basis for using your information

Under UK GDPR we need a lawful basis for using your personal information. We rely on legitimate interests (Article 6(1)(f)).

Our legitimate interest is running a music production business: reading enquiries from people who have deliberately contacted us, replying to them, and keeping our inbox usable by blocking bot spam. We think this is what you would reasonably expect when you fill in a form headed "contact us", and it has a minimal effect on your privacy because the information goes into an inbox and nowhere else.

You can object to this at any time. See "Your rights" below.

If you tick the marketing box, we rely on your consent for those emails rather than on legitimate interests, and you can withdraw it at any time using the unsubscribe link in any email or by emailing us.

Cookies and similar technologies

The law here is PECR, which is separate from UK GDPR. PECR does not just cover cookies. The ICO's guidance is explicit that it applies to anything that stores information on your device or reads information back off it, including web storage, tracking pixels and "link decoration", which is the practice of adding extra information to a web address so it can be passed to the destination site.

There are two things on this site that fall under those rules.

1. The anti-spam check. We use Cloudflare Turnstile to tell humans from bots. When you complete it, Cloudflare processes signals from your browser including your IP address, and may store information in your browser. Cloudflare's own position is that these signals are strictly necessary for detecting and blocking bots. The ICO's list of activities likely to meet the "strictly necessary" exception includes ensuring the security of terminal equipment and preventing or detecting fraud, so we do not ask for your consent for this.

Checked on 6 September 2026: the anti-spam check is live and running on every form, and we measured what it stores on your device. On a normal visit this site sets no cookies at all, and stores nothing in your browser.

2. The advertising click IDs. This is the awkward one, and it is worth being straight about it rather than burying it.

If you arrive from a Google or Meta advert, the advert appends a code (gclid or fbclid) to the web address. The site reads that code and stores it in your browser's session storage until you either submit the application form or close the tab. If you submit the form, the code is included so we can tell which advert worked.

Session storage is web storage, which PECR regulation 6 covers. The ICO's guidance gives a worked example that matches this almost exactly: an advertiser places adverts, the platform adds a unique ID to the URL when someone clicks, and the advertiser stores that identifier. The ICO's conclusion in that example is "Regulation 6 applies." The guidance also says plainly that there are no advertising purposes that meet the strictly necessary exception.

Other than these, this site does not set cookies. There is no analytics and no advertising tracking on the page itself.

Booking a call. The booking page at /book embeds a calendar from Cal.com so you can pick a time without leaving this site. That embed loads from app.cal.com and may set its own cookies, and anything you enter to book a call (your name, email and any notes) goes to Cal.com as well as to us. Cal.com is a US company and processes booking data in the United States. For transfers out of the UK and EEA they rely on Standard Contractual Clauses or an adequacy mechanism, and they process attendee data on our instructions under their Data Processing Agreement. Their privacy policy is at cal.com/privacy and their subprocessor list at trust.cal.com.

Where your information goes

Most of the people who contact us are in the United States, so it is worth being plain about this: we are a UK business, and your information is handled in the UK by us. We are regulated by UK data protection law wherever you happen to live, and the rights described further down apply to you either way.

The services we use to run the site and send email are:

WhoWhat they doWhere
Cloudflare, Inc.Hosts the site, runs the anti-spam checkUnited States
Plus Five Five, Inc. (Resend)Turns your message into an email and delivers it to usUnited States
Cal.com, Inc.Runs the booking calendar, if you book a callUnited States
BunnyWay d.o.o.Serves the fonts the site is set inEuropean Union
Dropbox InternationalReceives the audio files clients uploadUnited States / Ireland

If you are in the US, most of that will feel unremarkable, since the companies involved are American and your data largely stays where it already was. If you are in the UK or Europe, the relevant point is that some of your information is handled by US companies, and UK law requires us to have proper safeguards in place for that. We do:

  • Resend's data processing terms say transfers out of the UK are made under the standard contractual clauses as amended by the UK Addendum, and become binding when a customer accepts their Terms of Service.
  • Cloudflare's say the same, that the UK Addendum is deemed executed, and that they comply with the Data Privacy Framework including the UK extension.
  • Cal.com rely on standard contractual clauses or an adequacy mechanism for transfers out of the UK and EEA, and process booking data on our instructions under their data processing agreement.

All three publish standard terms covering transfers out of the UK, and we rely on those. If you would like the specifics for any of them, email us and we will point you at the relevant documents.

If you would like a copy of the safeguards that cover these transfers, email us at [email protected] and we will point you at the relevant terms.

How long we keep it

We keep enquiry and application emails for as long as we are working with you, and for as long afterwards as we may reasonably need them, which in practice means they stay in our inbox. Records connected to paid work are kept for six years, because HMRC requires business records to be retained for that long. You can ask us to delete your information at any time and we will, unless we are required to keep it for tax purposes.

How applications are sorted

When you send an application, the form checks two of your answers automatically and uses them to decide which page you see next. If you say you only need mixing and mastering, or that you are not able to invest right now, you are sent to a page explaining that we are probably not the right fit. Everyone else is sent to a confirmation page.

That is the whole of it. It is a simple rule, it does not score you or build a profile of you, and it does not decide anything about you beyond which page loads. A person reads every single application that comes in, and you are welcome to reply to the confirmation email and tell us the form got you wrong.

Your rights

You have the following rights over the information we hold about you:

  • to ask what we have and get a copy of it
  • to have it corrected if it is wrong or incomplete
  • to have it deleted
  • to ask us to restrict what we do with it
  • to get a copy in a portable format, in some circumstances

You also have the right to object to us using your information. Because we rely on legitimate interests, you can object at any time and we will stop unless we have a compelling reason not to. The ICO requires this right to be brought to your attention clearly and separately from the others, which is why it has its own paragraph.

To do any of this, email us at [email protected]. It is free and we will reply within one month.

Complaining

If you are unhappy with how we have handled your information, please tell us first, at [email protected], and we will try to sort it out.

You also have the right to complain to the Information Commissioner's Office, who regulate this in the UK. You can do that at ico.org.uk/make-a-complaint, or find their contact details at ico.org.uk/global/contact-us. You do not have to complain to us first.

Changes to this policy

If we change how the site handles your information, we will update this page and change the date at the top.