SONIC ARTISTES
Applications Closed
Apply Now

The whole
company.
One screen.

Live · Accepting Applications
EST. 2014 — MMXIV
HQ. United Kingdom
ROSTER. 320+ Artists
REACH. 40+ Countries
// Find work
  • Opportunities 01
  • Job Board 02
  • Live Auditions 03
  • Ways to Perform 04
  • Apply Now 05
// Our roster
  • Artists 06
  • Backstage Pass 07
// The agency
  • About 08
  • Meet the Team 09
  • Sonic Studios 10
// Support
  • FAQs 11
  • Contact 12

Data Protection and Privacy Policy

How Sonic Artistes collects, uses and protects your personal information.

Last updated: 29 May 2026

Who we are

Sonic Artistes (Aljo Ents Ltd) is a UK-based musicians' agency. We are the data controller responsible for the personal information described in this policy.

1. Introduction

Purpose: To detail how we collect, use, and protect personal data, ensuring compliance with UK GDPR and Data Protection Act 2018.

2. Nature of Data Collected

  • Personal Information: Name, contact details (telephone, email), date of birth, bank details.
  • Professional Data: Links to videos/audio/documents (showreels, performances), CVs/Resumes, and other supporting documents.
  • Compliance Documents: Passport details, seafarers medical records, Seaman's Discharge Booklet, vaccination records, and other documents as required by cruise lines.
  • Protected characteristics: We collect and store the following data that is defined as protected characteristics (see definition below) under the GDPR policy: age, sex/gender, disability (only as outlined in a medical certificate). We do not collect or store data associated with the following protected characteristics: gender reassignment, pregnancy and maternity, race, religion or belief, and sexual orientation.

3. Sources of Data

  • Submission Form: Initial collection through a form for auditions or interviews.
  • Direct Communication: Data collected via email and online contracts.
  • Online Agreements: Musicians sign contracts or agreements digitally once offered a position.

4. Purpose of Data Collection

  • Compliance: Ensuring musicians possess the necessary documentation to work legally at sea, including verification of legal and medical documents.
  • Operational Use: Maintaining records for contact purposes, payroll processing, and contract management.

5. Data Sharing

  • Third-Party Disclosure: Personal data shared with cruise lines for compliance purposes. Payroll data (e.g., Payee name, IBAN) shared with relevant financial institutions for payment processing.
  • Data Handling: Musicians paid directly by the cruise line will have their data managed and held by the cruise line.

6. Data Retention Policy

  • Personal Identification and Contact Information: Retained for the duration of the contract plus 6 years for legal and auditing purposes.
  • Financial and Payroll Data: Held for the contract period and 6 years after, to comply with financial regulations.
  • Compliance-Related Documentation: Maintained for the contract duration and 6 years post-contract for verification and compliance.
  • Video/Audio Links and Supporting Documents: Retained during consideration and up to 6 years after for potential re-evaluation.

Please see more detail in our Data Retention Policy [SAP009].

7. Security Measures

  • Data Storage: All data is stored on self-hosted, UK-based Hostinger VPS infrastructure. Musician documents are held in enterprise-grade, S3-compatible cloud storage with AES-256 encryption at rest and TLS 1.2+ encryption in transit. Application data resides in a PostgreSQL database on a UK-based VPS. Access is controlled through role-based permissions enforced at the database level (Row Level Security), with time-limited signed URLs for document access. The platform architecture includes a private internal network, CDN with DDoS protection and WAF, least-privilege service credentials rotated every 90 days, and comprehensive audit logging across all key areas. Full details are set out in our Security & Data Protection Overview document.
  • Access Control: Data access restricted to Sonic Artistes team members and end-users with fully encrypted username and password protection.

8. Access to Data

  • Internal Access: Limited to team members responsible for processing musician data.
  • External Requests: Musicians can request access to their data via email.

9. Data Subject Rights

  • Exercise of Rights: Musicians have the right to access, rectify, erase, restrict processing, and object to the processing of their personal data. They can submit requests via email.

10. Data Breach Protocol

  • Notification: Affected individuals will be informed promptly, but no later than 72 hours after discovering a breach. Notification to the Information Commissioner's Office (ICO) is required if the breach poses a risk to individuals' rights and freedoms.

11. International Transfers

  • Current Status: Data is stored in our database system provided by Hostinger VPS in Manchester, United Kingdom.
  • Recommended Safeguards: Sonic Artistes has a Data Processing Addendum (DPA) with Airtable that sets out the terms that apply when a customer's personal data is processed by Airtable, including the appropriate technical and organisational measures implemented to protect such personal data.

12. Data Protection Officer (DPO)

  • Role: The DPO oversees compliance with data protection laws and acts as a point of contact for data protection issues.

Additional Considerations

Protected characteristics:

In the context of the GDPR (General Data Protection Regulation), "protected characteristics" refer to specific attributes or traits of individuals that are particularly sensitive and require special consideration when processing personal data. These characteristics are given additional protection under the law because they can be used to identify or discriminate against individuals. The GDPR places stricter requirements on the processing of data related to these characteristics to ensure individuals' rights and freedoms are respected.

The idea is to protect individuals from unfair treatment or discrimination based on these attributes, ensuring equal treatment and safeguarding privacy. This means that when organisations handle data related to protected characteristics, they must implement stronger security measures and have legitimate, lawful grounds for processing such data. Additionally, individuals have enhanced rights concerning their data related to these characteristics, such as the right to access, correct, or delete their data.

Questions about this policy? Contact us.

Sonic Artistes

// Sonic Artistes

A musicians' agency placing exceptional artists into world-class roles across cruise, live and studio.

  • Instagram
  • Facebook
  • TikTok
  • Email

Navigate

OpportunitiesJob BoardArtistsAboutProcessFAQ

For Artists

Apply NowLive AuditionsMeet the TeamSonic StudiosBackstage Pass

Contact

Contact UsData ProtectionData RetentionRecruitment PolicyComplaints PolicyPortal Access
© 2014–2026 Sonic Artistes (Aljo Ents Ltd.) All rights reserved
Made for musicians ● Live