Privacy Policy
Effective date: 17 September 2026 · Last updated: 17 September 2026
1. Who we are and what this policy covers
Novick Law PLLC ("the Firm," "we," "us," "our") is a law firm with its principal office at 818 18th Ave. S., Floor 10, Nashville, TN 37203, practicing under the name Music Maker Law. We are the controller of the personal information described in this policy.
This policy explains how we collect, use, disclose, and protect personal information through www.musicmakerlaw.com (the "Site") and through email, telephone, and other correspondence with visitors, prospective clients, clients, and business contacts.
It does not cover:
• Information governed by our engagement letter and the attorney-client relationship, which is addressed in Section 7 and in your engagement documents.
• Third-party sites we link to. Their practices are their own.
• Information about our personnel, applicants, and contractors, which is handled under a separate internal notice.
By using the Site you accept this policy. If you do not agree with it, please do not use the Site or send us information through it.
2. Before you write to us
Contacting Novick Law PLLC, or sending us information by email, does not create an attorney-client relationship and does not make you a client. Information you send before we have confirmed in writing that we can represent you may not be protected by the attorney-client privilege, and we may already represent someone whose interests are adverse to yours.
Please keep your first message to your name, contact details, and a general description of the matter. Do not send documents, contracts, or detailed facts until we have cleared conflicts and confirmed an engagement in writing. Email is not a secure channel — ask us for a secure upload link if you need to send us something sensitive.
If you are already a client, this section does not apply to communications about your matter.
3. Information we collect
The Site has no forms. The Contact button and the email address on the Site open your own email program addressed to daniel@musicmakerlaw.com. We collect nothing from you through the Site unless you choose to write to us.
You give us directly, by email, telephone, or in the course of an engagement:
• Identifiers: name, stage or professional name, email address, postal address, telephone number.
• Professional information: your role in the music industry, and your band, label, publisher, management, or agency affiliations.
• Matter information: whatever you choose to tell us about your situation, which may reveal contract terms, royalty positions, catalog ownership, disputes, or other sensitive commercial detail.
• Billing information for clients: payment or bank details, handled through our billing arrangements and not collected on the Site.
• Any other content you send us, including attachments.
Collected automatically when you visit. The Site runs on Squarespace, which records for us:
• IP address and the approximate location derived from it, browser and device type, and operating system.
• Pages viewed, referring URL, time on page, and the dates and times of visits.
• A cookie identifier that distinguishes a first visit from a return visit.
We do not run Google Analytics, advertising pixels, chat widgets, or session-recording tools on the Site.
From third parties. We may receive information about you from referral sources — other lawyers, managers, and existing clients — and from public and subscription sources used for conflicts checks and client due diligence, such as corporate registries, court records, trademark and copyright registers, and rights-organization databases.
Sensitive information. We do not seek special-category data under Article 9 GDPR or "sensitive personal information" as US state laws define it. Where a matter requires it, we collect it only with your consent or under the legal-claims exemption, and use it only for that matter.
4. How we use information, and our legal basis
The right-hand column identifies our lawful basis under the EU and UK GDPR, which is relevant to you if you are in the EEA, the UK, or Switzerland.
Purpose
Legal basis (GDPR Art. 6)
Responding to your enquiry and assessing whether we can act
Steps prior to entering a contract; legitimate interests in running a practice
Conflicts checking and client due diligence
Legal obligation under professional conduct rules; legitimate interests
Providing legal services and managing your matter
Performance of our engagement contract; establishment or defence of legal claims (Art. 9(2)(f) for any special-category data)
Billing, collections, and accounting
Contract; legal obligation
Operating, securing, and debugging the Site
Legitimate interests in a functioning, secure site
Measuring how the Site is used
Consent where the ePrivacy Directive requires it; otherwise legitimate interests
Complying with court orders, subpoenas, regulators, and tax rules
Legal obligation
Our legitimate interests are in operating a law practice, understanding demand for our services, and protecting the Site and our clients. Where we rely on legitimate interests you may object under Section 10.
Automated decision-making. We do not make decisions about you that produce legal or similarly significant effects using solely automated processing, and we do not profile you for that purpose.
5. Cookies and similar technologies
The Site sets only Squarespace’s own cookies. There are no advertising, social media, or third-party analytics cookies.
Strictly necessary cookies - keeps the Site working, secures it against abuse, and remembers your cookie choices - Set without consent, yes.
Analytics cookies - Squarespace’s visitor measurement — distinguishes unique visits and records which pages are viewed - Not set without consent, where consent is required
Cookie choices. The only non-essential cookie the Site sets is Squarespace’s visitor measurement, which records which pages are viewed. We do not currently display a cookie banner. If you are in the EEA, the UK, or Switzerland and would prefer that we not record your visit, write to us and we will tell you what we hold and delete it, or use the browser controls described below.
Global Privacy Control and Do Not Track. Because we do not sell or share personal information and run no advertising trackers, there is nothing on this Site for an opt-out signal to switch off. We nonetheless treat an enabled Global Privacy Control signal as a valid opt-out request. Browser Do Not Track headers have no agreed standard and we do not respond to them.
Browser controls. You can block or delete cookies in your browser settings. Blocking strictly necessary cookies may stop parts of the Site working.
What we do not use. We do not use session-recording or replay tools, chat widgets, embedded third-party video, or any tool that shares your browsing with an advertising network.
6. How we disclose information
Service providers. We use vendors who process information on our instructions and are bound by written agreements restricting them to our purposes. For the Site, that is Squarespace, which hosts it and provides its visitor analytics. Away from the Site we use providers for email and calendaring, document management and storage, practice management and billing, payment processing, and IT security. We will name the provider handling a particular category on request.
In the course of representing you. With your instruction or where reasonably necessary to carry out the engagement: opposing counsel, courts and tribunals, co-counsel and local counsel, expert witnesses, mediators and arbitrators, and counterparties in a transaction.
Professional and corporate. Our accountants, insurers, banks, and professional advisers; our malpractice carrier; and the relevant bar or regulator in the event of an audit, complaint, or ethics inquiry.
Legal compliance. Where required by law, subpoena, court order, or regulator. Where the demand seeks privileged or confidential client information, we will assert every applicable privilege and objection and, unless legally barred, will notify the affected client before producing anything.
Business transfer. In connection with a merger, sale, or dissolution of the practice, subject to the confidentiality and client-notice obligations that professional conduct rules impose on the transfer of client files.
With your consent. For anything else.
We do not sell your personal information, and we have not sold or shared it in the preceding twelve months. The Site carries no advertising or social media trackers, so there is no cross-context behavioral advertising of the kind California, Colorado, and Connecticut define as a "sale" or "share."
We have never sold or shared the personal information of anyone we know to be under 16.
7. Confidentiality and privilege come first
Information covered by the attorney-client privilege, the work-product doctrine, or our duty of confidentiality under the applicable rules of professional conduct is governed by those rules, not by this policy. Where this policy and our professional obligations conflict, our professional obligations control.
We will refuse a privacy request that would require us to disclose or delete privileged or confidential material. If you ask us to delete your personal information while we hold a file we are required to retain, or that contains another person’s confidential information, we will explain what we can and cannot do and why.
Privacy rights belonging to people other than our clients — for example a counterparty whose information appears in a matter file — are subject to the same limits. Both the GDPR and the US state statutes contain exemptions for information processed in connection with legal services, claims, and professional privilege, and we rely on them where they apply.
8. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold: encryption in transit and at rest, access controls limiting matter files to the people working on them, multi-factor authentication, vendor due diligence, backups, and an incident response plan.
No system is perfectly secure. Email in particular is not a secure channel — if you need to send us something sensitive, ask us for a secure upload link.
If a breach affects your personal information we will notify you and the relevant authorities where the law requires, and we will notify affected clients in accordance with our professional obligations.
9. International transfers
We are based in the United States and our service providers may process information in the United States and elsewhere. Privacy laws in these countries may differ from those where you live.
Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, and on the EU–US, UK, and Swiss–US Data Privacy Frameworks where a recipient is certified. You can request a copy of the relevant safeguards using the contact details in Section 12.
10. Your rights
Which rights you have depends on where you live. We do not discriminate against anyone who exercises them.
If you are in the EEA, the UK, or Switzerland, you may request access to your personal information; correction of inaccurate information; erasure; restriction of processing; portability of information you gave us; and you may object to processing based on legitimate interests or to direct marketing. Where we rely on consent you may withdraw it at any time, without affecting processing already carried out. You may also complain to your supervisory authority — in the UK, the Information Commissioner’s Office; in the EU, the authority in your member state.
If you are in California, you may request to know the categories and specific pieces of personal information we have collected, the sources, our purposes, and the categories of recipients; to correct inaccurate information; to delete personal information; to opt out of sale, sharing, and cross-context behavioral advertising; and to limit the use of sensitive personal information. Section 3 lists what we collect. An authorized agent may submit a request with written permission and proof of identity.
If you are in another US state with a consumer privacy law, you have broadly equivalent rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, and profiling. Several of those states let you appeal a refusal; if we deny your request we will explain how to appeal, and you may then contact your state attorney general.
If you are in Canada, PIPEDA gives you the right to access your personal information, challenge its accuracy, and withdraw consent subject to legal and contractual restrictions. You may complain to the Office of the Privacy Commissioner of Canada.
How to make a request. Email daniel@musicmakerlaw.com or write to us at the address in Section 12, describing what you want. We will verify your identity in proportion to the sensitivity of the request. We respond within 30 days (45 for US state requests, extendable once by a further 45 days with notice; one month under the GDPR, extendable by two).
When we may say no. Professional conduct rules, file-retention obligations, an exemption for information processed in connection with legal services or claims, or another person’s rights may prevent us from complying in full. We will tell you which ground applies and comply to whatever extent we can.
11. Children, links, and changes
Children. The Site is intended for adults. We do not knowingly collect personal information from anyone under 16 through the Site, and we do not direct the Site to children. If a matter involves a minor artist, we collect information about that minor from the parent, guardian, or representative who instructs us, and we handle it under the engagement, not through the Site. If you believe a child has given us information through the Site, contact us and we will delete it.
Other sites. The Site links to third-party sites. We do not control them and are not responsible for their privacy practices.
Changes. We will post any revised policy here with a new "Last updated" date. If a change materially affects how we use information you already gave us, we will tell you directly — by email where we have your address — before it takes effect, and obtain consent where the law requires it.
12. Contact us
Privacy enquiries and requests
Post
Novick Law PLLC, 818 18th Ave. S., Floor 10, Nashville, TN 37203
Telephone
615.761.9949
Data protection contact
Daniel M. Novick, Esq.
This policy is available in an accessible format on request.