Privacy Policy

PRIVACY POLICY Last Updated: 2026-01-27 1. Data Controller The data controller responsible for processing your data is: Your Company Name Your Street Address City, Postal Code Country Email: [email protected] 2. Collection and Storage of Personal Data We collect and process the following personal data: - Email address (for registration and authentication) - Password (encrypted storage) - Payment information (processed via Stripe, no credit card data stored on our servers) - IP address, browser type, device information - Audio files (temporary storage, automatically deleted after 20 minutes) 3. Legal Basis for Processing We process your data based on: - Article 6(1)(b) GDPR (contract performance) - Article 6(1)(f) GDPR (legitimate interests) - Article 6(1)(a) GDPR (consent) 4. Purpose of Data Processing - Providing the audio mastering service - Processing payments and subscriptions - Customer support - Service improvement - Security, abuse prevention and chargeback/fraud defense 5. Data Sharing We only share your data with: - Stripe (payment processing, PCI-DSS compliant) - AWS SES (email delivery) - Cloud hosting providers We do not sell your data to third parties. 6. Data Retention - Audio files: automatically deleted after 20 minutes - Account data: as long as your account is active - Payment data: 7 years (legal/tax retention requirement per EU regulations) - Webhook events: 7 days for audit purposes, then automatically deleted - Deleted accounts: personal data removed within 30 days - Payment history: anonymized upon account deletion (email replaced with anonymous identifier) while maintaining records for legal/accounting requirements - Dispute, anti-fraud and chargeback evidence: retained as needed for legitimate interests, legal defense and financial compliance 7. Your Rights You have the right to: - Access (Article 15 GDPR) - Request copy of your data - Rectification (Article 16 GDPR) - Correct inaccurate data - Erasure (Article 17 GDPR) - Request account deletion with data anonymization - Restriction of processing (Article 18 GDPR) - Data portability (Article 20 GDPR) - Export your data - Object (Article 21 GDPR) - Object to data processing - Lodge a complaint with a supervisory authority When you delete your account: - Your email and personal information are removed immediately - Payment history is anonymized (email replaced with 'deleted-user-[ID]@anonymized.local') - Payment records are retained for 7 years as required by law but cannot be linked back to you Contact for exercising your rights: [email protected] 8. Cookies We use: - Essential cookies (authentication, CSRF protection) - Functional cookies (user preferences) You can manage cookies in your browser settings. 9. Data Security We implement technical and organizational measures to protect your data: - TLS/HTTPS encryption - Encryption of sensitive data - Access controls - Regular security updates 10. Supervisory Authority You have the right to lodge a complaint with a data protection supervisory authority. List of authorities: https://edpb.europa.eu/about-edpb/board/members_en