We process personal data only where the law allows it. The data is grouped below by the legal basis for each activity.
3.1 To provide the Service and your contract (Art 6(1)(b) GDPR)
When you register and use the Service, we process the data needed to provide it:
- Account data — your email address, password (stored securely, never in readable form), and account settings.
- Orders, payments and invoices — what you bought, your billing address, VAT ID if you provide one, and the invoices, receipts, cancellations and credit notes we generate. Your card details are handled by our payment provider (Stripe), not stored by us.
- Subscriptions, licences, credits and downloads — your plan, connected channels, monthly credits, the licences you hold, and the tracks you download.
- Claims and whitelisting — the YouTube video and channel identifiers you give us so we can find and release Claims for you. As noted above, these come from public metadata and our Partner's claim data, matched to your account — not from your YouTube account. These identifiers are personal data, and we process them to perform your contract.
- Favourites — tracks you save.
Without this data we cannot operate your account, complete a purchase, or whitelist your videos.
3.2 To keep the Service secure (legitimate interest, Art 6(1)(f) GDPR)
To protect you, us, and the Service, we process limited data — such as your IP address and account identifier — for login-attempt monitoring, rate limiting, fraud prevention, and audit logs. Our sign-up and web forms use a self-hosted verification check that runs a small cryptographic (proof-of-work) challenge in your browser; it operates entirely on our own infrastructure, involves no third party, and sets no cookie or tracking identifier. Our legitimate interest is the security and integrity of the Service, and this is also part of our security obligation under Art 32 GDPR. You can object to this processing on grounds relating to your situation (Section 6); we may still process what is strictly necessary for security.
3.3 Support access to your account (Legitimate interest, Art. 6(1)(f) GDPR)
When you contact us regarding an issue with your account, authorized staff may access a read-only view of your account to diagnose and resolve the issue.
Scope and safeguards of support access:
- Read-only access: Staff can view the pages and notices visible to you, but cannot make purchases, download assets, release claims, submit content, cancel services, or modify your account details (such as passwords, email addresses, or payment methods). This restriction is enforced programmatically by the system architecture.
- Time-limited sessions: Support access sessions expire automatically after one hour and cannot be manually extended.
- No impact on your session: Support access will not log you out of active sessions, send automated notifications, or attribute staff actions to your account activity history.
- Audit logging: Every instance of support access is logged, including the staff member, account accessed, and timestamp. These audit logs are stored securely as described in Section 5.
Legitimate interest and your rights:
Our legitimate interest is providing accurate customer support and maintaining security records of internal system access. You have the right to object to this processing on grounds relating to your particular situation (Section 6). Please note that if you object, we may be unable to fully investigate or resolve certain technical issues you report to us. Support access is strictly restricted to personnel who require it to perform their duties.
3.4 To meet our legal obligations (Art 6(1)(c) GDPR)
We must keep certain records:
- Tax and accounting records — orders and invoices are retained as immutable records to satisfy Austrian tax law.
- Consent records — we keep a record of the consents and acknowledgements you give (see Section 7) so we can demonstrate them.
3.5 With your consent (Art 6(1)(a) GDPR)
The following are processed only with your consent:
- Analytics — a session-based measurement of unique visitors, sessions, traffic sources and sign-up funnels, using an analytics cookie, and OpenReplay session replay. These run only for visitors who accept via the cookie banner. Details are in the Cookie Policy. If you are logged in, the analytics identifier (as_sid) is linked to your account, so for logged-in users who consent, analytics is not anonymous.
- Newsletter — if you opt in, we send marketing emails through Brevo. Every newsletter has an unsubscribe link, and you can withdraw at any time.
You can withdraw any consent at any time, without affecting processing that already took place (Section 7).
3.6 Anonymous counting — not personal data
We also keep purely anonymous counts — for example page-view totals, search terms, zero-result searches, and track-play counters. These counters involve no reading from or writing to your device, use no cookie, and are stored with no session or user identifier attached (the identifier field is left empty). That is precisely why they run regardless of the cookie banner and apply to everyone, including visitors who decline analytics: nothing links them to a person or a device, so they are not personal data and this policy's rights do not apply to them. Note that a search term you enter is stored as text; do not enter personal information into the search box. If a search term contains personal information, it remains unlinked to you.
3.7 No automated decision-making or profiling
We do not carry out profiling or make automated decisions that produce legal or similarly significant effects concerning you (Article 22 GDPR). Automated checks used within our platform (such as verifying Credit Text in a video description or validating available channel credits) are automated features necessary to fulfill our service and manage your copyright licenses. Automated tools or AI models used to analyze or classify video or audio content evaluate the media file itself, not your personal data or user behavior.
3.8 AI infrastructure providers
To run two features we send limited text to specialised AI providers. We do not send your account profile, email address, or account credentials to either of them.
Claim classification (OpenAI)
When our claim system checks whether a YouTube video is music-focused, it sends the video's public metadata — its title, description and category, the channel description, and the video identifier — to OpenAI's API for that check. This metadata can describe a video's creator, who may be someone other than you (a third party). We do this on the basis of our legitimate interest (Art 6(1)(f) GDPR): the data is already public, the scope is minimal, and it is necessary to run the whitelisting our users ask for. Because this information is public and contacting each affected creator individually would involve disproportionate effort, this policy serves as their notice under Art 14(5)(b) GDPR.
Search interpretation (Anthropic)
When you use our search, the text of your query — with no user ID or IP address attached — is sent to Anthropic's API to interpret what you are looking for. If you type personal information into the search box, it becomes part of that query.
Transfers and data protection
Both providers — OpenAI, L.L.C. and Anthropic, PBC — are in the United States. We have signed data-processing agreements with each that incorporate the European Commission's Standard Contractual Clauses. Under those agreements they process the data only on our instructions, and are contractually barred from using our inputs or prompts to train their models. You can ask us for a copy of the safeguards.