Privacy Policy
This policy explains, in line with Art. 13 and 14 GDPR, which personal data we process on music.vandebeat.com, for which purpose and for how long. The platform is members-only — access requires registration.
What we collect
• Your email address (required for the account login).
• If you log in with Google OAuth: additionally your display name and Google profile picture — transmitted by Google after your consent in the Google consent dialog.
• A salted, irreversible hash of your IP address — solely to bind stream tokens and prevent abuse.
• Play logs: track ID, timestamp, approximate listening duration — for recommendations and stats.
• Download logs including the assigned watermark ID — to identify the source of any leak.
• Your language preference, stored in the `vdb_lang` cookie.
Purpose of processing
Data is processed solely to operate the platform: authentication, audio streaming, personalised recommendations, anti-piracy measures (watermarking, stream-token binding) and to fulfil statutory retention duties.
Legal basis
• Art. 6 (1) (b) GDPR (performance of contract) for account, login and streaming.
• Art. 6 (1) (f) GDPR (legitimate interest) for watermarking, token binding and abuse prevention — our legitimate interest being the protection of unreleased tracks from unauthorised distribution.
• Art. 6 (1) (a) GDPR (consent) for optional newsletters and non-essential cookies.
Retention period
• Account data: while your membership is active, plus a 30-day grace period for restoration, then full deletion.
• Play logs: personal references are stripped after 12 months; aggregate stats remain anonymised.
• Download and watermark logs: up to 24 months, then deletion — except where an active legal case requires longer retention.
Recipients of data
• Google LLC — only during OAuth login (authentication).
• Hostfactory AG (Switzerland) — as the hosting provider (data processor).
• No ad networks, no third-party trackers, no data sales — ever.
Transfers to third countries
During Google OAuth login, data is transmitted to Google LLC (USA). Google is certified under the EU-US Data Privacy Framework; additionally, Standard Contractual Clauses (Art. 46 GDPR) apply. All other processing takes place within the EU/EEA or in Switzerland (hosting).
Your rights
At any time you have the right to:
• Access (Art. 15 GDPR)
• Rectification (Art. 16)
• Erasure (Art. 17)
• Restriction of processing (Art. 18)
• Data portability (Art. 20)
• Object to processing based on legitimate interests (Art. 21)
• Withdraw any previously granted consent (with effect for the future)
• Lodge a complaint with a supervisory authority (e.g. Garante per la protezione dei dati personali in Italy, or your national DPA).
Audio watermarking
Downloaded audio files contain an inaudible, individual watermark linked to the downloader's account. This technique serves solely to protect unreleased works against unauthorised distribution. The watermark does not alter audio quality for human listeners. It is only inspected in the event of a concrete suspicion of an unauthorised release.
Privacy contact
For any privacy-related request, please email office@vandebeat.com with the subject line "Privacy" so we can route your message quickly.