Privacy Policy
1. Data Controller
The controller within the meaning of the GDPR is:
Michael Clas · UpMaDo
Plaidter Str. 31 · 56648 Saffig · Germany
Email: info@re-beatz.com
2.1 Audio Files
Uploaded original audio files are used exclusively to process the mastering job and are deleted from the server immediately after processing is complete (at most within 60 minutes).
Mastered output files are retained on the server for 2 hours (standard) or 24 hours (Studio plan) after processing to allow download. After this period, files are automatically and permanently deleted. No permanent audio library or archive is maintained.
No permanent storage, no sharing, no analysis of audio content. Legal basis: Art. 6(1)(b) GDPR (performance of contract).
2.2 Usage Data (Fair Use)
To enforce usage limits (masters per day / month), anonymised counters are stored in the database. These counters are used solely for quota management and are not linked to personal data. Legal basis: Art. 6(1)(f) GDPR (legitimate interest).
2.3 Server Logs
Automatically logged: IP address, date/time, requested URL, HTTP status, bytes transferred. Retention period: 7 days, then automatically deleted. Legal basis: Art. 6(1)(f) GDPR (legitimate interest — operational security).
2.4 Account and Contract Data
For registered users (Creator, Pro, Pro+, Studio plans), the following data is stored:
- Email address (required for account creation)
- Name (optional)
- Subscription status, plan type and billing period
- Masters used in the current month (quota counter)
- Mastering history (metadata): file name, date, selected platform, mastering intensity, LUFS measurements before/after processing, AI parameters — explicitly no audio content
Legal basis: Art. 6(1)(b) GDPR (performance of contract). Retention: until account deletion. Billing data (purchase receipts, subscription records) are retained for 10 years in accordance with § 147 AO (German Fiscal Code).
2.5 PayPal as Payment Processor
Payment is processed via PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal acts as a data processor under Art. 28 GDPR. When making a payment, data required for the transaction (name, email, amount) is transmitted to PayPal. UpMaDo does not store payment instruments (card numbers, bank details).
Legal basis: Art. 6(1)(b) GDPR (performance of contract). PayPal Privacy Policy: paypal.com/en/webapps/mpp/ua/privacy-full
2.6 AI Services (Data Processor)
For plans with AI-assisted parameter selection (Creator, Pro, Pro+, Studio), technical metadata extracted from the audio file (e.g. loudness measurements, frequency analysis, dynamics values) is transmitted as a structured text prompt to an AI language model service provider for parameter recommendations. No audio data (no raw signal, no binary audio file content) and no personal data (no email address, no name) is shared with third parties — only anonymised technical analysis values in text form.
Current service provider: Anthropic PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104-5401, USA. Anthropic is contractually bound as a data processor in accordance with Art. 28 GDPR. The transfer of data to the USA is based on the EU-US Data Privacy Framework (DPF, adequacy decision by the European Commission of 10 July 2023, Art. 45 GDPR). The transmitted metadata is not used by Anthropic for model training and is not permanently retained after the API response.
Legal basis: Art. 6(1)(b) GDPR (performance of contract). Anthropic Privacy Policy: anthropic.com/privacy
2.7 Hosting (Data Processor)
This website is hosted on servers of DomainFactory GmbH (df.eu), Oskar-Messter-Str. 33, 85737 Ismaning, Germany. DomainFactory acts as a data processor under Art. 28 GDPR; a Data Processing Agreement (DPA) is in place. The servers are located within the European Union. No transfer to third countries takes place through the hosting provider.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest — reliable operation of the website). DomainFactory Privacy Policy: df.eu/de/datenschutz
3. Local Storage
This website uses only technically necessary local storage. No tracking cookies, no advertising cookies, no analytics. Stored locally:
- User preferences (platform, preset, intensity, language) — local only, not uploaded
- Notice status (cookie banner confirmation)
Technically necessary storage does not require consent (§ 25(2)(2) TDDDG). All local data remains exclusively on your device.
4. Your Rights (Art. 15–22 GDPR)
- Access (Art. 15) — What data we hold about you
- Rectification (Art. 16) — Correction of inaccurate data
- Erasure (Art. 17) — "Right to be forgotten"
- Restriction (Art. 18) — Restriction of processing
- Data portability (Art. 20) — Export your data in machine-readable format via your account page
- Objection (Art. 21) — Against processing based on legitimate interests
To exercise your rights, contact: info@re-beatz.com
You may also lodge a complaint with a supervisory authority. For users in Germany:
Landesbeauftragter für Datenschutz und Informationsfreiheit Rheinland-Pfalz, datenschutz.rlp.de
5. No Automated Decision-Making
No automated decision-making or profiling within the meaning of Art. 22 GDPR takes place. The mastering service processes audio files purely technically (signal processing and AI-assisted parameter selection) and makes no decisions with legal or similarly significant effects on individuals.
6. Data Security & Retention Summary
All data transmissions are encrypted via TLS/HTTPS. Retention periods at a glance:
- Uploaded audio file: deleted immediately after processing (max. 60 min.)
- Mastered output file: 2 hours after processing completion (Studio plan: 24 hours)
- Server logs: 7 days
- Account and mastering metadata: until account deletion
- Billing data: 10 years (§ 147 AO)
EU Online Dispute Resolution: The European Commission provides an ODR platform at ec.europa.eu/consumers/odr. We are neither obliged nor willing to participate in dispute resolution proceedings before a consumer arbitration board.