Privacy Policy
Version 2026-07-27
1. Data Controller
Media Rosenqvist is the data controller for personal data processing in this service. Contact for data protection inquiries: dataskydd@mediarosenqvist.com.
2. Data We Process
- Account: email, display name, password (hashed), role.
- Artist Profile: name, bio, links, images, and uploaded content.
- Listening Data: plays and favorites.
- Payments and subscriptions: amount, currency, date, customer, price and subscription IDs, and status from Stripe. We never store card details.
- Consents: your cookie banner choices, version, and timestamp.
- Technical: IP address (hashed), browser type, and event logs for security.
3. Purpose and Legal Basis
- Service delivery — contract.
- Payments and accounting — legal obligation.
- Security, intrusion detection, incident reporting (NIS2) — legitimate interest.
- Analytics and marketing — consent (can be withdrawn anytime).
4. Retention Period
- Account data: while account is active + 90 days.
- Accounting records (donations): 7 years per accounting law.
- Security logs: 12 months.
- Consent logs: 3 years after withdrawal.
5. Recipients and Subprocessors
- Supabase (EU region) — database, authentication, file storage.
- Stripe — checkout, payments, subscriptions, invoices, and customer portal.
- Spotify, Suno, AzuraCast — only metadata we entered ourselves.
- Meta (Facebook) — when publishing, we post release title, artist name, cover image, and link on our Facebook page. No account or contact info shared.
6. Your Rights
You have the right to access, correct, delete, restrict, data portability, and object. Many of these can be exercised directly under Settings → Privacy:
- Export your data as JSON.
- Delete your account (irreversible).
- Withdraw consents via the cookie banner.
You also have the right to file a complaint with the Swedish Authority for Privacy Protection (IMY).
7. Security (NIS2)
We apply appropriate technical and organizational measures: TLS during transfer, encryption at rest with Supabase, least privilege principle, audit logging of admin actions, and an incident management process per NIS2 directive. Serious incidents are reported to authorities within 24/72 hours.
8. Changes
When the policy updates, we increase the version number and, for major changes, request renewed consent.