GDPR Compliance & DPA

Last updated: April 2026Version 2026.2

This Data Processing Agreement and GDPR Compliance Policy ("DPA" or "Agreement") is an integral addendum to the DistroVibe Terms of Service, Privacy Policy, and Digital Music Distribution Agreement. It outlines how DistroVibe ("Data Controller") processes the personal data of users residing in the European Economic Area (EEA), the United Kingdom, and Switzerland.

By creating a DistroVibe account or distributing music through our platform, you acknowledge and agree to the data processing conditions outlined in this Agreement.

1. Roles of the Parties and Scope of Processing

1.1. DistroVibe as Data Controller

DistroVibe acts as the primary Data Controller for account registration, financial/tax information, and music metadata. We determine the purposes and means of processing this data.

1.2. Sub-Processors

We use vetted sub-processors, including our backend infrastructure provider and our payment processor, Polar.sh, for royalty remittances.

1.3. DSPs as Independent Controllers

Once metadata is delivered to Spotify, Apple Music, or YouTube, these platforms act as independent data controllers governing the public display of your data.

2. Lawful Basis for Processing Personal Data

  • Contractual Necessity

    Art. 6(1)(b) — processing is required to deliver your music and collect royalties.

  • Legal Obligation

    Art. 6(1)(c) — compliance with local tax authorities and region-specific tax forms.

  • Legitimate Interests

    Art. 6(1)(f) — platform security, software optimization, and fraud prevention.

3. Data Retention and the "Right to be Forgotten" Limitations

The right to erasure is restricted in the regulated music industry to prevent fraud and ensure financial accountability.

Erasure Limitations

DistroVibe reserves the right to retain segments of personal data for up to seven (7) yearsfor financial records, or indefinitely for fraud prevention blocklists.

3.1. Account Deletion: Requests for erasure require account termination and global takedowns of your entire music catalog from all DSPs.

4. International Data Transfers and Cross-Border Compliance

DistroVibe and our backend providers operate globally. Data is processed in various international jurisdictions under approved Standard Contractual Clauses (SCCs).

By using our services, you consent to the cross-border transfer of your digital assets and metadata to fulfill global distribution requirements.

5. Artificial Streaming, Fraud Detection, and Data Sharing

Music streaming fraud causes financial and legal damage to the industry ecosystem.

Fraud Investigation Protocol

If artificial streaming or bot activity (e.g. incurring €10 fines) is detected, DistroVibe reserves the right to share your personal data (IPs, payment info, metadata) with anti-fraud alliances, DSPs, and law enforcement agencies.

6. Exercising Your GDPR Data Subject Rights

Residents of the EEA, UK, or Switzerland have specific rights over their data:

Right of Access

Request a structured copy of all personal data held by DistroVibe.

Right to Rectification

Correction of inaccurate or incomplete dashboard information.

Right to Data Portability

Request metadata in structured, machine-readable JSON formats.

Right to Restrict or Object

Object to processing for direct marketing purposes.

Contact our Data Protection Officer at privacy@distrovibe.com. Identity verification via 2FA is required before any data disclosure.

7. Security Measures and Data Breach Notification

72-Hour Breach Notification

In the event of a data breach, DistroVibe will notify relevant supervisory authorities within 72 hours and inform affected users without undue delay via registered email.