This Data Processing Agreement and GDPR Compliance Policy ("DPA" or "Agreement") is an integral addendum to the DistroVibe Terms of Service, Privacy Policy, and Digital Music Distribution Agreement. It outlines how DistroVibe ("Data Controller") processes the personal data of users residing in the European Economic Area (EEA), the United Kingdom, and Switzerland.
By creating a DistroVibe account or distributing music through our platform, you acknowledge and agree to the data processing conditions outlined in this Agreement.
1. Roles of the Parties and Scope of Processing
1.1. DistroVibe as Data Controller
DistroVibe acts as the primary Data Controller for account registration, financial/tax information, and music metadata. We determine the purposes and means of processing this data.
1.2. Sub-Processors
We use vetted sub-processors, including our backend infrastructure provider and our payment processor, Polar.sh, for royalty remittances.
1.3. DSPs as Independent Controllers
Once metadata is delivered to Spotify, Apple Music, or YouTube, these platforms act as independent data controllers governing the public display of your data.
2. Lawful Basis for Processing Personal Data
- Contractual Necessity
Art. 6(1)(b) — processing is required to deliver your music and collect royalties.
- Legal Obligation
Art. 6(1)(c) — compliance with local tax authorities and region-specific tax forms.
- Legitimate Interests
Art. 6(1)(f) — platform security, software optimization, and fraud prevention.
3. Data Retention and the "Right to be Forgotten" Limitations
The right to erasure is restricted in the regulated music industry to prevent fraud and ensure financial accountability.
Erasure Limitations
DistroVibe reserves the right to retain segments of personal data for up to seven (7) yearsfor financial records, or indefinitely for fraud prevention blocklists.
3.1. Account Deletion: Requests for erasure require account termination and global takedowns of your entire music catalog from all DSPs.
4. International Data Transfers and Cross-Border Compliance
DistroVibe and our backend providers operate globally. Data is processed in various international jurisdictions under approved Standard Contractual Clauses (SCCs).
By using our services, you consent to the cross-border transfer of your digital assets and metadata to fulfill global distribution requirements.
5. Artificial Streaming, Fraud Detection, and Data Sharing
Music streaming fraud causes financial and legal damage to the industry ecosystem.
Fraud Investigation Protocol
If artificial streaming or bot activity (e.g. incurring €10 fines) is detected, DistroVibe reserves the right to share your personal data (IPs, payment info, metadata) with anti-fraud alliances, DSPs, and law enforcement agencies.
6. Exercising Your GDPR Data Subject Rights
Residents of the EEA, UK, or Switzerland have specific rights over their data:
Right of Access
Request a structured copy of all personal data held by DistroVibe.
Right to Rectification
Correction of inaccurate or incomplete dashboard information.
Right to Data Portability
Request metadata in structured, machine-readable JSON formats.
Right to Restrict or Object
Object to processing for direct marketing purposes.
Contact our Data Protection Officer at privacy@distrovibe.com. Identity verification via 2FA is required before any data disclosure.
7. Security Measures and Data Breach Notification
72-Hour Breach Notification
In the event of a data breach, DistroVibe will notify relevant supervisory authorities within 72 hours and inform affected users without undue delay via registered email.