DistroVibe Logo
  • Pricing
  • News
LoginGet Started
Legal Hub

DistroVibe · Legal

GDPR Privacy Addendum & DPA

Last updated: August 2026Version 2026.3

On this page

  1. Introduction
  2. 1. Roles of the Parties & Scope
  3. 2. Lawful Bases (UK & EU GDPR)
  4. 3. Retention & Right to Erasure Limits
  5. 4. Global Transfers (IDTA & SCCs)
  6. 5. Anti-Fraud & Automated Decisions
  7. 6. Data Subject Rights & ICO Complaints
  8. 7. Security & 72-Hour Breach Protocols

Questions about this document? Contact us.

On this page
  1. Introduction
  2. 1. Roles of the Parties & Scope
  3. 2. Lawful Bases (UK & EU GDPR)
  4. 3. Retention & Right to Erasure Limits
  5. 4. Global Transfers (IDTA & SCCs)
  6. 5. Anti-Fraud & Automated Decisions
  7. 6. Data Subject Rights & ICO Complaints
  8. 7. Security & 72-Hour Breach Protocols

This Data Processing Agreement and GDPR Compliance Policy ("DPA" or "Privacy Addendum") is an integral legal addendum to the DistroVibe Terms of Service, Global Privacy Policy, and Digital Music Distribution Agreement. It details how DistroVibe ("Data Controller"), an entity incorporated and governed under the laws of England and Wales, processes the personal data of creators and licensors residing in the United Kingdom, the European Economic Area (EEA), and Switzerland.

By creating a DistroVibe account, submitting releases, or distributing music across our global network, you acknowledge and agree unconditionally to the data processing standards, sub-processor frameworks, and statutory safeguards outlined in this Agreement.

1. Roles of the Parties and Scope of Processing

1.1. DistroVibe as Data Controller

DistroVibe acts as the primary Data Controller under the UK GDPR and EU GDPR for account registration records, KYC identity verifications, financial ledgers, and catalog metadata. We determine the purposes and means of processing this data.

1.2. Enterprise Sub-Processors

We utilize vetted, enterprise-grade sub-processors, including our technical backend ingestion partners, cloud hosting providers, and our authorized merchant of record, Polar.sh, for royalty remittances and billing.

1.3. DSPs as Independent Data Controllers

Once track metadata is ingested by Spotify, Apple Music, YouTube, Meta, or TikTok, these platforms act as independent data controllers governing the public display and global streaming of your content under their respective privacy policies.

2. Lawful Bases for Processing Personal Data

  • Contractual Necessity

    Art. 6(1)(b) UK GDPR — Processing is required to deliver your music catalogue, generate DDEX feeds, and collect/remit streaming royalties.

  • Legal Obligation

    Art. 6(1)(c) UK GDPR — Compliance with UK HM Revenue & Customs (HMRC), international tax reporting, and anti-money laundering (AML) mandates.

  • Legitimate Interests

    Art. 6(1)(f) UK GDPR — Platform cybersecurity, stream anomaly detection, fraud mitigation, and defending against intellectual property infringement.

3. Data Retention and the "Right to be Forgotten" Limitations

The statutory right to erasure (Right to be Forgotten) is restricted in the regulated music distribution industry to prevent streaming fraud and satisfy statutory accounting requirements.

Statutory Retention & Fraud Blocklists

DistroVibe is legally mandated to retain financial, invoicing, and tax transaction data for up to seven (7) years in compliance with UK corporate and HMRC legislation. In cases of confirmed streaming fraud or copyright theft, forensic metadata and IP blocklists are retained indefinitely to protect the platform.

3.1. Account Deletion: Legitimate requests for personal data erasure require complete catalogue takedown from all connected DSPs prior to account closure.

4. Post-Brexit Global Transfers (IDTA & SCCs)

DistroVibe and our backend infrastructure operate globally. Because content is distributed to stores located worldwide (including servers in the United States), personal data and metadata are processed across international borders under approved Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) or UK Addendum, ensuring full compliance with both the UK GDPR and EU GDPR.

By utilizing our distribution pipelines, you consent to these cross-border data transfers backed by approved UK and European statutory transfer mechanisms.

5. Anti-Fraud Data Sharing & Automated Decision-Making

Artificial streaming and store manipulation cause substantial financial and reputational harm to creators and DSPs.

Fraud Investigation & Industry Data Sharing

If artificial streaming, bot farm traffic (e.g. incurring €10 DSP fines), or copyright infringement is detected, DistroVibe reserves the contractual right to share forensic telemetry (IP addresses, payment metadata, device IDs) with anti-fraud alliances, affected DSPs, and international law enforcement agencies.

5.1. Automated Decision-Making & Right to Human Review (Article 22 UK GDPR)

For fraud prevention, automated stream monitoring, and platform security, DistroVibe employs algorithmic telemetry systems. If your account or catalogue is restricted, withheld, or subjected to penalties based solely on automated processing, you possess the statutory right under Article 22 of the UK GDPR to request human intervention by contacting our Compliance Department to review and contest the determination.

6. Exercising Data Subject Rights & ICO Complaints

Residents of the UK, EEA, or Switzerland have specific statutory rights under data protection laws:

Right of Access

Request a formal copy of all personal data held by DistroVibe.

Right to Rectification

Correction of inaccurate, outdated, or incomplete dashboard records.

Right to Data Portability

Receive your account metadata in a structured, machine-readable JSON format.

Right to Restrict or Object

Object to processing based on legitimate interests or direct marketing.

Contact our Data Protection Team at privacy@distrovibe.com. Identity verification via Two-Factor Authentication is required prior to data disclosure.

Right to Lodge a Complaint with the UK ICO

You have the statutory right to lodge a complaint at any time with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters (www.ico.org.uk).

7. Security Measures and 72-Hour Breach Protocols

72-Hour ICO & User Breach Notification Protocol

In the event of a confirmed personal data breach posing a risk to user rights, DistroVibe will notify the relevant supervisory authorities, including the UK Information Commissioner's Office (ICO), within 72 hours of becoming aware of the breach, and will inform affected users without undue delay via registered email.

This Agreement is governed by and construed in accordance with the laws of England and Wales. Exclusive jurisdiction resides with the Courts of London, United Kingdom.
All legal documentsBack to top
DistroVibe Logo

Music distribution, rights management, and reporting for independent artists and labels.

Solutions

  • Music Distribution
  • Switch to DistroVibe
  • VEVO Distribution
  • Publishing Administration
  • Analytics & Reporting
  • Marketing Services
  • Royalty Splits

Resources

  • Compare Distributors
  • Product Roadmap
  • Blog
  • vs DistroKid
  • vs TuneCore
  • vs CD Baby
  • Supported Platforms

Company

  • About
  • Team
  • Careers
  • Contact
  • Help Center
  • Trustpilot Reviews

Legal

  • Terms of Service
  • Privacy Policy
  • DMCA & Takedown
  • Anti-Fraud Policy
  • Content ID Policy
  • Legal Hub
© 2023 - 2026 DistroVibe. All rights reserved.
CookiesData ProtectionRefunds