This Data Processing Agreement and GDPR Compliance Policy ("DPA" or "Privacy Addendum") is an integral legal addendum to the DistroVibe Terms of Service, Global Privacy Policy, and Digital Music Distribution Agreement. It details how DistroVibe ("Data Controller"), an entity incorporated and governed under the laws of England and Wales, processes the personal data of creators and licensors residing in the United Kingdom, the European Economic Area (EEA), and Switzerland.
By creating a DistroVibe account, submitting releases, or distributing music across our global network, you acknowledge and agree unconditionally to the data processing standards, sub-processor frameworks, and statutory safeguards outlined in this Agreement.
1. Roles of the Parties and Scope of Processing
1.1. DistroVibe as Data Controller
DistroVibe acts as the primary Data Controller under the UK GDPR and EU GDPR for account registration records, KYC identity verifications, financial ledgers, and catalog metadata. We determine the purposes and means of processing this data.
1.2. Enterprise Sub-Processors
We utilize vetted, enterprise-grade sub-processors, including our technical backend ingestion partners, cloud hosting providers, and our authorized merchant of record, Polar.sh, for royalty remittances and billing.
1.3. DSPs as Independent Data Controllers
Once track metadata is ingested by Spotify, Apple Music, YouTube, Meta, or TikTok, these platforms act as independent data controllers governing the public display and global streaming of your content under their respective privacy policies.
2. Lawful Bases for Processing Personal Data
- Contractual Necessity
Art. 6(1)(b) UK GDPR — Processing is required to deliver your music catalogue, generate DDEX feeds, and collect/remit streaming royalties.
- Legal Obligation
Art. 6(1)(c) UK GDPR — Compliance with UK HM Revenue & Customs (HMRC), international tax reporting, and anti-money laundering (AML) mandates.
- Legitimate Interests
Art. 6(1)(f) UK GDPR — Platform cybersecurity, stream anomaly detection, fraud mitigation, and defending against intellectual property infringement.
3. Data Retention and the "Right to be Forgotten" Limitations
The statutory right to erasure (Right to be Forgotten) is restricted in the regulated music distribution industry to prevent streaming fraud and satisfy statutory accounting requirements.
Statutory Retention & Fraud Blocklists
DistroVibe is legally mandated to retain financial, invoicing, and tax transaction data for up to seven (7) years in compliance with UK corporate and HMRC legislation. In cases of confirmed streaming fraud or copyright theft, forensic metadata and IP blocklists are retained indefinitely to protect the platform.
3.1. Account Deletion: Legitimate requests for personal data erasure require complete catalogue takedown from all connected DSPs prior to account closure.
4. Post-Brexit Global Transfers (IDTA & SCCs)
DistroVibe and our backend infrastructure operate globally. Because content is distributed to stores located worldwide (including servers in the United States), personal data and metadata are processed across international borders under approved Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) or UK Addendum, ensuring full compliance with both the UK GDPR and EU GDPR.
By utilizing our distribution pipelines, you consent to these cross-border data transfers backed by approved UK and European statutory transfer mechanisms.
5. Anti-Fraud Data Sharing & Automated Decision-Making
Artificial streaming and store manipulation cause substantial financial and reputational harm to creators and DSPs.
Fraud Investigation & Industry Data Sharing
If artificial streaming, bot farm traffic (e.g. incurring €10 DSP fines), or copyright infringement is detected, DistroVibe reserves the contractual right to share forensic telemetry (IP addresses, payment metadata, device IDs) with anti-fraud alliances, affected DSPs, and international law enforcement agencies.
For fraud prevention, automated stream monitoring, and platform security, DistroVibe employs algorithmic telemetry systems. If your account or catalogue is restricted, withheld, or subjected to penalties based solely on automated processing, you possess the statutory right under Article 22 of the UK GDPR to request human intervention by contacting our Compliance Department to review and contest the determination.
6. Exercising Data Subject Rights & ICO Complaints
Residents of the UK, EEA, or Switzerland have specific statutory rights under data protection laws:
Right of Access
Request a formal copy of all personal data held by DistroVibe.
Right to Rectification
Correction of inaccurate, outdated, or incomplete dashboard records.
Right to Data Portability
Receive your account metadata in a structured, machine-readable JSON format.
Right to Restrict or Object
Object to processing based on legitimate interests or direct marketing.
Contact our Data Protection Team at privacy@distrovibe.com. Identity verification via Two-Factor Authentication is required prior to data disclosure.
Right to Lodge a Complaint with the UK ICO
You have the statutory right to lodge a complaint at any time with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection matters (www.ico.org.uk).
7. Security Measures and 72-Hour Breach Protocols
72-Hour ICO & User Breach Notification Protocol
In the event of a confirmed personal data breach posing a risk to user rights, DistroVibe will notify the relevant supervisory authorities, including the UK Information Commissioner's Office (ICO), within 72 hours of becoming aware of the breach, and will inform affected users without undue delay via registered email.