Privacy policy
This page explains which personal data Bitsound processes, for what purpose, on which legal basis, for how long, and what rights you have.
Last updated: 6 October 2026
Controller
Dr. Peter Mayer
Sole proprietor, trading as Bitsound
Würzburgerweg 18
4840 Vöcklabruck
Austria
Email: support@bitsound.com
Phone: +43 699 81816699
No data protection officer has been appointed. For all questions about data protection you can reach us at support@bitsound.com.
In short
- We use our own analysis of how Bitsound is used. IP addresses are processed temporarily and day-specific identifiers are created for page views. We treat these identifiers as pseudonymous data.
- Cookies and local storage support sign-in, security and the features you choose. Details are in the section "Cookies and local storage".
- We do not sell personal data. Recipients are the service providers described below and artists, as far as you have consented to their fan list.
- We keep listening events in your account for at most 90 days. You can control listening history and radio personalisation separately.
- ID images are processed in encrypted form and deleted as soon as a decision on the verification has been made, at the latest after 30 days if not reviewed. Details are in the section on verification.
Legal bases
- Contract (Art. 6(1)(b) GDPR): account, sign-in, streaming, purchases, credit, downloads, artist agreement and payouts.
- Legal obligation (Art. 6(1)(c) GDPR): accounting and retention of records (§ 132 BAO, § 212 UGB), VAT, obligations under the Digital Services Act.
- Legitimate interest (Art. 6(1)(f) GDPR): security of the service, protection against abuse and fraud, recommendations in Bitsound Radio, pseudonymous audience measurement. You can object at any time.
- Consent (Art. 6(1)(a) GDPR): entry in an artist's fan list and in the interest list for artists. You can withdraw your consent at any time with effect for the future.
Hosting and storage
Bitsound uses Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, as hosting processor. The servers used for operation and the music and image storage are located in Germany. Encrypted additional backups are also kept at Hetzner in Germany.
Local database backups are kept for at most 14 days. Additional database and file backups, including backed-up file versions, are kept for at most 30 days. ID images are not backed up. Backups serve only for restoring the service; after a restore, deletions made in the meantime are applied again. Records that must be kept by law are handled separately according to the periods that apply to them.
Visiting the website, logs and abuse protection
When you visit the site, your browser transmits technically necessary data such as IP address, time, requested address and user agent. Our web server writes no access logs. The application logs errors and background jobs. These logs are deleted after 30 days at the latest; they may be overwritten earlier due to size limits. If a specific security incident requires longer preservation of evidence, only the extracts needed for that are kept separately until the matter is resolved.
To protect against abuse, for example too many sign-in codes, we count requests per IP address and per email address. We delete these counters at the latest one hour after they expire. For VAT purposes the country can be determined from your IP address. This is done with a database on our own server, the IP address is not passed on.
Legal basis: legitimate interest in secure operation (Art. 6(1)(f) GDPR) and legal obligation to determine the country of taxation (Art. 6(1)(c) GDPR).
Audience measurement
To see which pages and tracks are used, we count page views and plays ourselves, without any third-party service, without cookies and without entries in your browser's local storage. A small script from our own server reports the requested address when the page changes.
- Visitor identifier: From IP address, user agent and domain we compute a check value (HMAC) with a secret daily key. The key is generated anew every day (Vienna time) and the old one is deleted. The identifier distinguishes visitors within one day; linking identifiers across days is not intended for this analysis. We treat the identifiers as pseudonymous personal data. We do not store the IP address itself.
- Stored data: hour of the visit, requested page without parameters (user identifiers and access codes removed, release and artist pages remain recognisable), domain of the referring page, country (determined locally from the IP address, only the country), device type, browser family, language and whether someone is signed in, but not who.
- Music: per play the track, source (for example release page, radio or playlist), preview or full length, seconds listened, whether it was played to the end and the position where it was stopped (rounded to 5 seconds), without account or visitor identifier. Artists see these figures for their own releases only in aggregated form.
- Retention: We delete the individual events after 30 days. After that only daily totals without visitor identifiers remain.
- Recipients: The analysis takes place in our hosting infrastructure. Our hosting processors may have access as part of their tasks. Artists only receive aggregated usage figures for their own releases.
- Do Not Track and Global Privacy Control: If your browser sends one of these signals, we do not count you. We do not count automated access (bots) either.
The server-side processing of pseudonymous usage data serves to improve the service and to create aggregated usage figures for artists, based on our legitimate interests (Art. 6(1)(f) GDPR). You can object to the processing on grounds relating to your particular situation. Regardless of this, we treat Do Not Track and Global Privacy Control as an opt-out from audience measurement. Where access to information on your device requires consent, this access only takes place after your consent; you can withdraw it at any time with effect for the future. You can reach us about this at support@bitsound.com.
Account and sign-in
For an account we need your email address. Optional are a display name, your country and your settings. Bitsound has no passwords: you sign in with a code we send you by email, or with a passkey.
- Sign-in codes are only valid for a short time and are deleted one day after they expire.
- Passkeys: We only store the public key and a device name. Fingerprint or face recognition stay on your device, we get nothing from them.
- Authenticator app: We store the secret key encrypted. Recovery codes are stored only as a check value.
- Sessions: While you are signed in, we store a session with the user agent, for at most 30 days. In the settings you can see all sessions and end them.
Signed-in devices and sign-in notification
So that we can warn you when someone signs in to your account from an unknown device, we recognise devices on which you have already been signed in. For this we set the cookie bs_device with a random identifier when you sign in. We only store a check value (hash) of it, together with platform and browser from the user agent (for example "Chrome on Windows"), when the device was first and last active and a check value of your IP address. We do not store the IP address itself. For this device recognition we use the random cookie identifier.
If someone signs in from a new device, we send you an email with device, time, sign-in method and approximate location. We determine the location (city and country) only at the moment of the email from the IP address, with a database on our own server. The IP address is not passed on and the location is not stored. IP geolocation by DB-IP.com (licence CC BY 4.0).
With the link "This wasn't me" in the email you sign the device out. The link is valid for seven days and only once. In the settings you can see all signed-in devices and sign them out individually or everywhere. Fans can turn the email off, accounts with payouts and admins always receive it.
We automatically delete devices that have not been active for a year, and immediately when you delete your account. Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and legitimate interest in protecting your account and your credit (Art. 6(1)(f) GDPR).
Credit, purchases and payment
For a top-up and for purchases we process the amount, time, purchased tracks and releases, VAT, your country and the receipts. For VAT purposes we determine your country at the top-up from the country of your payment method (card country), your billing country and the country of your IP address and keep this information as evidence. Of the IP address we only store the country for this.
If you withdraw from a top-up or a storage plan, we process the refund via Stripe. We keep the confirmation email and the cancellation receipt for seven years like other receipts.
For payments we use Stripe Payments Europe, Limited, Ireland. You enter payment data directly at Stripe. We receive the information needed for payment, accounting and fraud prevention, in particular payment reference, status and country of the payment method. Where Stripe processes payment data on our instructions, it acts as a processor; for its own legal obligations and its own defined purposes Stripe acts as an independent controller. Stripe may also process data outside the EEA. Depending on the transfer, adequacy decisions, including the EU-US Data Privacy Framework for certified recipients, or standard contractual clauses are used. Information about recipients and safeguards is available in the Stripe Privacy Center and from support@bitsound.com.
We generally keep receipts, invoices, credit notes and bookings for seven years from the end of the calendar year (§ 132 BAO). Where the special record-keeping obligations of the EU One-Stop-Shop scheme (OSS) apply, the period for those records is ten years from the end of the year of the transaction. In pending proceedings we keep the necessary records until they are concluded.
Gift cards, gifts and download codes
If you give music as a gift, we process the same information as for a purchase. In addition we process the name of the recipient and your message, if you enter them, the type of delivery and, for delivery by email, the email address of the recipient and the delivery date. The legal basis is the performance of the contract with you (Art. 6(1)(b) GDPR).
We use the email address of the recipient only to deliver the gift email with the code and the redeem link, not for advertising and not for other purposes. We delete it once the gift is redeemed. The legal basis is our legitimate interest and that of the recipient in the delivery of the gift (Art. 6(1)(f) GDPR). We tell the recipient in the gift email where we got the address from.
When a code is redeemed we store which account redeemed it and when, so that every code works only once. Whoever gave music as a gift only sees whether and when the gift was redeemed. For vouchers from Bitsound our admins see which account redeemed the code and how much of it was spent, so we can account for the promotion and detect abuse. Artists only see the status and the date of redemption of their download codes, not who redeemed them. To prevent guessing of codes we limit the attempts per account and per IP address (see "Visiting the website, logs and abuse protection").
Press links from artists work without an account. For them we only count the downloads and store the time of the last download, no personal data. We keep gifts, vouchers and the related receipts for seven years like other receipts.
Listening, listening history and Bitsound Radio
As a guest, the list of your listening history is kept in your browser's local storage. Independently of this, usage events are transmitted for the statistics described in the section "Audience measurement".
When you are signed in, we store which track you listened to, when, for how long and from where (for example release page or radio), and whether you played it to the end, skipped or liked it. We use this for your listening history and for recommendations in Bitsound Radio. Together with your likes, purchases and the artists you follow, these are the radio signals.
- We automatically delete listening events after 90 days.
- In the settings you can turn off listening history and radio personalisation separately. If both are off, we do not store listening events for these two purposes. Counting to limit free plays and the separately described audience measurement are not affected.
- In the settings you can see an overview of your radio signals and delete listening history and signals at any time.
- For tracks you play in full length without buying, we count the plays per track to apply fair limits for free listening.
Recommendations are created automatically but have no legal or similarly significant effect on you (no automated decision under Art. 22 GDPR).
Public information
Comments, public playlists and your profile are visible to others. Whether comments show your name, whether your profile is public and whether you appear as a supporter of artists is up to you in the settings.
Artists' fan lists
Artists can add you to their fan list, but only with your express consent, for example with a separate checkbox when you collect a free song. We then store your email address, your display name, the time, version and wording of the consent and the occasion.
The artist gets access to the fan list and can export it. Where sending through Bitsound is enabled, the artist can send messages through it within the scope of your consent. The artist is the controller under data protection law for their own use of an exported list. The email service providers described here are used for sending.
You can withdraw your consent at any time: with the unsubscribe link in every email or on the artist's page. After withdrawal we send no further fan emails from this artist through Bitsound. We inform the artist about your withdrawal so that they also apply it to lists they have already exported; for their own sending the artist must respect the withdrawal. You can contact the artist or support@bitsound.com about this. We keep the proof of consent while it is used and then generally for three years after withdrawal or the last message based on it. Proof needed for specific pending proceedings is kept separately until they are concluded. After a withdrawal we no longer use this proof for marketing emails. If you delete your account, we keep the proof separately and anonymised, without your email address in plain text (only a check value of the address, artist, times, version and wording of the consent), and delete it after three years.
Sending emails
We send emails (sign-in codes, receipts, notifications, fan emails) through Brevo (Sendinblue SAS, 55 rue d'Amsterdam, 75008 Paris, France) as processor. We log recipient, type and time of every email and delete this log after 90 days. You choose which notifications you receive in the settings.
Contact form and enquiries by email
If you write to us via the contact form or by email, we process your email address, your name (if given), the chosen topic and your message to answer your enquiry. The message goes to our support mailbox, you do not get a copy. To protect against abuse we count messages per IP address and per email address (see above). Legal basis: performance of the contract or pre-contractual measures (Art. 6(1)(b) GDPR) and our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR). We delete the enquiry once it has been dealt with and no retention obligation applies.
Text messages and mobile number
Artists confirm their mobile number with a code by text message. We also confirm changes to payout details by text message. For this we use seven communications GmbH & Co. KG, Willestr. 4-6, 24103 Kiel, Germany, as processor. The mobile number and the text of the message are transmitted.
Artists: verification and payout
Anyone who sells music must verify themselves. For this we process legal name, address, country, mobile number, IBAN, VAT ID or the statement that you are a small business, and the time at which you accepted the artist agreement before your first upload. If you are a member of a collecting society, we also store the society and your membership or IPI number. We only use them to clarify the licence needed for your works; only admins can see them.
- ID: We store the photo of your ID encrypted (AES-256), only an admin can view it for the review. It is never included in a backup. We delete it as soon as a decision on your verification has been made. If it has not been reviewed by then, we delete it after 30 days at the latest; you then get an email and upload it again.
- VAT ID: We can check it via the EU Commission's VAT Information Exchange System (VIES).
- Tax: For the credit notes and any withholding tax to be deducted (§ 99 EStG) we process your tax status, your country of residence, your tax number or VAT ID and, where applicable, a certificate of residence. We store the certificate encrypted.
- Payouts and credit notes are kept for seven years (§ 132 BAO).
- Public are the artist name, image, text, location and links of your artist profile, and your releases. Uploaded images are re-encoded, metadata such as the location where the photo was taken is removed.
Legal basis: contract (Art. 6(1)(b) GDPR), legal obligations under tax and company law (lit. c) and protection against fraud (lit. f).
Interest list and invitations for artists
While new artist sign-ups are paused, you can put yourself on an interest list. Purpose: we send you an information email as soon as sign-ups open again. For this we process your artist or band name and your email address and, optionally, your country, your genre, a link to your music, a message and whether you are a member of a collecting society.
After you confirm, the page "For artists" shows a public list of everyone signed up with country, genre and the approximate date of confirmation (for example "3 days ago"), plus the total number. Your artist or band name is shown there only if you choose this explicitly with a separate checkbox, otherwise you appear anonymously (for example "An artist from Austria"). Your email address, the link and your message are never published. Unconfirmed entries do not appear. When you withdraw your consent or your entry is deleted, you also disappear from the list.
The legal basis is your consent (Art. 6(1)(a) GDPR). You confirm it via a link in an email (double opt-in) and can withdraw it at any time with effect for the future, for example by email to support@bitsound.com. We delete unconfirmed entries after seven days, confirmed ones after the invitation or earlier at your request.
If we invite you, we store your email address together with the invitation link. The link is valid for 14 days.
Checking uploaded music
So that nobody sells other people's recordings as their own, we compute an acoustic fingerprint (Chromaprint) for every uploaded track on our server and compare it with the other tracks on Bitsound. The fingerprint is used to compare recordings. Through its link to a track or artist it can also relate to a person.
In addition, we have every track checked by the music recognition service AudD (audd.io), based in the USA. AudD is a recipient of the data for this purpose. We cut two to three short excerpts of about 12 seconds each from the track and send only these excerpts to AudD. We do not transmit personal or account data such as name, email address or IP address. The recording itself may, however, contain voices. AudD reports back whether the recording is already known under another artist (artist, title, label). The purpose is checking rights. Legal basis: our legitimate interest in preventing infringements (Art. 6(1)(f) GDPR).
Because AudD is based in the USA, the excerpts are transferred to a third country outside the European Economic Area. The transfer is based on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). You can get a copy of the safeguards from support@bitsound.com.
Reports and moderation
When you report content, we store the report, reason, time and your account, or, for a report without an account, the email address you give and, if given, your name. We use this to handle the report, confirm its receipt and inform you of the outcome (Art. 16 DSA). Anyone affected by a decision receives the statement of reasons by email (Art. 17 DSA). If you delete your account, the link to the report is removed.
Retention at a glance
- Account and settings: until you delete your account.
- Listening events: 90 days.
- Audience measurement: individual events 30 days, then only daily totals. Daily key: one day.
- Sign-in codes: one day after expiry. Sessions: until sign-out, at most 30 days.
- Signed-in devices: up to one year after the last activity. "This wasn't me" links: 30 days after expiry.
- Counters for abuse protection: one hour after expiry.
- Email log: 90 days.
- ID image: until the decision on the verification, at most 30 days if not reviewed. Not in backups.
- Interest list: unconfirmed entries seven days, confirmed ones until the invitation or until you withdraw your consent. Invitation links: valid for 14 days.
- Error and job logs of the application: at most 30 days.
- Proof of consent for fan lists: generally three years after withdrawal or the last message based on it; after account deletion three years in anonymised form.
- Receipts, invoices, credit notes and bookings: generally seven years from the end of the calendar year; records for the EU One-Stop-Shop scheme (OSS), where it is used, ten years. Extended for pending proceedings only as far as necessary.
- Local database backups: 14 days; additional database and file backups including file versions: at most 30 days.
- Gift cards and gifts: seven years like receipts; the email address of the recipient until the gift is redeemed.
Deleting your account
You can delete your account yourself in the settings. We then delete passkeys, likes, playlists, wishlist, listening history, active fan list entries, verification data and the email log. Your email address and name are removed from the account. Comments that someone has already replied to remain as "removed" without content. We keep purchases and receipts because of the retention obligation.
The delete function in the settings is available once there is no credit and no artist project left. If you have remaining credit or artist projects, write to support@bitsound.com; we handle closing the account and the refund or final settlement together. You do not have to spend your credit on further purchases. You can exercise your statutory data protection rights independently of this technical function.
Records required by law and necessary proof of consent and withdrawal are kept separately, only for their respective purposes of proof and periods. Proof of consent for fan lists is kept only in anonymised form, without your email address in plain text, for three years. A deleted account is not continued for further use or marketing as a result.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). You can withdraw consent at any time (Art. 7(3)). In the settings you can download your data as a file at any time. For everything else write to support@bitsound.com.
You can lodge a complaint with the data protection authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria, dsb@dsb.gv.at, www.dsb.gv.at.
For account, purchases and payouts we need the information marked as required; without it we cannot provide the respective function. Voluntary profile information and fan consents are not a condition for buying music. We also receive information about payments from our payment service provider, and, where applicable, results of external rights checks from the service named in the section "Checking uploaded music".
Security
All connections are encrypted (TLS). Backups are encrypted. Admins must sign in with a second factor. Only people who need personal data for their task have access to it.
Changes
When the service changes, we update this privacy policy. The version published here applies. We inform signed-in users of material changes by email.