Privacy Policy — TEAMWAVE Artist Upload Platform
DRAFT — not reviewed by a lawyer
1. Controller
[TEAMWAVE FM — operator details see imprint]
For data protection questions: info@teamwavefm.de
2. Your Rights
You have the following rights:
- Access: What data do we store about you?
- Rectification: Correct inaccurate data
- Erasure: Delete data (except legally required retention)
- Restriction: Limit data processing
- Portability: Receive data in standard format
- Objection: Object to processing (where applicable)
Submit requests to: info@teamwavefm.de
3. Data We Collect
3.1 Login Data
- Email address (required for magic-link login)
- Nostr public key (optional, if using NIP-07/NIP-46 login)
- Login timestamp and last login
- Session cookies (`tw_sess`, `tw_lang`)
3.2 Artist Profile
- Artist name (display name)
- Legal name (required for tax and rights declaration)
- Country / Tax residency (ISO-3166-1 alpha-2)
- Bio (free text)
- External links (website, Instagram, Nostr npub, Bandcamp, etc.)
- GEMA membership (yes/no)
- GVL membership (yes/no)
- Other CMO memberships (free text)
- Profile image / avatar (JPG, max. 1400×1400px, metadata removed)
- Nostr profile data (optional, read from NIP-07 profile: name, bio, picture, LUD-16, NIP-05)
3.3 Uploaded Content
- Audio files (WAV, FLAC, AIFF, MP3; original stored + processed radio version)
- Metadata: title, track number, genre, tags, explicit flag, ISRC, BPM, story, lyrics
- Cover images (JPG/PNG, normalized to max. 1400×1400px)
- SHA-256 hash of original file (for integrity verification)
3.4 Contributors and Rights
- Contributors with legal names (Composer, Lyricist, Performer, Producer, Other)
- CMO status per contributor (GEMA, GVL, both, other, none)
- Rights declaration (version, text SHA-256, acceptance timestamp, IP address, User-Agent)
3.5 Payout Destinations
- Type: Lightning address (LUD-16), PayPal email, IBAN
- Value: Encrypted (AES-256-GCM) in database
- Masked display: e.g., `ni…ll@fountain.fm`, `DE12 ** ** 3456`
- Verification status and method (1-sat test, checksum validation, confirmation link)
- Verification errors (if any)
3.6 Split and Payout
- Split versions (version date, recipients with destination ID, shares in ppm)
- Payout history (payout runs, amounts, status, external transaction IDs)
3.7 Server Logs and Technical Data
- IP address (with every request, automatically)
- User-Agent (browser, operating system)
- Request path, HTTP status, response size
- Timestamp
- Retention: 14 days, then deleted automatically
3.8 Audit Log
- All changes to track status, payout destinations, split versions
- Who, when, what, before/after (visible to admin/curators only)
- Retention: for the life of the account, then 3 years (limitation period); immutable (append-only)
3.9 Consent and Permissions
- Nostr posts reading: Optional; consent recorded separately, revocable anytime
- Newsletter / notifications: Optional; consent recorded separately
4. Purpose and Legal Basis
Purpose
- Account management and authentication (magic-link, sessions)
- Artist profile management
- Upload and storage of musical content
- Curation (team decisions)
- Payout (manage payout destinations, statistics)
- Rights declaration compliance (proof, audit trail)
- Technical hosting (server logs, monitoring, security)
- Legal requirements (taxes, accounting, data protection)
Legal Basis (Art. 6 GDPR)
| Data | Basis | |---|---| | Login, profile, content | Art. 6 (1)(b) GDPR — Contract performance (upload service) | | Payout destinations | Art. 6 (1)(b) GDPR — Contract performance (payouts) | | Rights declaration, IP/UA | Art. 6 (1)(b) GDPR — Contract performance + evidence | | Tax / accounting | Art. 6 (1)(c) GDPR — Legal obligation (tax law) | | Security, logs | Art. 6 (1)(f) GDPR — Legitimate interest (operational security) | | Nostr posts reading | Art. 6 (1)(a) GDPR — Explicit consent (opt-in) |
5. Data Sharing
We do not share your data with third parties, except:
- Curators and radio engine (internal): title, artist, streams, split (masked)
- Hostinger (hoster): Complete platform data per DPA (data processor, EU server)
- Payment partner (once set up): IBAN/PayPal for payouts via a licensed payment service provider
No sharing with:
- Social media platforms
- Advertising partners
- Analytics firms (Google Analytics, etc.)
6. Retention
| Data | Retention | Reason | |---|---|---| | Login, profile | While account active | Contract performance | | Uploaded content | While account active; deletion on request | Contract performance | | Payout destinations | While account active; deleted 12 months after last use | Compliance | | Audit log | account lifetime + 3 years | Proof of changes (Art. 6(1)(f) GDPR) | | Rights declaration | account lifetime + 3 years after last broadcast | Proof of the grant of rights | | Server logs | 14 days | Security, troubleshooting | | Session cookies | 30 days inactivity | Security |
Deleted data is permanently destroyed within 30 days, except where legally required retention applies.
7. Cookies and Local Storage
Cookies (Server)
- `tw_sess`: Session cookie, HttpOnly, Secure, SameSite=Lax, 30 days
- `tw_lang`: Language preference, 1 year
Browser Storage (localStorage/sessionStorage)
- `uploadId`: for upload progress (stored locally on your device only)
- `nostr_nwc`: Nostr Wallet Connect string (stored locally, never sent to server)
- No tracking, no sharing with third parties
8. Data Security
Measures per Art. 32 GDPR (state of the art):
- Encryption at rest: Payout destinations with AES-256-GCM
- Encryption in transit: TLS 1.2+ (HTTPS)
- Access control: User authentication via magic-link/Nostr
- Audit logging: All changes recorded
- Backup: Daily encrypted backup via restic to via-cloud
- Restore test: Monthly
There is no industry-mandated standard (like PCI DSS for payments) we must certify, as long as we don't store card data (TEAMWAVE doesn't self-pay; listeners pay directly).
9. Data Subject Rights (Art. 15–22 GDPR)
Access
Write to: info@teamwavefm.de with subject „Data Protection Request" Response within 30 days.
Rectification / Erasure / Restriction
Via account dashboard or email (as above).
Objection
You may object to processing (except where legally required). Email: info@teamwavefm.de
Complaint
Contact your local data protection authority (e.g., your regional data protection supervisory authority).
10. Data Protection Officer
[Enter name and contact if appointed. Currently: no appointment required.]
11. Record of Processing Activities
Available on request: info@teamwavefm.de
*Version v1 — valid as of 04.10.2026*
