Privacy Policy — TEAMWAVE Artist Upload Platform

DRAFT — not reviewed by a lawyer

1. Controller

[TEAMWAVE FM — operator details see imprint]

For data protection questions: info@teamwavefm.de

2. Your Rights

You have the following rights:

Submit requests to: info@teamwavefm.de

3. Data We Collect

3.1 Login Data

3.2 Artist Profile

3.3 Uploaded Content

3.4 Contributors and Rights

3.5 Payout Destinations

3.6 Split and Payout

3.7 Server Logs and Technical Data

3.8 Audit Log

3.9 Consent and Permissions

4. Purpose and Legal Basis

Purpose

Legal Basis (Art. 6 GDPR)

| Data | Basis | |---|---| | Login, profile, content | Art. 6 (1)(b) GDPR — Contract performance (upload service) | | Payout destinations | Art. 6 (1)(b) GDPR — Contract performance (payouts) | | Rights declaration, IP/UA | Art. 6 (1)(b) GDPR — Contract performance + evidence | | Tax / accounting | Art. 6 (1)(c) GDPR — Legal obligation (tax law) | | Security, logs | Art. 6 (1)(f) GDPR — Legitimate interest (operational security) | | Nostr posts reading | Art. 6 (1)(a) GDPR — Explicit consent (opt-in) |

5. Data Sharing

We do not share your data with third parties, except:

No sharing with:

6. Retention

| Data | Retention | Reason | |---|---|---| | Login, profile | While account active | Contract performance | | Uploaded content | While account active; deletion on request | Contract performance | | Payout destinations | While account active; deleted 12 months after last use | Compliance | | Audit log | account lifetime + 3 years | Proof of changes (Art. 6(1)(f) GDPR) | | Rights declaration | account lifetime + 3 years after last broadcast | Proof of the grant of rights | | Server logs | 14 days | Security, troubleshooting | | Session cookies | 30 days inactivity | Security |

Deleted data is permanently destroyed within 30 days, except where legally required retention applies.

7. Cookies and Local Storage

Cookies (Server)

Browser Storage (localStorage/sessionStorage)

8. Data Security

Measures per Art. 32 GDPR (state of the art):

There is no industry-mandated standard (like PCI DSS for payments) we must certify, as long as we don't store card data (TEAMWAVE doesn't self-pay; listeners pay directly).

9. Data Subject Rights (Art. 15–22 GDPR)

Access

Write to: info@teamwavefm.de with subject „Data Protection Request" Response within 30 days.

Rectification / Erasure / Restriction

Via account dashboard or email (as above).

Objection

You may object to processing (except where legally required). Email: info@teamwavefm.de

Complaint

Contact your local data protection authority (e.g., your regional data protection supervisory authority).

10. Data Protection Officer

[Enter name and contact if appointed. Currently: no appointment required.]

11. Record of Processing Activities

Available on request: info@teamwavefm.de


*Version v1 — valid as of 04.10.2026*