Eveara Music - Distribution Platform

Distribute your music to all major streaming platforms worldwide

Last Updated: January 2025

GDPR Compliance Statement

Eveara Music Limited (Company Number 16626941) is committed to protecting and respecting your privacy in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This document outlines how we comply with GDPR requirements and your rights under this regulation.

1. Data Controller Information

Data Controller: Eveara Music Limited
Company Number: 16626941
Contact Email: privacy@evearamusic.com
Data Protection Officer: dpo@evearamusic.com

2. Legal Basis for Processing

We process your personal data under the following legal bases as defined in Article 6 of the GDPR:

  • Consent (Article 6(1)(a)): You have given clear consent for us to process your personal data for specific purposes, such as marketing communications.
  • Contract (Article 6(1)(b)): Processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract (e.g., providing music distribution services).
  • Legal Obligation (Article 6(1)(c)): Processing is necessary to comply with legal obligations, such as tax reporting and anti-money laundering requirements.
  • Legitimate Interests (Article 6(1)(f)): Processing is necessary for our legitimate interests or those of a third party, except where such interests are overridden by your rights and freedoms (e.g., fraud prevention, network security).

3. Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR:

3.1 Right to Access (Article 15)

You have the right to obtain confirmation as to whether or not your personal data is being processed and, if so, to access that personal data and information about how it is being used.

3.2 Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and to have incomplete personal data completed.

3.3 Right to Erasure (Article 17)

Also known as the "right to be forgotten," you have the right to request deletion of your personal data in certain circumstances, including:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • The data must be erased to comply with a legal obligation

3.4 Right to Restriction of Processing (Article 18)

You have the right to restrict processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

3.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

3.6 Right to Object (Article 21)

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

3.7 Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.

4. How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

  • Email: privacy@evearamusic.com or dpo@evearamusic.com
  • Subject Line: "GDPR Rights Request"
  • Required Information: Please include your full name, email address, and specific right you wish to exercise

We will respond to your request within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.

5. Data We Collect

We collect and process the following categories of personal data:

  • Identity Data: Name, username, artist name
  • Contact Data: Email address, phone number, postal address
  • Financial Data: Payment information, bank account details, tax identification numbers
  • Technical Data: IP address, browser type, device information, cookies
  • Usage Data: Information about how you use our platform and services
  • Content Data: Music files, metadata, artwork, biographical information
  • Marketing Data: Your preferences for receiving marketing communications

6. How We Use Your Data

We use your personal data for the following purposes:

  • To provide and maintain our music distribution services
  • To process your music releases and distribute them to streaming platforms
  • To facilitate royalty payments and financial transactions
  • To communicate with you about your account and services
  • To comply with legal and regulatory obligations
  • To detect and prevent fraud and ensure platform security
  • To improve our platform and develop new features
  • To send you marketing communications (with your consent)

7. Data Sharing and Third Parties

We share your personal data with the following categories of recipients:

  • Digital Service Providers (DSPs): Spotify, Apple Music, Amazon Music, and other streaming platforms for music distribution
  • Payment Processors: PayPal, HSBC Bank for financial transactions
  • Technology Providers: ACRCloud (copyright detection), AWS Amazon (cloud infrastructure), Fastly and Cloudflare (content delivery)
  • Music Industry Organizations: PPL for licensing and royalty collection, DDEX for industry standards compliance
  • Legal and Regulatory Authorities: When required by law or to protect our rights

We ensure that all third parties respect the security of your personal data and treat it in accordance with the law through appropriate data processing agreements.

8. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer your data outside the EEA, we ensure adequate protection through:

  • European Commission approved Standard Contractual Clauses
  • Transfers to countries with adequacy decisions
  • Other appropriate safeguards as required by GDPR

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account Data: For the duration of your account plus 7 years to comply with financial and tax obligations
  • Music Content: For the duration of distribution agreements plus any legal hold periods
  • Financial Records: 7 years as required by UK tax law
  • Marketing Data: Until you withdraw consent or for a maximum of 2 years of inactivity
  • Technical Logs: 90 days for security and operational purposes

10. Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest
  • Regular security assessments and penetration testing
  • Access controls and multi-factor authentication
  • Employee training on data protection and security
  • Incident response and breach notification procedures
  • Regular backups and disaster recovery planning

11. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where required by law)
  • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms
  • Document all data breaches, including facts, effects, and remedial actions taken

12. Children's Privacy

Our services are not intended for children under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information as quickly as possible.

13. Automated Decision-Making and Profiling

We use automated decision-making and profiling for the following purposes:

  • Copyright Detection: Automated scanning via ACRCloud to detect potential copyright infringement
  • Fraud Prevention: Automated analysis to detect suspicious account activity
  • Content Recommendations: Algorithmic suggestions based on your music preferences and listening history

You have the right to object to automated decision-making and request human intervention in these processes.

14. Cookies and Tracking

We use cookies and similar tracking technologies in accordance with GDPR requirements. You can manage your cookie preferences through your browser settings. For more information, please see our Cookie Policy.

15. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR requirements. In the UK, the relevant authority is:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire SK9 5AF
Tel: 0303 123 1113
Website: www.ico.org.uk

16. Updates to This Statement

We may update this GDPR Compliance Statement from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated statement on our website and updating the "Last Updated" date.

17. Contact Us

If you have any questions about our GDPR compliance or wish to exercise your rights, please contact:

Eveara Music Limited
Company Number: 16626941
Email: privacy@evearamusic.com
Data Protection Officer: dpo@evearamusic.com
Website: www.evearamusic.com

18. Data Protection Principles

We adhere to the GDPR data protection principles as outlined in Article 5:

  • Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and in a transparent manner
  • Purpose Limitation: We collect data for specified, explicit, and legitimate purposes
  • Data Minimization: We collect only data that is adequate, relevant, and limited to what is necessary
  • Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date
  • Storage Limitation: We retain data only for as long as necessary for the purposes for which it was collected
  • Integrity and Confidentiality: We process data in a manner that ensures appropriate security
  • Accountability: We take responsibility for compliance and can demonstrate our compliance with GDPR
WHY NOT Support Us
OR ENTER CUSTOM AMOUNT
Type any amount and the PayPal button will update automatically
Accept payments around the world
With love from Eveara Music