Privacy Policy
1. Controller
Controller within the meaning of the General Data Protection Regulation (GDPR):
Diztree
Owner: Benjamin Klügel
Achtern Diek 7
25436 Uetersen
Germany
Email: [email address]
Phone: [phone number]
A data protection officer has not been appointed by law (no obligation to appoint one). If you have any questions regarding data protection, please contact us using the contact details listed above.
2. General Information & Legal Bases
This statement provides information on the nature, scope and purpose of the processing of personal data when using the Diztree platform.
The legal bases for processing are in particular:
- Art. 6(1)(a) GDPR – consent;
- Art. 6(1)(b) GDPR – performance of a contract and pre-contractual measures;
- Art. 6(1)(c) GDPR – legal obligation (e.g. retention under commercial and tax law);
- Art. 6(1)(f) GDPR – legitimate interest (e.g. security, fraud prevention, functionality).
3. Your Rights
You have the right at any time to:
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on legitimate interests (Art. 21 GDPR).
You may withdraw any consent you have given at any time with effect for the future (Art. 7(3) GDPR). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), e.g. the authority responsible for our place of business.
4. Hosting & Server Log Files
The platform is hosted by a service provider in Germany: [hosting provider + address]. A data processing agreement (Art. 28 GDPR) is in place with the provider. The legal basis is Art. 6(1)(f) GDPR (secure, efficient operation).
When the platform is accessed, access data is automatically recorded in server log files: IP address, date/time, requested resource, referrer, browser type/version, operating system. This data serves the technical delivery, stability and security (defense against attacks) and is deleted or anonymized after a short period. Legal basis: Art. 6(1)(f) GDPR.
5. Cookies & Consent
We use cookies and comparable technologies. Via a consent banner, you can choose between the categories necessary, functional, analytics and marketing. Your selection is stored in the cookie_consent cookie and can be changed at any time via the cookie settings.
- Necessary cookies are required for operation (e.g. session/login cookie, language setting
i18n_redirected); legal basis: § 25(2) TDDDG in conjunction with Art. 6(1)(f) GDPR. - Functional, analytics and marketing cookies are only set with your consent; legal basis: § 25(1) TDDDG in conjunction with Art. 6(1)(a) GDPR. You may withdraw your consent at any time via the cookie settings.
6. Registration & User Account
To use the platform, you create an account. The data processed includes, among others, your email address, password (stored exclusively as a cryptographic hash), name/display name, and optionally profile information (e.g. avatar). For billing and payouts, additional billing/business data may be collected (name or company name, address, where applicable tax details). Legal basis: Art. 6(1)(b) GDPR (contract); for statutory retention, Art. 6(1)(c) GDPR.
7. Sign-In & Account Linking via Third-Party Providers (OAuth)
You can connect third-party accounts or sign in through them. In doing so – depending on the service and your authorization – profile/account data is transmitted to us (e.g. name, email, profile picture, account IDs, access tokens). Services used:
- Spotify (provider: Spotify AB) – including email, follower/playlist features;
- SoundCloud;
- Meta/Facebook & Instagram (Meta Platforms Ireland Ltd.) – login as well as management of pages/advertising/publishing features;
- TikTok – advertising account/publishing features;
- Dropbox – file import from your own Dropbox account.
The legal basis is your consent or the performance of a contract (Art. 6(1)(a) or (b) GDPR). The privacy notices of the respective provider also apply. In some cases this involves a transfer to third countries (see the section on third-country transfers).
8. Payments & Payouts
Payments (Stripe): Payments and the purchase of balance ("Credits") are processed via Stripe (Stripe Payments Europe Ltd., Ireland; where applicable Stripe, Inc., USA). In doing so, payment-related data (e.g. name, email, billing address, payment method/transaction data) is processed by Stripe. Full card data is processed by Stripe and not stored by us. Legal basis: Art. 6(1)(b) GDPR.
Payouts (Stripe Connect / Wise): For payouts to creators (e.g. royalties/sales proceeds) we use Stripe Connect and/or Wise (Wise Europe SA, among others). For this purpose, recipient and bank/payment data that you provide is processed. Legal basis: Art. 6(1)(b) GDPR; retention under tax and commercial law pursuant to Art. 6(1)(c) GDPR.
9. Music Distribution & Smart Links
Distribution (FUGA): To deliver your releases to streaming/download services (DSPs such as Spotify, Apple Music, Deezer, among others), we use the distributor FUGA. In particular, release/track metadata, artist/contributor details and associated identifiers are transmitted, which – insofar as they constitute personal data – are passed on to FUGA and the respective DSPs worldwide. Legal basis: Art. 6(1)(b) GDPR.
Smart/Pre-Save Links (Found.ee): For landing/smart links to DSPs we use Found.ee. When such links are accessed, usage/click data may be processed by the provider. Legal basis: Art. 6(1)(b) or (f) GDPR.
10. AI Features
The platform offers optional AI features. When using them, the content you enter (prompts/parameters) as well as, where applicable, associated analysis/metadata is transmitted to the respective service:
- AI Marketing (Anthropic, "Claude"): Anthropic PBC, USA – processing of inputs to create marketing/campaign texts.
- AI Music Generation (Suno / sunoapi.org): processing of your inputs to generate audio.
- AI Image/Video (Vast.ai + ComfyUI): processing on rented GPU instances (Vast.ai, USA).
Legal basis: Art. 6(1)(b) GDPR (provision of the booked feature) or your consent. Do not enter sensitive personal data of third parties into AI features. For US services, a third-country transfer takes place (see below).
11. Communication: Email & Chat
Email: For sending system/transactional and, where applicable, other emails, as well as for mailbox functions, we operate our own mail server (Mailcow). The sender/recipient address, subject, content and metadata are processed. Legal basis: Art. 6(1)(b) or (f) GDPR.
Chat & Calls: The platform offers chat and real-time audio/video features (via self-operated components, including mediasoup and a TURN server). Message content, connection/presence data and technical connection data are processed. Legal basis: Art. 6(1)(b) or (f) GDPR.
12. File Storage, File Import & Translation
Object storage: Uploaded files (e.g. audio, artwork, documents, media) are stored in an object storage: [object storage provider]. Legal basis: Art. 6(1)(b) GDPR.
Dropbox import: At your request, you can import files from your own Dropbox account (OAuth, see Section 7).
Translation: For translations we use a self-hosted instance (LibreTranslate); no transfer to third parties takes place in this context.
13. Marketing & Audience Measurement
If you use paid advertising/marketing features, campaign data is transmitted to the respective advertising platforms: Meta Ads (Meta Platforms Ireland Ltd.) and TikTok Ads.
TikTok Pixel: The TikTok Pixel may be used on the pages for audience/conversion measurement. It is loaded only after your consent in the "Marketing" category. In doing so, usage/device/event data is transmitted to TikTok. Legal basis: Art. 6(1)(a) GDPR; withdrawal at any time via the cookie settings.
Merch fulfillment: When ordering physical products, the data required for production/shipping (name, delivery address) is transmitted to our service provider Shirtigo GmbH (Cologne). Legal basis: Art. 6(1)(b) GDPR.
14. Transfer to Third Countries
Some of the services mentioned process data outside the EU/EEA, in particular in the USA (including Stripe, Anthropic, Suno, Vast.ai, Meta, TikTok, Dropbox, Spotify). Insofar as no adequacy decision by the EU Commission applies (e.g. the EU-US Data Privacy Framework for providers certified accordingly), we base the transfer on appropriate safeguards pursuant to Art. 46 GDPR, in particular the EU Standard Contractual Clauses. Residual risks remain, as third countries do not guarantee a level of data protection comparable to that of the EU.
15. Storage Period
We store personal data only for as long as it is necessary for the respective purposes or as long as statutory retention obligations exist (in particular under commercial and tax law, generally 6 or 10 years). Thereafter, the data is deleted or blocked.
16. Data Security
We take appropriate technical and organizational measures (including TLS encryption of transmission, encryption of sensitive data at rest, access restrictions) to protect your data.
17. Changes to This Privacy Policy
We will amend this privacy policy if the legal situation or our processing changes. The version published here at any given time applies.
—