1. Who is responsible
The controller of your personal data under the EU General Data Protection Regulation (“GDPR”) is the provider of CatalogArmor:
- Provider
- The operator of CatalogArmor, a Hungarian sole trader (egyéni vállalkozó). Registration in progress — published here before paid plans launch.
- Registered seat
- Registration in progress — published here before paid plans launch
- Registration
- Registration in progress — published here before paid plans launch
- [email protected]
CatalogArmor is in a free, invitation-only beta. The full legal details above will be completed as soon as registration is finished, and before any paid plan is sold.
We have not appointed a data protection officer, because the law does not require one for our activities. For any privacy question or request, email [email protected].
We plan to transfer the Service to a Hungarian company (Kft.) controlled by the same person (see Terms, section 20). If that happens, the company becomes the controller. We will update this section on the day of the transfer and tell existing users by email in advance.
2. Data about our users
This section covers people who have a CatalogArmor account, or who have been invited to one. Giving us your name, email address and a password (or signing in with Google) is necessary to create an account. Everything else is optional or depends on the features you use.
Your account
- What
- Name, email address, password (stored only as a salted hash), profile picture, and, if you sign in with Google, your Google account ID.
- Why
- Create and run your account, let you sign in, and send you essential service emails such as password resets and account notices.
- Legal basis
- Performance of our contract with you (GDPR Art. 6(1)(b))
- How long
- While your account exists. See section 8 for what happens after you delete it.
Sign-in security
- What
- IP address and browser user agent of active sessions; IP address at registration and at your last sign-in; the result of the bot check at sign-up and sign-in; two-factor secrets and backup codes (encrypted).
- Why
- Keep your account secure, detect account takeover and abuse, and run two-factor authentication.
- Legal basis
- Our legitimate interest in keeping the Service and accounts secure (GDPR Art. 6(1)(f)); for two-factor authentication, performance of our contract with you (GDPR Art. 6(1)(b))
- How long
- Sessions expire after 7 days. Registration and last sign-in IP addresses are kept while your account exists. Two-factor data is kept until you turn it off.
Activity log
- What
- Records of actions in your account and team, such as sign-ins (with IP address and browser), changes to alert settings, whitelist and artist changes, team changes, alert status changes, and your acceptance of these documents. Actions our staff take on your account, such as a password reset they trigger, are also logged.
- Why
- Show you and your team what happened and when, investigate security incidents, and document how takedown-related features were used.
- Legal basis
- Performance of our contract with you (GDPR Art. 6(1)(b)) and our legitimate interest in accountability and abuse prevention (GDPR Art. 6(1)(f))
- How long
- While your account (or, for entries about shared artists, your team) exists. Sign-in and security entries are deleted after 12 months.
Monitoring data
- What
- The artist profiles you add, your whitelist (release titles, UPCs, notes, dates), alerts (threats) raised for your artists, and the status you give them (for example “whitelisted” or “takedown requested”).
- Why
- Provide monitoring, alerts, distributor detection and the takedown wizard. Takedown drafts are generated in your browser. We do not store them, and we do not know whether you send them.
- Legal basis
- Performance of our contract with you (GDPR Art. 6(1)(b))
- How long
- While your account exists, or until you remove the item.
Alert channels
- What
- The alert email address, SMS or WhatsApp phone number, Telegram chat ID, Discord webhook URL, and Slack workspace, channel and access token (encrypted) that you set up, plus the content of the alerts we send.
- Why
- Deliver alerts to the destinations you chose.
- Legal basis
- Performance of our contract with you (GDPR Art. 6(1)(b))
- How long
- Until you remove the channel or delete your account. Earlier values stay in the activity log (see above).
Teams
- What
- Team membership, roles, per-artist access, and invitations (the invitee’s email address and who sent the invitation).
- Why
- Let teams share artists and control who can see and do what.
- Legal basis
- Performance of our contract with you (GDPR Art. 6(1)(b)); for invitees who are not yet users, the legitimate interest of the team owner and us in enabling collaboration (GDPR Art. 6(1)(f))
- How long
- Membership lasts as long as the team relationship. Invitations are deleted within 30 days after they are accepted, revoked or expired.
Plan and billing
- What
- Your plan, billing period, subscription status, allowances, and the customer and subscription IDs that Paddle gives us. We never receive your full card details.
- Why
- Provide the plan you bought and keep it in sync with Paddle.
- Legal basis
- Performance of our contract with you (GDPR Art. 6(1)(b)); for records we must keep, compliance with a legal obligation (GDPR Art. 6(1)(c))
- How long
- While your account exists. Records that tax and accounting law requires us to keep are retained for the statutory period, generally up to 8 years.
Support and other communication
- What
- What you write to us and our replies, including your email address and any details you share.
- Why
- Answer your questions and handle requests, including data-protection requests.
- Legal basis
- Performance of our contract with you (GDPR Art. 6(1)(b)) or our legitimate interest in responding to enquiries (GDPR Art. 6(1)(f))
- How long
- Up to 2 years after the conversation ends, unless we need the messages longer to establish or defend legal claims.
Beta invitations and waitlist
- What
- The email addresses invited to the closed beta, and email addresses submitted to our waitlist.
- Why
- Control who can register during the beta and tell waitlist members when the Service opens.
- Legal basis
- Beta invitations: our legitimate interest in running an invitation-only beta (GDPR Art. 6(1)(f)). Waitlist: your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time
- How long
- Beta invitations are kept until the beta ends. Waitlist entries are kept until you ask us to remove them, and at the latest 12 months after the public launch.
Technical logs
- What
- Web server and application logs, which contain IP addresses, requested URLs, timestamps, browser information and error details.
- Why
- Operate the Service, fix errors, and detect and investigate attacks.
- Legal basis
- Our legitimate interest in operating a secure and reliable service (GDPR Art. 6(1)(f))
- How long
- Up to 90 days, or longer only where needed to investigate a specific incident.
We do not use your data for advertising, we do not sell it, and we do not build marketing profiles. We send service emails (for example about security, billing or changes to our terms). We will only send marketing emails if you opt in, and every such email will include an unsubscribe link.
3. Data about people who are not our users
To work, the Service also processes limited data about people who do not have an account with us. We rely on legitimate interests (GDPR Art. 6(1)(f)): our customers’ interest, and ours, in protecting music catalogs against fraudulent and unauthorised releases. We have balanced these interests against the rights of the people concerned. The data is already public and professional in nature, we use only what is needed, and no one is subject to automated decisions with legal effect.
- Artists and other people in release metadata. Artist names and platform IDs, public profile images, public social-media handles shown on artist profiles, release titles, and names that appear in label or ℗/© lines. This data comes from the public data of Spotify, Apple Music, Deezer and YouTube. We keep artist profile details while at least one customer monitors the artist, and delete or anonymise them within 12 months after that. We keep release metadata for as long as it is useful for detection, and review it at least once a year.
- Distributor contacts. Names of distributors and the business contact details and takedown channels they publish. We use them to point our customers to the right place to report an unauthorised release. We keep them until they are out of date or until the person concerned objects.
- Team invitees and alert recipients. Email addresses and phone numbers that a customer enters for a colleague. These are covered in section 2 and are only used for the invitation or the alerts.
You can object to this processing at any time by emailing [email protected]. We will stop unless we have compelling legitimate grounds, for example keeping a record needed to protect a catalog against a proven fraudulent release.
4. Where the data comes from
We get personal data:
- from you, when you sign up, configure the Service or contact us;
- from your team owner or team admins, when they invite you or give you access;
- from Google, when you sign in with Google (your name, email address, Google account ID and profile picture);
- from Paddle, about your subscription status once you buy a plan;
- from public streaming-platform data (Spotify, Apple Music, Deezer, YouTube) and from information that distributors publish themselves.
6. Who receives personal data
Service providers (processors). These providers process personal data only on our instructions and under data processing terms that meet GDPR Art. 28:
| Provider | What for | Where |
|---|---|---|
| netcup GmbH (Germany) | Server hosting for the application, database and backups | EU |
| Cloudflare, Inc. | Network, DNS and security services; Turnstile bot check; storage of uploaded profile pictures (Cloudflare R2, EU jurisdiction) | Global network; EU storage for R2 |
| Twilio Inc. (SendGrid) | Account emails such as password resets, team invitations and account notices | USA |
| Zoho Corporation B.V. (ZeptoMail) | Alert emails | EU data centre |
| Twilio Inc. | SMS alerts | USA |
| Meta Platforms Ireland Ltd. (WhatsApp Business Platform) | WhatsApp alerts | EU / USA |
Independent recipients. These parties receive data and process it under their own terms and privacy policies:
- Paddle (Paddle.com Market Ltd. and its affiliates) is our reseller and Merchant of Record. When you buy a plan, Paddle collects your billing details and payment data directly, under its own privacy notice.
- Google provides Sign in with Google under the Google Privacy Policy.
- Slack, Discord and Telegram receive the content of your alerts when you connect them as alert channels. They deliver it to the workspace, server or chat you chose.
- Streaming platforms (Spotify, Apple, Deezer and Google/YouTube) receive only public artist and release identifiers in our requests to their interfaces, never personal data about you.
- Authorities, courts and advisers. We share data with authorities and courts where the law requires it, and with our lawyers and accountants, who are bound by confidentiality, where needed.
- A successor company, if the Service is transferred as described in section 1.
When you send a takedown email that you drafted with the Service, you send it yourself, from your own mailbox or account. It does not pass through CatalogArmor.
7. Transfers outside the EEA
Some providers are based in, or access data from, countries outside the European Economic Area, in particular the United States. We rely on the EU–U.S. Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses (GDPR Art. 46). Telegram, Slack and Discord receive alert content because you asked us to deliver alerts to them (GDPR Art. 49(1)(b)). You can ask us for a copy of the relevant safeguards at [email protected].
8. Deletion and backups
How long we keep each type of data is listed in sections 2 and 3. In addition:
- Deleting your account. When you delete your account in your settings, we sign you out everywhere and schedule the deletion for 14 days later. This lets us reverse accidental or unauthorised deletions if you contact us. After that, we permanently delete or anonymise your account data within 30 days. The exceptions are records we must keep by law, and data about shared artists that belongs to your team.
- Backups. Deleted data can remain in our encrypted backups for up to 30 days, until those backups are overwritten.
- Legal claims. If data is needed to establish, exercise or defend a specific legal claim, we may keep it until that matter is resolved.
9. Security
We protect personal data with measures that fit the risk. These include encryption in transit (TLS), hashed passwords, encrypted two-factor secrets and third-party access tokens, optional two-factor authentication, server-side session revocation, bot checks, least-privilege access to production systems, and a staff panel reachable only over a private VPN. If a personal data breach occurs, we will notify the NAIH within 72 hours unless it is unlikely to put anyone’s rights at risk, and we will inform you directly if it is likely to result in a high risk to you.
10. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy (Art. 15);
- rectify inaccurate data (Art. 16);
- erasure of your data (Art. 17);
- restrict processing in certain cases (Art. 18);
- data portability, meaning your data in a structured, machine-readable format (Art. 20);
- object at any time to processing based on legitimate interests (Art. 21); and
- withdraw your consent at any time, where we rely on consent, without affecting processing that has already taken place (Art. 7(3)).
You can change most of your data yourself in your dashboard, including your profile, alert channels and team, and you can delete your account in your settings. For anything else, email [email protected]. We may ask you to confirm your identity. We reply within one month, which can be extended by two further months for complex requests, in which case we will tell you why. Requests are free of charge.
11. Complaints
If you think we have not handled your data lawfully, please contact us first. We will try to put it right. You also have the right to lodge a complaint with the Hungarian supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, Pf. 9.
Phone: +36 1 391 1400 · Email: [email protected] · Web: naih.hu
You can also complain to the supervisory authority in the EU country where you live or work, or go to court. In Hungary, such cases are heard by the regional court (törvényszék), and you may choose the court for the place where you live.
12. Automated decisions
Alerts are produced automatically by comparing releases with your whitelist. They are signals for a human to review, not decisions. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (GDPR Art. 22). What to do about an alert is always your decision.
13. YouTube API Services and Google
CatalogArmor uses YouTube API Services to monitor public YouTube channels and uploads for the artists you add. We use them only with our own API key, to read public data. We do not access your YouTube or Google account through them. For how Google handles data, see the Google Privacy Policy. The YouTube Terms of Service also apply.
If you use Sign in with Google, you can revoke CatalogArmor’s access to your Google account at any time on Google’s security settings page. We receive only your name, email address, Google account ID and profile picture (scopes: openid, email, profile).
14. Changes to this policy
We will update this policy when our processing changes. For material changes, we will email you before they take effect. The version and date at the top of this page show which version is current. Previous versions are available on request.
