Privacy Policy

At a glance

Preamble

With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and particularly on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online services").

The terms used are not gender-specific.

As of: March 12, 2025

Legal text by Dr. Schwenke - click for more information.

Table of Contents

Responsible Entity

WPYM GmbH
Teerhof 59
28199 Bremen

Email address: info@wepublishyourmusic.com

Overview of Processing Activities

The following overview summarizes the types of data processed, the purposes of processing, and refers to the affected individuals.

Types of Processed Data

  • Master data.
  • Payment data.
  • Contact data.
  • Content data.
  • Contract data.
  • Usage data.
  • Meta, communication, and procedural data.
  • Log data.

Categories of Affected Persons

  • Service recipients and clients.
  • Employees.
  • Prospective clients.
  • Communication partners.
  • Users.
  • Business and contractual partners.
  • Third parties.

Purposes of Processing

  • Provision of contractual services and fulfillment of contractual obligations.
  • Communication.
  • Security measures.
  • Office and organizational procedures.
  • Organizational and administrative procedures.
  • Feedback.
  • Marketing.
  • Provision of our online services and user-friendliness.
  • IT infrastructure.
  • Financial and payment management.
  • Public relations.
  • Sales promotion.
  • Business processes and operational procedures.

Applicable Legal Bases

Applicable Legal Bases under the GDPR: Below is an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR regulations, national data protection provisions may apply in your or our country of residence or establishment. If more specific legal bases are applicable in individual cases, we will inform you in the privacy policy.

  • Consent (Art. 6 Para. 1 S. 1 lit. a) GDPR) - The data subject has given their consent to the processing of their personal data for a specific purpose or purposes.
  • Contract fulfillment and pre-contractual inquiries (Art. 6 Para. 1 S. 1 lit. b) GDPR) - The processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation (Art. 6 Para. 1 S. 1 lit. c) GDPR) - The processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Legitimate interests (Art. 6 Para. 1 S. 1 lit. f) GDPR) - The processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, provided that the interests, fundamental rights, and freedoms of the data subject, which require the protection of personal data, do not override those interests.

National Data Protection Regulations in Germany: In addition to the GDPR, national data protection regulations in Germany apply. This includes the Federal Data Protection Act (BDSG), which contains specific regulations on the right to access, the right to deletion, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making, including profiling. Furthermore, state data protection laws of the individual federal states may also apply.

Applicable Legal Bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data based on the Federal Act on Data Protection (Swiss DPA). Unlike the GDPR, the Swiss DPA does not generally require stating a legal basis for the processing of personal data. Processing is carried out in good faith, lawfully, and proportionately (Art. 6 Para. 1 and 2 of the Swiss DPA). Furthermore, personal data is only collected for a specific, identifiable purpose and processed only in ways compatible with that purpose (Art. 6 Para. 3 of the Swiss DPA).

Note on the Application of the GDPR and Swiss DPA: These privacy notices serve both for information under the Swiss DPA and the GDPR. Therefore, please note that due to broader territorial application and clarity, the terms used in the GDPR are applied. Specifically, instead of the terms used in the Swiss DPA such as "processing" of "personal data," "overriding interest," and "special categories of personal data," the terms used in the GDPR such as "processing" of "personal data" and "legitimate interest" and "special categories of data" are used. However, the legal meaning of the terms will continue to be determined in accordance with the Swiss DPA within its scope.

Security Measures

We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of technology, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.

These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, entry, sharing, availability, and separation of data. Additionally, we have established procedures to ensure the exercise of rights by data subjects, the deletion of data, and responses to data threats. We also take into account the protection of personal data during the design and selection of hardware, software, and procedures according to the principle of data protection by design and by default.

Securing online connections via TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted through our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured with an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL, signaling to users that their data is being securely and encrypted during transmission.

Transmission of Personal Data

In the course of processing personal data, it may be transmitted to other parties, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and conclude appropriate contracts or agreements with the recipients of your data to protect your data.

Data transmission within the corporate group: We may transfer personal data to other companies within our corporate group or grant them access to it. This data transfer is based on our legitimate business and operational interests. These include, for example, improving business processes, ensuring efficient and effective internal communication, optimizing the use of our personnel and technological resources, and enabling well-informed business decisions. In certain cases, data transfer may also be necessary to fulfill our contractual obligations, or it may be based on the consent of the data subjects or legal permission.

Data transmission within the organization: We may transfer personal data to other departments or units within our organization or grant them access to it. If the data transfer occurs for administrative purposes, it is based on our legitimate business and operational interests or occurs if it is necessary to fulfill our contractual obligations or if consent from the data subjects or legal permission is present.

International Data Transfers

Data processing in third countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in the context of using third-party services or disclosing/transmitting data to other individuals, entities, or companies (which can be identified by the provider’s postal address or when the privacy policy explicitly mentions data transfers to third countries), this is always done in accordance with legal regulations.

For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission on 07/10/2023. Additionally, we have concluded standard contractual clauses with the respective providers that comply with the EU Commission’s requirements and establish contractual obligations for the protection of your data.

This dual protection ensures comprehensive data security: the DPF serves as the primary level of protection, while the standard contractual clauses provide additional security. If changes occur within the DPF, the standard contractual clauses serve as a reliable fallback option. This ensures that your data remains adequately protected even in the event of political or legal changes.

For individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. More information about the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English).

For data transfers to other third countries, appropriate security measures apply, particularly standard contractual clauses, explicit consents, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the EU Commission’s information offerings: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.

Disclosure of personal data abroad: In accordance with the Swiss Data Protection Act (DSG), we only disclose personal data abroad if adequate protection for the affected individuals is ensured (Art. 16 Swiss DSG). If the Federal Council has not determined adequate protection (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we implement alternative security measures.

For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of Switzerland on 06/07/2024. Additionally, we have concluded standard data protection clauses with the respective providers, which have been approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC) and establish contractual obligations for the protection of your data.

This dual protection ensures comprehensive data security: the DPF serves as the primary level of protection, while the standard data protection clauses provide additional security. If changes occur within the DPF, the standard data protection clauses serve as a reliable fallback option. This ensures that your data remains adequately protected even in the event of political or legal changes.

For individual service providers, we inform you whether they are certified under the DPF and whether standard data protection clauses are in place. The list of certified companies and further information about the DPF can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English).

For data transfers to other third countries, appropriate security measures apply, including international agreements, specific guarantees, standard data protection clauses approved by the FDPIC, or company-internal data protection regulations that have been recognized in advance by the FDPIC or a competent data protection authority of another country.

General Information on Data Storage and Deletion

We delete personal data that we process in accordance with legal regulations as soon as the underlying consents are revoked or no further legal grounds for processing exist. This applies in cases where the original processing purpose ceases to exist or the data is no longer needed. Exceptions to this rule apply when legal obligations or special interests require longer retention or archiving of the data.

In particular, data that must be retained for commercial or tax reasons or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons must be archived accordingly.

Our privacy notices contain additional information on data retention and deletion that specifically apply to certain processing operations.

If multiple retention periods or deletion deadlines apply to a specific piece of data, the longest period is always decisive.

If a period does not explicitly begin on a specific date and is at least one year long, it automatically starts at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the effective date of termination or any other termination of the legal relationship.

Data that is no longer needed for the originally intended purpose but is retained due to legal requirements or other reasons is processed exclusively for the purposes that justify its retention.

Further notes on processing operations, procedures, and services:

  • Retention and deletion of data: The following general retention periods apply according to German law:
    • 10 years - Retention period for books and records, annual financial statements, inventories, management reports, opening balance sheets, and the work instructions and other organizational documents required for their understanding (§ 147 Abs. 1 Nr. 1 in conjunction with Abs. 3 AO, § 14b Abs. 1 UStG, § 257 Abs. 1 Nr. 1 in conjunction with Abs. 4 HGB).
    • 8 years - Accounting records, such as invoices and cost documents (§ 147 Abs. 1 Nr. 4 and 4a in conjunction with Abs. 3 Satz 1 AO as well as § 257 Abs. 1 Nr. 4 in conjunction with Abs. 4 HGB).
    • 6 years - Other business documents: received commercial or business letters, copies of sent commercial or business letters, other documents relevant to taxation, e.g., hourly wage slips, business calculation sheets, calculation documents, price markings, but also payroll records...
    • Business Services

      We process data from our contractual and business partners, such as customers and prospects (collectively referred to as "contractual partners"), within the framework of contractual and similar legal relationships, as well as related measures and communications with the contractual partners (or pre-contractually), for example, to respond to inquiries.

      We use this data to fulfill our contractual obligations. This includes, in particular, obligations to provide agreed-upon services, any update obligations, and remedies for warranty and other service disruptions. Furthermore, we use the data to protect our rights and for administrative tasks related to these obligations, as well as corporate organization. Additionally, we process the data based on our legitimate interests in the proper and economically efficient business operation, as well as security measures to protect our contractual partners and our business operations from misuse, threats to their data, secrets, information, and rights (e.g., involving telecommunications, transportation, and other support services, subcontractors, banks, tax and legal advisors, payment service providers, or financial authorities). Where permitted by applicable law, we only share data from contractual partners with third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners are informed of additional forms of processing, such as for marketing purposes, within the scope of this privacy policy.

      We inform contractual partners in advance or during data collection about which data is necessary for the aforementioned purposes, for example, in online forms, through special markings (e.g., colors) or symbols (e.g., asterisks), or personally.

      We delete the data after the expiration of statutory warranty and similar obligations, i.e., generally after four years, unless the data is stored in a customer account, e.g., as long as it must be retained for legal archiving purposes (for example, for tax purposes, typically ten years). Data disclosed to us as part of an order by the contractual partner is deleted according to the specifications and generally upon completion of the order.

      • Processed Data Types: Inventory data (e.g., full name, home address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or phone numbers); contract data (e.g., contract subject, duration, customer category).
      • Affected Persons: Service recipients and clients; interested parties; business and contractual partners.
      • Processing Purposes: Provision of contractual services and fulfillment of contractual obligations; communication; office and organizational procedures; organizational and administrative procedures; business processes and economic procedures.
      • Retention and Deletion: Deletion as specified in the section "General Information on Data Storage and Deletion".
      • Legal Bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

      Further Notes on Processing Operations, Procedures, and Services:

      • Agency Services: We process our customers' data as part of our contractual services, which may include conceptual and strategic consulting, campaign planning, software and design development/consulting or maintenance, implementation of campaigns and processes, handling, server administration, data analysis/consulting services, and training services; Legal Bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).

      Business Processes and Procedures

      Personal data of service recipients and clients – including customers, clients, or, in special cases, legal clients, patients, or business partners as well as other third parties – are processed within the framework of contractual and comparable legal relationships, as well as pre-contractual measures such as initiating business relationships. This data processing supports and facilitates business operations in areas such as customer management, sales, payment transactions, accounting, and project management.

      The collected data serves to fulfill contractual obligations and to efficiently organize operational processes. This includes processing business transactions, managing customer relationships, optimizing sales strategies, and ensuring internal accounting and financial processes. Additionally, the data supports the protection of the responsible party's rights and facilitates administrative tasks as well as corporate organization.

      Personal data may be shared with third parties if necessary to fulfill the stated purposes or legal obligations. Data is deleted after the expiration of statutory retention periods or if the purpose of processing no longer applies. This also includes data that must be retained for tax and legal documentation purposes.

      • Processed Data Types: Inventory data (e.g., full name, home address, contact information, customer number, etc.); payment data (e.g., bank details, invoices, payment history); contact data (e.g., postal and email addresses or phone numbers); content data (e.g., textual or visual messages and posts, as well as related information such as authorship details or timestamps); contract data (e.g., contract subject, duration, customer category); log data (e.g., log files related to logins or data access times); usage data (e.g., page views and duration, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions); meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
      • Affected Persons: Service recipients and clients; interested parties; communication partners; business and contractual partners; third parties; users (e.g., website visitors, users of online services); employees (e.g., employees, applicants, temporary workers, and other staff).
      • Processing Purposes: Provision of contractual services and fulfillment of contractual obligations; office and organizational procedures; business processes and economic procedures; communication; marketing; sales promotion; public relations; financial and payment management; information technology infrastructure (operation and provision of information systems and technical devices (computers, servers, etc.)).
      • Retention and Deletion: Deletion as specified in the section "General Information on Data Storage and Deletion".
      • Legal Bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR); legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR); legal obligation (Art. 6 para. 1 sentence 1 lit. c) GDPR).

      Further Notes on Processing Operations, Procedures, and Services:

      • Contact Management and Maintenance: Procedures required for the organization, maintenance, and security of contact information (e.g., setting up and maintaining a central contact database, regular updates of contact information, monitoring data integrity, implementing data protection measures, ensuring access controls, performing backups and restores of contact data, training employees in the effective use of contact management software, regular review of communication history and adjustment of contact strategies); Legal Bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).
      • General Payment Transactions: Procedures required for conducting payment transactions, monitoring bank accounts, and controlling payment flows (e.g., creation and verification of transfers, processing of direct debits, checking account statements, monitoring incoming and outgoing payments, managing chargebacks, account reconciliation, cash management); Legal Bases: Fulfillment of contract and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR), legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

      Notes on legal bases for data protection: Whether we process personal data using cookies depends on consent. If consent is given, it serves as the legal basis. Without consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and processes.

      Storage duration: With regard to the storage duration, the following types of cookies are distinguished:

      • Temporary cookies (also: session cookies): Temporary cookies are deleted at the latest after a user leaves an online service and closes their device (e.g., browser or mobile application).
      • Permanent cookies: Permanent cookies remain stored even after the device is closed. For example, the login status can be saved, and preferred content can be displayed directly when the user revisits a website. Likewise, user data collected via cookies can be used for reach measurement. Unless we provide users with explicit information on the type and storage duration of cookies (e.g., as part of obtaining consent), they should assume that they are permanent and that the storage period may be up to two years.

      General information on revocation and objection (opt-out): Users can revoke the consent they have given at any time and also object to processing in accordance with legal regulations, including via the privacy settings of their browser.

      • Types of processed data: Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
      • Affected persons: Users (e.g., website visitors, online service users).
      • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

      Further information on processing procedures, methods, and services:

      • Processing of cookie data based on consent: We use a consent management solution in which users' consent to the use of cookies or the procedures and providers specified in the consent management solution is obtained. This process serves to obtain, record, manage, and revoke consents, particularly concerning the use of cookies and similar technologies used for storing, reading, and processing information on users' devices. As part of this process, users' consents for the use of cookies and related data processing, including the specific processing and providers mentioned in the consent management process, are obtained. Users also have the option to manage and revoke their consents. Consent declarations are stored to avoid repeated requests and to provide proof of consent in accordance with legal requirements. Storage takes place server-side and/or in a cookie (so-called opt-in cookie) or through similar technologies to associate the consent with a specific user or their device. Unless specific details about consent management service providers are available, the following general information applies: The storage duration of consent is up to two years. A pseudonymous user identifier is created, stored along with the time of consent, details on the scope of consent (e.g., categories of cookies and/or service providers involved), as well as information about the browser, system, and device used; Legal bases: Consent (Art. 6 para. 1 sentence 1 lit. a) GDPR).

      Special notes on applications (apps)

      We process the data of users of our application insofar as it is necessary to provide them with the application and its functionalities, to monitor its security, and to further develop it. Furthermore, we may contact users in compliance with legal requirements if communication is necessary for administrative purposes or the use of the application. Otherwise, regarding the processing of users' data, we refer to the privacy notices in this privacy policy.

      Legal bases: The processing of data necessary for providing the functionalities of the application serves to fulfill contractual obligations. This also applies if the provision of functions requires user authorization (e.g., granting permissions for device functions). If the processing of data is not necessary for providing the application's functionalities but serves the security of the application or our business interests (e.g., collecting data for optimizing the application or for security purposes), it is based on our legitimate interests. If users are explicitly asked for their consent to process their data, the processing of the data covered by the consent is based on that consent.

      • Types of processed data: Inventory data (e.g., full name, home address, contact details, customer number, etc.); usage data (e.g., page views and duration, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
      • Affected persons: Users (e.g., website visitors, online service users).
      • Processing purposes: Provision of contractual services and fulfillment of contractual obligations; security measures; provision of our online offering and user-friendliness.
      • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion."
      • Legal bases: Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR). Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR).

      Further information on processing procedures, methods, and services:

      • Device permissions for accessing functions and data: The use of our application or its functionalities may require users to grant permissions to access certain functions of the devices used or to data stored on or accessible via the devices. By default, these permissions must be granted by users and can be revoked at any time in the settings of their respective devices. The exact procedure for controlling app permissions may depend on the device and software used by users. If explanations are needed, users can contact us. Please note that refusing or revoking the respective permissions may affect the functionality of our application.

      Contact and inquiry management

      When contacting us (e.g., by mail, contact form, email, phone, or social media) and in the context of existing user and business relationships, the information provided by the inquiring persons is processed as necessary to respond to contact requests and any requested actions.

      • Types of processed data: Inventory data (e.g., full name, home address, contact details, customer number, etc.); contact data (e.g., postal and email addresses or phone numbers); content data (e.g., textual or visual messages and posts, as well as related information such as authorship details or creation timestamps); usage data (e.g., page views and duration, click paths, usage intensity and frequency, device types and operating systems used, interactions with content and functions). Meta, communication, and procedural data (e.g., IP addresses, timestamps, identification numbers, involved persons).
      • Affected persons: Communication partners.
      • Processing purposes: Communication; organizational and administrative processes; feedback (e.g., collecting feedback via online forms); provision of our online offering and user-friendliness.
      • Retention and deletion: Deletion according to the information in the section "General information on data storage and deletion."
      • Legal bases: Legitimate interests (Art. 6 para. 1 sentence 1 lit. f) GDPR). Contract fulfillment and pre-contractual inquiries (Art. 6 para. 1 sentence 1 lit. b) GDPR).