With the following privacy policy, we would like to inform you about the types of your personal data (hereinafter also referred to as "data") that we process, for what purposes, and to what extent. The privacy policy applies to all processing of personal data carried out by us, both in the course of providing our services and particularly on our websites, in mobile applications, and within external online presences, such as our social media profiles (hereinafter collectively referred to as "online services").
The terms used are not gender-specific.
As of: March 12, 2025
WPYM GmbH
Teerhof 59
28199 Bremen
Email address: info@wepublishyourmusic.com
The following overview summarizes the types of data processed, the purposes of processing, and refers to the affected individuals.
Applicable Legal Bases under the GDPR: Below is an overview of the legal bases of the GDPR on which we process personal data. Please note that in addition to the GDPR regulations, national data protection provisions may apply in your or our country of residence or establishment. If more specific legal bases are applicable in individual cases, we will inform you in the privacy policy.
National Data Protection Regulations in Germany: In addition to the GDPR, national data protection regulations in Germany apply. This includes the Federal Data Protection Act (BDSG), which contains specific regulations on the right to access, the right to deletion, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making, including profiling. Furthermore, state data protection laws of the individual federal states may also apply.
Applicable Legal Bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data based on the Federal Act on Data Protection (Swiss DPA). Unlike the GDPR, the Swiss DPA does not generally require stating a legal basis for the processing of personal data. Processing is carried out in good faith, lawfully, and proportionately (Art. 6 Para. 1 and 2 of the Swiss DPA). Furthermore, personal data is only collected for a specific, identifiable purpose and processed only in ways compatible with that purpose (Art. 6 Para. 3 of the Swiss DPA).
Note on the Application of the GDPR and Swiss DPA: These privacy notices serve both for information under the Swiss DPA and the GDPR. Therefore, please note that due to broader territorial application and clarity, the terms used in the GDPR are applied. Specifically, instead of the terms used in the Swiss DPA such as "processing" of "personal data," "overriding interest," and "special categories of personal data," the terms used in the GDPR such as "processing" of "personal data" and "legitimate interest" and "special categories of data" are used. However, the legal meaning of the terms will continue to be determined in accordance with the Swiss DPA within its scope.
We implement appropriate technical and organizational measures in accordance with legal requirements, taking into account the state of technology, implementation costs, and the nature, scope, circumstances, and purposes of processing, as well as the varying probabilities of occurrence and the extent of the threat to the rights and freedoms of natural persons, to ensure a level of protection appropriate to the risk.
These measures include, in particular, ensuring the confidentiality, integrity, and availability of data by controlling physical and electronic access to the data, as well as access, entry, sharing, availability, and separation of data. Additionally, we have established procedures to ensure the exercise of rights by data subjects, the deletion of data, and responses to data threats. We also take into account the protection of personal data during the design and selection of hardware, software, and procedures according to the principle of data protection by design and by default.
Securing online connections via TLS/SSL encryption technology (HTTPS): To protect the data of users transmitted through our online services from unauthorized access, we use TLS/SSL encryption technology. Secure Sockets Layer (SSL) and Transport Layer Security (TLS) are the cornerstones of secure data transmission on the internet. These technologies encrypt the information transmitted between the website or app and the user's browser (or between two servers), protecting the data from unauthorized access. TLS, as the more advanced and secure version of SSL, ensures that all data transmissions meet the highest security standards. When a website is secured with an SSL/TLS certificate, this is indicated by the display of HTTPS in the URL, signaling to users that their data is being securely and encrypted during transmission.
In the course of processing personal data, it may be transmitted to other parties, companies, legally independent organizational units, or individuals. Recipients of this data may include, for example, service providers entrusted with IT tasks or providers of services and content integrated into a website. In such cases, we comply with legal requirements and conclude appropriate contracts or agreements with the recipients of your data to protect your data.
Data transmission within the corporate group: We may transfer personal data to other companies within our corporate group or grant them access to it. This data transfer is based on our legitimate business and operational interests. These include, for example, improving business processes, ensuring efficient and effective internal communication, optimizing the use of our personnel and technological resources, and enabling well-informed business decisions. In certain cases, data transfer may also be necessary to fulfill our contractual obligations, or it may be based on the consent of the data subjects or legal permission.
Data transmission within the organization: We may transfer personal data to other departments or units within our organization or grant them access to it. If the data transfer occurs for administrative purposes, it is based on our legitimate business and operational interests or occurs if it is necessary to fulfill our contractual obligations or if consent from the data subjects or legal permission is present.
Data processing in third countries: If we transfer data to a third country (i.e., outside the European Union (EU) or the European Economic Area (EEA)) or if this occurs in the context of using third-party services or disclosing/transmitting data to other individuals, entities, or companies (which can be identified by the provider’s postal address or when the privacy policy explicitly mentions data transfers to third countries), this is always done in accordance with legal regulations.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of the EU Commission on 07/10/2023. Additionally, we have concluded standard contractual clauses with the respective providers that comply with the EU Commission’s requirements and establish contractual obligations for the protection of your data.
This dual protection ensures comprehensive data security: the DPF serves as the primary level of protection, while the standard contractual clauses provide additional security. If changes occur within the DPF, the standard contractual clauses serve as a reliable fallback option. This ensures that your data remains adequately protected even in the event of political or legal changes.
For individual service providers, we inform you whether they are certified under the DPF and whether standard contractual clauses are in place. More information about the DPF and a list of certified companies can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, appropriate security measures apply, particularly standard contractual clauses, explicit consents, or legally required transfers. Information on third-country transfers and applicable adequacy decisions can be found in the EU Commission’s information offerings: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en?prefLang=de.
Disclosure of personal data abroad: In accordance with the Swiss Data Protection Act (DSG), we only disclose personal data abroad if adequate protection for the affected individuals is ensured (Art. 16 Swiss DSG). If the Federal Council has not determined adequate protection (list: https://www.bj.admin.ch/bj/de/home/staat/datenschutz/internationales/anerkennung-staaten.html), we implement alternative security measures.
For data transfers to the USA, we primarily rely on the Data Privacy Framework (DPF), which was recognized as a secure legal framework by an adequacy decision of Switzerland on 06/07/2024. Additionally, we have concluded standard data protection clauses with the respective providers, which have been approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC) and establish contractual obligations for the protection of your data.
This dual protection ensures comprehensive data security: the DPF serves as the primary level of protection, while the standard data protection clauses provide additional security. If changes occur within the DPF, the standard data protection clauses serve as a reliable fallback option. This ensures that your data remains adequately protected even in the event of political or legal changes.
For individual service providers, we inform you whether they are certified under the DPF and whether standard data protection clauses are in place. The list of certified companies and further information about the DPF can be found on the website of the U.S. Department of Commerce at https://www.dataprivacyframework.gov/ (in English).
For data transfers to other third countries, appropriate security measures apply, including international agreements, specific guarantees, standard data protection clauses approved by the FDPIC, or company-internal data protection regulations that have been recognized in advance by the FDPIC or a competent data protection authority of another country.
We delete personal data that we process in accordance with legal regulations as soon as the underlying consents are revoked or no further legal grounds for processing exist. This applies in cases where the original processing purpose ceases to exist or the data is no longer needed. Exceptions to this rule apply when legal obligations or special interests require longer retention or archiving of the data.
In particular, data that must be retained for commercial or tax reasons or whose storage is necessary for legal prosecution or to protect the rights of other natural or legal persons must be archived accordingly.
Our privacy notices contain additional information on data retention and deletion that specifically apply to certain processing operations.
If multiple retention periods or deletion deadlines apply to a specific piece of data, the longest period is always decisive.
If a period does not explicitly begin on a specific date and is at least one year long, it automatically starts at the end of the calendar year in which the triggering event occurred. In the case of ongoing contractual relationships in which data is stored, the triggering event is the effective date of termination or any other termination of the legal relationship.
Data that is no longer needed for the originally intended purpose but is retained due to legal requirements or other reasons is processed exclusively for the purposes that justify its retention.
Further notes on processing operations, procedures, and services:
We process data from our contractual and business partners, such as customers and prospects (collectively referred to as "contractual partners"), within the framework of contractual and similar legal relationships, as well as related measures and communications with the contractual partners (or pre-contractually), for example, to respond to inquiries.
We use this data to fulfill our contractual obligations. This includes, in particular, obligations to provide agreed-upon services, any update obligations, and remedies for warranty and other service disruptions. Furthermore, we use the data to protect our rights and for administrative tasks related to these obligations, as well as corporate organization. Additionally, we process the data based on our legitimate interests in the proper and economically efficient business operation, as well as security measures to protect our contractual partners and our business operations from misuse, threats to their data, secrets, information, and rights (e.g., involving telecommunications, transportation, and other support services, subcontractors, banks, tax and legal advisors, payment service providers, or financial authorities). Where permitted by applicable law, we only share data from contractual partners with third parties to the extent necessary for the aforementioned purposes or to fulfill legal obligations. Contractual partners are informed of additional forms of processing, such as for marketing purposes, within the scope of this privacy policy.
We inform contractual partners in advance or during data collection about which data is necessary for the aforementioned purposes, for example, in online forms, through special markings (e.g., colors) or symbols (e.g., asterisks), or personally.
We delete the data after the expiration of statutory warranty and similar obligations, i.e., generally after four years, unless the data is stored in a customer account, e.g., as long as it must be retained for legal archiving purposes (for example, for tax purposes, typically ten years). Data disclosed to us as part of an order by the contractual partner is deleted according to the specifications and generally upon completion of the order.
Further Notes on Processing Operations, Procedures, and Services:
Personal data of service recipients and clients – including customers, clients, or, in special cases, legal clients, patients, or business partners as well as other third parties – are processed within the framework of contractual and comparable legal relationships, as well as pre-contractual measures such as initiating business relationships. This data processing supports and facilitates business operations in areas such as customer management, sales, payment transactions, accounting, and project management.
The collected data serves to fulfill contractual obligations and to efficiently organize operational processes. This includes processing business transactions, managing customer relationships, optimizing sales strategies, and ensuring internal accounting and financial processes. Additionally, the data supports the protection of the responsible party's rights and facilitates administrative tasks as well as corporate organization.
Personal data may be shared with third parties if necessary to fulfill the stated purposes or legal obligations. Data is deleted after the expiration of statutory retention periods or if the purpose of processing no longer applies. This also includes data that must be retained for tax and legal documentation purposes.
Further Notes on Processing Operations, Procedures, and Services:
Notes on legal bases for data protection: Whether we process personal data using cookies depends on consent. If consent is given, it serves as the legal basis. Without consent, we rely on our legitimate interests, as explained above in this section and in the context of the respective services and processes.
Storage duration: With regard to the storage duration, the following types of cookies are distinguished:
General information on revocation and objection (opt-out): Users can revoke the consent they have given at any time and also object to processing in accordance with legal regulations, including via the privacy settings of their browser.
Further information on processing procedures, methods, and services:
We process the data of users of our application insofar as it is necessary to provide them with the application and its functionalities, to monitor its security, and to further develop it. Furthermore, we may contact users in compliance with legal requirements if communication is necessary for administrative purposes or the use of the application. Otherwise, regarding the processing of users' data, we refer to the privacy notices in this privacy policy.
Legal bases: The processing of data necessary for providing the functionalities of the application serves to fulfill contractual obligations. This also applies if the provision of functions requires user authorization (e.g., granting permissions for device functions). If the processing of data is not necessary for providing the application's functionalities but serves the security of the application or our business interests (e.g., collecting data for optimizing the application or for security purposes), it is based on our legitimate interests. If users are explicitly asked for their consent to process their data, the processing of the data covered by the consent is based on that consent.
Further information on processing procedures, methods, and services:
When contacting us (e.g., by mail, contact form, email, phone, or social media) and in the context of existing user and business relationships, the information provided by the inquiring persons is processed as necessary to respond to contact requests and any requested actions.