§1. Data controller
The data controller for personal data processed by Seen Live is Charles Blethon, acting as a natural person during the private beta (a legal entity will be formed ahead of the public opening). Contact address: 1 rue Newton, 75116 Paris, France. For any privacy-related question or to exercise your RGPD rights: privacy@seenlivemusic.com.
§2. Personal data we collect
| Data | Source | Lawful basis |
|---|---|---|
| Email address | Waitlist + magic link sign-in | Beta consent (RGPD art. 6.1.a) |
| First name + last name | Waitlist | Consent (art. 6.1.a) |
| Artist name + Instagram handle | Waitlist | Consent (art. 6.1.a) |
| Uploaded MP3 files | Artist upload | Contract (art. 6.1.b — detection service) |
| Audio fingerprint | Detection provider | Legitimate interest (art. 6.1.f — service execution) |
| Analytics events | Site navigation | Explicit consent via banner |
| Error logs | Runtime errors | Legitimate interest (debug + security, IP scrubbed) |
| Email metadata | Transactional emails | Contract (art. 6.1.b) |
§3. Data retention
| Data | Phase 1 retention |
|---|---|
| Account profile | As long as the account is active, plus 30 days post-deletion (RGPD erasure) |
| Uploaded MP3 files | As long as the track is being tracked, plus a security buffer post-account deletion |
| Audio fingerprint | Indefinitely while the account is active |
| Detection records | As long as the account is active (cumulated identity proof) |
| Product analytics events | Per our analytics provider's retention policy |
| Error logs | Per our error monitoring provider's retention policy |
| Email metadata | Per our email provider's retention policy |
| DMCA / LCEN takedown register | For the duration required by applicable law (LCEN obligation) |
A future automatic purge policy for uploaded MP3 files will be introduced ahead of the public opening (Phase 2).
§4. Hosting and data residency
All operational data is hosted in the European Union by default:
| Service | Provider | Region | Role |
|---|---|---|---|
| Database + Storage + Auth | Supabase Inc. | Frankfurt (EU) | Primary data store |
| Application hosting | Vercel Inc. | Paris / Frankfurt (EU) | Static + serverless |
| Async jobs | Inngest Inc. | EU region | Pipeline orchestration |
| Transactional emails | Resend | EU region | Waitlist + magic link + digests |
| Error monitoring | Sentry | EU region | Errors + performance |
| Product analytics | PostHog Cloud | EU region | Consent-gated |
§5. Sub-processors and international transfers
We rely on the following Phase 1 sub-processors: Supabase, Vercel, Inngest, Resend, Sentry, PostHog, Upstash (rate limiting), Loops (waitlist provider, US-based) and ACRCloud (detection provider).
Upstash (rate limiting). To prevent abuse of the magic-link sign-in, Upstash processes your email address and IP address as rate-limiting counters over a rolling one-hour window. Nothing else is sent, and these counters are not used for any other purpose.
Loops (US transfer). Loops processes waitlist emails and confirmation messages on US-based infrastructure under EU Standard Contractual Clauses (SCC, art. 46 RGPD).
ACRCloud (transfer outside the EU — detection provider). Audio fingerprinting and detection scanning are performed by ACRCloud PTE. LTD. (Singapore-based). Your uploaded audio file is transmitted for fingerprint generation only and is permanently deleted by the provider once the fingerprint is created — the original file remains hosted in the EU (see §4). Only the non-reversible fingerprint (which cannot be turned back into audio) is retained for scanning. This transfer is governed by EU Standard Contractual Clauses (SCC, art. 46 RGPD); a Data Processing Agreement with the provider is being finalized ahead of the beta opening.
A live list of sub-processors will be published at /legal/sub-processors starting Phase 2. The current Phase 1 list is enumerated above and updated in this section for any new processor added.
§6. Your rights (RGPD)
- Access (art. 15) — copy of all your data within 30 days.
- Rectification (art. 16) — via your account settings or by email.
- Erasure (art. 17) — right to be forgotten within 30 days.
- Restriction (art. 18) — pause processing on request.
- Portability (art. 20) — a machine-readable copy of your data, on request by email, within 30 days.
- Object (art. 21) — opt out of analytics processing at any time (cookie banner or email).
- Withdraw consent (art. 7) — via cookie banner or email.
- Lodge a complaint with the CNIL (FR Data Protection Authority, cnil.fr).
§7. Cookies and tracking
We use a single first-party consent layer stored in your browser's local storage. When you accept, an EU-hosted product analytics SDK starts capturing page views, clicks, and feature usage events (no PII — IP scrubbed, email scrubbed at SDK level). When you reject (or by default — opt-out), no event leaves your browser. To revoke consent at any time: clear your browser storage or email privacy@seenlivemusic.com.
§8. Security measures
- TLS 1.3 in transit, AES-256 at rest.
- JWT httpOnly cookies for authentication (magic-link via Supabase Auth).
- Strict security headers including Content-Security-Policy.
- Rate limiting on sensitive endpoints.
- Automated backups via point-in-time recovery.
- Error monitoring with PII scrubbing at instrumentation level.
§9. Data breach notification
In the event of a data breach affecting your personal data, we will notify the CNIL within 72 hours (RGPD art. 33) and you directly within 7 days (best effort, RGPD art. 34) via email and a status page.
§10. Contact and DPO
For any privacy-related question or to exercise your RGPD rights, contact privacy@seenlivemusic.com. For Phase 1 beta, no formal DPO is appointed: Seen Live operates below the RGPD art. 37 thresholds (fewer than 250 employees, no large-scale processing of special-category data). DPO designation will be re-evaluated for the Phase 2 public opening.
§11. Updates to this policy
This policy is versioned. Any material change will be communicated by email to all active beta users with prior notice.