01
General information and controller
Protecting your personal data is important to us. Personal data means any information that can be used to identify you directly or indirectly.
02
Server log files and website delivery
When you access our website, the hosting provider processes connection data that is technically required. This may include your IP address, date and time of access, requested file, referrer URL, browser type and version, operating system and the volume of data transferred.
Processing is based on Article 6(1)(f) GDPR. Our legitimate interest is the secure, stable and functional delivery of the website and the prevention of abusive access. Data is not combined with other sources unless this is required to investigate a specific security incident.
03
Contact via form or email
When you contact us through a form or by email, we process the information you provide, including your name, email address, telephone number, selected artist, subject and message.
Processing is based on Article 6(1)(b) GDPR where your enquiry relates to pre-contractual measures or performance of a contract; otherwise it is based on Article 6(1)(f) GDPR. Our legitimate interest is the professional handling of incoming communications.
04
Music licence requests and agreement preparation
When you use the “Licence Approval & Agreement Preparation” form, we process the company, contact, project, usage, territorial, budget and contractual information entered there, together with any references and attachments submitted voluntarily.
This information is required to assess rights availability, the requested scope, commercial terms and the potential preparation of a licence agreement. The legal basis is Article 6(1)(b) GDPR. Where additional information is provided voluntarily, processing may also be based on your consent under Article 6(1)(a) GDPR.
Attachments are stored in a non-public server area accessible only to authorised administrators. Use of the requested musical work is permitted only after written approval and execution of a licence agreement.
05
Cookies and consent management
Our website uses essential cookies and local storage entries to provide core functions such as sessions, CSRF protection, language preferences, login status and storage of your cookie choice. Processing is based on Section 25(2)(2) TDDDG and Article 6(1)(f) GDPR.
Optional categories are enabled only after you provide express consent through the cookie banner. You can change your choice at any time using the permanently visible cookie icon at the bottom left. Processing carried out before consent is withdrawn remains lawful.
EssentialAlways activeSession, security, language preferences, forms and consent storage.
External mediaOptionalEmbedded audio, video or streaming content supplied by external providers, where used.
AnalyticsOptionalPrivacy-conscious audience or usage analysis, where enabled.
06
Media Pool, user accounts and downloads
For registration and use of the Media Pool, we process information including first name, surname, institution, telephone number, email address, country, password hash, account status and technical timestamps. Passwords are not stored in plain text.
Processing is necessary to provide the requested user account and approved music downloads and is based on Article 6(1)(b) GDPR. Security and access logs may be processed under Article 6(1)(f) GDPR to prevent unauthorised access and abusive downloads.
07
Newsletter and performance measurement
When you subscribe to the newsletter, we process your first name, surname, email address, selected language, subscription and confirmation timestamps and unsubscribe status. Processing is based on your consent under Article 6(1)(a) GDPR.
Delivery status, opens and interactions may be recorded for technical delivery and quality assurance. Where optional tracking technologies are required, they are used only with the corresponding consent. You may unsubscribe at any time through the unsubscribe link or by emailing info@bpeats-music.de.
After you unsubscribe, your address is removed from the active distribution list. A minimal suppression record may be retained to ensure that no further messages are sent.
08
External music and social-media platforms
Our website contains direct links to external platforms, including Spotify, Apple Music, Deezer, YouTube, YouTube Music, Amazon Music, SoundCloud, TIDAL, Instagram, TikTok and other providers. You leave our website only when you select an external link.
When an external platform is opened, that provider’s privacy policy applies. The provider may process information including your IP address, device information, cookies and usage activity. We have no control over the nature, scope or duration of that processing.
09
Recipients and disclosure of data
Personal data is disclosed only where this is necessary for contractual performance or technical delivery, where you have expressly consented or where disclosure is required by law. Potential recipients include hosting and IT service providers, email and delivery service providers, professional advisers and contractual partners directly involved in a requested licence.
Where required, data-processing agreements under Article 28 GDPR are concluded with processors.
10
Retention periods
We retain personal data only for as long as necessary for the relevant purpose or as required by statutory retention obligations. Contact enquiries are generally deleted once communication has concluded, unless contractual or legal grounds require continued retention.
Licence and contractual data may be retained in accordance with commercial and tax-law retention periods. Media Pool data is deleted or restricted after the user account is closed, unless security or evidentiary obligations require otherwise.
11
Your rights under Articles 15–21 GDPR
Subject to the applicable legal requirements, you have the right of access, rectification, erasure, restriction of processing, data portability and objection. Consent may be withdrawn at any time with effect for the future.
To exercise your rights, send a message to info@bpeats-music.de. You also have the right to lodge a complaint with a competent data-protection supervisory authority.
12
Data security
We apply appropriate technical and organisational measures under Article 32 GDPR to protect personal data against loss, manipulation, unauthorised access and other misuse. These measures include encrypted transmission, protected storage areas, access restrictions, secure password hashing, CSRF protection and regular technical maintenance.
13
Updates to this Privacy Policy
We may update this Privacy Policy to reflect changes in legal, technical or organisational requirements. The version published on this website at the relevant time applies.
Last updated: 21 July 2026