1. Controller
Müller Service UG (haftungsbeschränkt)Scheinerstraße 5650737 CologneGermanyEmail: benjamin.mueller80@icloud.comPhone: +49 (0) 176 460 47 273No data protection officer has currently been appointed. If a statutory obligation to appoint one arises in the future, the relevant contact details will be added here.
2. General legal bases
We process personal data only where a legal basis exists. Depending on the processing activity, the following bases may apply in particular:
- Article 6(1)(b) GDPR for contracts, orders, accounts, downloads, artist and scout agreements and pre-contractual measures;
- Article 6(1)(c) GDPR for compliance with legal obligations, especially commercial, tax and payment-law requirements;
- Article 6(1)(f) GDPR for the secure, efficient and abuse-free operation of the portal, IT security, error analysis and legal defence;
- Article 6(1)(a) GDPR where we expressly request consent for optional processing.
Where required, additional information is provided directly in the relevant form at the time data is collected.
3. Website provision, hosting and server log files
When our pages are accessed, the hosting provider used by us processes technically necessary connection data. This may include the IP address, date and time, requested file, data volume transferred, referrer, browser type, operating system, host name, status messages and error messages.
Processing serves secure delivery, stability, error analysis, protection against attacks and detection of misuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure and functional operation of the portal.
The hosting provider processes data on our behalf unless it is independently responsible for a specific processing activity. The exact retention period for log data depends on security and operational requirements. Log data is deleted or anonymised once it is no longer required for these purposes, unless a security incident or statutory obligation justifies longer retention.
4. Cookies, sessions and local storage
The portal uses technically necessary session cookies or comparable storage mechanisms. They are used in particular for the shopping cart, login, permission checks, profile switching, form protection and maintaining a secure session.
Storage or access is necessary to provide functions expressly requested by the user. Where consent is not required, this is based on Section 25(2) TDDDG; subsequent processing of personal data is based, depending on the function, on Article 6(1)(b) or (f) GDPR.
Technically necessary session data generally becomes invalid on logout, on expiry of the session or after a reasonable period of inactivity. Browsers may delete or block cookies earlier; in that case, shopping-cart and account functions may be restricted.
According to the current functionality, we do not use our own analytics or advertising trackers. If analytics, marketing or non-essential third-party technologies are added in the future, they will be activated only after valid consent and this policy and the consent-management process will be updated accordingly.
5. Registration, accounts, login and administration
For artist, scout and administrator accounts, we process in particular name, email address, role, account status, password hash, login and session information, PayPal verification status, balances, commissions, assignments and administrative changes.
Passwords are not stored in plain text but processed as cryptographic hash values. Administrators may manage accounts and, where provided by the portal, open views of other roles for support or troubleshooting. Such access must be limited to legitimate administrative purposes.
The legal basis is Article 6(1)(b) GDPR for use of the account and Article 6(1)(f) GDPR for security, support, abuse prevention and internal administration.
6. Shopping cart, orders, invoices and digital downloads
For contract performance, we may process names, email addresses, billing and contact details, shopping-cart contents, prices, tax information, order and payment status, transaction references and download tokens.
Download tokens enable controlled delivery of purchased or unlocked digital content. For security and evidentiary purposes, creation, validity, use and technical access data may be logged.
The legal basis is Article 6(1)(b) GDPR. Where data is required for invoicing, accounting or tax evidence, processing is additionally based on Article 6(1)(c) GDPR.
7. Payment processing via PayPal
We use PayPal to process the payment methods offered. Depending on the selected payment method, identification, contact, device, transaction, shopping-cart and payment data may be transmitted to PayPal or collected directly by PayPal. PayPal may also use its own cookies and comparable technologies.
The provider for European users is generally PayPal (Europe) S.à r.l. et Cie, S.C.A., Luxembourg. Payment processing is based on Article 6(1)(b) GDPR. Where PayPal processes data for its own purposes—particularly fraud prevention, risk assessment, statutory payment-service obligations or its own services—PayPal acts as an independent controller.
When PayPal is used, data may also be processed outside the European Economic Area. PayPal describes the safeguards used and its own processing activities in its current privacy policy.
8. Artist, profile, upload and scout data
Artists may provide profile information, images, banners, descriptions, origin, genres, equipment, social-media links, audio files and cover files. Data expressly intended for the public profile is displayed on publicly accessible artist pages.
For music uploads, we additionally process metadata such as track name, genre, release year, BPM, album, label, ISRC, composer, copyright details, description, price, preview range and file paths. This data is used for publication, contract performance, rights allocation, sales presentation and accounting.
Scout data may include name, email/PayPal address, verification status, balances, commissions, attributed sales, invitation and switching information and payout data. Invitation links contain random tokens and are time-limited.
The legal basis is Article 6(1)(b) GDPR. Public display of voluntary profile information is based on the profile function requested by the user; information can be changed or removed in the dashboard. Statutory retention and documentation obligations remain unaffected.
9. Audio previews and media files
When an audio preview is played, the browser requests the relevant media file from the server. Technically necessary connection and access data is generated in the process. The preview may be limited to a defined segment. The legal basis is Article 6(1)(b) GDPR for the requested use and Article 6(1)(f) GDPR for secure technical delivery.
11. Email communication and password reset
If you contact us by email, we process the sender address, content, metadata and any attachments in order to handle the request. The legal basis is Article 6(1)(b) GDPR for contract-related enquiries and otherwise Article 6(1)(f) GDPR.
For password resets, we process the email address, user assignment, a random token with limited validity, the time and usage status. For security, the link can be used only once. Tokens are deleted or invalidated after expiry or use.
12. Recipients and service providers
Data is received only by parties that need it for the relevant purpose. Categories of recipients may include hosting and IT service providers, email providers, PayPal and other payment participants, tax or legal advisers, and public authorities or courts where legally required.
Processors are bound by agreements under Article 28 GDPR where required. Data is not disclosed for advertising purposes unless separate consent has been given.
13. Retention period
We retain data only for as long as necessary for the relevant purpose. Account data is generally stored for the duration of the account and afterwards until outstanding claims have been clarified. Profile and upload data that is no longer required is deleted unless contractual, security-related or statutory reasons prevent this.
Commercial, tax and accounting documents are retained for the legally prescribed periods; depending on the type of document, these may be six, eight or ten years in particular. Data required for legal defence may be retained until the relevant limitation periods expire.
14. Rights of data subjects
Subject to the statutory requirements, you have in particular the right to:
- access personal data processed about you (Article 15 GDPR),
- rectification of inaccurate data (Article 16 GDPR),
- erasure (Article 17 GDPR),
- restriction of processing (Article 18 GDPR),
- data portability (Article 20 GDPR),
- object to processing based on legitimate interests (Article 21 GDPR),
- withdraw consent with effect for the future (Article 7(3) GDPR).
To exercise your rights, a message to the email address stated above is sufficient. Where necessary, we may request additional information to verify your identity.
Right to lodge a complaint
You also have the right to lodge a complaint with a data-protection supervisory authority. In particular, you may contact the authority at your habitual residence, workplace or the place of the alleged infringement. For our registered office, the competent authority is generally the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia.
15. Data security
We use TLS/HTTPS transport encryption and appropriate technical and organisational measures to protect data against loss, manipulation and unauthorised access. These include access and role restrictions, secure password hashes, time-limited tokens, server-side validation, database transactions and regular updates of security-relevant components.
Despite appropriate safeguards, data transmission over the internet cannot be made completely risk-free. Users are responsible for keeping access credentials confidential and using secure, unique passwords.
16. Minors
Contracts, artist accounts and scout accounts are generally intended for adults or persons with valid legal representation. Persons under 18 may use registration-required or payment-related functions only where the necessary consent or representation by a parent or legal guardian is in place.
17. Changes to this privacy policy
We update this policy when functions, service providers or legal requirements change. The version published on this page at the relevant time is authoritative. We will inform registered users in an appropriate manner of material changes affecting them.
Last updated: 26 July 2026
10. External platforms and social-media links
Public artist profiles may contain links to TikTok, Instagram, SoundCloud, YouTube, Spotify, Beatport, Bandcamp or the artist’s own website. According to the current functionality, these are ordinary external links; no connection to the destination platform is established merely by displaying the link.
When you click such a link, you leave our portal. The destination platform receives at least the technically necessary connection data and processes data under its own terms. Depending on the platform, data may be processed in third countries, especially the United States. Please review the respective provider’s privacy information before use.
Links entered by artists are supplied by those artists. We cannot guarantee that external content will remain unchanged or available.