Legal
Privacy Policy
Status: August 2026 · Version 3.0
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Stefan Meyer — ALL AUDIO PRODUCTIONS
Am Neuen Teich 46, 22926 Ahrensburg, Germany
Phone: +49 172 7359898 · Email: info@allaudioproductions.com
A data protection officer is not required by law to be appointed. If you have any questions regarding data protection, please contact the controller directly.
2. Your rights as a data subject
You have the following rights at any time: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21). You may revoke consent given at any time with effect for the future (Art. 7(3)). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in our case, the Independent Centre for Privacy Protection Schleswig-Holstein (ULD) is competent.
3. Provision of the website & server log files
When visiting our website, technically necessary connection data (IP address, date/time, requested resource, data volume transferred, referrer, user agent) is processed by our hosting provider. Processing is carried out to provide the website and ensure system security based on Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation).
Hosting takes place on the edge platform Cloudflare Workers (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses additionally apply. Log files are generally anonymised or deleted after 14 days.
4. Contacting us via email or phone
When you contact us by email or phone, your details will be stored to process the inquiry and in case of follow-up questions. The legal basis is Art. 6 (1) lit. b GDPR (initiation/performance of a contract), and otherwise Art. 6 (1) lit. f GDPR (efficient handling of inquiries). Data will be deleted as soon as the purpose ceases to apply; statutory retention periods remain unaffected.
5. Contact form and project inquiries
Via the form on the page Contact as well as via inquiries regarding exclusive licenses, we process the data you enter: name, email address, project type, requested service, budget range, optional deadline and reference link as well as your message. The sole purpose is processing and answering your inquiry. The legal basis is Art. 6 (1) lit. b GDPR (pre-contractual measures) or Art. 6 (1) lit. f GDPR.
Your inquiry is delivered to us by email; you will automatically receive an acknowledgment of receipt at the address provided. We delete inquiries as soon as they have been conclusively processed and no statutory retention requirements conflict, but at the latest after 24 months.
Protection against abuse: When submitting the form, we briefly process your IP address to limit the number of submissions per sender (spam and abuse prevention). The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in protection against automated mass submissions). The counter values are kept strictly transiently in RAM and discarded after one hour at the latest.
6. Customer account & order processing
To open a customer account and process orders, we process the data provided by you (name, email address, billing address, order history, login data). Processing takes place for contract performance in accordance with Art. 6 (1) lit. b GDPR.
Database and authentication are provided via Supabase (Postgres instance hosted within the EU, operated via Lovable Cloud). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the provider. Customer accounts are stored until deleted by yourself or up to 3 years after the last activity, and subsequently deleted unless statutory retention requirements conflict.
7. Ordering as a guest (without a customer account)
You can place an order without registering. In this case, we process the data required for the contract (email address, billing data, order content) on the basis of Art. 6 (1) lit. b GDPR without creating a login account. To secure access to your order, we generate a random, unguessable token contained exclusively in the order link in your confirmation email. Only persons possessing this link can access order details, downloads, license, and invoice.
If you register later using the same email address, the guest order is automatically assigned to your account so that you can access it permanently. The same retention periods apply to guest orders as to orders from a customer account; invoice-related data is subject to the 10-year tax retention obligation.
8. Payment processing via Stripe
Payments are processed via the payment service provider Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). When accessing the checkout, the data required for payment (name, email, payment data, IP address, amount, order reference) is transmitted directly to Stripe. Payment data (in particular credit card number) is not received by us; this data is processed exclusively by Stripe.
The legal basis is Art. 6 (1) lit. b GDPR (contract performance) as well as Art. 6 (1) lit. f GDPR (secure payment transactions and fraud prevention). Stripe may transmit data to its parent company Stripe, Inc. in the USA; the transfer takes place on the basis of the EU-US Data Privacy Framework and additional standard contractual clauses. Further information: stripe.com/de/privacy.
9. Invoicing via Lexware Office
For the creation and archiving of invoices, we use Lexware Office (Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany). Transmitted to Lexware are the invoice recipient, address, order, and invoice data. The legal basis is Art. 6 (1) lit. c GDPR in conjunction with Sec. 14 UStG, Sec. 147 AO (statutory obligation for invoicing and retention). Invoice data is retained for 10 years in accordance with Sec. 147 AO, Sec. 257 HGB.
10. Verification of the Value Added Tax Identification Number (VIES)
If you specify a VAT identification number as a business customer during the ordering process, we transmit it for validity verification to the MwSt-Informationsaustauschsystem (VIES) of the European Commission (ec.europa.eu). Only the country code and VAT ID are transmitted; we store the response (valid/invalid, company name if applicable) together with the verification timestamp for evidence purposes. The legal basis is Art. 6 (1) lit. c GDPR in conjunction with Sec. 18e UStG or Art. 6 (1) lit. b GDPR, as the verification is a prerequisite for tax-free invoicing under the reverse charge procedure. Verification records are stored within the scope of tax retention periods.
11. Email dispatch (order and system messages)
To send confirmation, invoice, download, account, and newsletter emails, we use the email infrastructure of the Lovable platform, which sends via our verified sender subdomain notify.hub.allaudioproductions.com . Processed in this context are your email address, subject, and content of the message, as well as technical dispatch and delivery information (including delivery errors, bounces, complaints). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the service provider.
The legal basis is Art. 6 (1) lit. b GDPR (contract performance) for order-related messages, Art. 6 (1) lit. a GDPR for the newsletter, and Art. 6 (1) lit. f GDPR for delivery security. Permanently undeliverable addresses are kept on a blocklist to avoid further delivery attempts.
12. Cookies and similar technologies
We use technically necessary cookies and LocalStorage entries to the extent required for the operation of the website and the functions actively requested by you (Section 25 (2) No. 2 TTDSG; legal basis Art. 6 (1) lit. b and f GDPR). This includes in particular storing your cookie consent, login sessions, and Stripe cookies during the checkout process.
Analytics cookies (Google Analytics 4, see Section 13) are set exclusively after your consent. Marketing cookies are currently not used. A detailed list can be found on the page Cookies. You can adjust your settings at any time .
13. Web Analytics with Google Analytics 4
We use Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) for statistical evaluation of website usage to improve content and offerings. Processed data includes shortened IP address, device and browser information, approximate location (country/region), pages visited, duration of stay, referrer, and a pseudonymous user ID in cookies _ga and _ga_<ID>.
This usage takes place exclusively on the basis of your consent (Section 25 (1) TTDSG, Art. 6 (1) lit. a GDPR). Without consent, the analytics script will not be loaded and no analytics cookies will be set. We have activated IP anonymization; Google signals, advertising features, and remarketing are disabled.
A transfer of data to Google LLC in the USA cannot be ruled out; it takes place on the basis of the EU-US Data Privacy Framework as well as supplementary standard contractual clauses. A data processing agreement pursuant to Art. 28 GDPR has been concluded with Google. The storage period for analytics data in Google Analytics is limited to 14 months.
You can revoke your consent at any time with future effect via the revoke. In this case, tracking will be disabled immediately and any set analytics cookies will be deleted. Further information: policies.google.com/privacy.
13a. Course videos via Cloudflare Stream
Videos of our online courses are delivered via Cloudflare Stream (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Playback takes place via the domains videodelivery.net or iframe.videodelivery.net. Technically required data such as IP address, timestamp, browser/device information, and the accessed video stream are processed to deliver the video and secure access. The legal basis is Art. 6 para. 1 lit. b GDPR (provision of the purchased course). A data processing agreement exists with Cloudflare; transfers to the USA take place on the basis of the EU-US Data Privacy Framework as well as supplementary Standard Contractual Clauses.
13b. Appointment management with Google Calendar and Google Meet
For coaching sessions, we can connect the coach's calendar to Google Calendar / Google Meet (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland) at the request of the respective coach. If this connection is used, the appointment data required for scheduling and creating a video conference link is transmitted to Google: appointment date and time, duration, appointment title, participant email addresses, and the generated meeting link. The legal basis is Art. 6 para. 1 lit. b GDPR (performance of the booked appointment). Without a connected Google account, no transmission takes place; the appointment is then organized without Google services.
13c. Publishing on YouTube
To market our own productions, we use an upload interface to YouTube (Google Ireland Limited). Only content and metadata created by us for our own channel are transferred — no YouTube videos are embedded on this website and no data is transmitted to YouTube when visiting this website.
14. Fonts
Fonts are served locally from our server (self-hosting via @fontsource). There is no connection to Google Fonts or other external font CDNs.
15. Delivery of Digital Content (Downloads)
Purchased beat files as well as license and invoice PDFs are provided from our Object Storage (Supabase Storage, EU). Logged-in customers access them permanently via their account; for guest orders, we generate signed, temporarily valid download links. The processing of the data required for this (order ID, buyer or guest token, timestamp) is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.
16. Newsletter (Double Opt-in)
During the checkout process, you can voluntarily consent, without preselection, to receive our email newsletter with news about new beats and offers. The legal basis is your consent pursuant to Art. 6 Para. 1 lit. a GDPR in conjunction with § 7 Para. 2 No. 3 UWG.
We use the double opt-in procedure: After purchase, you will receive an email containing a confirmation link. You will only be added to the mailing list after clicking this link. Stored data includes your email address, subscription status, time of registration and confirmation, the wording of the consent, and the associated order ID — this serves as proof of consent.
You can revoke your consent at any time with effect for the future, via the unsubscribe link in any newsletter email or informally by email to us. After unsubscribing, we store your address exclusively in a blocklist to prevent further sendouts. If you do not confirm your registration, we will not send you any newsletter.
17. Use of AI Systems
In our internal editorial area, we use AI-supported text generation to create product descriptions and license explanations. Only product data (e.g. title, BPM, key, genre) is transmitted to the AI service. Personal data of customers is not transferred to AI services and is not used for training.
17a. Vocal Coaching and Bookings
For coaching inquiries, paid vocal analysis, bookings, and session packages, we process: contact details, information from the inquiry/intake form (including experience level, goals, music style, voluntary information about the voice), booked time slots, appointment and status history, cancellations/reschedulings, as well as the analysis results and internal follow-up. The legal basis is Art. 6(1)(b) GDPR (contract initiation and performance); voluntary additional information is based on Art. 6(1)(a) GDPR.
Health-related information is not required for coaching; please share such information only if you explicitly wish to do so (in which case Art. 9(2)(a) GDPR applies). Coaching data is stored for the duration of the customer relationship and subsequently for a maximum of 3 years; billing-relevant data is subject to the statutory 10-year tax retention period.
If an online session takes place via video conference, you will receive the access link via email; we do not record sessions unless explicit and separate consent is given.
17b. On-site Workshops
For workshop inquiries, we process: organization/church, contact person, contact details, venue location and address, preferred dates, group size and type, core topics, and information required for quote calculation (travel, accommodation needs). The legal basis is Art. 6(1)(b) GDPR. We use location data exclusively for calculation and execution; no movement profiling takes place. Inquiries without contract conclusion are deleted after 24 months at the latest.
17c. Studio Services (File Uploads, Review, Revisions)
In the context of mixing, mastering, and production orders, we process your uploaded audio files and project data, your comments in the review player (including timestamps), version and approval statuses, and the project history. The legal basis is Art. 6(1)(b) GDPR. The files are stored in a private, non-publicly accessible storage area (Supabase Storage, EU); access is restricted to authorized persons via row-level security.
Project files are retained for 90 days after completion of the project and then deleted; prior to expiration, we will remind you by email so you can back up your files. We strongly recommend making your own backup.
17d. Licenses and Proof of License
For beats, stems/multitracks, and sample packs, we generate license documents containing your name or company name, order number, selected license tier, and license scope at the time of purchase. We process this documentation for contract fulfillment (Art. 6(1)(b) GDPR) and to comply with legal verification obligations (Art. 6(1)(c) and (f) GDPR) and retain them within statutory periods.
17e. Reviews and Account Features (Badges)
Product reviews can only be submitted following a verified purchase. Published data includes your specified display name, rating, text, and date; linking to the order serves exclusively to verify the purchase. The legal basis is Art. 6(1)(a) GDPR (publication) and Art. 6(1)(f) GDPR (authenticity verification, prohibition of fake reviews). You can revoke publication at any time; we will then remove the review.
In the customer account, we display voluntary progress badges calculated from your order and usage data. This display is visible only to you, serves user convenience (Art. 6(1)(f) GDPR), and has no legal or financial consequences.
17f. Roles, Assistants, and Internal Access
Access to customer data in the backend is restricted based on roles. Coaches and providers only see inquiries and appointments assigned to them; persons acting as assistants (role "Editor") exclusively see data of the providers assigned to them. Product partners see exclusively aggregated revenue data for their own products, no customer identities. For support purposes, Super Admins can access a read-only view of a customer account; changes and downloads are technically disabled in this mode and the action is logged. Legal basis is Art. 6(1)(b) and (f) GDPR.
17g. Legal Consents, Revocations, and Logging
For verification purposes, we store your confirmations provided during checkout (Terms, Privacy Policy, explicit request for early commencement of performance) in an audit-proof manner including wording, timestamp, context, and order reference. If you submit a revocation via our electronic revocation feature, we additionally store the content of your declaration, date and time of receipt, abbreviated browser/device details, and a hashed IP address. The legal basis is Art. 6(1)(c) GDPR (statutory verification and confirmation obligations, including Sections 312f, 355, 356a BGB) and Art. 6(1)(f) GDPR (preservation of evidence). These records are stored until the expiration of statutory limitation and retention periods.
Security-relevant actions in the backend (e.g., role changes, refunds, approvals) are recorded in an internal log to detect abuse and ensure traceability (Art. 6(1)(f) GDPR).
18. Data Security
Transmission to and from our website is TLS-encrypted throughout. Access to personal data in the database is restricted to the respective authorized user via row-level security rules. Administrative access is additionally protected by password and, if applicable, multi-factor authentication.
19. Validity and Changes to this Privacy Policy
This privacy policy is currently valid. Due to the further development of our website or changed legal or regulatory requirements, it may become necessary to amend this policy. The current version can be accessed on this page.