Skip to content

Legal

Privacy Policy

As of: July 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Stefan Meyer — ALL AUDIO PRODUCTIONS
Am Neuen Teich 46, 22926 Ahrensburg, Germany
Phone: +49 172 7359898 · Email: info@allaudioproductions.com

A data protection officer is not required by law to be appointed. If you have any questions regarding data protection, please contact the controller directly.

2. Your rights as a data subject

You have the following rights at any time: access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing based on Art. 6(1)(e) or (f) GDPR (Art. 21). You may revoke consent given at any time with effect for the future (Art. 7(3)). You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR) — in our case, the Independent Centre for Privacy Protection Schleswig-Holstein (ULD) is competent.

3. Provision of the website & server log files

When visiting our website, technically necessary connection data (IP address, date/time, requested resource, data volume transferred, referrer, user agent) is processed by our hosting provider. Processing is carried out to provide the website and ensure system security based on Art. 6(1)(f) GDPR (legitimate interest in stable and secure operation).

Hosting takes place on the edge platform Cloudflare Workers (Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA). Cloudflare is certified under the EU-US Data Privacy Framework; standard contractual clauses additionally apply. Log files are generally anonymised or deleted after 14 days.

4. Contacting us via email or phone

When you contact us by email or phone, your details will be stored to process the inquiry and in case of follow-up questions. The legal basis is Art. 6 (1) lit. b GDPR (initiation/performance of a contract), and otherwise Art. 6 (1) lit. f GDPR (efficient handling of inquiries). Data will be deleted as soon as the purpose ceases to apply; statutory retention periods remain unaffected.

5. Contact form and project inquiries

Via the form on the page Contact as well as via inquiries regarding exclusive licenses, we process the data you enter: name, email address, project type, requested service, budget range, optional deadline and reference link as well as your message. The sole purpose is processing and answering your inquiry. The legal basis is Art. 6 (1) lit. b GDPR (pre-contractual measures) or Art. 6 (1) lit. f GDPR.

Your inquiry is delivered to us by email; you will automatically receive an acknowledgment of receipt at the address provided. We delete inquiries as soon as they have been conclusively processed and no statutory retention requirements conflict, but at the latest after 24 months.

Protection against abuse: When submitting the form, we briefly process your IP address to limit the number of submissions per sender (spam and abuse prevention). The legal basis is Art. 6 (1) lit. f GDPR (legitimate interest in protection against automated mass submissions). The counter values are kept strictly transiently in RAM and discarded after one hour at the latest.

6. Customer account & order processing

To open a customer account and process orders, we process the data provided by you (name, email address, billing address, order history, login data). Processing takes place for contract performance in accordance with Art. 6 (1) lit. b GDPR.

Database and authentication are provided via Supabase (Postgres instance hosted within the EU, operated via Lovable Cloud). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the provider. Customer accounts are stored until deleted by yourself or up to 3 years after the last activity, and subsequently deleted unless statutory retention requirements conflict.

7. Ordering as a guest (without a customer account)

You can place an order without registering. In this case, we process the data required for the contract (email address, billing data, order content) on the basis of Art. 6 (1) lit. b GDPR without creating a login account. To secure access to your order, we generate a random, unguessable token contained exclusively in the order link in your confirmation email. Only persons possessing this link can access order details, downloads, license, and invoice.

If you register later using the same email address, the guest order is automatically assigned to your account so that you can access it permanently. The same retention periods apply to guest orders as to orders from a customer account; invoice-related data is subject to the 10-year tax retention obligation.

8. Payment processing via Stripe

Payments are processed via the payment service provider Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland). When accessing the checkout, the data required for payment (name, email, payment data, IP address, amount, order reference) is transmitted directly to Stripe. Payment data (in particular credit card number) is not received by us; this data is processed exclusively by Stripe.

The legal basis is Art. 6 (1) lit. b GDPR (contract performance) as well as Art. 6 (1) lit. f GDPR (secure payment transactions and fraud prevention). Stripe may transmit data to its parent company Stripe, Inc. in the USA; the transfer takes place on the basis of the EU-US Data Privacy Framework and additional standard contractual clauses. Further information: stripe.com/de/privacy.

9. Invoicing via Lexware Office

For the creation and archiving of invoices, we use Lexware Office (Haufe-Lexware GmbH & Co. KG, Munzinger Straße 9, 79111 Freiburg, Germany). Transmitted to Lexware are the invoice recipient, address, order, and invoice data. The legal basis is Art. 6 (1) lit. c GDPR in conjunction with Sec. 14 UStG, Sec. 147 AO (statutory obligation for invoicing and retention). Invoice data is retained for 10 years in accordance with Sec. 147 AO, Sec. 257 HGB.

10. Verification of the Value Added Tax Identification Number (VIES)

If you specify a VAT identification number as a business customer during the ordering process, we transmit it for validity verification to the MwSt-Informationsaustauschsystem (VIES) of the European Commission (ec.europa.eu). Only the country code and VAT ID are transmitted; we store the response (valid/invalid, company name if applicable) together with the verification timestamp for evidence purposes. The legal basis is Art. 6 (1) lit. c GDPR in conjunction with Sec. 18e UStG or Art. 6 (1) lit. b GDPR, as the verification is a prerequisite for tax-free invoicing under the reverse charge procedure. Verification records are stored within the scope of tax retention periods.

11. Email dispatch (order and system messages)

To send confirmation, invoice, download, account, and newsletter emails, we use the email infrastructure of the Lovable platform, which sends via our verified sender subdomain notify.hub.allaudioproductions.com . Processed in this context are your email address, subject, and content of the message, as well as technical dispatch and delivery information (including delivery errors, bounces, complaints). A data processing agreement pursuant to Art. 28 GDPR has been concluded with the service provider.

The legal basis is Art. 6 (1) lit. b GDPR (contract performance) for order-related messages, Art. 6 (1) lit. a GDPR for the newsletter, and Art. 6 (1) lit. f GDPR for delivery security. Permanently undeliverable addresses are kept on a blocklist to avoid further delivery attempts.

12. Cookies and similar technologies

We exclusively use technically necessary cookies and LocalStorage entries required for operating the website and the functions actively requested by you (Sec. 25 (2) TTDSG; legal basis Art. 6 (1) lit. b and f GDPR). These include, in particular, storing your cookie consent, login sessions, and Stripe cookies during the payment process.

Analytics or marketing cookies are currently not used. A detailed list can be found on the page Cookies. You can adjust your settings at any time .

13. Fonts

Fonts are served locally from our server (self-hosting via @fontsource). There is no connection to Google Fonts or other external font CDNs.

14. Delivery of Digital Content (Downloads)

Purchased beat files as well as license and invoice PDFs are provided from our Object Storage (Supabase Storage, EU). Logged-in customers access them permanently via their account; for guest orders, we generate signed, temporarily valid download links. The processing of the data required for this (order ID, buyer or guest token, timestamp) is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.

15. Newsletter (Double Opt-In)

During the checkout process, you can voluntarily consent, without preselection, to receive our email newsletter with news about new beats and offers. The legal basis is your consent pursuant to Art. 6 Para. 1 lit. a GDPR in conjunction with § 7 Para. 2 No. 3 UWG.

We use the double opt-in procedure: After purchase, you will receive an email containing a confirmation link. You will only be added to the mailing list after clicking this link. Stored data includes your email address, subscription status, time of registration and confirmation, the wording of the consent, and the associated order ID — this serves as proof of consent.

You can revoke your consent at any time with effect for the future, via the unsubscribe link in any newsletter email or informally by email to us. After unsubscribing, we store your address exclusively in a blocklist to prevent further sendouts. If you do not confirm your registration, we will not send you any newsletter.

16. Use of AI Systems

In our internal editorial area, we use AI-supported text generation to create product descriptions and license explanations. Only product data (e.g. title, BPM, key, genre) is transmitted to the AI service. Personal data of customers is not transmitted to AI services and is not used for training.

17. Data Security

Transmission to and from our website is TLS-encrypted throughout. Access to personal data in the database is restricted to the respective authorized user via row-level security rules. Administrative access is additionally protected by password and, if applicable, multi-factor authentication.

18. Timeliness and Changes to This Privacy Policy

This privacy policy is currently valid. Due to the further development of our website or changed legal or regulatory requirements, it may become necessary to amend this policy. The current version can be accessed on this page.