Privacy Policy
What we do with personal data, and which of us is answerable for it.
- Effective:
- Last updated:
We are the controller of the data we hold about account holders, billing contacts, and visitors to this website. We decide why and how that data is used, and this policy explains it.
For data about listeners flowing through a customer’s station, the customer is the controller and we act only as their processor, on their instructions. If you are a listener with a question about a station, ask the station operator — the Data Processing Addendum governs what we do with that data on their behalf.
The summary above is provided for convenience only. Where it differs from the full text of this document, the full text governs.
1. Who we are and what this covers
TODO_LEGAL: registered company name (e.g. "RadioHeart Ltd") (“RadioHeart”, “we”, “us”), registered under number TODO_LEGAL: company registration number at TODO_LEGAL: registered office street address, TODO_LEGAL: city, postal code, TODO_LEGAL: country of incorporation, operates this website and the RadioHeart platform.
This policy covers personal data we handle as a controller: data about people who visit radioheart.io, create or administer an account, hold a subscription, contact support, or otherwise deal with us directly. It does not cover the practices of any customer’s station, nor of any third-party platform you reach through a link.
2. Our role: controller for some data, processor for the rest
- We are controller for
- Account and profile data, subscription and billing records, support correspondence, security and audit logs of platform administration, and analytics about visitors to radioheart.io.
- We are processor for
- Personal data that a customer routes through the service in operating their station — listener connection data, chat messages and moderation records, station-level audience analytics, and anything the customer uploads that contains personal data.
- The customer is responsible for
- Having a lawful basis for the listener data it collects, publishing its own privacy notice to its listeners, obtaining any consents required, and answering data-subject requests addressed to it. See the Data Processing Addendum and the Acceptable Use Policy.
If you are a listener and your question concerns a particular station, contact that station’s operator. Where we receive such a request directly, we pass it to the relevant customer and assist them in responding, as our processor obligations require.
3. Personal data we collect, and where it comes from
- Account data
- Name, email address, password credentials (stored hashed), organisation name, role, station names and settings, and the preferences you set. Provided by you.
- Billing data
- Plan, billing period, billing address, tax and VAT identifiers, invoices, and payment status. Card details are entered directly with our payment processor and are not stored by us. Provided by you and by the processor.
- Support and correspondence
- Messages you send us, the contents of support tickets, and records of what we did in response. Provided by you.
- Usage and technical data
- Log records of platform actions — sign-ins, configuration changes, uploads, broadcast starts and stops — together with IP address, device and browser type, and timestamps. Collected automatically.
- Website analytics
- Aggregated, cookieless measurement of page views and performance for radioheart.io (see the Cookie Policy for exactly what runs). Collected automatically.
- Marketing data
- Where you subscribe to updates: your email address, subscription status, and whether messages were opened. Provided by you.
We do not seek special-category data (health, religion, political opinions, biometrics, and similar) and ask that you do not send it to us. We do not buy personal data from data brokers.
4. Why we use it, and our legal bases
- To provide the service
- Creating and running your account, hosting your stations, delivering streams, and providing support. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- To take payment
- Billing, invoicing, tax accounting, and collections. Legal basis: performance of a contract and compliance with a legal obligation (Art. 6(1)(b) and (c)).
- To keep the service secure and reliable
- Detecting abuse, fraud, and attacks; monitoring capacity; investigating incidents; enforcing our Terms and the Acceptable Use Policy. Legal basis: legitimate interests in operating a secure service (Art. 6(1)(f)).
- To improve the service
- Understanding aggregate usage and performance so we can prioritise work. Legal basis: legitimate interests (Art. 6(1)(f)).
- To communicate with you
- Service messages about availability, security, billing, and changes to terms. Legal basis: performance of a contract and legitimate interests (Art. 6(1)(b) and (f)).
- To send marketing
- Product news and offers, only where you have asked for them or where a soft opt-in applies. Legal basis: consent, or legitimate interests where permitted (Art. 6(1)(a) or (f)). You can unsubscribe from every marketing message.
- To meet legal obligations
- Responding to lawful requests, keeping accounting records, and handling copyright notices. Legal basis: legal obligation and, for the establishment or defence of legal claims, legitimate interests (Art. 6(1)(c) and (f)).
Where we rely on legitimate interests, we have considered the impact on you and concluded that the processing is proportionate and would be expected. You can object — see your rights below — and we will stop unless we have compelling grounds that override your interests.
6. Categories of service providers
- Cloud hosting and storage
- Running the platform, storing media, and holding backups.
- Content delivery and streaming
- Distributing streams and static assets to listeners.
- Payment processing
- Taking card payments, issuing invoices, and handling tax calculation.
- Transactional and marketing email
- Delivering service notices and, where you have opted in, product updates.
- Support tooling
- Managing support conversations and their history.
- Product and website analytics
- Aggregated usage and performance measurement.
- Error monitoring and logging
- Capturing diagnostics so faults can be found and fixed.
- Named list
- TODO_LEGAL: DPO or Art. 27 representative name and contact — the current named sub-processor list is maintained under the Data Processing Addendum and is available on request.
Every provider is bound by a written contract limiting them to processing on our instructions, with confidentiality and security obligations at least as protective as those in this policy.
7. International transfers
We and our providers may process personal data outside the country where you are located, including outside the European Economic Area and the United Kingdom.
Where we transfer personal data out of the EEA or the UK to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with a transfer risk assessment and any supplementary technical and organisational measures the assessment identifies. You can request a copy of the safeguards we rely on using the contact details below.
8. How long we keep it
- Account data
- For the life of the account, then deleted or anonymised within 90 days of closure.
- Media and station configuration
- For the life of the account; deleted after closure subject to the backup cycle below.
- Billing and tax records
- For the period required by tax and accounting law in the relevant jurisdiction — commonly six to ten years.
- Support correspondence
- Up to 24 months after the ticket is closed.
- Security and audit logs
- Typically 12 months, longer where an investigation or legal claim requires it.
- Backups
- Expire on their ordinary rotation, normally within 35 days of deletion from the live systems.
- Marketing data
- Until you unsubscribe, plus a suppression record kept so we do not contact you again.
Where a legal claim, regulatory request, or copyright dispute is live, we keep the relevant records until it is resolved.
9. Security
We maintain technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption at rest for stored media and backups, role-based access control with least privilege, credential hashing, network segmentation, logging and monitoring, vulnerability patching, backup and restore procedures, staff confidentiality obligations, and a documented incident-response process.
No system is perfectly secure. You are responsible for the security of your own credentials and for who you give access to your account. If we become aware of a personal-data breach affecting data we control, we notify the competent supervisory authority and, where required, affected individuals, within the timescales the law sets.
10. Your rights under GDPR and UK GDPR
Where we are the controller and the GDPR or UK GDPR applies to you, you have the right to:
- be told what we hold about you, and obtain a copy of it (access);
- have inaccurate data corrected and incomplete data completed (rectification);
- have data deleted where there is no continuing basis to keep it (erasure);
- have processing restricted while a dispute about accuracy or basis is resolved (restriction);
- receive data you provided in a structured, machine-readable format and have it sent to another controller where technically feasible (portability);
- object to processing based on legitimate interests, and to object to direct marketing at any time and without giving a reason;
- withdraw consent at any time, where consent is the basis, without affecting processing already carried out.
To exercise any of these, email support@radioheart.io. We respond within one month, extendable by two further months for complex requests, and we will tell you if an extension applies. We may ask for information to verify your identity. Exercising these rights is free unless a request is manifestly unfounded or excessive.
11. Your rights under US state privacy law
If you are a resident of California or of another US state with a comprehensive privacy law, you may have the right to know what personal information we collect and for what purposes, to obtain a copy of it, to have it corrected or deleted, to limit the use of sensitive personal information, and not to be discriminated against for exercising those rights.
Submit a request to support@radioheart.io. An authorised agent may submit on your behalf with written proof of authority. We verify requests against the information we already hold before acting on them.
12. Complaints
If you are unhappy with how we have handled your personal data, please tell us first at support@radioheart.io so we can try to put it right. You also have the right to complain to a supervisory authority — in our case TODO_LEGAL: lead supervisory authority for the establishment — or to the authority in the country where you live or work, or where the alleged infringement took place.
13. Children
The service is not directed at children, and accounts may only be opened by adults. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Where a customer operates a station for a school, youth group, or similar setting, that customer is the controller for any data it collects from young listeners and is responsible for the additional protections that context requires.
14. Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22 GDPR. Automated checks used for fraud and abuse prevention are reviewed by a person before any account is closed on their basis.
15. Changes to this policy
We update this policy as the service and the law change. The version in force is the one published here, with its revision date shown at the top. Where a change materially affects how we use personal data, we give notice by email or in the service before it takes effect.
Contact
For privacy questions, data-subject requests, and requests for a copy of our transfer safeguards:
- support@radioheart.io
- Data protection contact
- TODO_LEGAL: DPO or Art. 27 representative name and contact
- Entity
- TODO_LEGAL: registered company name (e.g. "RadioHeart Ltd")
- Registered office
- TODO_LEGAL: registered office street address, TODO_LEGAL: city, postal code, TODO_LEGAL: country of incorporation
- Supervisory authority
- TODO_LEGAL: lead supervisory authority for the establishment