GDPR Summary
Version 6.1 | Effective Date: 20 July 2026 | Supersedes Version 5.0 (15 January 2026)
This policy applies during the initial Resomix production beta and may be updated as the Service develops.
Related Documents: This document should be read in conjunction with our Terms of Service, Privacy Policy, Cookie Policy, Refund Policy, Copyright & DMCA Policy, Acceptable Use Policy, Platform Disclaimer, and Music Content & Licensing Transparency Policy, all available from the Resomix legal hub at /legal
1. INTRODUCTION AND PURPOSE
Section titled “1. INTRODUCTION AND PURPOSE”1.1 About This Summary
Section titled “1.1 About This Summary”This GDPR Compliance Summary provides an accessible overview of how Resomix (operated by Reform Studios, a company registered in Greece operating under the trade name Resomix) processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Greek data protection law, including Law 4624/2019. Resomix is live in production as a beta service during its initial three-month beta period. Depending on the user’s access level, the Service may include Sonic Discovery, Track Intelligence, Catalogue Intelligence and authorised Discovery API functionality for catalogue ingestion and similarity retrieval, together with customer-authorised Private Resomix Libraries and partner catalogue processing. Resomix searches its own pre-analysed sonic index. Apple MusicKit supports catalogue metadata, previews and authorised playback presentation within the current beta experience. Apple MusicKit does not perform PYXIS-1 analysis, generate Resomix sonic profiles or calculate Resomix similarity rankings. This Summary is a plain-language overview; the Privacy Policy is the controlling detailed notice.
1.2 Our Commitment
Section titled “1.2 Our Commitment”Resomix is committed to protecting the privacy and security of our users’ personal data. We process data lawfully, fairly, and transparently, collecting only what is necessary for our legitimate purposes and ensuring appropriate security measures are in place.
2. DATA CONTROLLER INFORMATION
Section titled “2. DATA CONTROLLER INFORMATION”The data controller responsible for your personal data is:
Reform Studios, operating under the trade name Resomix, Sokratous 8, Kalamaria, 551 34 Thessaloniki, Greece | Legal: [email protected] | Privacy Inquiries: [email protected] | Website: www.resomix.com
Data Protection Officer (DPO) Assessment: We have assessed our processing activities in accordance with Article 37 GDPR and determined that the appointment of a DPO is not mandatory at this time. All privacy inquiries are managed directly by our designated privacy team at the email above. This assessment will be revisited as commercial processing volumes grow.
3. PERSONAL DATA WE COLLECT
Section titled “3. PERSONAL DATA WE COLLECT”3.1 Categories of Personal Data
Section titled “3.1 Categories of Personal Data”We collect and process the following categories of personal data:
Account Information:
Email address
Username or display name
Account credentials (encrypted)
Account preferences and settings
Subscription and Billing Data (where paid checkout is active):
Subscription plan, billing period, and subscription status
Transaction and invoice records (amount, date, VAT country/rate, invoice number)
VAT/tax identification number (business customers, for reverse-charge purposes)
Payment method reference data provided by our payment provider (e.g., card brand and last four digits). We do NOT store full card details — payment is processed by our payment provider (see Section 10A)
Usage Data:
Listening history and playback data
Playlist creation and management activity
Search queries and discovery interactions
Feature usage patterns
Technical Data:
IP address
Browser type and version
Device information and identifiers
Cookies and similar technologies (see our Cookie Policy)
Audio Upload Data:
Temporary Reference Uploads: audio submitted for one-off similarity or Track Intelligence analysis. Audio submitted as a Temporary Reference Upload is retained only for processing and deleted no later than 24 hours after upload or analysis; it is not made publicly available, is not accessible to other users, and is not used to train or fine-tune PYXIS-1. Temporary previews and processing artefacts are retained only for as long as reasonably necessary to provide, troubleshoot and secure the requested processing.
Private Resomix Library audio: may be retained for the duration necessary to provide the user-authorised catalogue-analysis and discovery service; deletion may follow a user removal request, Private Library deletion, account termination, or the applicable account-retention schedule.
Partner catalogue content: may be retained and processed for the duration and purposes authorised by the applicable partner agreement; it is logically isolated and restricted to authorised access.
Derived sonic-profile data: PYXIS-1 creates a numerical sonic profile from analysed audio. The derived sonic profile is created for analysis and similarity retrieval and is not intended to function as a playable substitute for the source recording. Retention is described in Section 6.
3.2 Data We Do Not Collect
Section titled “3.2 Data We Do Not Collect”We do not collect: full payment card numbers or card security codes (where paid checkout is active, payments are processed by our payment provider under its own PCI-DSS compliant infrastructure); government-issued identification; sensitive personal data as defined under Article 9 GDPR (including racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sexual orientation); precise geolocation data; or data from third-party social media profiles.
4. LEGAL BASES FOR PROCESSING
Section titled “4. LEGAL BASES FOR PROCESSING”We process your personal data under the following legal bases as specified in Article 6 GDPR:
| Legal Basis | Processing Purposes |
|---|---|
| Contract Performance (Art. 6(1)(b)) | Account creation and management; providing core platform functionality; processing of Temporary Reference Uploads and Private Library audio to deliver the requested analysis and discovery services; subscription and billing management where paid plans are active (plan administration, renewals, cancellations, refunds); playlist creation and sharing features |
| Legitimate Interests (Art. 6(1)(f)) | Platform security and fraud prevention; service improvement and analytics; responding to legal requests; protecting our intellectual property |
| Consent (Art. 6(1)(a)) | Marketing communications (where applicable); non-essential cookies and first-party analytics; participation in surveys or feedback programs |
| Legal Obligation (Art. 6(1)(c)) | Tax and accounting obligations — invoices and related billing records are retained for the period required under applicable law; responding to court orders or regulatory requests; copyright compliance |
5. YOUR RIGHTS UNDER GDPR
Section titled “5. YOUR RIGHTS UNDER GDPR”As a data subject, you have the following rights under the GDPR. To exercise any of these rights, contact us at [email protected].
5.1 Right of Access (Article 15)
Section titled “5.1 Right of Access (Article 15)”You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with information about processing purposes, categories of data, recipients, retention periods, and the source of the data. Please note that, because Temporary Reference Upload source audio is deleted no later than 24 hours after upload or analysis, it may already have been deleted before an access request is received. In such cases, we will confirm the deletion and provide any remaining data associated with your account.
5.2 Right to Rectification (Article 16)
Section titled “5.2 Right to Rectification (Article 16)”You have the right to have inaccurate personal data corrected without undue delay. You also have the right to have incomplete personal data completed.
5.3 Right to Erasure (Article 17)
Section titled “5.3 Right to Erasure (Article 17)”You have the right to request deletion of your personal data in certain circumstances, including when the data is no longer necessary for its original purpose, when you withdraw consent, or when the data has been unlawfully processed. Note that invoicing and tax records may be retained after account deletion where required by applicable tax law (Article 17(3)(b) GDPR).
5.4 Right to Restriction (Article 18)
Section titled “5.4 Right to Restriction (Article 18)”You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of the data or when processing is unlawful but you prefer restriction over erasure.
5.5 Right to Data Portability (Article 20)
Section titled “5.5 Right to Data Portability (Article 20)”You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where processing is based on consent or contract and carried out by automated means.
5.6 Right to Object (Article 21)
Section titled “5.6 Right to Object (Article 21)”You have the right to object, on grounds relating to your particular situation, to processing based on legitimate interests (Article 6(1)(f)), and to object at any time to processing for direct marketing purposes. Where you object to direct marketing, we will stop that processing without exception. Temporary Reference Upload source audio is deleted no later than 24 hours after upload or analysis and may no longer exist at the time an objection is received.
5.7 Right to Withdraw Consent
Section titled “5.7 Right to Withdraw Consent”Where processing is based on consent, you have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5.8 Right to Lodge a Complaint
Section titled “5.8 Right to Lodge a Complaint”You have the right to lodge a complaint with a supervisory authority pursuant to Article 77 GDPR. For users in Greece, the relevant authority is the Hellenic Data Protection Authority (HDPA/ΑΠΔΠΧ) at www.dpa.gr. EU residents may also contact their local data protection authority.
6. DATA RETENTION
Section titled “6. DATA RETENTION”We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements:
Account data: Retained for the duration of the active account and for 30 days following a deletion request, plus any additional period required to comply with legal obligations.
Billing and invoice records: Where paid checkout is active, retained for the period required under applicable tax and accounting law, including after account deletion where the law requires it.
Consent records: Cookie-consent choices and, where paid checkout is active, checkout consent records are retained for the duration of the account plus the period necessary to evidence compliance.
Usage data: Up to 24 months, then anonymised or deleted.
Temporary Reference Uploads (source audio): Deleted no later than 24 hours after upload or analysis.
Temporary previews and processing artefacts: Retained only for as long as reasonably necessary to provide, troubleshoot and secure the requested processing.
Private Resomix Library audio: Retained for the duration necessary to provide the user-authorised catalogue-analysis and discovery service; deleted following a user removal request, Private Library deletion, account termination, or the applicable account-retention schedule.
Partner catalogue content: Retained and processed for the duration and purposes authorised by the applicable partner agreement and Data Processing Addendum.
Saved analysis results and discovery records (Track Intelligence reports, saved analysis history, playlists, user preferences, exported reports): Retained until the user deletes them, closes the relevant Library or account, or the applicable retention period expires.
Unsaved one-off analysis results (including sonic profiles and similarity results from Temporary Reference Uploads): May be retained temporarily for service delivery, troubleshooting and security.
Communication records: Up to 36 months.
Processing and security logs: Typically up to 90 days, unless needed longer for security investigations or legal obligations.
Cookie data: Session cookies are deleted when the browser closes; other cookie durations are listed in the Cookie Policy.
7. DATA SECURITY MEASURES
Section titled “7. DATA SECURITY MEASURES”We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures include:
TLS on public service endpoints
Encrypted HLS for controlled media delivery
Logical isolation of partner catalogues, restricted to authorised partner access
Access controls that restrict systems and data according to account and service roles
Backup controls that are partially implemented and continue to develop during the beta period
Incident-response and breach-notification procedures in accordance with Articles 33 and 34 GDPR
We review and strengthen these measures as the Service develops.
7A. Data Breach Notification
Section titled “7A. Data Breach Notification”In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, Resomix will notify the Hellenic Data Protection Authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay in accordance with Article 34 GDPR, describing the nature of the breach, likely consequences, and measures taken or proposed to address it.
8. INTERNATIONAL DATA TRANSFERS
Section titled “8. INTERNATIONAL DATA TRANSFERS”Resomix is based in Greece within the European Economic Area (EEA). Where we transfer personal data outside the EEA — including transfers connected to global content-delivery and security services and, where paid checkout is active, payment processing — we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR, including:
Transfers to countries with an adequacy decision from the European Commission
Standard Contractual Clauses approved by the European Commission
Other appropriate safeguards as permitted under Chapter V of the GDPR
You may request a copy of the safeguards we use for international transfers by contacting [email protected].
9. AUTOMATED DECISION-MAKING AND ALGORITHMIC PROCESSING
Section titled “9. AUTOMATED DECISION-MAKING AND ALGORITHMIC PROCESSING”Resomix uses proprietary algorithmic technology (our PYXIS-1 engine) to analyse audio characteristics and provide music recommendations. This processing:
Analyses over 70 distinct sonic characteristics of audio (including spectral profile, energy, rhythm, timbre, and harmony) and may segment audio into structural sections (e.g., intro, drop, outro) to identify similar tracks with enhanced precision
Is used solely to enhance your music discovery experience
Uses an engine that was developed and tuned over approximately one year using openly licensed CC BY 4.0 test material
PYXIS-1 is not a trained machine-learning model or neural-network system: it does not train or fine-tune itself using user or partner audio, does not adapt from user interactions, and does not generate, synthesise or recreate audio. The same source audio processed with the same PYXIS-1 version and processing configuration produces the same sonic profile; similarity rankings are reproducible against the same index version and ranking configuration, and results may change when the searchable catalogue, index or engine version is updated. Music recommendations are provided to enhance your discovery experience; they do not restrict your access to the Service and are not used to make decisions about you outside the Service.
Recommendations are generated algorithmically based on audio analysis and are not influenced by marketing budgets, chart positions, or commercial relationships unless explicitly stated.
10. THIRD-PARTY DATA SHARING
Section titled “10. THIRD-PARTY DATA SHARING”We may share personal data with the following categories of third parties, subject to appropriate safeguards:
**Service Providers: **Hosting and infrastructure providers, payment processors (where paid checkout is active), and analytics and email providers who process data on our behalf under appropriate agreements (see Section 10A).
Legal Authorities: Where required by law, court order, or to protect our legal rights.
Business Partners: With your consent where required, we may share data with licensing partners or distributors for purposes of content delivery under data processing agreements compliant with Article 28 GDPR.
We do not sell personal data to third parties.
10A. Service Providers
Section titled “10A. Service Providers”| Provider | Purpose | Location / role |
|---|---|---|
| Alwyzon | Application, account and API infrastructure | Austria |
| Hetzner | Audio processing, media and related infrastructure | Germany |
| Cloudflare | DNS, content delivery, traffic security and edge services | Global service provider |
| Google Workspace | Business and transactional email administration | Google service |
| Stripe Payments Europe | Payment processing when paid checkout is active | EEA payment provider |
| Self-hosted PostHog | First-party product analytics where consent applies | Operated on Resomix-controlled infrastructure |
| Ghost | Self-hosted publishing software | Operated on Resomix-controlled infrastructure |
We will update this list when providers change and, where required, provide notice of material changes. Self-hosted components (PostHog, Ghost) run on Resomix-controlled infrastructure with the infrastructure providers listed above. Cookie-consent choices are managed through Resomix first-party consent controls.
11. CHILDREN’S PRIVACY
Section titled “11. CHILDREN’S PRIVACY”Resomix is not intended for individuals under eighteen (18) years of age or the age of majority in their jurisdiction, whichever is greater. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental or guardian consent, we will promptly delete that information.
12. UPDATES TO THIS SUMMARY
Section titled “12. UPDATES TO THIS SUMMARY”We may update this GDPR Summary from time to time to reflect changes in our practices or legal requirements. We will notify users of material changes by posting the updated summary on our website and updating the effective date. We encourage you to review this summary periodically.
13. CONTACT INFORMATION
Section titled “13. CONTACT INFORMATION”For questions about this GDPR Summary or to exercise your data protection rights, please contact us:
Reform Studios, operating under the trade name Resomix, Sokratous 8, Kalamaria, 551 34 Thessaloniki, Greece.
Privacy Inquiries: [email protected] | Legal: [email protected] | Support: [email protected] | Website: www.resomix.com
For complaints regarding data protection, you may also contact the Hellenic Data Protection Authority (HDPA/ΑΠΔΠΧ) at www.dpa.gr.