Privacy Policy
Reform Studios, a company registered in Greece operating under the trade name Resomix.
Version 7.1 | Effective Date: 20 July 2026 | Supersedes Version 6.0 (15 January 2026)
This Privacy Policy applies during the initial Resomix production beta and may be updated as the Service develops.
Related Documents: This document should be read in conjunction with our Terms of Service, Cookie Policy, Refund Policy, Copyright & DMCA Policy, Acceptable Use Policy, Platform Disclaimer, GDPR Compliance Summary, and Music Content & Licensing Transparency Policy, all available from the Resomix legal hub at /legal
1. INTRODUCTION AND DATA CONTROLLER
Section titled “1. INTRODUCTION AND DATA CONTROLLER”1.1 About This Policy
Section titled “1.1 About This Policy”This Privacy Policy describes how Reform Studios, a company registered in Greece operating under the trade name Resomix (“Resomix,” “we,” “us,” or “our”), collects, uses, shares and protects your personal information when you use our music discovery platform and related services (the “Service”). Resomix is live in production as a beta service during its initial three-month beta period. Depending on the user’s access level, the Service may include Sonic Discovery, Track Intelligence, Catalogue Intelligence and authorised Discovery API functionality for catalogue ingestion and similarity retrieval, together with customer-authorised Private Resomix Libraries and partner catalogue processing. Resomix searches its own pre-analysed sonic index. Apple MusicKit supports catalogue metadata, previews and authorised playback presentation within the current beta experience. Apple MusicKit does not perform PYXIS-1 analysis, generate Resomix sonic profiles or calculate Resomix similarity rankings. This policy applies to all users of resomix.com, beta.resomix.com, and any related applications or services.
1.2 Data Controller
Section titled “1.2 Data Controller”For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Greek data protection law (Law 4624/2019), Reform Studios, operating under the trade name Resomix, Sokratous 8, Kalamaria, 551 34 Thessaloniki, Greece, is the data controller responsible for your personal data. Contact: [email protected].
1.3 Data Protection Officer Assessment
Section titled “1.3 Data Protection Officer Assessment”Resomix has assessed its data processing activities in accordance with Article 37 of the GDPR and has determined that the appointment of a Data Protection Officer (DPO) is not mandatory at this time. We have designated a privacy contact at [email protected]. This assessment is reviewed annually.
2. DATA WE COLLECT
Section titled “2. DATA WE COLLECT”2.1 Account Data
Section titled “2.1 Account Data”When you create an account, we collect information including your email address, username, password (stored in encrypted form), and any profile information you choose to provide.
2.2 Usage Data
Section titled “2.2 Usage Data”We collect information about how you use the Service, including tracks you listen to, search queries, playlists you create, sharing activity, features you use, time spent on the platform, and interaction patterns with our recommendation system.
2.3 Device and Technical Data
Section titled “2.3 Device and Technical Data”We automatically collect technical information, including IP address, browser type and version, operating system, device type, unique device identifiers, screen resolution, language preferences, time zone, and referring URLs.
2.4 Audio Data — Upload and Processing Lifecycles
Section titled “2.4 Audio Data — Upload and Processing Lifecycles”The Service processes audio in distinct ways, with different retention rules.
(a) Temporary Reference Uploads: When you upload audio for one-off similarity or Track Intelligence analysis (a “Temporary Reference Upload”), the PYXIS-1 engine analyses more than 70 measurable audio characteristics and may segment the audio into structural sections to deliver the requested results. Audio submitted as a Temporary Reference Upload is retained only for processing and deleted no later than 24 hours after upload or analysis. It is not made publicly available, is not accessible to other users, and is not used to train or fine-tune PYXIS-1. Temporary previews and processing artefacts are retained only for as long as reasonably necessary to provide, troubleshoot and secure the requested processing.
(b) Private Resomix Libraries: Audio supplied to a Private Resomix Library may be retained for the duration necessary to provide the user-authorised catalogue-analysis and discovery service. Deletion may occur following a user removal request, Private Library deletion, account termination, or the applicable account-retention schedule.
(c) Partner catalogue content: Audio delivered under a partner catalogue arrangement may be retained and processed for the duration and purposes authorised by the applicable partner agreement. Partner content is logically isolated, restricted to authorised access, and subject to the partner agreement and applicable Data Processing Addendum.
(d) Derived analysis data: PYXIS-1 creates a numerical sonic profile from analysed audio. The derived sonic profile is created for analysis and similarity retrieval and is not intended to function as a playable substitute for the source recording. Retention of sonic profiles, similarity results, Track Intelligence reports, saved analysis history, playlists, user preferences and exported reports is described in Section 8.
2.5 Subscription and Billing Data
Section titled “2.5 Subscription and Billing Data”Paid plans and metered API services may be introduced or activated during or after the beta period. Where paid checkout is active, we collect and process: subscription plan, billing period and status; transaction and invoice records (amount, date, VAT country and rate, invoice number); VAT/tax identification number for business customers; checkout consent records; and payment method reference data provided by our payment provider (such as card brand and last four digits). Where paid checkout is active, payment and billing information is processed by Stripe Payments Europe. Resomix does not store full payment-card details.
2.6 Cookies and Analytics
Section titled “2.6 Cookies and Analytics”Strictly necessary cookies support authentication, sessions, security and consent-choice storage. Self-hosted PostHog may be used for first-party product analytics only under the applicable consent settings. Resomix does not currently use third-party advertising or retargeting cookies; any future marketing cookies will be introduced only after this policy and the consent controls have been updated. Cookie-consent choices are managed through Resomix first-party consent controls. For cookie categories and durations, see our Cookie Policy.
3. DATA MINIMISATION
Section titled “3. DATA MINIMISATION”In accordance with Article 5(1)(c) of the GDPR, we adhere to the principle of data minimisation. We collect only the personal data that is adequate, relevant, and limited to what is necessary. Payment card data is minimised by design: where paid checkout is active, full card details are handled exclusively by our payment provider and are never stored on Resomix systems. The temporary processing of Temporary Reference Uploads — with source audio deleted no later than 24 hours after upload or analysis — reflects our commitment to minimising data retention.
4. LEGAL BASIS FOR PROCESSING
Section titled “4. LEGAL BASIS FOR PROCESSING”In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases:
Contract Performance (Art. 6(1)(b)): Account creation and management; providing core platform functionality; processing of Temporary Reference Uploads and Private Library audio to deliver the requested analysis and discovery services; subscription and billing management where paid plans are active (plan administration, renewals, cancellations, refunds); playlist creation and sharing.
Legitimate Interests (Art. 6(1)(f)): Platform security and fraud prevention, service improvement and analytics, responding to legal requests, protecting intellectual property.
Consent (Art. 6(1)(a)): Marketing communications (where applicable); non-essential cookies and first-party analytics; participation in surveys or feedback programs.
Legal Obligation (Art. 6(1)(c)): Tax and accounting obligations — invoices and related billing records are retained for the period required under applicable law; responding to court orders; copyright compliance.
5. PROFILING AND AUTOMATED DECISION-MAKING
Section titled “5. PROFILING AND AUTOMATED DECISION-MAKING”5.1 Music Recommendations
Section titled “5.1 Music Recommendations”Our Service uses automated algorithmic processing to analyse audio characteristics and provide personalised music recommendations. This processing is based on audio characteristics (rhythm, harmony, timbre, energy) rather than demographic profiling. PYXIS-1 is not a trained machine-learning model or neural-network system: it does not train or fine-tune itself using user or partner audio, does not adapt from user interactions, and does not generate, synthesise or recreate audio. The same source audio processed with the same PYXIS-1 version and processing configuration produces the same sonic profile; similarity rankings are reproducible against the same index version and ranking configuration, and results may change when the searchable catalogue, index or engine version is updated.
5.2 Effect of Recommendations
Section titled “5.2 Effect of Recommendations”Music recommendations are provided to enhance your discovery experience. They do not restrict your access to the Service and are not used to make decisions about you outside the Service.
5.3 Your Rights Regarding Automated Processing
Section titled “5.3 Your Rights Regarding Automated Processing”You may at any time: (a) request information about the logic involved in our recommendation algorithms; (b) express your point of view regarding recommendations; and (c) reset your recommendation profile by contacting [email protected].
6. DATA SHARING
Section titled “6. DATA SHARING”6.1 Service Providers
Section titled “6.1 Service Providers”We may share your data with trusted service providers under data processing agreements compliant with Article 28 GDPR. Our current service providers and infrastructure partners are listed in Section 6.3.
6.2 No Sale of Personal Data
Section titled “6.2 No Sale of Personal Data”We do not sell your personal data to third parties.
6.3 Service Providers
Section titled “6.3 Service Providers”| Provider | Purpose | Location / role |
|---|---|---|
| Alwyzon | Application, account and API infrastructure | Austria |
| Hetzner | Audio processing, media and related infrastructure | Germany |
| Cloudflare | DNS, content delivery, traffic security and edge services | Global service provider |
| Google Workspace | Business and transactional email administration | Google service |
| Stripe Payments Europe | Payment processing when paid checkout is active | EEA payment provider |
| Self-hosted PostHog | First-party product analytics where consent applies | Operated on Resomix-controlled infrastructure |
| Ghost | Self-hosted publishing software | Operated on Resomix-controlled infrastructure |
We will update this list when providers change and, where required, provide notice of material changes. Self-hosted components (PostHog, Ghost) run on Resomix-controlled infrastructure with the infrastructure providers listed above. Cookie-consent choices are managed through Resomix first-party consent controls.
7. INTERNATIONAL TRANSFERS
Section titled “7. INTERNATIONAL TRANSFERS”When we transfer personal data outside the EEA — including transfers connected to global content-delivery and security services and, where paid checkout is active, payment processing — we ensure appropriate safeguards in accordance with Chapter V of the GDPR, including adequacy decisions, Standard Contractual Clauses, and supplementary measures.
8. DATA RETENTION
Section titled “8. DATA RETENTION”We retain data only as long as necessary:
Account data: Retained for the duration of the active account and for 30 days following a deletion request, plus any additional period required to comply with legal obligations.
Billing and invoice records: Where paid checkout is active, retained for the period required under applicable tax and accounting law, including after account deletion where the law requires it.
Consent records: Cookie-consent choices and, where paid checkout is active, checkout consent records are retained for the duration of the account plus the period necessary to evidence compliance.
Usage data: Up to 24 months, then anonymised or deleted.
Temporary Reference Uploads (source audio): Deleted no later than 24 hours after upload or analysis.
Temporary previews and processing artefacts: Retained only for as long as reasonably necessary to provide, troubleshoot and secure the requested processing.
Private Resomix Library audio: Retained for the duration necessary to provide the user-authorised catalogue-analysis and discovery service; deleted following a user removal request, Private Library deletion, account termination, or the applicable account-retention schedule.
Partner catalogue content: Retained and processed for the duration and purposes authorised by the applicable partner agreement and Data Processing Addendum.
Saved analysis results and discovery records (Track Intelligence reports, saved analysis history, playlists, user preferences, exported reports): Retained until the user deletes them, closes the relevant Library or account, or the applicable retention period expires.
Unsaved one-off analysis results (including sonic profiles and similarity results from Temporary Reference Uploads): May be retained temporarily for service delivery, troubleshooting and security.
Communication records: Up to 36 months.
Processing and security logs: Typically up to 90 days, unless needed longer for security investigations or legal obligations.
Cookie data: Session cookies are deleted when the browser closes; other cookie durations are listed in the Cookie Policy.
9. YOUR RIGHTS UNDER GDPR
Section titled “9. YOUR RIGHTS UNDER GDPR”You have rights of Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Portability (Art. 20), Objection (Art. 21), and Withdrawal of Consent.
To exercise any of these rights, contact [email protected]. We will acknowledge your request within five (5) business days and provide a substantive response within one (1) month. Where requests are complex or numerous, this period may be extended by a further two (2) months in accordance with Article 12(3) GDPR, in which case we will inform you of the extension and the reasons for the delay within the initial one-month period. Note that billing and invoice records may be retained after an erasure request where required by Greek tax law (Art. 17(3)(b) GDPR).
10. SECURITY MEASURES
Section titled “10. SECURITY MEASURES”We implement appropriate technical and organisational measures under Article 32 GDPR, aligned with the current beta stage of the Service, including: TLS on public service endpoints; encrypted HLS for controlled media delivery; logical isolation of partner catalogues, restricted to authorised partner access; access controls that restrict systems and data according to account and service roles; and backup controls that are partially implemented and continue to develop during the beta period. We review and strengthen these measures as the Service develops, and we maintain incident-response and breach-notification procedures in accordance with Articles 33 and 34 GDPR.
Data Breach Notification
Section titled “Data Breach Notification”In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, Resomix will notify the Hellenic Data Protection Authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay in accordance with Article 34 GDPR, describing the nature of the breach, likely consequences, and measures taken or proposed to address it.
11. CHILDREN’S PRIVACY
Section titled “11. CHILDREN’S PRIVACY”The Service is not intended for individuals under eighteen (18) years of age or the age of majority in their jurisdiction, whichever is greater. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental or guardian consent, we will take steps to delete that information promptly.
12. POLICY UPDATES
Section titled “12. POLICY UPDATES”We may update this Privacy Policy from time to time. Material changes will be notified via email or prominent notice on the Service.
13. CONTACT AND COMPLAINTS
Section titled “13. CONTACT AND COMPLAINTS”Reform Studios, operating under the trade name Resomix, Sokratous 8, Kalamaria, 551 34 Thessaloniki, Greece. Privacy Inquiries: [email protected] | Legal: [email protected] | Supervisory Authority: Hellenic Data Protection Authority (HDPA/ΑΠΔΠΧ) at www.dpa.gr. EU residents may also contact their local data protection authority in accordance with Article 77 GDPR.