Skip to content

Privacy Policy

Reform Studios, a company registered in Greece operating under the trade name Resomix.

Version 7.1 | Effective Date: 20 July 2026 | Supersedes Version 6.0 (15 January 2026)

This Privacy Policy applies during the initial Resomix production beta and may be updated as the Service develops.

Related Documents: This document should be read in conjunction with our Terms of Service, Cookie Policy, Refund Policy, Copyright & DMCA Policy, Acceptable Use Policy, Platform Disclaimer, GDPR Compliance Summary, and Music Content & Licensing Transparency Policy, all available from the Resomix legal hub at /legal

This Privacy Policy describes how Reform Studios, a company registered in Greece operating under the trade name Resomix (“Resomix,” “we,” “us,” or “our”), collects, uses, shares and protects your personal information when you use our music discovery platform and related services (the “Service”). Resomix is live in production as a beta service during its initial three-month beta period. Depending on the user’s access level, the Service may include Sonic Discovery, Track Intelligence, Catalogue Intelligence and authorised Discovery API functionality for catalogue ingestion and similarity retrieval, together with customer-authorised Private Resomix Libraries and partner catalogue processing. Resomix searches its own pre-analysed sonic index. Apple MusicKit supports catalogue metadata, previews and authorised playback presentation within the current beta experience. Apple MusicKit does not perform PYXIS-1 analysis, generate Resomix sonic profiles or calculate Resomix similarity rankings. This policy applies to all users of resomix.com, beta.resomix.com, and any related applications or services.

For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Greek data protection law (Law 4624/2019), Reform Studios, operating under the trade name Resomix, Sokratous 8, Kalamaria, 551 34 Thessaloniki, Greece, is the data controller responsible for your personal data. Contact: [email protected].

Resomix has assessed its data processing activities in accordance with Article 37 of the GDPR and has determined that the appointment of a Data Protection Officer (DPO) is not mandatory at this time. We have designated a privacy contact at [email protected]. This assessment is reviewed annually.

When you create an account, we collect information including your email address, username, password (stored in encrypted form), and any profile information you choose to provide.

We collect information about how you use the Service, including tracks you listen to, search queries, playlists you create, sharing activity, features you use, time spent on the platform, and interaction patterns with our recommendation system.

We automatically collect technical information, including IP address, browser type and version, operating system, device type, unique device identifiers, screen resolution, language preferences, time zone, and referring URLs.

2.4 Audio Data — Upload and Processing Lifecycles

Section titled “2.4 Audio Data — Upload and Processing Lifecycles”

The Service processes audio in distinct ways, with different retention rules.

(a) Temporary Reference Uploads: When you upload audio for one-off similarity or Track Intelligence analysis (a “Temporary Reference Upload”), the PYXIS-1 engine analyses more than 70 measurable audio characteristics and may segment the audio into structural sections to deliver the requested results. Audio submitted as a Temporary Reference Upload is retained only for processing and deleted no later than 24 hours after upload or analysis. It is not made publicly available, is not accessible to other users, and is not used to train or fine-tune PYXIS-1. Temporary previews and processing artefacts are retained only for as long as reasonably necessary to provide, troubleshoot and secure the requested processing.

(b) Private Resomix Libraries: Audio supplied to a Private Resomix Library may be retained for the duration necessary to provide the user-authorised catalogue-analysis and discovery service. Deletion may occur following a user removal request, Private Library deletion, account termination, or the applicable account-retention schedule.

(c) Partner catalogue content: Audio delivered under a partner catalogue arrangement may be retained and processed for the duration and purposes authorised by the applicable partner agreement. Partner content is logically isolated, restricted to authorised access, and subject to the partner agreement and applicable Data Processing Addendum.

(d) Derived analysis data: PYXIS-1 creates a numerical sonic profile from analysed audio. The derived sonic profile is created for analysis and similarity retrieval and is not intended to function as a playable substitute for the source recording. Retention of sonic profiles, similarity results, Track Intelligence reports, saved analysis history, playlists, user preferences and exported reports is described in Section 8.

Paid plans and metered API services may be introduced or activated during or after the beta period. Where paid checkout is active, we collect and process: subscription plan, billing period and status; transaction and invoice records (amount, date, VAT country and rate, invoice number); VAT/tax identification number for business customers; checkout consent records; and payment method reference data provided by our payment provider (such as card brand and last four digits). Where paid checkout is active, payment and billing information is processed by Stripe Payments Europe. Resomix does not store full payment-card details.

Strictly necessary cookies support authentication, sessions, security and consent-choice storage. Self-hosted PostHog may be used for first-party product analytics only under the applicable consent settings. Resomix does not currently use third-party advertising or retargeting cookies; any future marketing cookies will be introduced only after this policy and the consent controls have been updated. Cookie-consent choices are managed through Resomix first-party consent controls. For cookie categories and durations, see our Cookie Policy.

In accordance with Article 5(1)(c) of the GDPR, we adhere to the principle of data minimisation. We collect only the personal data that is adequate, relevant, and limited to what is necessary. Payment card data is minimised by design: where paid checkout is active, full card details are handled exclusively by our payment provider and are never stored on Resomix systems. The temporary processing of Temporary Reference Uploads — with source audio deleted no later than 24 hours after upload or analysis — reflects our commitment to minimising data retention.

In accordance with Article 6 of the GDPR, we process your personal data on the following legal bases:

Contract Performance (Art. 6(1)(b)): Account creation and management; providing core platform functionality; processing of Temporary Reference Uploads and Private Library audio to deliver the requested analysis and discovery services; subscription and billing management where paid plans are active (plan administration, renewals, cancellations, refunds); playlist creation and sharing.

Legitimate Interests (Art. 6(1)(f)): Platform security and fraud prevention, service improvement and analytics, responding to legal requests, protecting intellectual property.

Consent (Art. 6(1)(a)): Marketing communications (where applicable); non-essential cookies and first-party analytics; participation in surveys or feedback programs.

Legal Obligation (Art. 6(1)(c)): Tax and accounting obligations — invoices and related billing records are retained for the period required under applicable law; responding to court orders; copyright compliance.

5. PROFILING AND AUTOMATED DECISION-MAKING

Section titled “5. PROFILING AND AUTOMATED DECISION-MAKING”

Our Service uses automated algorithmic processing to analyse audio characteristics and provide personalised music recommendations. This processing is based on audio characteristics (rhythm, harmony, timbre, energy) rather than demographic profiling. PYXIS-1 is not a trained machine-learning model or neural-network system: it does not train or fine-tune itself using user or partner audio, does not adapt from user interactions, and does not generate, synthesise or recreate audio. The same source audio processed with the same PYXIS-1 version and processing configuration produces the same sonic profile; similarity rankings are reproducible against the same index version and ranking configuration, and results may change when the searchable catalogue, index or engine version is updated.

Music recommendations are provided to enhance your discovery experience. They do not restrict your access to the Service and are not used to make decisions about you outside the Service.

5.3 Your Rights Regarding Automated Processing

Section titled “5.3 Your Rights Regarding Automated Processing”

You may at any time: (a) request information about the logic involved in our recommendation algorithms; (b) express your point of view regarding recommendations; and (c) reset your recommendation profile by contacting [email protected].

We may share your data with trusted service providers under data processing agreements compliant with Article 28 GDPR. Our current service providers and infrastructure partners are listed in Section 6.3.

We do not sell your personal data to third parties.

Provider Purpose Location / role
Alwyzon Application, account and API infrastructure Austria
Hetzner Audio processing, media and related infrastructure Germany
Cloudflare DNS, content delivery, traffic security and edge services Global service provider
Google Workspace Business and transactional email administration Google service
Stripe Payments Europe Payment processing when paid checkout is active EEA payment provider
Self-hosted PostHog First-party product analytics where consent applies Operated on Resomix-controlled infrastructure
Ghost Self-hosted publishing software Operated on Resomix-controlled infrastructure

We will update this list when providers change and, where required, provide notice of material changes. Self-hosted components (PostHog, Ghost) run on Resomix-controlled infrastructure with the infrastructure providers listed above. Cookie-consent choices are managed through Resomix first-party consent controls.

When we transfer personal data outside the EEA — including transfers connected to global content-delivery and security services and, where paid checkout is active, payment processing — we ensure appropriate safeguards in accordance with Chapter V of the GDPR, including adequacy decisions, Standard Contractual Clauses, and supplementary measures.

We retain data only as long as necessary:

Account data: Retained for the duration of the active account and for 30 days following a deletion request, plus any additional period required to comply with legal obligations.

Billing and invoice records: Where paid checkout is active, retained for the period required under applicable tax and accounting law, including after account deletion where the law requires it.

Consent records: Cookie-consent choices and, where paid checkout is active, checkout consent records are retained for the duration of the account plus the period necessary to evidence compliance.

Usage data: Up to 24 months, then anonymised or deleted.

Temporary Reference Uploads (source audio): Deleted no later than 24 hours after upload or analysis.

Temporary previews and processing artefacts: Retained only for as long as reasonably necessary to provide, troubleshoot and secure the requested processing.

Private Resomix Library audio: Retained for the duration necessary to provide the user-authorised catalogue-analysis and discovery service; deleted following a user removal request, Private Library deletion, account termination, or the applicable account-retention schedule.

Partner catalogue content: Retained and processed for the duration and purposes authorised by the applicable partner agreement and Data Processing Addendum.

Saved analysis results and discovery records (Track Intelligence reports, saved analysis history, playlists, user preferences, exported reports): Retained until the user deletes them, closes the relevant Library or account, or the applicable retention period expires.

Unsaved one-off analysis results (including sonic profiles and similarity results from Temporary Reference Uploads): May be retained temporarily for service delivery, troubleshooting and security.

Communication records: Up to 36 months.

Processing and security logs: Typically up to 90 days, unless needed longer for security investigations or legal obligations.

Cookie data: Session cookies are deleted when the browser closes; other cookie durations are listed in the Cookie Policy.

You have rights of Access (Art. 15), Rectification (Art. 16), Erasure (Art. 17), Restriction (Art. 18), Portability (Art. 20), Objection (Art. 21), and Withdrawal of Consent.

To exercise any of these rights, contact [email protected]. We will acknowledge your request within five (5) business days and provide a substantive response within one (1) month. Where requests are complex or numerous, this period may be extended by a further two (2) months in accordance with Article 12(3) GDPR, in which case we will inform you of the extension and the reasons for the delay within the initial one-month period. Note that billing and invoice records may be retained after an erasure request where required by Greek tax law (Art. 17(3)(b) GDPR).

We implement appropriate technical and organisational measures under Article 32 GDPR, aligned with the current beta stage of the Service, including: TLS on public service endpoints; encrypted HLS for controlled media delivery; logical isolation of partner catalogues, restricted to authorised partner access; access controls that restrict systems and data according to account and service roles; and backup controls that are partially implemented and continue to develop during the beta period. We review and strengthen these measures as the Service develops, and we maintain incident-response and breach-notification procedures in accordance with Articles 33 and 34 GDPR.

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, Resomix will notify the Hellenic Data Protection Authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals without undue delay in accordance with Article 34 GDPR, describing the nature of the breach, likely consequences, and measures taken or proposed to address it.

The Service is not intended for individuals under eighteen (18) years of age or the age of majority in their jurisdiction, whichever is greater. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental or guardian consent, we will take steps to delete that information promptly.

We may update this Privacy Policy from time to time. Material changes will be notified via email or prominent notice on the Service.

Reform Studios, operating under the trade name Resomix, Sokratous 8, Kalamaria, 551 34 Thessaloniki, Greece. Privacy Inquiries: [email protected] | Legal: [email protected] | Supervisory Authority: Hellenic Data Protection Authority (HDPA/ΑΠΔΠΧ) at www.dpa.gr. EU residents may also contact their local data protection authority in accordance with Article 77 GDPR.