GDPR Compliance

Your data, your rights. Last updated: December 2024

Our Commitment to GDPR

Royalty Sync is committed to compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We believe in transparency about how we collect, use, and protect your personal data.

This page provides an overview of how we comply with GDPR and explains your rights as a data subject. For full details, please read our Privacy Policy.

Your Data Rights

Right of Access

You can request a copy of all personal data we hold about you. We will provide this within one month of your request.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to have it corrected.

Right to Erasure

You can request deletion of your personal data (the "right to be forgotten"), subject to legal retention requirements.

Right to Restrict Processing

You can request that we limit how we use your data while disputes or concerns are being resolved.

Right to Data Portability

You can request your data in a structured, machine-readable format to transfer to another service.

Right to Object

You can object to processing based on legitimate interests, including direct marketing at any time.

How to Exercise Your Rights

To make a data subject access request or exercise any of your rights, please contact us:

Email: support@royaltysync.ai
Subject line: GDPR Request - [Your Request Type]

We may need to verify your identity before processing your request. We will respond to all requests within one month. If we need more time (up to two additional months for complex requests), we will inform you within the first month.

Data Retention

We only retain your personal data for as long as necessary. Our retention periods include:

  • Account data: Duration of account + 30 days after deletion
  • Financial/billing records: 7 years (UK legal requirement)
  • Support tickets: 3 years from resolution
  • Usage logs: 12 months
  • Marketing preferences: Until consent is withdrawn

Data Security

We implement appropriate technical and organisational measures to protect your data:

  • Encryption in transit (TLS/HTTPS) and at rest
  • Secure password hashing (bcrypt)
  • Role-based access controls
  • Regular security audits and penetration testing
  • Secure cloud infrastructure with SOC 2 compliance
  • Staff training on data protection

Data Breach Procedures

In the unlikely event of a personal data breach that poses a risk to your rights and freedoms:

  • We will notify the ICO within 72 hours of becoming aware of the breach
  • We will notify affected individuals without undue delay if there is a high risk
  • We will document all breaches and remedial actions taken

Data Processing Agreements

When acting as a data processor on behalf of our customers (e.g., processing their catalogue data), we enter into Data Processing Agreements (DPAs) that comply with Article 28 of UK GDPR.

If you require a DPA for your organisation, please contact us at support@royaltysync.ai.

International Data Transfers

Some of our service providers may process data outside the UK. When this occurs, we ensure appropriate safeguards are in place:

  • UK adequacy decisions for the destination country
  • Standard Contractual Clauses (SCCs) as approved by the ICO
  • Additional technical measures where required

Complaints

If you're not satisfied with how we handle your data or respond to your requests, you have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Phone: 0303 123 1113
Live chat: Available on ICO website

We encourage you to contact us first so we can try to resolve your concerns directly.

Contact Our Data Protection Team

For any questions about GDPR compliance or data protection:

Email: support@royaltysync.ai
General enquiries: support@royaltysync.ai
Address: Bspoke Music Ltd, 111 Charterhouse Street, 5th Floor, London, England, EC1M 6AW