Privacy policy
Last updated: October 5, 2026 | Version 3.3
Contents
1. Data controller
99Eyes Entertainment ("we", "us", or "our") is the data controller responsible for your personal data.
We work with artists and users around the world, including in the European Economic Area (EEA) and the United Kingdom. This policy describes the information we process, why we process it, and how to exercise the rights available to you under applicable law.
If you are located in the EEA or UK, you keep all of the rights described in this policy and may lodge a complaint with your local data protection authority (see "Your Rights" below).
2. Data we collect
We collect different types of personal data depending on how you interact with our services:
Account information
- Email address
- Full name
- Artist or label name
- Payment email (for royalty distributions)
Artist & rights holder information
- Artist name and profile information
- Country of residence
- Performing Rights Organization (PRO) membership (e.g., ASCAP, BMI, BUMA/STEMRA)
- IPI/CAE number (for royalty identification)
- Social media handles and links
Demo submissions
- Contact name and email address
- The direct-message handles you give us (Instagram, Discord, WhatsApp number)
- Audio file links (SoundCloud, Dropbox, Google Drive)
- Artwork links (if provided)
- Collaborator names
- Additional notes
Contract & signing information
When you fill in our artist information form so we can prepare a recording agreement, we collect:
- Full legal name (as it appears on your ID)
- Date of birth
- Full residential address (street, city, postal code, country)
- Spotify artist profile link and the track title(s) being signed
- For artists under 18: the parent or legal guardian's full legal name, email address, date of birth, and residential address, so they can co-sign the agreement
When you submit this form we also record the date, the version of the consent text you agreed to, your IP address and your browser's user agent, as evidence of that consent. The IP address is deleted after 90 days. We use this information only to prepare and execute your recording agreement, and we give details about minors and their guardians extra protection.
Track & distribution data
- Track metadata (title, genre, release date)
- Audio and artwork files
- ISRC codes
- Revenue split information (recipient names, emails, percentages)
Data we receive from other people
- Collaborators: when an artist lists you as a producer, featured artist or split recipient, they give us your name, email address, role and proposed share. We use it to credit you, prepare agreements and route royalties, and we contact you before anything about you is final.
- Streaming, sales and royalty reports from our distribution partners for the releases you are credited on.
- Public artist and release information from Spotify and other music services, such as your artist name, profile picture and follower count.
Creators we work with on promotion
If we book you to post videos promoting a release, we keep:
- Your handle and public profile statistics (followers, views on the posts you made for us)
- What we agreed and the links to the posts you delivered
- The payment details you give us and our payment records
Technical data
- Browser type and version
- Device information
- IP address (for security and abuse prevention where logged)
- Usage data and analytics (if you consent to analytics cookies)
3. How we use your data
We process your personal data for the following purposes:
- Account management: Creating and managing your user account
- Demo evaluation: Reviewing and responding to demo submissions
- Contract preparation: Drafting, sending, and executing recording agreements (including obtaining parent or guardian co-signature where the artist is a minor)
- Distribution services: Preparing and delivering your music to distribution partners
- Royalty payments: Processing and distributing royalty payments to rights holders
- Marketing campaigns: Managing promotional activities for your releases (if applicable)
- Communication: Sending service-related notifications and updates
- Security: Protecting against fraud and maintaining platform security
- Legal compliance: Meeting regulatory and fiscal requirements
- Analytics: Improving our services (only with your consent)
4. Legal basis for processing
We process your personal data based on the following legal grounds under GDPR Article 6:
Contract Performance (Article 6(1)(b))
Processing necessary for user accounts, track submissions, distribution services, and royalty payments.
Legitimate Interests (Article 6(1)(f))
Security, fraud prevention, service administration, and improvements that do not require consent. We balance these interests against your rights.
Consent (Article 6(1)(a))
Optional analytics and any other processing where we ask for your permission. You may withdraw consent at any time.
Legal Obligation (Article 6(1)(c))
Fiscal record-keeping, tax reporting, and regulatory compliance requirements.
5. Data recipients & processors
We share personal data only where we need to, with these categories of recipients:
| Recipient | Why |
|---|---|
| Technical service providers | Sign-in, hosting, data storage, email delivery, e-signature and error monitoring. They process data only on our instructions. |
| Distribution partners | Delivering releases to streaming services and stores, and reporting streams and revenue. Your name and credits appear on the release. |
| Royalty and payment providers | Calculating and paying royalties, and paying people we book for promotion. They receive the payee's name, email, payment details and share. |
| Music and video services | Looking up public artist and release information, and playing the links you send us (embedded players load only after you allow them). |
| Professional advisers and authorities | Accountants and lawyers bound by confidentiality, and authorities where the law requires it. |
Service providers that process personal data for us do so under written terms. We do not sell personal data. If you need to know which provider handles your data, email us and we will tell you.
6. International data transfers
As a U.S.-based company, we process personal data in the United States, and some of our service providers operate globally. When we transfer the personal data of individuals in the European Economic Area (EEA) or United Kingdom outside those regions, we put appropriate safeguards in place:
- Standard Contractual Clauses (SCCs): We use EU-approved contractual clauses with our US-based providers
- Supplementary measures: Additional technical and organizational measures where necessary
- Adequacy decisions: For countries with an EU adequacy decision
You may request a copy of the safeguards we use by contacting us at contact@the99eyes.com.
7. Data retention
We retain your personal data only for as long as necessary:
| Data Category | Retention Period | Reason |
|---|---|---|
| User account data | Account lifetime + 7 years | U.S. tax & recordkeeping requirements |
| Track & distribution data | Contract duration + 7 years | Royalty accounting & audits |
| Demo submissions | Contact details removed 1 year after we decline a demo, and 2 years after submission for any other demo that did not become a release. A demo that became a release is kept with that release's records. | Business legitimate interest |
| Campaign data | 5 years | Marketing analytics & reporting |
| Signed contracts & contract-preparation details | 7 years from signing | Contract performance, royalty accounting & disputes |
| Consent records (what you agreed to, when, which version) | 7 years | Proof of a lawful basis for processing |
| Release details forms | The unfinished copy is deleted 60 days after the link expires. Once a release is approved, your submitted answers are kept for as long as the release is distributed and deleted 1 year after it is taken down; earlier saved versions are deleted 90 days after you submit. A form that does not become a release is deleted 1 year after you submit it | Preparing the release, and checking who is credited and paid on it while it earns |
| Promotion bookings and payments to creators | 7 years from payment | U.S. tax & recordkeeping requirements |
| Security and audit logs | 1 year | Security & accountability for access to personal data |
| Artist information forms we reject | Deleted after 180 days | Data minimisation |
| IP addresses recorded with a form submission | Deleted after 90 days | Security & evidence of consent |
8. Your rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
Request a copy of your personal data. You can export your data from your account settings.
Right to Rectification
Correct inaccurate or incomplete data through your account settings.
Right to Erasure
Request deletion of your data. We delete or anonymise everything we are not legally required to keep; payout, contract and tax records are retained for the periods in section 7.
Right to Restriction
Limit how we process your data in certain circumstances.
Right to Portability
Receive your data in a machine-readable format (JSON).
Right to Object
Object to processing based on legitimate interests.
To exercise these rights, use our data request form (no account needed), email contact@the99eyes.com, or, if you have an account, use the export and deletion options in your account settings. Deleting your sign-in account opens a deletion request that a person reviews; it does not by itself erase contract or payout records. We confirm requests from the email address they concern. Where the GDPR applies, we normally respond within one month; in some cases the law allows more time, and we will let you know.
If you are located in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. EEA residents can find their authority via the European Data Protection Board; UK residents can contact the Information Commissioner's Office (ICO).
10. Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption in transit and at rest
- Extra protection for details about minors and their guardians
- Access limited to the people who need it for their work
- Regular security reviews
In the event of a data breach that poses a high risk to your rights and freedoms, we will notify affected users and the relevant supervisory authority without undue delay. For individuals in the EEA or UK, we will notify the competent authority within 72 hours as required by the GDPR.
11. Children's privacy
Our website is not directed at children. As a music label, though, we sometimes work with recording artists who are under 18. When someone under 18 fills in our artist information form, we collect limited personal data about them and their parent or legal guardian for one purpose only: preparing a recording agreement.
If the date of birth on the form shows the artist is under 18, the form asks for their parent or guardian's details and for confirmation that the guardian knows about and agrees to the submission. We record that confirmation, and we email the guardian directly to let them know what was submitted and how to withdraw it. No agreement with a minor is binding until the guardian has co-signed it. We encrypt these details and never use a minor's data for marketing or analytics.
If you are a parent or guardian and believe your child has provided us with personal data without your involvement, or you wish to review, correct, or delete that data, please contact us at contact@the99eyes.com.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Posting a notice on our platform
- Sending an email to registered users (for significant changes)
- Updating the "Last updated" date at the top of this policy
Where a change requires a new consent choice, we will ask for it before enabling that processing.
13. Contact us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Protection Inquiries
Email: contact@the99eyes.com
We aim to respond promptly. Where the GDPR applies, the usual response period for a rights request is one month.