
The General Data Protection Regulation, or GDPR, is a European Union law designed to give individuals in the EU and EEA meaningful control over how their personal data is collected, used, stored, and shared. This page explains how Sonorous Zen complies with the GDPR and what rights you have as a data subject if you live in the EU, the European Economic Area, the United Kingdom (UK GDPR), or any other jurisdiction where similar protections apply.
This GDPR Policy is a companion document to our Privacy Policy and Cookie Policy. If you want the full picture of how we handle personal data across the Platform, please read all three together. Where there is any conflict, the document that is more specific to the topic at hand controls.
Sonorous Zen is operated by Sonorous Zen LLC ("Sonorous Zen", "we", "us", or "our"). When you use our website, dashboard, or mobile experience — whether as a registered Creator, Collaborator, team member, or fan opening a smart link — Sonorous Zen acts as the data controller for most of the personal data we process, and as a data processor in limited cases where we process data on your behalf (for example, when you upload fan contacts to run a Fan Blast campaign).
If you'd like to contact us about GDPR matters, please email privacy@sonorouszen.com.
Account and profile data. Your name, email address, username, chosen language, chosen theme, display name, avatar, and role inside your tenant.
Identity and KYC data. Government-issued identification documents, proof of address, tax information, and related verification data submitted when you complete KYC. This data is stored in our private secured storage and only accessed by authorized staff during verification and compliance reviews.
Payment and payout data. Subscription records, invoices, and the payout methods you set up (such as bank, PayPal, or mobile wallet details). Card numbers are never stored on our servers — they are handled directly by Stripe, our payment processor.
Creator Content and metadata. Your music, artwork, release metadata, lyrics, credits, ISRC/ISWC/UPC identifiers, royalty splits, and other information you upload to the Platform.
Collaboration data. Information about the collaborators you invite to releases and royalty splits, such as their email and the percentage you assign to them.
Financial and royalty data. Earnings delivered by DSPs, platform fee calculations, wallet ledger entries, transfers, and withdrawal history.
Usage data. How you interact with the dashboard (which pages you open, what features you use, session diagnostics, and error logs) so we can keep the Platform stable and improve it.
Fan and audience data. If you use Fan Blast, Smart Links, or public artist pages, we process the contact details of your fans (such as email addresses they provided to subscribe) and aggregate analytics on link clicks and opens.
Device and technical data. IP address, browser type, operating system, device identifiers, and cookie IDs used for session management, fraud prevention, and analytics.
Support and feedback data. Tickets, messages, attachments, and correspondence you send through the Support Center.
Performance of a contract. To deliver the Service you signed up for — distributing your releases, paying royalties, running KYC, handling withdrawals, processing subscriptions, and operating collaboration tools.
Legitimate interests. To keep the Platform secure and free of fraud, to detect abuse and artificial streaming, to improve product quality, to monitor system performance, to protect our users and partners, and to conduct analytics where doing so does not override your rights.
Legal obligation. To comply with tax, accounting, anti-money-laundering, KYC, sanctions, and other laws that apply to a music distribution and payments platform.
Consent. For optional activities that require it — for example, subscribing to a Creator's fan-email list, enabling non-essential cookies, or receiving marketing emails from Sonorous Zen. You can withdraw your consent at any time without affecting the lawfulness of any processing that occurred before you withdrew it.
Vital interests and public interest. In rare circumstances, where processing is necessary to protect someone's life or to comply with a request from a public authority acting within its lawful powers.
Provide and operate the Platform, including onboarding, release delivery, royalty ingestion, wallet operations, KYC verification, and support.
Bill subscriptions and one-time purchases (AI Mastering, Cover Song Licensing, etc.) and process payouts to Creators.
Detect and investigate fraud, artificial streaming, chargebacks, and identity misuse under our Anti-Fraud Policy.
Communicate with you about your account, service updates, security notices, and policy changes.
Improve the product through aggregated analytics and user research.
Comply with legal and regulatory obligations, including tax and financial reporting.
Respond to lawful requests from courts, regulators, and law enforcement.
We do not run ad networks on Sonorous Zen, we do not sell your personal data, and we do not use your data to build profiles for third-party advertising. If that ever changes, we will update this policy, notify you in advance, and give you the chance to opt out where required by law.
We only share personal data with parties who need it to help us run Sonorous Zen or because the law requires us to. Specifically:
Digital Service Providers (DSPs) such as Spotify, Apple Music, YouTube Music, Amazon Music, TikTok, and Deezer, where sharing your release metadata and Creator Content is necessary to distribute your music on the services you have selected.
Stripe, our payment processor, for subscription checkout, payment security, 3-D Secure authentication, and payouts.
Trusted service providers that help us run the Platform, including email delivery providers (for transactional emails and fan blasts), cloud hosting and storage providers, customer support tooling, error-monitoring services, and audio-fingerprinting providers such as ACRCloud when you actively use the AI Scan or Audio Recognition features.
Collective management organizations and collecting societies, where necessary to support royalty collection and rights administration.
Professional advisers such as lawyers, accountants, and auditors, bound by confidentiality.
Authorities and courts, when we are required to disclose information by law, regulation, legal process, or a lawful request from a public authority.
Successor entities, if Sonorous Zen is involved in a merger, acquisition, restructuring, or sale of assets. In that case, personal data may be transferred to the successor as part of the transaction, subject to the protections of this policy.
Every third party we share data with is selected carefully and bound by contractual obligations to handle data only for specific purposes, with appropriate safeguards.
Sonorous Zen operates globally, with infrastructure and partners in multiple regions, including Asia, Europe, and the United States. When we transfer personal data outside the EU/EEA or the UK, we use appropriate safeguards required by law, such as Standard Contractual Clauses, equivalent transfer mechanisms, or the recipient's participation in a recognized cross-border framework. Where you contact us, we can provide more details about the transfer mechanism used.
We keep personal data only for as long as we need it for the purposes described in this policy, or for as long as the law requires. In practice:
Active account data is kept while your account is active and for a reasonable period afterward to handle disputes, refunds, royalty reconciliation, and DSP reversals.
Financial and tax records, including wallet ledger entries and invoices, are kept for the period required by applicable law, typically several years.
KYC and identity-verification data is kept for the period required by anti-money-laundering and financial laws.
Marketing preferences are kept until you withdraw consent or unsubscribe.
Fan contact lists uploaded by Creators are kept while the Creator's account is active, unless the Creator deletes them earlier or a fan unsubscribes.
When data is no longer needed, we securely delete or anonymize it. For backups, deletion happens according to our backup retention cycle.
If GDPR applies to you, you have the following rights, which you can exercise free of charge (unless a request is manifestly unfounded or excessive):
Right of access. You have the right to know what personal data we hold about you and to receive a copy of it.
Right to rectification. You can ask us to correct any inaccurate or incomplete personal data.
Right to erasure ("right to be forgotten"). You can ask us to delete your personal data when it is no longer necessary for the purposes we collected it for, when you withdraw consent and there is no other legal basis, or when you object to processing. This right is subject to exceptions where we must keep data for legal reasons, such as tax, financial, fraud, or dispute purposes.
Right to restrict processing. You can ask us to pause processing in certain circumstances, for example while we verify the accuracy of your data or consider an objection.
Right to data portability. For data you have provided to us and that we process by automated means under a contract or on the basis of consent, you can request a structured, machine-readable copy, or ask us to send it to another controller where technically feasible.
Right to object. You have the right to object to processing based on legitimate interests, including profiling for marketing. If you object to direct marketing, we will stop processing your data for that purpose.
Right to withdraw consent. Where we rely on your consent (for example, for non-essential cookies or marketing emails), you can withdraw it at any time without affecting prior processing.
Right to lodge a complaint. If you believe we have handled your data unlawfully, you have the right to file a complaint with your local data protection authority. We ask that you contact us first at privacy@sonorouszen.com so we can try to resolve the issue directly.
Right not to be subject to solely automated decisions. We do not take decisions about you that have significant legal or similar effects based purely on automated processing without human involvement. Where automated systems flag unusual activity (for example, suspected artificial streaming or fraud), human reviewers are involved before any meaningful action is taken against your account.
To exercise any of the rights above, please email privacy@sonorouszen.com with a clear description of your request. We may need to verify your identity before acting, to protect you and your data. We aim to respond within one month of receiving a valid request. In complex cases we may extend that period by up to two additional months and will notify you if we need the extra time.
Many of these actions can also be taken directly inside the Platform. For example, you can update profile details, change your language and theme, manage notification preferences, and request account deletion from the Settings and Preferences pages.
We use industry-appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, secure credential storage, tenant isolation, audit logging, and regular security reviews. Sensitive documents such as KYC files are stored in a private secured bucket accessible only through time-limited signed URLs and only to authorized staff. No system is perfectly secure, but we work hard to reduce risk and respond quickly to incidents.
Sonorous Zen is not directed to children under 16, and we do not knowingly collect personal data from anyone under that age. If you believe a child has provided us with personal data, please contact privacy@sonorouszen.com and we will take steps to delete it.
We may update this GDPR Policy from time to time, for example as laws change or as our product evolves. When we make material updates, we will update the "Effective Date" above and, where required, notify you in-app or by email at least 30 days in advance. Minor clarifications or typo fixes may be published without notice.
Questions, requests, or concerns about this GDPR Policy? We'd like to hear from you. privacy@sonorouszen.com
If you are in the EU or UK and prefer to contact a local supervisory authority, you can find the list of national data-protection authorities on the European Data Protection Board's website.