Privacy
As at 9 September 2026
This policy describes which personal data are processed when you use Music is my Life, for what purpose, on what legal basis and for how long. It follows Articles 13 and 14 of the General Data Protection Regulation (GDPR).
If you are in the United Kingdom, read every reference to the GDPR as a reference to the UK GDPR and the Data Protection Act 2018. If you are in California, please also read section 27.
1. Controller
Music is my Life
Marcus Feuerbach
Dittersdorferstrasse 4
61137 Schoeneck (Oberdorfelden)
Germany (DE)
Email for data protection matters: privacy@musicismylife.eu
2. Data protection officer
No data protection officer has been appointed, and none is required by law. The provider does not employ twenty persons who are constantly engaged in the automated processing of personal data (section 38(1) first sentence of the German Federal Data Protection Act).
The two further grounds in section 38(1) second sentence do not apply either: no data are processed commercially for the purpose of transfer or for market or opinion research, and the processing is not subject to a data protection impact assessment under Article 35 GDPR. The identity document data used for artist verification are not special categories of personal data under Article 9 GDPR; they are evaluated neither on a large scale nor systematically, the images are deleted when the application is decided (section 15), no profiling with legal effect takes place (section 23), and no publicly accessible area is systematically monitored. None of the cases in Article 35(3) GDPR therefore applies.
Please direct data protection enquiries to privacy@musicismylife.eu.
3. Competent supervisory authority
Der Hessische Beauftragte fuer Datenschutz und Informationsfreiheit
Postfach 31 63, 65021 Wiesbaden, Germany
Telephone +49 611 1408-0
poststelle@datenschutz.hessen.de
Independently of this, you have the right to lodge a complaint with any supervisory authority, in particular the one at your habitual residence (Article 77 GDPR). In the United Kingdom this is the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF.
4. Principles of this platform
So that you can place the following sections in context, four points that apply to the whole platform:
- No audience measurement tools, no tracking and no profiling for advertising purposes are used. No data are sold and no data are passed on for advertising purposes.
- On every page other than the payment page, no third party content is loaded. Fonts, scripts and images are held on our own server. Visiting those pages creates no connection to external providers.
- On the payment page this is different. Components of the payment service provider and of a bot protection service are loaded there, and data are transmitted to those providers in the process, including to the United States. Which data these are and on what basis this happens is set out in sections 10, 20 and 22.
- Outside the payment process, no transfer takes place to countries outside the European Union.
5. Visiting the website and server logs
When you visit the website, technical data transmitted by your browser are processed: IP address, date and time, address requested, volume of data transferred, status code, referring page, and browser and operating system details.
Purpose: delivery of the page, operational security, detection and defence against attacks and disruptions. Legal basis: Article 6(1)(f) GDPR. The legitimate interest lies in secure and undisturbed operation. Retention: at most 14 days, then automatic deletion. In the case of a specific security incident, for as long as the investigation takes.
Determining the country for the choice of language
So that the site appears in a language you understand, the country your IP address comes from is determined once on your first visit. The lookup runs exclusively against a file on our own server. No external service is queried, and your IP address does not leave our server in the process. Only the country is determined, not your place of residence, not your city and no coordinates.
The IP address is neither stored nor logged for this purpose. A language is suggested from the result. Your choice is then recorded in a cookie so that no guess has to be made on every visit.
The order is: the language stored in your settings, then your most recent choice from the cookie, then your browser language setting, then the country determined from the IP address. If none of these applies, the site appears in German.
Purpose: delivering the site in a language you can understand. Legal basis: Article 6(1)(f) GDPR. The legitimate interest lies in showing visitors a page in their own language. Objection: you can change the language at any time in the footer. Your choice takes precedence over the determination. Retention: none. Nothing is stored except the language you chose.
6. Registration and user account
For an account the following are processed: username, email address, password, date of birth and nationality. In addition, an internal account identifier, the time of registration and of the last login, and the records of the confirmations given at registration are created.
The password is stored exclusively as a check value using the Argon2id procedure. It cannot be recovered from that value.
Purpose: establishing and performing the user relationship, login, attribution of your content, compliance with the protection of minors. Legal basis: Article 6(1)(b) GDPR (contract). For the age statement additionally Article 6(1)(c) GDPR in conjunction with the rules on the protection of minors in the media. Retention: for the duration of the account. What happens after deletion, which data must be kept for a limited period for legal reasons and for how long, is set out in section 7.
Why the date of birth is collected
The platform may contain content that is not suitable for children and young people. Tracks and cover images are given an age rating. Without a date of birth, delivery could not be controlled.
The statement is self declared. No technical age verification takes place. The statement can only be changed afterwards through a separate procedure, because otherwise it could operate as a circumvention of the protection of minors.
Why nationality is collected
The entry determines the language in which the platform first appears to you. You can change the language yourself at any time afterwards.
The entry is not public. It appears in no profile, no search and no interface, but only in your own account under “My account”.
The entry does not determine the currency. Which currency is shown to you depends on the country you access the platform from and on your own choice (section 20).
7. Deleting your account and statutory retention
You can delete your account yourself at any time. The way to do so is on the "My account" page. Before deletion, the consequences below are shown to you once more.
What is deleted immediately
Your access, your public profile, your profile picture, your playlists, your favourite tracks, the artists you follow, your listening history, your participation in the track comparison and in the guessing game, and your registered devices. An existing artist profile is shut down; tracks you have published are no longer retrievable from that point.
Your account record itself remains in anonymised form. It then contains neither your name nor your email address, your date of birth or your password, and no longer allows any conclusion about you. It remains because declarations of rights and consents of other participating artists are attached to it. Those records do not belong to us and not to you alone; deleting them along with your account would deprive third parties of their evidence.
Your email address becomes free again in the process. You can register again with the same address at any time.
What is kept for a limited period
A small part of your data is not deleted but restricted in processing and kept encrypted, separately from live operations:
- first name, surname and username,
- email address,
- date of birth,
- time of registration and of deletion,
- the contract data of your memberships,
- the records of the declarations you gave, each with version and check value.
These data are held exclusively for the fulfilment of statutory retention obligations and for the establishment, exercise or defence of legal claims. They are not used for any other purpose.
Legal basis: Article 17(3)(b) and (e) GDPR in conjunction with Article 6(1)(c) GDPR.
For how long
Retention ends three years after the end of the calendar year in which you deleted your account. That corresponds to the standard limitation period under German law.
If a paid contract existed, longer periods apply to the associated documents:
- six years for commercial and business letters and other documents of fiscal significance,
- eight years for accounting vouchers and invoices.
The eight year period has applied since 1 January 2025. Previously it was ten years; it was shortened by the Fourth Bureaucracy Relief Act. The later exception returning to ten years concerns exclusively banks, insurers and securities institutions and therefore not this platform.
Each of these periods begins at the end of the calendar year in which the transaction was completed. The longest applicable period governs. After it expires, the retained data are deleted permanently, automatically and without any further request. A daily check ensures that no period is exceeded.
Your rights continue to apply
Even during retention you keep your rights under Articles 15 to 21 GDPR, in particular the right of access to the retained data. Please direct enquiries to privacy@musicismylife.eu.
If you consider that data are being kept longer than is necessary, you can object to the processing under Article 21 GDPR and lodge a complaint with a supervisory authority under Article 77 GDPR.
8. Termination through the cancellation button
A cancellation button is available for terminating paid contracts, as required by German law. It is linked in the footer of every page and reachable without logging in.
Data processed: type of termination and, in the case of extraordinary termination, the reason given, first name, surname, email address of the account, a customer or contract number where given, the designation of the contract, the desired end date, the email address for the confirmation, and the date and time of receipt. In addition, a check value of your IP address and the identifier of your browser are stored.
Your IP address is not stored in clear text but exclusively as a check value that cannot be reversed.
Purpose: receipt and handling of the termination and the legally required confirmation of receipt. Legal basis: Article 6(1)(c) GDPR in conjunction with section 312k(6) of the German Civil Code for the confirmation, Article 6(1)(b) GDPR for performing the contractual relationship, and Article 6(1)(f) GDPR for the check value of the IP address; the legitimate interest lies in preventing abusive mass submissions.
Retention: until the limitation period for claims arising from the terminated contractual relationship expires, at the longest in accordance with the periods named in section 7.
Logging in is expressly not required for termination. You do not have to provide a password in order to terminate.
9. Login, session and device management
After you log in, a session is established and a session cookie is set in your browser. In addition, an entry is kept for each logged in device with an identifier, the time, a shortened browser statement and the last activity, so that you can see and end your active logins and so that the number of simultaneous playbacks per plan is observed.
Purpose: login, account security, compliance with plan limits. Legal basis: Article 6(1)(b) GDPR. Retention: until you log out, until the session expires or until you remove the device yourself.
10. Cookies and storage on your device
Only such information is stored on or read from your device as is strictly necessary for the service you have expressly requested. Under section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, no consent is required for this. The duty to inform you nevertheless remains, and this section discharges it.
No information is stored for statistical, analytical or advertising purposes, and no cross site recognition takes place.
On your first visit a notice appears containing the same list. You can call it up again at any time through the "Cookie settings" entry in the footer. As soon as anything is added in future that is not necessary, that notice becomes a consent notice: such items are then switched off by default and are set only after your express consent.
Information this website stores itself
| Name | Type | Duration | Purpose |
|---|---|---|---|
| music-is-my-life-session | Cookie, encrypted, httpOnly, SameSite Lax | Until the browser is closed | Keeps you logged in and attributes your entries |
| XSRF-TOKEN | Cookie | Until the browser is closed | Prevents other sites from submitting forms in your name |
| mml_sprache | Cookie | One year | Remembers the language you chose |
| mml_cookies | Cookie | One year | Records what you were told and how you decided |
| mml_erscheinung | Local storage | Until you clear site data | Remembers the light or dark view |
| mml_geraeteklasse | Local storage | Until you clear site data | Remembers the screen class so the page does not jump while loading |
| mml_leistenhoehe | Local storage | Until you clear site data | Remembers the height of the player bar so content is not covered |
| mml_volume, mml_muted, mml_repeat, mml_shuffle | Local storage | Until you clear site data | Remember volume, mute, repeat and shuffle |
| mml_player | Session storage | Until the tab is closed | Keeps the current track so playback survives a page change |
| mml_listen_session | Session storage | Until the tab is closed | Attributes plays to a listening session so a play is not counted twice |
The entries in local storage and session storage remain in your browser. They are not transmitted to the server and not evaluated. You can delete them at any time through your browser settings.
Information that is added only when you pay
The following cookies are set exclusively on the payment page, and are set there by the providers embedded on that page. They are not set on any other page of the platform.
| Name | Provider | Duration | Purpose |
|---|---|---|---|
| __stripe_mid | Stripe | One year | Detects fraudulent payment attempts |
| __stripe_sid | Stripe | Until the browser is closed | Detects fraudulent payment attempts |
| m | Stripe | Up to two years | Detects fraudulent payment attempts |
| __cf_bm | hCaptcha | Until the browser is closed | Distinguishes humans from automated access |
These cookies too are necessary for carrying out the payment you requested. A payment without fraud prevention is not accepted by the payment service providers. Which data flow to whom is set out in section 22.
11. Use of the library
When you favourite tracks, mark them with "like", add them to playlists or bookmark releases, these assignments are stored with your account. You can set playlists to public or private.
Purpose: provision of the features you use. Legal basis: Article 6(1)(b) GDPR. Retention: until you remove the assignment or delete the account.
12. Playback and play statistics
An event is stored for each playback: track, time, sections heard, jumps forward and back, pauses, cancellations and playback speed. From this it is assessed whether a playback counts as heard.
Purpose: accounting for listening towards artists, detection of manipulation, production of evaluations and charts, display of your own listening history. Legal basis: Article 6(1)(b) GDPR for displaying your history and providing the service, Article 6(1)(f) GDPR for detecting manipulation. Retention: the individual events are deleted after 90 days. Before that they are condensed into daily figures per track. That condensed form no longer contains any reference to individual persons.
Artists see condensed figures only. They do not learn who listened to a track.
13. Track comparison (song against song)
In the track comparison, the time listened per track within the current session and your choice are stored. The vote cast is assigned to your account so that the number of votes per plan is observed and multiple counting is prevented.
Legal basis: Article 6(1)(b) GDPR. Retention: the vote is kept for the evaluation. The listening progress of the current pairing is held only in the session.
14. Public profile
Username, profile picture, short description, favourite tracks, public playlists and the number of followers are visible to other logged in users. You decide yourself whether your following list is visible.
Your civil name, your email address, your date of birth and your account identifier are never displayed publicly.
Legal basis: Article 6(1)(b) GDPR.
15. Artist verification
Anyone who wishes to publish music goes through an identity check. The following are processed: civil name, address, date of birth, type and number of the identity document, and an image of the front and back.
This process is based on your consent (Article 6(1)(a) GDPR), and for the image of a German identity card additionally on section 20(2) of the German Identity Card Act. You give the consent in three separate declarations, each confirmed individually.
Consent is voluntary. The platform can be used as a listener in full and unchanged. You can withdraw your consent at any time with effect for the future (Article 7(3) GDPR). The withdrawal does not affect the lawfulness of processing carried out up to that point.
What happens to the identity document images
| Storage location | a separate area outside the directory reachable over the internet |
| Retrievability | no public address, not even for you |
| Inspection | exclusively by the person carrying out the check, every retrieval is logged |
| Deletion | immediately upon the decision on the application, irreversibly |
| Abandoned applications | automatic deletion after 30 days |
| Backup | the area is excluded from the backup run |
After deletion, a record without image content remains: a check value of the deleted file, the time and the person acting. It proves that the deletion took place.
On the number of the identity document
The number is stored encrypted and additionally held as a check value. The check value serves solely to establish whether the same document has already been used for another account.
No automated retrieval of personal data takes place on the basis of the document, and the number is not used to bring together data from different sources; section 20(3) of the German Identity Card Act therefore does not stand in the way of this use. Both forms of storage can be switched off independently of one another.
Retention: the identity data are stored for as long as the artist profile exists. The records of the declarations given are kept beyond that because they evidence the lawfulness of the processing (Article 5(2) GDPR).
16. Publishing music
On upload the following are processed: the audio file and its technical properties, the cover image, title, description, genre, an optional set of lyrics, identifiers such as the ISRC, and your statements on ownership of rights and on whether and to what extent artificial intelligence was involved.
For each track and each set of lyrics given, you make separate declarations. These are recorded immutably with version, wording check value, time, a check value of your IP address and the browser statement.
Purpose: provision of the service, evidence of ownership of rights, fulfilment of the obligations under the German Copyright Service Provider Act and Regulation (EU) 2022/2065. Legal basis: Article 6(1)(b) and (c) GDPR. Retention: for as long as the track is published. Records of declarations are kept beyond that for as long as claims can be asserted.
17. Reports about content
Through the reporting form you can report tracks, cover images, profiles and playlists. Your account identifier, the reported content, the reason given, your description and the time are processed. Evidence attached is stored in a separate area that is not publicly reachable.
Purpose: examination of the report and fulfilment of the obligations under Article 16 of Regulation (EU) 2022/2065. Legal basis: Article 6(1)(c) GDPR. Retention: until the matter is closed, and beyond that for as long as claims can be asserted from it.
If content is removed or blocked, the person concerned receives a statement of reasons (Article 17 of Regulation (EU) 2022/2065).
18. Warnings and measures
Warnings may be issued for breaches of the terms of use. The occasion, the wording, the time and the acknowledgement by the person concerned are stored.
Legal basis: Article 6(1)(b) and (f) GDPR.
19. Logging of security relevant operations
Operations with a heightened need for protection are logged, in particular every retrieval of an identity document image, every deletion, every change of the verification or account status and every administrative measure. The log contains the person acting, the time and the operation, but no content.
In addition, sign-in events are recorded: a successful sign-in, a failed sign-in, a sign-out, the rejection of a sign-in for a blocked account, and the initial registration. For a failed sign-in the e-mail address entered is recorded; the password entered is not stored in any form, not even as a check value.
Each entry contains the IP address in two forms: as a check value from which the address cannot be recalculated, and in plain text. The plain text is removed automatically after 90 days. The check value and the rest of the entry remain, because a log with gaps would lose its evidential purpose and the retention duties in section 7 run considerably longer.
The log can be viewed only by the administration of the platform.
Purpose: evidence towards the supervisory authority and investigation of abuse. Legal basis: Article 5(2) and Article 6(1)(c) and (f) GDPR. Retention: the IP address in plain text for 90 days. The rest of the entry for the duration of the retention duties under section 7.
20. Memberships and payments
The platform provides for plans with differing scopes of service. The plan chosen, the start and end, scheduled changes and the agreed currency are stored.
Payments are processed by Stripe Payments Europe, Ltd., Dublin, Ireland. When you begin a payment, you enter your payment details directly with Stripe. Card numbers, account numbers and comparable payment data do not reach our server and are not stored by us.
What is stored by us are only the identifiers needed for attribution: the customer identifier at Stripe, the identifier of the subscription, the identifier of the payment, the amount, the currency, the time and the status. In addition, the details that must appear on an invoice.
For fraud prevention, Stripe independently processes further data, in particular your IP address and technical characteristics of your device. In that respect Stripe acts on its own responsibility. Further details are set out in Stripe's privacy policy.
If your device offers Apple Pay, your browser establishes a connection to Apple for that purpose. Without Apple Pay that connection does not take place.
Purpose: performance of the contract, billing, fraud prevention, fulfilment of commercial and tax obligations. Legal basis: Article 6(1)(b) GDPR for the processing, Article 6(1)(c) GDPR for the retention, Article 6(1)(f) GDPR for fraud prevention. Retention: billing documents are subject, after they arise, to the commercial and tax retention periods of up to ten years. Until then they remain restricted and are used only for that purpose.
Note on the current state: payment processing is currently in test operation. No charges are collected.
Determining the country for the currency shown
So that prices can be shown to you in a suitable currency, your IP address is matched against a country database held on this platform’s own server.
The lookup happens locally only. Your IP address is not transmitted to any third party and is not stored for this purpose. Only the country is determined, and it is not retained either.
You can choose the currency yourself at any time. Your choice takes precedence over the determination from the IP address. If a paid subscription is already running, its currency stays unchanged until the end of the term; during the term it cannot be changed either by you or by the provider.
Purpose: showing prices in a currency suitable for you. Legal basis: Article 6(1)(b) GDPR. Retention: no storage.
The country database used is named in the legal notice.
21. Sending of email
System messages such as confirmation of the email address, resetting the password or notices about a procedure are sent through our own mail server. No external dispatch service provider is used.
Legal basis: Article 6(1)(b) GDPR.
22. Recipients and processors
Ongoing operation
| Recipient | Service | Place | Basis |
|---|---|---|---|
| Hetzner Online GmbH, Gunzenhausen, Germany | Server operation and storage for media files | Germany | Processing under Article 28 GDPR |
As long as you only use the platform, your data do not leave these data centres. No transfer to countries outside the European Union takes place in that context.
When you pay
As soon as you begin a payment, your browser loads components of the following providers. Your IP address is transmitted to those providers in the process, because without it no connection can be established. This does not happen on any other page.
| Recipient | Service | Place | Basis |
|---|---|---|---|
| Stripe Payments Europe, Ltd., Dublin, Ireland | Processing of payments, fraud prevention, invoicing | Ireland, with transfer to the United States to Stripe, LLC | Article 6(1)(b) GDPR for the payment; Article 6(1)(f) GDPR for fraud prevention |
| Intuition Machines, Inc. (hCaptcha), United States | Distinguishing humans from automated access | United States | Article 6(1)(f) GDPR. The legitimate interest lies in defending against automated attacks |
| Apple Inc., United States | Provision of Apple Pay, where your device offers that payment method | United States | Article 6(1)(b) GDPR |
The connection to Apple is established by your browser itself if it supports Apple Pay. On a device without Apple Pay it does not take place.
Transfer to the United States
The United States is not a member state of the European Union. The following applies to transfers there:
By its adequacy decision of 10 July 2023, the European Commission established that transfers to companies certified under the EU-US Data Privacy Framework enjoy an adequate level of protection within the meaning of Article 45 GDPR.
Stripe, LLC is certified under that framework. The transfer to Stripe is based on it. In addition, the European Commission's standard contractual clauses apply, which form part of the data processing agreement concluded with Stripe.
For Intuition Machines, Inc. and for Apple Inc., the transfer is based on the European Commission's standard contractual clauses under Article 46(2)(c) GDPR, to the extent that no certification under the EU-US Data Privacy Framework exists for the company concerned.
Which companies are certified can be seen in the public list of the US Department of Commerce at dataprivacyframework.gov.
Beyond that
Further data are passed on only where a legal obligation exists or where it is necessary for the establishment, exercise or defence of legal claims, for example towards law enforcement authorities or rights holders in a disclosure procedure.
No sale of data takes place. No disclosure for advertising purposes takes place.
23. No automated decision in the individual case
No automated decision making, including profiling, with legal effect or a similarly significant impact takes place (Article 22 GDPR). Verification applications, reports and measures are always decided by a human being.
The assessment of playbacks and the checking of cover images are carried out by machine, but lead to no decision about you as a person. Anomalies are put before a person for checking.
24. Your rights
Under the GDPR you have the following rights:
| Right | Basis |
|---|---|
| Access to the data processed about you | Article 15 |
| Rectification of inaccurate data | Article 16 |
| Erasure | Article 17 |
| Restriction of processing | Article 18 |
| Data portability | Article 20 |
| Objection to processing based on legitimate interests | Article 21 |
| Withdrawal of consent given, with effect for the future | Article 7(3) |
| Complaint to a supervisory authority | Article 77 |
Please contact privacy@musicismylife.eu for this. Enquiries are answered without undue delay and at the latest within one month.
Handling an enquiry requires attribution to your account. Where there are doubts about your identity, additional information may be requested (Article 12(6) GDPR). A copy of an identity document is not requested for this.
25. Whether provision is required
Username, email address, password and date of birth are required in order to set up an account. Without these, no account can be created.
All further information is voluntary. The identity data are required exclusively for artist verification, not for use as a listener.
26. Changes to this policy
This policy is adjusted when the processing changes. The version published on this page at the relevant time governs.
27. Additional information for residents of California
This section supplements the sections above for residents of California under the California Consumer Privacy Act as amended by the California Privacy Rights Act.
Categories of personal information collected. Identifiers (username, email address, account identifier, IP address), personal information under Cal. Civ. Code section 1798.80 (name, address, date of birth, identity document data in the case of artist verification), commercial information (plans, payments), internet activity (playback and usage data), and audio and visual information that you upload yourself.
Sources. Directly from you, and automatically from your device when you use the site.
Purposes. Those set out in the sections above.
Sale and sharing. We do not sell personal information and we do not share it for cross context behavioural advertising. We have not done so in the preceding twelve months. This also applies to personal information of minors under 16 years of age.
Sensitive personal information. The identity document data processed in artist verification are collected only with your consent and are used solely for that verification. They are not used to infer characteristics.
Your rights. You have the right to know, to access, to delete, to correct, to opt out of sale and sharing, and to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights. Requests go to privacy@musicismylife.eu. We verify a request by attributing it to your account.
Authorised agents. An authorised agent may make a request on your behalf on presentation of written authorisation.
Retention. We keep personal information for the periods set out in section 7.
28. Additional information for the United Kingdom
The controller has no establishment in the United Kingdom and has not appointed a representative under Article 27 of the UK GDPR, as processing is occasional and does not involve large scale processing of special category data of persons in the United Kingdom. Please direct enquiries to privacy@musicismylife.eu.
You may lodge a complaint with the Information Commissioner's Office at ico.org.uk.
29. Additional information for other countries
This policy applies unchanged wherever you live. This section adds what applies in addition in a number of countries. It takes nothing away from the rights described above.
The platform is operated in Germany and the processing takes place in Germany. The GDPR and German law therefore apply, and the competent supervisory authority is the one named in section 3.
There is no data localisation. Your data are not stored in your own country but in the data centres named in section 22. If the law where you live requires the data of its residents to remain within the country, this platform does not meet that requirement. We write this out plainly so that you can decide knowing it.
Article 77 GDPR names the supervisory authority of your habitual residence. If you live outside the European Union and the European Economic Area, that route is not open to you, because there is no GDPR supervisory authority there. The authority in Hesse named in section 3 remains open to you, and independently of that you may turn to the authority of your own country named below.
Ireland
Ireland is a member of the European Union, so everything described above applies to you in full. The supervisory authority competent for you is the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963, www.dataprotection.ie.
The Data Protection Act 2018 supplements the GDPR in Ireland. It changes nothing about the rights described above, but it regulates, among other things, the powers of the Data Protection Commission and the age from which a child can consent to information society services, which in Ireland is 16 years. This platform requires 16 years for an account in any case.
Canada and Quebec
To the extent that Canadian law applies to our processing, the rights it gives you apply alongside those named in section 24: at the federal level the Personal Information Protection and Electronic Documents Act, and in Quebec the Act respecting the protection of personal information in the private sector as amended by Law 25.
The authorities are the Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec K1A 1H3, and, in Quebec, the Commission d'accès à l'information.
Australia
To the extent that Australian law applies to our processing, the Privacy Act 1988 and the Australian Privacy Principles give you rights corresponding to those described above, in particular access to and correction of your personal information. The authority is the Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001, www.oaic.gov.au.
New Zealand
To the extent that New Zealand law applies to our processing, the Privacy Act 2020 and its information privacy principles give you rights corresponding to those described above. The authority is the Office of the Privacy Commissioner, PO Box 10094, Wellington 6143, www.privacy.org.nz.
India
To the extent that Indian law applies to our processing, the Digital Personal Data Protection Act 2023 gives you rights corresponding to those described above, in particular access, correction, erasure and the withdrawal of consent, as and when its provisions come into force. Requests are to be addressed first to privacy@musicismylife.eu.
South Africa
To the extent that South African law applies to our processing, the Protection of Personal Information Act 4 of 2013 gives you rights corresponding to those described above, in particular access, correction and deletion. The authority is the Information Regulator, JD House, 27 Stiemens Street, Braamfontein, Johannesburg 2001, inforegulator.org.za.
How this works in practice
The rights named in section 24 are granted to you wherever you live. Where the law where you live grants you more, the wider right applies. In either case the contact address is privacy@musicismylife.eu.