Privacy Policy
Last updated: 15 August 2026
Translation notice
This page is a translation for guidance only. The German version of this page is the sole legally binding version.
Privacy Policy
Last updated: 15 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other data protection provisions for the processing of personal data in connection with Artist League is:
Hani Chami
Artist League
Sole proprietorship
c/o COCENTER
Koppoldstr. 1
86551 Aichach
Germany
E-mail: info@artistleague.de
Hereinafter referred to as "Artist League", "we" or "us".
2. General information on data processing
We process personal data only to the extent necessary to provide and operate Artist League, to fulfil our contractual obligations, to communicate with users, to run competitions and platform features, to process payments, to ensure security, or to comply with legal obligations.
Personal data is any information relating to an identified or identifiable natural person.
Depending on the specific processing activity, processing is based in particular on:
- Art. 6(1)(a) GDPR – consent,
- Art. 6(1)(b) GDPR – performance of a contract or pre-contractual measures,
- Art. 6(1)(c) GDPR – compliance with a legal obligation,
- Art. 6(1)(f) GDPR – protection of legitimate interests.
3. Minimum age
Use of Artist League, and in particular the creation of a user account, is permitted exclusively to persons who are at least 18 years old.
Persons under the age of 18 may not create a user account and may not use the services of Artist League that require registration.
4. Provision of the website and technical access data
When Artist League is accessed, technically necessary information may be processed. This may include in particular:
- IP address,
- date and time of access,
- pages and resources accessed,
- browser type and version,
- operating system,
- device type,
- referrer / access source,
- technical request and connection information,
- error, security and diagnostic data.
This processing serves to provide the website, ensure stability and security, analyse errors, and detect and prevent misuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional operation of Artist League.
5. Registration and user account
A user account is required for various features of Artist League. In this context, the following data may in particular be processed:
- e-mail address,
- user ID,
- authentication information,
- chosen login method,
- time of registration,
- time of logins,
- user role,
- profile and account data,
- technical security information.
This processing is carried out to create, manage and secure the user account and to provide the features associated with the account. The legal basis is Art. 6(1)(b) GDPR.
6. Login by e-mail
Users can register and log in using their e-mail address.
Verification e-mails may be sent to confirm an e-mail address. E-mails relating to password resets, security measures and account management may also be sent.
This processing is carried out pursuant to Art. 6(1)(b) GDPR and, to the extent security measures are concerned, on the basis of Art. 6(1)(f) GDPR.
7. Login with Google
Artist League enables login via a Google account.
When this feature is used, the data required for authentication may be exchanged between Google and Artist League. This may include in particular a unique account ID, e-mail address, and other basic information released by the user or Google.
The use of Google login takes place at the user's request for registration or login and is therefore based on Art. 6(1)(b) GDPR.
Google's own data processing is additionally subject to Google's privacy policy.
8. Login with Apple
Artist League also enables login via Sign in with Apple.
In this case, the information required for authentication is transmitted from Apple to Artist League.
Depending on the user's settings, Apple may provide a relay e-mail address instead of the actual e-mail address.
This processing is carried out for registration and login at the user's request pursuant to Art. 6(1)(b) GDPR.
Apple's own data processing is additionally subject to Apple's privacy policy.
9. User roles and permissions
Artist League uses different user roles and permissions, for example for regular users and administrators.
The following information may in particular be processed for this purpose:
- user ID,
- assigned role,
- time of role assignment.
This processing serves access control, administration and security of the platform.
The legal basis is Art. 6(1)(b) GDPR and, with regard to security and administrative purposes, Art. 6(1)(f) GDPR.
10. Artist profiles
Users can create or use artist profiles as part of Artist League. Depending on use, the following information may in particular be processed:
- artist name,
- profile picture or avatar,
- biography,
- city,
- country,
- genre,
- social media links,
- music and platform links,
- other voluntarily provided profile information,
- technical IDs and timestamps.
Certain profile information is intentionally publicly visible and can therefore also be viewed by other users or non-registered visitors. Users should not publish any information in publicly visible profile areas that they do not want to make publicly accessible. The legal basis is Art. 6(1)(b) GDPR.
11. Music, video and performance content
Artist League enables the upload, storage, linking or publication of music, audio, video, image or performance content. In this context, the following may in particular be processed:
- uploaded files,
- video or music links,
- title,
- file paths,
- assignment to the user or artist,
- technical file information,
- creation and modification timestamps,
- other related metadata.
This processing is carried out to provide the corresponding platform features pursuant to Art. 6(1)(b) GDPR. Users are themselves responsible for ensuring that they hold the rights required for the content they provide or publish.
12. Beats
Artist League enables producers or users to provide beats. In this context, the following information may in particular be processed:
- producer ID,
- title,
- description,
- audio file or storage path,
- cover or cover path,
- genre,
- BPM,
- mood,
- tags,
- preview start,
- preview duration,
- publication status,
- deactivation status,
- play counter,
- creation and modification timestamps.
This processing is carried out to provide the beat features of Artist League pursuant to Art. 6(1)(b) GDPR.
13. Beat plays
When beat previews are used, the number of plays may be recorded.
This serves in particular to provide usage information and to ensure the functionality of the platform.
Where a play must be attributed to a logged-in user, this is done to the extent necessary.
The legal basis is Art. 6(1)(b) GDPR or, with regard to aggregated usage statistics, Art. 6(1)(f) GDPR.
14. Competitions
Artist League organises and/or manages competitions ("Competitions").
In this context, the following information may in particular be processed:
- competition,
- competition title,
- period,
- entry deadline,
- voting period,
- entry fee,
- competition status,
- technical IDs and timestamps.
Where this information is personal data or is linked to personal data, processing is carried out to run the competition pursuant to Art. 6(1)(b) GDPR.
15. Competition entries
When participating in a competition, the following information may in particular be processed:
- user or artist ID,
- competition,
- song title,
- video or song link,
- entry status,
- payment status,
- publication status,
- internal review information, where applicable,
- creation and modification timestamps.
This processing is carried out to conduct and manage participation in the competition pursuant to Art. 6(1)(b) GDPR.
16. Review and moderation of entries
Entries may be reviewed, accepted or rejected before or during a competition.
In this context, status information as well as internal review or moderation notes may in particular be processed.
This processing is carried out to run the competitions, ensure compliance with platform rules, and safeguard the quality and security of the platform.
The legal basis is Art. 6(1)(b) GDPR as well as Art. 6(1)(f) GDPR.
17. Voting
Artist League may enable voting on artists or submissions.
In this context, the following may in particular be processed:
- User ID,
- Artist ID,
- Competition,
- Voting category,
- Time of the vote,
- Technical assignment or verification information.
This processing serves to conduct the vote and, in particular, to prevent impermissible multiple voting and manipulation.
The legal basis is Art. 6(1)(b) GDPR as well as, with regard to fraud and manipulation prevention, Art. 6(1)(f) GDPR.
18. Competition winners
After a competition ends, information about winners may be stored and published.
In this context, the following may in particular be processed:
- Competition,
- Artist,
- Category,
- Number or result of votes,
- Time of winning.
This processing takes place to carry out and document the competition pursuant to Art. 6(1)(b) GDPR.
19. Following artists
Artist League may allow users to follow artists. In this context, the following may in particular be stored:
- User ID,
- Artist ID,
- Time of following.
This processing takes place to provide the feature requested by the user pursuant to Art. 6(1)(b) GDPR.
20. Saving artists or content
Artist League may offer features allowing users to save or bookmark artists or content. In this context, in particular the user ID, artist ID and timestamps may be processed. The legal basis is Art. 6(1)(b) GDPR.
21. Notifications
Artist League may display notifications to users within the platform. In this context, the following data may in particular be processed:
- User ID,
- Type of notification,
- Title,
- Content,
- Target link,
- Read status,
- Creation and modification time.
Notifications may, for example, be created in connection with platform interactions, beats, competitions or other processes relevant to the respective user. The legal basis is Art. 6(1)(b) or (f) GDPR, depending on the context.
22. Contact and interest features
Artist League may offer features through which users can express interest in beats, artists or other offerings, or initiate contact. In this context, in particular user information, the relevant content, and messages entered by the user may be processed. This processing takes place to carry out the contact requested by the user pursuant to Art. 6(1)(b) GDPR.
23. Artist verification
Artists may, where applicable, request verification of their profile. In this context, the following may in particular be processed:
- User ID,
- Artist ID,
- Category,
- Stated follower count,
- Proof links,
- Voluntary explanations,
- Processing status,
- Review notes,
- Time of review,
- Assignment to the reviewing administrator.
This processing takes place to review the verification request pursuant to Art. 6(1)(b) GDPR and on the basis of our legitimate interest in authentic and trustworthy profiles pursuant to Art. 6(1)(f) GDPR.
24. Industry applications
Artist League may offer special industry features to individuals and companies from the music and creative industries. As part of a corresponding application, the following may in particular be processed:
- User ID,
- Full name,
- Company,
- Position or job title,
- Company type,
- Website,
- Business e-mail address,
- Message or application text,
- Processing status,
- Internal review notes,
- Time of review,
- Reviewing administrator,
- Creation and modification times.
This processing takes place to handle the application or request pursuant to Art. 6(1)(b) GDPR, or to manage and secure access to industry features pursuant to Art. 6(1)(f) GDPR.
25. Industry shortlists
Authorized industry users may, where applicable, save artists to an internal shortlist.
In this context, the following may in particular be processed:
- User ID,
- Artist ID,
- Notes,
- Creation time.
This processing takes place to provide this platform feature pursuant to Art. 6(1)(b) GDPR.
26. Reporting beats and other content
Artist League may provide features for reporting beats or other problematic, unlawful or rule-violating content.
In this context, the following may in particular be processed:
- ID of the reported content,
- User ID of the reporting person,
- Reason for the report,
- Message or explanation,
- Processing status,
- Creation and modification time.
This processing serves to review reports, enforce our platform rules, prevent abuse and protect Artist League and its users.
The legal basis is Art. 6(1)(f) GDPR as well as, where applicable, Art. 6(1)(c) GDPR, to the extent legal obligations apply.
27. Payment processing via Stripe
For paid services on Artist League, in particular paid competition entries and, where applicable, other paid offerings, we use Stripe as a payment service provider.
In the context of a payment, the following may in particular be processed:
- Name and contact details,
- Payment and transaction information,
- Amount and currency,
- Payment status,
- Time of the transaction,
- Assignment to the respective service or competition entry,
- Technical information for carrying out and securing the payment,
- Where applicable, invoicing and tax-related information required by law.
Payment data such as complete credit card data is, to the extent it is collected directly via Stripe, processed by Stripe. Artist League does not generally store complete credit card data.
For business customers, Stripe in particular processes transaction data to carry out payments and may also process certain data for its own purposes, such as fraud prevention, security and regulatory obligations. [Stripe](https://stripe.com/de/privacy)
Payment processing takes place on the basis of Art. 6(1)(b) GDPR. To the extent payment and transaction data must be stored due to statutory commercial or tax law obligations, processing takes place on the basis of Art. 6(1)(c) GDPR.
As part of the Stripe services, data may also be processed outside the European Economic Area. Stripe names, among other things, adequacy mechanisms, EU standard contractual clauses and, where applicable, the EU-U.S. Data Privacy Framework. (Stripe)
[Stripe's privacy policy] (https://stripe.com/de/privacy)
28. Payment and transaction records at Artist League
In addition to the actual payment processing, Artist League may store information for assigning and documenting a payment.
This may in particular include:
- User or competition entry,
- Payment reference,
- Amount,
- Payment status,
- Time of payment,
- Technical transaction references.
This processing is required to assign payments to a service, determine the entry or service status, and to be able to trace transactions.
The legal basis is Art. 6(1)(b) GDPR as well as, where applicable, Art. 6(1)(c) GDPR.
29. E-mail communication
Artist League sends transactional and account-related e-mails.
This may in particular include:
- E-mail confirmation,
- Password reset,
- Authentication messages,
- Changes to the user account,
- Security-related notices,
- Other messages required to provide the platform service.
These e-mails serve to carry out the usage relationship and the security of the user account.
The legal basis is Art. 6(1)(b) GDPR as well as, for security-related messages, Art. 6(1)(f) GDPR.
Should Artist League send newsletters or other promotional e-mails in the future, separate consent will be obtained for this to the extent legally required.
30. Hosting and Lovable Cloud
Artist League is technically operated using Lovable Cloud.
According to the current configuration of the Artist League project, Europe (Ireland) is set as the project location.
Lovable states that Lovable Cloud supports regional data residency, including within the EU, and that customer data by default remains within the selected region and is not moved across regions. [Lovable] (https://lovable.dev/de/security)
As part of the technical provision, the following may in particular be processed:
- User and account data,
- Database content,
- Uploaded files,
- Authentication data,
- Technical log and security information,
- IP addresses and connection information,
- Other information required to provide the application.
Lovable notes in its privacy and contractual information that certain service, log, aggregated or de-identified data may be processed for its own purposes. [Lovable] (https://lovable.dev/de/data-processing-agreement)
Processing by Artist League takes place in particular to provide the platform pursuant to Art. 6(1)(b) GDPR as well as to ensure secure and stable operation pursuant to Art. 6(1)(f) GDPR.
[Lovable's privacy information] (https://lovable.dev/privacy)
Note on the data processing agreement:
Lovable publishes a data processing agreement (DPA), but currently notes on its website that it applies to Business and Enterprise plans. Operators on other plans
should therefore check which agreement applies to data processing for their specific plan. [Lovable] (https://lovable.dev/de/data-processing-agreement)
31. Storage of files
For storing certain user content, storage areas within Artist League's cloud infrastructure are used. These currently include storage areas in particular for:
- Avatars,
- Beats,
- Performance content.
The corresponding storage areas are, according to the current configuration, set to private.
Individual content may nevertheless be made available within Artist League to other users or publicly, as intended, when this is part of the respective platform feature.
32. Secrets and platform access credentials
Artist League uses technical secrets and access credentials for secure connections with external services.
Such secret access credentials are not intended to be made publicly accessible to users.
Lovable states that it stores secrets encrypted at rest, restricts access on a role basis, and does not expose secrets in plain text in logs or interfaces. [Lovable] (https://lovable.dev/de/security)
33. Audit logs
Artist League uses audit logs to make certain database operations and administrative or security-relevant changes traceable.
In doing so, the following may in particular be processed:
- the type of operation, e.g. INSERT, UPDATE or DELETE,
- the affected table,
- the ID of the affected record,
- the previous and/or new values,
- the time of the operation,
- the user or actor ID, where available.
This processing serves in particular security, error analysis, misuse prevention and traceability of changes.
The legal basis is Art. 6(1)(f) GDPR.
34. Technical logs and security data
In addition, technical logs may be processed to the extent necessary for the secure and stable operation of the platform. This may include, in particular, error reports, server and connection information, security events and technical diagnostic data. Processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring IT security, error resolution, availability and misuse prevention.
35. Usage statistics and analytics
As part of the technical operation of Artist League, usage statistics are available. These may include, for example:
- visitor numbers,
- page views,
- views per visit,
- visit duration,
- bounce rate,
- pages visited,
- access source or referrer,
- device type,
- approximate country of origin.
To the extent this data is processed without the use of tracking technologies requiring consent, processing is carried out to analyse and improve the offering as well as for technical operational analysis on the basis of Art. 6(1)(f) GDPR.
Our legitimate interest lies in particular in understanding the use of Artist League, identifying technical problems and improving the platform.
Should non-technically necessary tracking technologies, marketing cookies or comparable methods be used in the future, these will — where legally required — only be activated after the user's consent.
36. Cookies, local storage and comparable technologies
Artist League may use technically necessary cookies, local storage or comparable technologies.
These may in particular be required for:
- login,
- authentication,
- session management,
- security functions,
- storage of technically necessary states.
Under Section 25 of the German TDDDG, consent is generally required to store information on a terminal device or to access information already stored there. An exception applies, among other things, where access is strictly necessary in order to provide a digital service explicitly requested by the user. (Gesetze im Internet)
Non-necessary analysis, marketing or tracking technologies will — where legally required — only be used after prior consent.
37. No sign-up by phone
Sign-up via a phone number is not currently activated as a regular sign-up method for Artist League. To the extent that data relating to phone numbers or verification procedures from an earlier technical implementation may still exist, it is not processed for longer than necessary for existing legal, security-related or technical purposes, and is intended to be removed in line with the planned discontinuation of this feature.
38. Recipients of personal data
Personal data is only transferred to third parties where this is necessary for the respective processing, a legal obligation exists, or another legal basis permits the transfer. Possible recipients or categories of recipients include in particular:
- hosting and cloud service providers,
- technical infrastructure and database service providers,
- e-mail service providers,
- authentication providers such as Google and Apple,
- payment service providers such as Stripe,
- technical subcontractors,
- authorities and public bodies where there is a corresponding legal obligation.
39. Data transfers outside the EEA
Some providers used by Artist League operate internationally. Therefore, it cannot be ruled out that personal data is processed outside the European Union or the European Economic Area. To the extent personal data is transferred to a third country, this is only done in compliance with the legal requirements. These may in particular include:
- an adequacy decision by the European Commission,
- the EU-U.S. Data Privacy Framework, to the extent the respective recipient is certified accordingly,
- standard contractual clauses of the European Commission,
- other legally permissible guarantees or exceptions.
Lovable's published DPA provides, for relevant transfers outside the EEA, among other things, adequacy decisions and EU standard contractual clauses. [Lovable] (https://lovable.dev/de/data-processing-agreement)
Stripe likewise refers, among other things, to adequacy mechanisms, standard contractual clauses and — where applicable — the EU-U.S. Data Privacy Framework. [Stripe] (https://stripe.com/de/privacy)
40. Retention period
We generally only store personal data for as long as necessary for the respective processing purpose.
Account data is generally processed for the duration of the user account.
After an account is deleted, personal data is deleted or anonymised, unless legal retention obligations or other legally permissible reasons require further storage.
Contract, payment and billing data may be stored beyond the end of the usage relationship due to commercial or tax law retention obligations.
Security, log and audit data is only retained for as long as necessary for security, evidentiary, error-analysis or misuse-prevention purposes.
Published content is generally processed until the respective content is deleted, the user account is terminated, or the respective processing purpose no longer applies, unless another legal basis permits or requires further storage.
Deleted data may continue to exist in technical backup copies for a limited period until the corresponding backups are overwritten or deleted.
41. Deletion of the user account
Where an account deletion is requested or carried out, the personal data associated with the user account is deleted or anonymised in accordance with legal requirements.
Exceptions may in particular apply to data that must continue to be stored due to legal retention obligations or whose further processing is necessary for the assertion, exercise or defence of legal claims.
Publicly published content is also removed or decoupled within the scope of technical and legal possibilities, provided no other legal basis exists for its processing.
42. Data security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access, unlawful disclosure and other unlawful processing.
These may in particular include:
- encrypted data transmission,
- authentication mechanisms,
- role-based access controls,
- database permissions,
- private storage areas,
- technical logging,
- secure management of credentials and secrets,
- security and abuse-prevention controls.
Despite such measures, absolute security of data transmissions over the internet cannot be guaranteed.
43. No decision based solely on automated processing with significant effect
Artist League does not currently carry out any decision-making based solely on automated processing within the meaning of Art. 22 GDPR that produces legal effects concerning users or similarly significantly affects them.
Should such processing be introduced in the future, affected persons will be informed in accordance with legal requirements.
44. Obligation to provide data
Certain personal data is required to create a user account, participate in competitions, make payments or use certain features of Artist League. Without the required data, the corresponding services may not be able to be provided. Other information — in particular additional profile information — may be voluntary.
45. Rights of data subjects
Data subjects have, subject to the legal requirements, in particular the following rights:
- the right of access pursuant to Art. 15 GDPR,
- the right to rectification pursuant to Art. 16 GDPR,
- the right to erasure pursuant to Art. 17 GDPR,
- the right to restriction of processing pursuant to Art. 18 GDPR,
- the right to data portability pursuant to Art. 20 GDPR,
- the right to object pursuant to Art. 21 GDPR,
- the right to withdraw consent pursuant to Art. 7(3) GDPR.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of the consent before its withdrawal.
To exercise these rights, a message can be sent to the following address:
info@artistleague.de
46. Right to object
To the extent personal data is processed on the basis of Art. 6(1)(f) GDPR, there is a right, pursuant to Art. 21 GDPR, to object to the processing for reasons arising from the data subject's particular situation.
Where personal data is processed for direct marketing purposes, there is the right to object at any time to processing for the purpose of such advertising.
The objection can be addressed to info@artistleague.de.
47. Right to lodge a complaint with a data protection supervisory authority
Data subjects have the right, pursuant to Art. 77 GDPR, to lodge a complaint with a data protection supervisory authority if they consider that the processing of their personal data violates data protection law.
The complaint can in particular be lodged with a supervisory authority in the member state of the data subject's habitual residence, place of work, or the place of the alleged infringement.
48. Changes to this privacy policy
Artist League may adapt this privacy policy if the platform, the services used, the processing procedures or legal requirements change. This applies in particular to the introduction of new features, service providers, analysis methods, communication services or payment methods. The version published on Artist League at the respective time shall apply.
Last updated: 15 August 2026