Legal
Privacy Policy
Last updated: 30 September 2026 · Version 2026-09-30
This policy explains what personal data Royal Streaming AB processes when you use GetMusicAt, why, who receives it, how long we keep it, and how you can use your rights.
Who is responsible
#GetMusicAt is a service and brand of Royal Streaming AB (org. no. 556697-4746), Vaksalagatan 16, Våning 3, 753 20 Uppsala, Sweden. Royal Streaming AB is the controller for the personal data described in this policy (“we”, “us”).
You can reach us about privacy at support@getmusic.at. We have not appointed a data protection officer. This policy follows the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act (2018:218) with its supplementary provisions.
Who this policy covers
#GetMusicAt is a service for businesses. This policy covers the people whose personal data we process when the service is used:
- users of the web app at app.getmusic.at: account owners and the staff they invite, and the billing contacts of our customers;
- visitors of getmusic.at and people who try the public demo;
- people who contact us, and business contacts we reach with information about GetMusicAt.
Company information about our customers (for example the legal name or VAT number of a limited company) is not personal data, but we treat it with the same care.
The data we process
#| Category | What it includes | Where it comes from |
|---|---|---|
| Account | First and last name, email address, password (stored only as a one-way hash), email verification status, the company name and country entered at sign-up. | You |
| Organization and billing | Your organization’s name, legal name, business type, country, VAT and organisation number, billing email and billing address, locations, and your membership: role, which locations you can use, who invited you. | You or the Owner of your organization |
| Legal acceptance | Which version of the Terms of Service and Privacy Policy you accepted and when, your browser’s user agent and a keyed hash of your IP address. | You |
| Music preferences and favourites | The answers you give in the setup wizard (for example mood, visitors, energy), sounds you like, and sounds recently played. | You |
| Playback and device | Playback sessions: which sound was played at which location, when and for how long, why it stopped, and whether it played in the browser or on Sonos. A random device identifier stored in your browser, basic device information (browser, operating system, language) and a keyed hash of your IP address. Diagnostic events from the player (for example buffering or network errors). | Your use of the app |
| Sign-in and security | Signed-in devices (start time, last activity, user agent), a keyed hash of the IP address used, and short-lived rate-limit counters based on IP address and email address. Audit records of important actions (for example sign-ins, role changes, billing changes, data exports). | Your use of the app |
| Payment | The card brand, last four digits and expiry date, invoices and payment status. The full card number and security code are entered on Stripe’s pages and never reach us. | Stripe |
| Which emails we sent you and when, whether they were delivered or bounced and, for marketing emails, whether they were opened or a link was clicked if our email provider reports it, and your email preferences and unsubscribes. | Our email provider, you | |
| Sonos | If your organization connects Sonos: encrypted access tokens and the names and identifiers of your Sonos households, speakers and groups. We do not receive your Sonos password. | Sonos, at your request |
| Product usage events | Pseudonymous records of 18 key actions in the service (for example account created, trial started, location created, playback started or stopped, sound favourited). They contain internal ids, not your name, email or IP address. | Your use of the app |
| Demo | A keyed hash of the IP address and basic device information of a demo session, and whether the visitor later created an account. | Your use of the demo |
| Support | Your messages to us and internal notes that our support staff keep about your organization’s cases. | You, our staff |
| Business contacts | Name, business email, company, country and business type of people we contact about GetMusicAt, with the source of the details and any consent or unsubscribe. | You or a business source |
We do not use precise location, device sensors, advertising identifiers or social media plug-ins, and we do not show advertising. A “keyed hash” means the IP address is replaced by a code computed with a secret key, which lets us recognise repeated use of the same address for security purposes without storing the address itself. Full IP addresses are stored only in audit records of actions taken by our own staff.
Why we process it and our legal basis
#| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account and organization, letting you invite and manage users, playing music, connecting Sonos, providing certificates and support. | Performance of the contract with you or your employer, Art. 6(1)(b); for staff invited by a customer, our and the customer’s legitimate interest in providing the service they use for work, Art. 6(1)(f) |
| Taking payments, invoicing and handling VAT. | Performance of the contract, Art. 6(1)(b), and legal obligations, Art. 6(1)(c) |
| Keeping accounting records, and responding to lawful requests from authorities. | Legal obligation, Art. 6(1)(c), including the Swedish Bookkeeping Act (1999:1078) |
| Recording your acceptance of our Terms and Privacy Policy. | Legitimate interest in being able to show what was agreed, Art. 6(1)(f) |
| Security: protecting accounts, preventing fraud, misuse of trials and unauthorised playback, rate limiting, audit logs and diagnostics. | Legitimate interest in keeping the service and our customers secure, Art. 6(1)(f) |
| Personalising the catalogue: suggesting sounds based on your answers, favourites and plays. | Performance of the contract, Art. 6(1)(b) |
| Improving the service with first-party usage statistics. | Legitimate interest in understanding how the service is used, Art. 6(1)(f) |
| Service and account emails (verification, password, invitations, help with getting set up, trial and billing notices). | Performance of the contract, Art. 6(1)(b) |
| Tips, offers and product news by email, to customers who ticked the separate box at sign-up or switched it on in Settings, and to business contacts who agreed to receive them. | Your consent, Art. 6(1)(a). You can withdraw it at any time in Settings → Email preferences or with the unsubscribe link in any marketing email |
| Establishing, exercising or defending legal claims. | Legitimate interest, Art. 6(1)(f) |
Where we rely on legitimate interests, we have balanced them against your interests and rights. You can object at any time (see “Your rights”). We do not make decisions based solely on automated processing that have legal or similarly significant effects on you. Sound suggestions are recommendations only.
Who receives your data
#We do not sell your personal data and do not share it with advertisers. We share it only with:
- Stripe (payments, invoicing and the billing portal). Stripe processes card data under its own responsibility and also acts as an independent controller for fraud prevention and its legal obligations.
- Resend (sending our emails and reporting delivery).
- Sonos, only if your organization connects a Sonos account: we send playback commands and stream links to Sonos. Sonos processes data under its own privacy policy.
- Hosting and infrastructure providers that run our servers, databases, streaming, file storage and encrypted backups, and an error monitoring provider if we use one. Error reports are scrubbed of passwords, cookies, request contents and personal details other than an internal user id.
- Other members of your organization, according to their roles: for example, the Owner can see members’ names, email addresses and roles, and which locations are playing.
- Anyone who checks your certificate sees your organization’s name, the location name and whether the subscription is valid, and nothing else.
- Authorities, advisers and buyers: courts and authorities when the law requires it, our auditors and legal advisers, and a buyer or successor if the GetMusicAt business is transferred.
Our service providers process personal data on our behalf under data processing agreements and may only use it to provide their services to us.
Transfers outside the EU/EEA
#We aim to process personal data within the EU/EEA. Stripe and Resend are companies based in the United States, and some data may be processed there. Such transfers rely on the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on the European Commission’s Standard Contractual Clauses with additional safeguards where needed. Sonos is also based in the United States; if you connect Sonos, the data needed to control your speakers is transferred to Sonos under its own terms. Contact us for more information about the safeguards.
How long we keep it
#| Data | How long |
|---|---|
| Your account | Until you delete it. When you delete your account, your name and email address are replaced, your password is made unusable, and your favourites, music preferences and memberships are deleted at once. |
| Sign-in sessions | A sign-in lasts at most 90 days. Session records are deleted 7 days after they expire. |
| Product usage events | 13 months, then deleted. When you delete your account, your events are unlinked from it. |
| Accounting records (invoices, payments) | Seven years after the end of the calendar year in which the financial year ended, as required by the Swedish Bookkeeping Act. |
| Proof of legal acceptance and audit records | Kept after account deletion for as long as needed to show what was agreed and done, and to defend legal claims. Audit records of customer actions contain no IP address. |
| Playback history | As long as the organization’s account exists, for music licence reporting. After account deletion, the history is no longer linked to you. |
| Player diagnostics (errors, network state, device type) | 90 days, then deleted. |
| Sonos command and event logs, stream checks | 30 days, then deleted. |
| Free demo and 30-second previews | Demo sessions (with a keyed hash of the network address) 90 days; previews 30 days; then deleted. |
| Payment provider notifications | The content of Stripe notifications (which can include names and addresses) is cleared after 90 days; the invoices themselves are kept as accounting records. |
| Organization data | As long as the organization exists. After an organization is deleted, its records are kept in closed form for accounting, security and legal claims. |
| Email log and email preferences | 13 months, then deleted. When you delete your account, your address is removed from the email log, delivery events, campaign lists and invitations at once. Unsubscribes and bounces are kept so that we keep respecting them. |
| Sonos tokens and speaker information | Until Sonos is disconnected or the organization is deleted; the tokens are then deleted. |
| Business contacts | Until you unsubscribe or ask us to delete your details (the email we sent you is then anonymized too); an unsubscribe is kept so that we do not contact you again. |
| One-time links and codes | Deleted 7 days after they expire. |
| Backups | Encrypted database backups are kept for 30 days, so deleted data disappears from backups within that time. |
How we protect your data
#- All traffic is encrypted with TLS. Passwords are stored with a strong one-way hash (Argon2id), and sign-in tokens only as hashes.
- Sonos tokens and other secrets are encrypted in our database. Backups are encrypted before they leave the server.
- Every customer’s data is separated from other customers’ data, and access inside an organization follows the member’s role.
- Our staff use separate staff accounts on a separate admin site, access is limited to what their role needs, sign-in attempts are rate limited, and important actions are recorded in an audit log.
- Support staff can only view the app as you, for troubleshooting, when that feature is enabled; every such session requires a written reason, is time-limited and is recorded.
Your rights
#Under the GDPR you have the right to:
- access your personal data and receive a copy (portability): in the app, go to Settings → Your data → Download my data to get a JSON file with your data;
- rectification: change your name in Settings → Profile; your organization’s Owner can change company details;
- erasure: delete your account in Settings → Danger zone. Some data is kept as described under “How long we keep it”;
- object to processing based on legitimate interests, and at any time to direct marketing: switch off “Tips and offers” in Settings → Email preferences, or use the unsubscribe link in any marketing email;
- restriction of processing in certain cases, and to withdraw consent at any time where we rely on consent, without affecting earlier processing.
For anything you cannot do in the app, email support@getmusic.at. We may need to confirm your identity, and we answer within one month. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se, or with the supervisory authority where you live or work.
Children
#GetMusicAt is a service for businesses and is not directed at children. Users must be at least 18 years old. We do not knowingly collect personal data about children.
Cookies
#We only use cookies and browser storage that are needed for the service to work, such as keeping you signed in. We do not use analytics or advertising cookies. See our Cookie Policy.
Changes to this policy
#We update this policy when our processing changes. The current version is always published at getmusic.at/privacy with its date and version number. We will tell account owners by email or in the app about significant changes before they take effect.
Contact
#Questions about privacy or requests about your data:
Royal Streaming AB (org. no. 556697-4746)Vaksalagatan 16, Våning 3, 753 20 Uppsala, Sweden
Email: support@getmusic.at