Privacy policy

Last updated: October 2026

1. Controller

VOID Creative GmbH
Bünteweg 26
30989 Gehrden
Germany
info@voidcreativegroup.com

Managing director: Finn Niermann.

2. Scope and legal bases

This policy covers the Void portal at portal.voidcreativegroup.com and the share pages at share.voidcreativegroup.com, where artists, songwriters, producers and companies working with Void send us their details, see the statements for their songs and open files we share with them, and what happens to that data afterwards. Access is by invitation only.

The portal is free of charge, but using it is a contract under our terms of use. Where we process your data to provide the portal to you, or to prepare or perform your contracts with us, the legal basis is Art. 6(1)(b) GDPR. Where you are not a party yourself, for example as a company's signatory, as a parent or guardian, as the recipient of a shared file or before you accept an invitation, the legal basis is our legitimate interest in working with you or with the person or company you act for, Art. 6(1)(f) GDPR. Where the law obliges us to keep data, the legal basis is Art. 6(1)(c) GDPR.

3. Invitation and account

When we invite you, we use your name and email address from our records of our work together. For your account we store your email address, your name, the sign-in methods you set up and the device, browser and IP address of each sign-in, held by our sign-in provider. We use them to give you access and to match your account to your invitation, and the sign-in records to protect your account. Legal basis: Art. 6(1)(b) GDPR; for the invitation and the sign-in records, Art. 6(1)(f) GDPR.

4. Signing in

We never receive your passwords for Google, Apple or Discord; their own privacy policies apply to the sign-in on their side. Legal basis: Art. 6(1)(b) GDPR.

5. Your details (intake)

Before an intake link opens, we send a six-digit code to the email address it was issued for; it stops working after 10 minutes. Through the link we ask for what we need to prepare and sign contracts with you and to credit and account to you correctly:

The address field suggests addresses through Loqate. Legal basis: Art. 6(1)(b) GDPR; for a guardian's and a signatory's details, Art. 6(1)(f) GDPR (concluding a valid contract with the minor or the company); for tax IDs and data we must keep for accounting, also Art. 6(1)(c) GDPR with tax and commercial law. We need these details to conclude a contract with you; without them we cannot sign it.

6. Statements

For songs in which you hold a share, the portal shows the marketing costs booked against each song per month, as we reported them to our distributor Label Engine. To decide which songs you see, we use the link between your account, our record of you and your shares. Legal basis: Art. 6(1)(b) GDPR.

7. Shared files

When we share files with you, such as unreleased recordings or artwork, a link is open either to anyone who has it or only to the email addresses we list. It expires after 30 days unless we chose 7 days, 90 days or no expiry when sharing it, and we can extend or withdraw it at any time. For a restricted link, we send a six-digit code to your email address before it opens. We record whom a link was sent to, when it was opened and which files were played or downloaded, with the verified email address where there is one. We do not store IP addresses for this. We do it to protect unreleased music and to trace leaks. Legal basis: Art. 6(1)(b) GDPR where you work with us on the release, otherwise Art. 6(1)(f) GDPR (protecting unreleased recordings).

8. Emails

We send invitations, codes, links and notices from os.voidcreativegroup.com through Resend, processing your email address, the content of the email and its delivery status. The portal sends no newsletters or advertising. Legal basis: Art. 6(1)(b) GDPR.

9. AI-assisted work in voidOS

Your details and contracts end up in voidOS, our internal system. Our team uses AI models from Anthropic and OpenAI there to read contract documents into structured data and to answer team members' questions about our catalogue, so your name, address, shares and contract terms can reach these providers. A person checks what a contract reading or an answer proposes before it changes any record. To sort tasks by area, voidOS also sends their titles, which can name you, to OpenAI; Typesafe AI, Inc. (USA) receives only the task text with the names and contact details voidOS knows removed. That sorting is applied without a check, and the team can change it. Anthropic and OpenAI act as our processors, may not use the data to train their models, and delete it after at most 30 days unless they must keep it longer to stop misuse or by law. Legal basis: Art. 6(1)(f) GDPR (efficient, accurate contract and catalogue work).

10. Security and operation

Legal basis: our legitimate interest in a secure, working portal, Art. 6(1)(f) GDPR.

11. Cookies and browser storage

The portal uses no cookies or browser storage for analytics or advertising. It stores only what it needs to work: the sign-in session cookies of your account; the intake or share session in your tab's session storage, valid for at most 24 hours and removed when you close the tab; and your light or dark appearance in local storage. These are strictly necessary for the service you asked for (§ 25(2) no. 2 TDDDG), so no consent is needed.

12. Service providers

These providers process data on our behalf under data processing agreements (Art. 28 GDPR):

13. Other recipients

When you sign in with Google, Apple or Discord, these companies are controllers for the sign-in on their side:

Label Engine and the distributors we release your music through receive what distribution and accounting need. Tax advisers, auditors and authorities receive data where the law requires it.

14. Transfers outside the EU

Where a provider in section 12 is certified under the EU-U.S. Data Privacy Framework, transfers to it rely on the European Commission's adequacy decision for that framework (Art. 45 GDPR). Transfers to Convex, and the processing of Anthropic and OpenAI in the USA, rely on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). Loqate is covered by the adequacy decision for the United Kingdom. A copy of the safeguards is available from us on request.

15. Retention

16. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). To use them, write to info@voidcreativegroup.com.

When you ask us to erase your data, we confirm it is you and erase it, except what we still need: to perform a contract that is still running (Art. 6(1)(b) GDPR), to keep by law, such as payments and bookings for up to ten years (§ 147 AO, § 257 HGB), or to establish, exercise or defend legal claims (Art. 17(3)(e) GDPR). Signed contracts are kept as long as the rights granted in them exist, and afterwards for the statutory periods. Credit names used on recordings and works stay, as the attribution we agreed. We keep the rest only for its purpose and erase or restrict it when the purpose ends. Where a backup can't be changed, we restrict its processing instead of erasing it (§ 35(1) BDSG). We answer every request within one month.

Right to object (Art. 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR.

You may also complain to a data protection supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, lfd.niedersachsen.de.

17. No automated decisions

We make no decisions based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.

18. Changes and language

We update this policy when the portal or the law changes. It is available in English and German; the English version governs.