Privacy policy
Last updated: October 2026
1. Controller
VOID Creative GmbHBünteweg 26
30989 Gehrden
Germany
info@voidcreativegroup.com
Managing director: Finn Niermann.
2. Scope and legal bases
This policy covers the Void portal at portal.voidcreativegroup.com and the share pages at share.voidcreativegroup.com, where artists, songwriters, producers and companies working with Void send us their details, see the statements for their songs and open files we share with them, and what happens to that data afterwards. Access is by invitation only.
The portal is free of charge, but using it is a contract under our terms of use. Where we process your data to provide the portal to you, or to prepare or perform your contracts with us, the legal basis is Art. 6(1)(b) GDPR. Where you are not a party yourself, for example as a company's signatory, as a parent or guardian, as the recipient of a shared file or before you accept an invitation, the legal basis is our legitimate interest in working with you or with the person or company you act for, Art. 6(1)(f) GDPR. Where the law obliges us to keep data, the legal basis is Art. 6(1)(c) GDPR.
3. Invitation and account
When we invite you, we use your name and email address from our records of our work together. For your account we store your email address, your name, the sign-in methods you set up and the device, browser and IP address of each sign-in, held by our sign-in provider. We use them to give you access and to match your account to your invitation, and the sign-in records to protect your account. Legal basis: Art. 6(1)(b) GDPR; for the invitation and the sign-in records, Art. 6(1)(f) GDPR.
4. Signing in
- Email code: our sign-in provider, Clerk, creates a one-time code, and we send it to your email address from a voidcreativegroup.com address through Resend. Clerk sets how long it is valid and how often it may be tried. We keep the code for its 10 minutes to send it and delete it within 30 minutes after it expires.
- Passkey: you can add a passkey and sign in with it; it is stored by our sign-in provider.
- Google: Google shares your name, email address and profile picture with us. We use them only to sign you in and to match your account to your invitation. We do not use Google user data for advertising, do not sell it, and share it only with the service providers in section 12 that run sign-in for us.
- Apple: Apple shares your name and email address. If you choose to hide your email, Apple gives us a relay address (ending in privaterelay.appleid.com) that forwards our emails to you.
- Discord: Discord shares your username, email address and profile picture.
We never receive your passwords for Google, Apple or Discord; their own privacy policies apply to the sign-in on their side. Legal basis: Art. 6(1)(b) GDPR.
5. Your details (intake)
Before an intake link opens, we send a six-digit code to the email address it was issued for; it stops working after 10 minutes. Through the link we ask for what we need to prepare and sign contracts with you and to credit and account to you correctly:
- confirmation of your shares in songs, with an optional note;
- legal name, date of birth, postal address and email address;
- credit name or stage name;
- IPI number and collecting society memberships with member numbers, if you have them;
- if you are under 18: the name and email address of a parent or legal guardian, who receives their own link;
- for companies: the company's name, address and tax IDs, and the signatory's name, email address and position.
The address field suggests addresses through Loqate. Legal basis: Art. 6(1)(b) GDPR; for a guardian's and a signatory's details, Art. 6(1)(f) GDPR (concluding a valid contract with the minor or the company); for tax IDs and data we must keep for accounting, also Art. 6(1)(c) GDPR with tax and commercial law. We need these details to conclude a contract with you; without them we cannot sign it.
6. Statements
For songs in which you hold a share, the portal shows the marketing costs booked against each song per month, as we reported them to our distributor Label Engine. To decide which songs you see, we use the link between your account, our record of you and your shares. Legal basis: Art. 6(1)(b) GDPR.
7. Shared files
When we share files with you, such as unreleased recordings or artwork, a link is open either to anyone who has it or only to the email addresses we list. It expires after 30 days unless we chose 7 days, 90 days or no expiry when sharing it, and we can extend or withdraw it at any time. For a restricted link, we send a six-digit code to your email address before it opens. We record whom a link was sent to, when it was opened and which files were played or downloaded, with the verified email address where there is one. We do not store IP addresses for this. We do it to protect unreleased music and to trace leaks. Legal basis: Art. 6(1)(b) GDPR where you work with us on the release, otherwise Art. 6(1)(f) GDPR (protecting unreleased recordings).
8. Emails
We send invitations, codes, links and notices from os.voidcreativegroup.com through Resend, processing your email address, the content of the email and its delivery status. The portal sends no newsletters or advertising. Legal basis: Art. 6(1)(b) GDPR.
9. AI-assisted work in voidOS
Your details and contracts end up in voidOS, our internal system. Our team uses AI models from Anthropic and OpenAI there to read contract documents into structured data and to answer team members' questions about our catalogue, so your name, address, shares and contract terms can reach these providers. A person checks what a contract reading or an answer proposes before it changes any record. To sort tasks by area, voidOS also sends their titles, which can name you, to OpenAI; Typesafe AI, Inc. (USA) receives only the task text with the names and contact details voidOS knows removed. That sorting is applied without a check, and the team can change it. Anthropic and OpenAI act as our processors, may not use the data to train their models, and delete it after at most 30 days unless they must keep it longer to stop misuse or by law. Legal basis: Art. 6(1)(f) GDPR (efficient, accurate contract and catalogue work).
10. Security and operation
- When you open the portal, our hosting provider processes your IP address, the time, the requested address and browser information to deliver the pages and protect them from abuse.
- Before an intake code is sent or an intake form is submitted, Cloudflare Turnstile checks that a person is making the request, using your IP address and browser characteristics. We pass your IP address to Cloudflare for this check and do not store it.
- Errors are reported to Sentry. Email addresses, codes, links, session tokens and form contents are removed before a report leaves your browser or our servers.
Legal basis: our legitimate interest in a secure, working portal, Art. 6(1)(f) GDPR.
11. Cookies and browser storage
The portal uses no cookies or browser storage for analytics or advertising. It stores only what it needs to work: the sign-in session cookies of your account; the intake or share session in your tab's session storage, valid for at most 24 hours and removed when you close the tab; and your light or dark appearance in local storage. These are strictly necessary for the service you asked for (§ 25(2) no. 2 TDDDG), so no consent is needed.
12. Service providers
These providers process data on our behalf under data processing agreements (Art. 28 GDPR):
- Clerk, Inc., 660 King Street Unit 345, San Francisco, CA 94107, USA: sign-in and accounts; USA; certified under the EU-U.S. Data Privacy Framework.
- Convex, Inc., 444 De Haro Street, Suite 218, San Francisco, CA 94107, USA: database and backend; stored in the EU (Ireland); access from the USA under standard contractual clauses.
- Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA: hosting of the portal; worldwide network; certified under the EU-U.S. Data Privacy Framework.
- Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA: DNS, Turnstile, and storage and delivery of files; files stored in the EU, delivery through a worldwide network; certified under the EU-U.S. Data Privacy Framework.
- Plus Five Five, Inc. (Resend), 2261 Market Street #5039, San Francisco, CA 94114, USA: sending emails; USA; certified under the EU-U.S. Data Privacy Framework.
- Functional Software, Inc. (Sentry), 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA: error reports; stored in the EU (Germany); certified under the EU-U.S. Data Privacy Framework.
- GB Group plc (Loqate), The Foundation, Herons Way, Chester Business Park, Chester CH4 9GB, United Kingdom: address suggestions; United Kingdom; adequacy decision of the European Commission.
- Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg: offsite backups; stored in the EU (Frankfurt, Germany).
- Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland: AI models (section 9); processing also in the USA, under standard contractual clauses.
- OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland: AI models (section 9); processing also in the USA, under standard contractual clauses.
13. Other recipients
When you sign in with Google, Apple or Discord, these companies are controllers for the sign-in on their side:
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
- Discord Netherlands BV, Schiphol Boulevard 195, 1118 BG Schiphol, Netherlands
Label Engine and the distributors we release your music through receive what distribution and accounting need. Tax advisers, auditors and authorities receive data where the law requires it.
14. Transfers outside the EU
Where a provider in section 12 is certified under the EU-U.S. Data Privacy Framework, transfers to it rely on the European Commission's adequacy decision for that framework (Art. 45 GDPR). Transfers to Convex, and the processing of Anthropic and OpenAI in the USA, rely on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). Loqate is covered by the adequacy decision for the United Kingdom. A copy of the safeguards is available from us on request.
15. Retention
- Intake codes: they stop working after 10 minutes and are deleted when used, replaced, entered wrongly five times, when the link is rotated, withdrawn or closes, or within an hour after they expire. Sign-in codes: with us, 10 minutes, then deleted within 30 minutes; at Clerk, as Clerk sets.
- Share codes: they stop working after 10 minutes, or once used, replaced or entered wrongly five times, and are deleted within two hours after they were requested.
- Intake and share sessions: 24 hours.
- Intake links: 14 days after they are issued.
- Your details, contracts and statement data: for as long as we work together, then as long as the law requires: ten years for books and annual accounts, eight years for accounting vouchers and six years for business letters (§ 147 AO, § 257 HGB), or as long as needed to establish, exercise or defend legal claims. Details you sent through an intake that we did not accept are erased 90 days after our decision, and the address you confirmed a link with 90 days after the link expired; details we accepted become part of our records of you and follow the periods above.
- Your account: until your access ends. 30 days later we delete your sign-in account at our sign-in provider and erase your address from our records; the record that you had access stays, without it.
- Records of shared files: 12 months after the link expires or is withdrawn; for a link without expiry, 12 months after it is withdrawn.
- Emails: 30 days at Resend; our own record of each email (recipient, content, delivery status) 90 days after we queued it.
- AI providers: at most 30 days, unless they must keep data longer (section 9).
- Logs: one day at Vercel, seven days at Cloudflare; Convex shows only the latest entries. Error reports: up to 90 days.
- Backups: database copies up to 12 months; copies of original files, such as signed contracts, are kept permanently in write-protected storage.
16. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). To use them, write to info@voidcreativegroup.com.
When you ask us to erase your data, we confirm it is you and erase it, except what we still need: to perform a contract that is still running (Art. 6(1)(b) GDPR), to keep by law, such as payments and bookings for up to ten years (§ 147 AO, § 257 HGB), or to establish, exercise or defend legal claims (Art. 17(3)(e) GDPR). Signed contracts are kept as long as the rights granted in them exist, and afterwards for the statutory periods. Credit names used on recordings and works stay, as the attribution we agreed. We keep the rest only for its purpose and erase or restrict it when the purpose ends. Where a backup can't be changed, we restrict its processing instead of erasing it (§ 35(1) BDSG). We answer every request within one month.
Right to object (Art. 21 GDPR): you may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR.
You may also complain to a data protection supervisory authority. Ours is Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, lfd.niedersachsen.de.
17. No automated decisions
We make no decisions based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR.
18. Changes and language
We update this policy when the portal or the law changes. It is available in English and German; the English version governs.