Privacy Policy

1. CONTROLLER AND SCOPE

André Fedorow, Sound of Prog, Kattowitzer Strasse 257, 38226 Salzgitter, Germany. Email: soundofprog@gmail.com. This notice covers soundofprog.com and related areas including MAIN, Sound of Prog Plus and the community chat, even where they are temporarily accessed via subdomains.

2. HOSTING AND ACCESS LOGS

When pages are accessed, the server may process IP addresses, access times, requested resources, browser/device information, referrers and technical status data. This supports delivery, troubleshooting and security (GDPR Article 6(1)(f)). Hosting is provided by IONOS. Log retention depends on the actual hosting configuration. IONOS kann als Hosting-Dienstleister technische Zugriffsdaten in unserem Auftrag verarbeiten. Soweit eine Auftragsverarbeitung stattfindet, gelten die Voraussetzungen des Art. 28 DSGVO. Die Dauer von Serverprotokollen richtet sich nach der jeweiligen Hosting-Konfiguration und erforderlichen Sicherheitszwecken.

3. ACCOUNTS, SIGN-IN AND PROFILES

Registered features process usernames, password hashes, account and role information, optional profile details and images, and session/authentication data. The purposes are account delivery and security (GDPR Article 6(1)(b), and (f) for security). Passwords are not stored in plaintext. Public profile fields can be visible to other visitors as indicated by the service.

4. COMMUNITY CHAT

Chat use, including guest access, may involve chosen names, messages, timestamps, shared pictures/GIFs, profile references and online/status information. Public chat content is visible to participants. Authorized moderators and administrators can process messages and moderation actions, including kick/ban reasons, to enforce community rules (GDPR Article 6(1)(b) and (f)). Please do not post confidential or sensitive personal information in public chat.

5. SOUND OF PROG PLUS

Where used, Plus associates favorites, watch/listen-later entries, listening history, playback positions, personal settings, comments, replies and comment reports with the relevant account. This provides requested personalization and community features (GDPR Article 6(1)(b)); abuse prevention may rely on Article 6(1)(f). Contributions may be publicly visible.

6. AIRPLAY SUBMISSIONS AND EDITORIAL CONTACTS

AIRPLAY submissions may contain contact, artist and project details, messages, links, processing statuses and optional ZIP/RAR promotional archives. The data is used to review submissions, communicate with artists and manage editorial tasks (GDPR Article 6(1)(b) where relevant to a requested arrangement, otherwise Article 6(1)(f)). Authorized team members have role-based access. The technical upload limit is 500 MB per archive. Please do not include unnecessary personal information about third parties.

7. EMAIL CONTACT

If you contact us by email, we process your address, message and voluntarily submitted details to respond (GDPR Article 6(1)(f), or (b) where applicable). Statutory retention obligations may apply.

8. COOKIES, SESSIONS AND CONSENT

The technically necessary SOPSESSID cookie supports login sessions. The chat may use sopchat_lang for language selection and temporary browser storage for system notices. Additional local settings may include your privacy choices. Strictly necessary device storage/access may be exempt from consent under section 25(2) TDDDG; other device access and third-party integrations requiring consent are subject to your prior choice (section 25(1) TDDDG and GDPR Article 6(1)(a)). The current consent interface distinguishes essential functionality from external media providers. You can change or withdraw your choice via “Privacy settings”. The browser-stored choice is currently designed to last no more than 180 days. Withdrawal takes effect for the future and cannot undo data already received by third parties.

9. EXTERNAL AUDIO AND VIDEO SERVICES

Sound of Prog uses or links to laut.fm (radio streaming), Mixcloud (show players), Bandcamp, Spotify, YouTube and potentially hearthis.at. Loading players or starting streams can transfer your IP address and browser data, and potentially further information, to those providers. Processing outside the EEA may occur. Integrations that require consent should only load after authorization; streaming requested by the user requires a technical connection to its provider. Please consult the respective providers’ privacy notices.

10. SECURITY, LOGS AND BACKUPS

We use HTTPS, access permissions, session management, security records and backups to protect the service (GDPR Article 6(1)(f)). Access and retention depend on purpose, authorization and actual deletion/backup cycles.

11. DATA RETENTION

Personal data is retained only as long as needed for its purpose, legitimate security needs or legal duties. Account data may remain until account deletion; public contributions may remain or be anonymized where legally justified. Technical logs, chat history, AIRPLAY archives and backups follow the actual configured retention periods.

12. RECIPIENTS

Only authorized personnel and necessary service providers, such as the host, receive access as required. External media providers may process data when their content is activated. We do not sell members’ personal data.

13. YOUR RIGHTS

Subject to legal conditions, you have rights of access (GDPR Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21) and withdrawal of consent (Article 7(3)). Contact soundofprog@gmail.com. Where reasonable doubts about identity exist, additional verification may be requested. You may also lodge a complaint with a data protection authority, including the Lower Saxony Data Protection Commissioner: https://www.lfd.niedersachsen.de/.

15. Required information and optional use

Browsing public pages does not require an account. Fields marked as required during optional registration are necessary to create an account and provide restricted features; without them, those functions cannot be used. AIRPLAY submissions and email enquiries are voluntary, but without a usable contact address an individual reply may not be possible. Optional profile details are not mandatory.

16. Legitimate interests, recipients and international transfers

Our legitimate interests are reliable operation of this non-commercial service, prevention of abuse, and security of accounts, posts and uploaded files. Recipients may include the hosting provider IONOS, authorized moderators and administrators, and external media services when you choose to load their content. YouTube, Spotify, Mixcloud and Bandcamp may process information outside the EU/EEA. Please consult each provider's current privacy notice for applicable transfer mechanisms and safeguards. Optional external media should not establish consent-dependent connections before permission has been given.

17. Automated decision-making

Based on the currently intended platform features, Sound of Prog does not make solely automated decisions producing legal or similarly significant effects under GDPR Article 22 and does not perform profiling for that purpose.

18. Data retention criteria in detail

Account-related favorites, listening history and settings are retained to provide the account and selected functions, until the account or relevant function ends or deletion is appropriately requested. CHAT displays messages for 24 hours. After activation of the 24-hour cleanup feature, messages, linked reactions and chat-uploaded message pictures are deleted from the active database during chat use and by the configured scheduled chat task. Comments outside the chat and moderation or security records have separate retention rules. Moderation and security records are held only as long as needed for incidents, abuse prevention or legal claims. AIRPLAY submissions are held for editorial review and necessary follow-up. Deleted information can temporarily persist in backups until their regular rotation; restoration must respect applicable deletion decisions. Other actual retention periods (including logs, AIRPLAY and backups) require verification against production settings. The 24-hour database deletion does not take effect until activated in the CHAT administration.

Handling privacy requests: When a specific access request is linked to a user account, chat messages and reactions still available at that time may be retained separately as an encrypted case-specific copy accessible only to administration. This does not affect the ordinary 24-hour deletion in CHAT. Case copies are deleted when the request is deleted, or during housekeeping following its completion (scheduled for 30 days after completion, on the next opening of the request manager). Temporary copies may remain in backups until their configured rotation. Processing a statutory access request is based on GDPR Article 6(1)(c), together with Articles 12 and 15.

19. Complaints and contact

For privacy enquiries and data subject requests contact soundofprog@gmail.com. The supervisory authority for Lower Saxony is the Landesbeauftragte für den Datenschutz Niedersachsen, www.lfd.niedersachsen.de. You may also complain to another competent data protection authority.

20. Changes

We may update this notice when our services, technology or applicable legal requirements change. The version published on our website applies.