This Privacy Policy explains how Eternal Media UG (haftungsbeschränkt) ("we", "us") processes personal data in connection with the platform at clearhly.com (the "Platform").
Rights holders on the Platform are businesses. Licensees can be businesses or private individuals (consumers). Data about business representatives is still "personal data" under the GDPR where it relates to an identifiable natural person (e.g., a representative's name, ID document, or email).
Eternal Media UG (haftungsbeschränkt) is the data controller for the processing described below.
1. Data We Collect
1.1 Account data
- Business legal name, registration number, country of incorporation;
- Representative's full name, work email, job title/role;
- Login credentials and session/device metadata.
- A profile picture or company logo you upload, which is shown to other users on your listings, requests and in the workspace; your display currency and interface preferences; your team membership and role, and the email address of anyone you invite to your team.
- If you sign up while Clearhly is in private beta, we keep your email address, the role you're interested in and your sign-up date to notify you when your access opens (performance of a contract, Art. 6(1)(b) GDPR). You can delete your account at any time.
1.2 KYB (Know Your Business) verification data
- Certificate of incorporation or equivalent commercial register extract;
- Beneficial ownership declaration and supporting documentation;
- Representative's government-issued photo ID;
- Rights-ownership or licensing-authority attestation;
- Tax identifiers where applicable (VAT ID, EIN, etc.).
This is sensitive data. See Section 8 for how it is protected.
ID card copies. When you upload a copy of an identity card, you may black out everything we do not need, in particular the access number (CAN) and serial number, and on German ID cards also the photo where it is not needed for the comparison. The copy is used only to verify your identity and is deleted as described in Section 4 (§ 20(2) PAuswG).
1.3 Marketplace activity data
- Listings published, clearance requests submitted, in-app messages;
- Files and attachments you upload to a clearance-request message thread (documents, images and their filenames, size, and upload metadata);
- Contributor invite and consent data, the name, email address, role, split and invite status of any contributor a rights holder adds to a listing, plus their confirm/dispute response and any note they submit;
- Negotiated deal terms and price history;
- Preview audio uploads and access/download logs;
- Presence and activity signals inside a clearance-request thread, whether you currently have the thread open, whether you are typing, and the time you were last active in that chat, which is shown to the other party to that request. You can switch the online and typing signals off in your notification settings; when off, they are not shared.
- Saved searches and the alerts you choose to receive about them; links and ISRCs you paste into the bulk lookup, used to check which tracks are listed.
1.4 Payment and payout data
Where a clearance carries an upfront cash component, payment is collected, held and released through Stripe Payments Europe, Ltd. and its affiliates ("Stripe"), including Stripe Connect. Stripe acts as an independent controller for its own regulatory, anti-money-laundering and fraud-prevention purposes, and as our processor for the transactions we instruct.
- Licensees: card or other payment-method details, billing name and address, and the payment amount, currency and outcome are collected directly by Stripe through Stripe-hosted fields.
- Rights Holders: connected-account onboarding data collected directly by Stripe, including bank account or payout details, tax identifiers, representative identity details and, where Stripe requires it, identity documents and beneficial-ownership information.
- What we receive and store: a Stripe customer or connected-account identifier, payment and payout status, timestamps (paid, held, released, refunded, disputed), the amount, our deducted success fee, and, at most, a card brand and last four digits for reconciliation and support.
We do not collect, store, or have access to full payment card numbers, CVC codes, or full bank account numbers. Those are captured directly by Stripe in Stripe-hosted fields that never pass through our servers, which keeps our systems outside the scope of most PCI DSS requirements. Stripe is a PCI DSS Level 1 certified service provider. Stripe's processing of your data is also governed by Stripe's own privacy policy and, for Rights Holders, by the Stripe Connected Account Agreement.
1.5 Technical data
- IP address, browser/device type, general location (city/country level);
- Cookies and similar technologies (see Section 9);
- Usage analytics (listing views, preview plays), only if you consent to the Analytics category (see Section 9).
1.6 Communications
- Support requests, KYB correspondence, and any information you provide when contacting us.
2. Purposes and Legal Basis (GDPR Art. 6)
- Creating and operating your account, performance of a contract (Art. 6(1)(b)).
- KYB verification and re-verification, performance of a contract; legal obligation for AML/fraud prevention where applicable (Art. 6(1)(b), (c)).
- Displaying listings and routing clearance requests, performance of a contract (Art. 6(1)(b)).
- Fraud prevention, account security, abuse detection, legitimate interests (Art. 6(1)(f)).
- Transactional emails (KYB status, new request, approval), performance of a contract (Art. 6(1)(b)).
- Product analytics, only with your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG).
- Business outreach to rights holders (Section 5.2), legitimate interests (Art. 6(1)(f)).
- Marketing communications (opt-in), consent (Art. 6(1)(a)).
- Collecting, holding and releasing license payments and deducting our success fee, performance of a contract (Art. 6(1)(b)); payment fraud, chargeback and AML checks by Stripe, legal obligation and legitimate interests (Art. 6(1)(c), (f)).
- Tax, accounting, and regulatory recordkeeping, legal obligation (Art. 6(1)(c)).
- Defending or pursuing legal claims, legitimate interests (Art. 6(1)(f)).
3. Who Sees KYB Data
KYB submissions are reviewed only by our internal verification team and, where necessary, a limited number of vetted third-party verification providers under written data-processing agreements. KYB documents are never shown to counterparties on the Platform. A published listing displays only the verified legal business name and country of registration, never underlying ID documents, ownership declarations, or tax identifiers.
4. Retention
- KYB document images (ID copies, incorporation certificates, ownership declarations as uploaded files): deleted automatically 30 days after the KYB decision (approval or rejection).
- Extracted KYB verification data (legal name, registration number, country, representative name, the outcome and date of the check): for the life of the business account plus 3 years (the standard limitation period).
- KYB approval/rejection audit trail (reviewer, timestamp, outcome, not underlying docs): 10 years.
- "Can't find it? Tell us" requests (what you asked for, including any Spotify link, what it is for, budget and your contact details): used only to find the requested music and to email you once when a matching listing goes live. Legal basis: performance of our service to you and legitimate interest in growing the catalog you ask for (Art. 6(1)(b), (f)). Kept until the request is closed or deleted, or for at most 24 months. You can delete a request at any time on your Wanted page and stop these alerts from the link in the email.
- Listings, requests, messages, deal terms: duration of account + 3 years (supports license enforcement/audit by transacting parties).
- Technical/security logs: 90 days, then deleted or aggregated.
- OCR text excerpts from KYB pre-checks: cleared automatically within 30 days of a KYB decision (approval or rejection), only the non-identifying match results are kept for audit. The underlying document images are deleted 30 days after the decision, as above.
- Invoices, payment and payout records (Stripe identifiers, amounts, status and timestamps, deducted fees): 10 years (§ 147 AO, § 257 HGB). Full card and bank details are held by Stripe under its own retention schedule, not by us.
- Marketing consent records: until consent withdrawn + 3 years proof-of-consent record.
Where you request earlier deletion (Section 7), we will comply unless a legal obligation, dispute-preservation duty, or overriding legitimate interest requires continued retention of specific records, in which case we retain only the minimum necessary and will tell you why.
5. Sharing and Disclosure
We do not sell personal data. We disclose personal data only:
- To processors performing services on our behalf (hosting/infrastructure, KYB verification vendors, email delivery, analytics, customer support tooling), under data processing agreements consistent with Art. 28 GDPR;
- To counterparties in a clearance request: your business or display name, your logo or profile picture, the messages, offers and files you send, whether you are online or typing in that thread (unless you switch this off), and, once both parties sign, the signer names and details recorded on the license document. A Rights Holder's verified legal name and address are shown in the deal room and on the license.
- To comply with law, responding to lawful requests from authorities, enforcing our Terms, or protecting the rights, property, or safety of us, our Users, or the public;
- In a corporate transaction (merger, acquisition, financing, asset sale), subject to the acquiring party being bound by materially equivalent protections.
- Via the public clearance lookup, once a clearance is approved it receives a verification number and can be looked up by anyone holding that number at /verify. This displays the track, rights holder, territory and license term, plus the licensee name and usage description only where both parties opted in. It never displays financial terms, negotiation messages, attachments, KYB documents, or contact details.
5.1 Processors and other recipients
These are the categories of recipients, what they do, and the transfer basis where data leaves the EU/EEA:
- Website hosting and delivery provider (EU, with infrastructure in the USA; Standard Contractual Clauses and the EU-US Data Privacy Framework), including the visitor analytics built into our hosting, which runs only if you allow the Analytics category.
- Database, sign-in and file storage provider (USA; Standard Contractual Clauses).
- Stripe (Stripe Payments Europe, Ltd., Ireland, and affiliates): payments, holds, transfers, refunds, invoices. Independent controller for its own regulatory purposes and processor for the transactions we instruct (Section 1.4); transfers to Stripe, Inc. based on the Data Privacy Framework and SCCs.
- Transactional email provider (USA; Standard Contractual Clauses).
- Business email and mailbox provider (EU, with transfers to the USA based on the EU-US Data Privacy Framework and Standard Contractual Clauses).
- Spotify (Sweden): track metadata lookups (no visitor data is sent) and, only with your consent, the embedded player.
- EU VIES (European Commission): VAT number validation for businesses. The VAT number is sent to the Commission's service.
- Public company registries: we send only a business name to look up public register entries during KYB review.
On request we will tell you the names of the specific recipients of your data (Art. 15 GDPR).
5.2 Business outreach contacts (Art. 14 GDPR)
- Source: the public website of the business (for example its contact or imprint page) or a public music-industry directory.
- Categories: business name, website, country, a business email address (we prefer role addresses such as info@ or licensing@), and a person's name only where that person is the addressee.
- Purpose: a single personalised email offering our marketplace to the business; we send at most one follow-up.
- Legal basis: our legitimate interest in offering our service to businesses (Art. 6(1)(f) GDPR). We do not email recipients in countries that require prior consent for advertising email to businesses, including Germany and Austria.
- Right to object: you can object at any time with the link in the email or by replying; we then add the address to a suppression list and never contact it again. Replies, bounces and objections stop any further message automatically.
- Retention: lead data is deleted 12 months after the last contact if no business relationship results; the suppression entry (email address only) is kept for as long as needed to honour your objection.
5.3 Other specific processing
- Contact-form verification codes: signed-out visitors receive a six-digit code by email to confirm their address. We store only a hash of the code, valid for 10 minutes and limited to 5 attempts, plus a rate-limit counter based on your IP address. Legal basis: legitimate interest in preventing abuse (Art. 6(1)(f)).
- UK waitlist: if you are in the United Kingdom and leave your email, we store the email, country, which side you came from and, if given, a business name, only to tell you when we open in the UK (consent, Art. 6(1)(a)). You can ask us to delete it at any time.
- E-signature images: when you sign a license we store your typed name, your drawn signature image, the time and your IP address as evidence of the signature (performance of the contract and legitimate interest in proof, Art. 6(1)(b), (f)), for the life of the license plus the limitation period.
- Withdrawal declarations: if you withdraw from a contract we store your name, clearance number, email, optional reason and the time, share it with the rights holder, and keep it for 3 years after the end of the year of withdrawal (legal obligation and legal claims, Art. 6(1)(c), (f)).
- Illegal-content reports: the reported URL, your explanation and, if given, your name and email, plus the submission IP, confirmation time, and exact legal statements you confirmed, used to handle the report, preserve evidence and send you our decision (legal obligation under the Digital Services Act and legitimate interests in legal claims, Art. 6(1)(c), (f)). For a copyright notice, we may forward the notice, including your name and contact details, to the listing owner so they can respond. For a counter-notice, we forward it, including your name, address, phone and email, to the person who filed the notice.
- Public /verify page: anyone holding a clearance number can look it up. It shows the verification status (including "pending payment"), the track title and artist, the rights holder's business name, territory, license term and whether the license is exclusive, plus the licensee name and usage description only where both parties opted in. It never shows prices, messages, attachments, KYB documents or contact details.
6. International Transfers
Where personal data is transferred outside the EEA/UK/Switzerland (e.g., to a hosting provider with servers in the United States), we rely on the European Commission's Standard Contractual Clauses, an adequacy decision, or another valid transfer mechanism, together with supplementary technical and organizational measures (encryption in transit and at rest, access controls).
7. Your Rights
Depending on your location, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data ("right to be forgotten"), subject to retention exceptions in Section 4;
- Restrict processing in certain circumstances;
- Data portability, receive your data in a structured, machine-readable format;
- Object to processing based on legitimate interests, including profiling;
- Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing;
- Lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work. The authority responsible for us is: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Postfach 30 40, 55020 Mainz, Germany, www.datenschutz.rlp.de.
Right to object (Art. 21 GDPR)
Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time, on grounds relating to your particular situation. We then stop unless we can show compelling legitimate grounds that override your interests, or the processing serves legal claims. Where we process your data for direct marketing, including business outreach emails, you can object at any time without giving reasons, and we will stop. To object, use the link in any outreach email, our contact form or legal@clearhly.com.
You can exercise the access/portability and erasure rights yourself at any time: use the Export tool in Settings → Danger Zone to download a structured, machine-readable copy of your data, and the Delete tool in the same place to close and erase your account. For any other right, or if you prefer to have us handle it, use the form on our contact page (category: Privacy), which is the fastest route. If you would rather put your request in writing by email, you can also write to hello@clearhly.com. We respond within one month of receiving your request (extendable by a further two months for complex or numerous requests, where we will tell you within that first month). A request sent through the form arrives instantly and is timestamped on arrival, so the one-month period starts on submission and you get a reference number to quote. A request sent by post starts that period on delivery; postal transit is outside our control.
8. Security
We apply encryption in transit (TLS) and at rest for stored data. KYB documents are stored in access-restricted storage and served only via short-lived signed URLs to authorized reviewers, they are never publicly indexable or accessible via direct link. Access to KYB and account data is role-restricted, logged, and reviewed periodically. No system is perfectly secure; we maintain an incident response process and will notify affected Users and, where legally required, supervisory authorities without undue delay in the event of a qualifying data breach (Art. 33–34 GDPR).
9. Cookies and Similar Technologies
We use cookies and browser storage (localStorage, sessionStorage) in five categories, the same five shown in our consent tool. Under § 25 TDDDG, everything that is not strictly necessary is stored or read only after you have given consent (Art. 6(1)(a) GDPR) in our own application. Our hosting provider's built-in analytics also runs only after you allow the Analytics category.
- Strictly necessary (no consent required, § 25(2) TDDDG): your sign-in session and authentication tokens, security and abuse prevention, the record of your cookie choice itself, and unfinished forms so a reload does not destroy your work.
- Preferences (consent): interface choices such as saved filters, dismissed hints, product tour progress and your last used workspace.
- Analytics (consent): first-party, aggregate counting of listing views and preview plays, de-duplicated once per day per browser, stored in our own database. Analytics consists of our own first-party counting and our hosting provider's built-in analytics, which sets the session-id cookie (30 minutes). We use no tag manager or advertising pixel.
- Embedded media (consent): lets embedded Spotify players load on listing pages. When one loads, Spotify receives your IP address and sets its own cookies under Spotify's privacy policy.
- Marketing (consent): none are set. The category exists so that, if this ever changes, it stays off until you allow it.
Your decision, the categories you allowed, the notice version and the timestamp are stored in your browser as our record of consent (Art. 7(1) GDPR). You can change or withdraw it at any time, as easily as it was given, via "Cookie settings" in the site footer or on the Cookie Policy page. Withdrawal deletes anything already stored for the categories you switch off.
10. Automated Decision-Making
KYB submissions may be initially screened using automated fraud/risk signals (e.g., document authenticity checks) before human review. No KYB approval or rejection decision is made solely by automated means without human review. You may request human review of, and contest, any automated screening outcome via our contact page.
As part of this pre-screening, text may be extracted from uploaded KYB documents using optical character recognition (OCR) and compared against the values you entered in the submission form (legal business name, registration number, representative name). The OCR runs locally in your own browser; the document is not sent to any third-party OCR or AI service for this step. The extracted text excerpt and match results are stored only to support the reviewer's triage, are cleared within 30 days of a KYB decision (Section 4), and never replace the human review guarantee stated above.
11. Children
The Platform is directed at rights-holder businesses and at adult licensees, and is not intended for use by individuals under 18. We do not knowingly collect personal data from minors.
12. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notice at least 15 days before taking effect. The "Last updated" date at the top reflects the current version.
13. Contact and data protection officer
We are not required to appoint a data protection officer. For all data protection questions, contact legal@clearhly.com.
Eternal Media UG (haftungsbeschränkt)
Buchenweg 6A, 76761 Rülzheim, Germany
Data protection queries: contact page or hello@clearhly.com · Full company details: Impressum