Overview
This privacy policy explains how personal data is processed when you use FreestyleMusic.de. FreestyleMusic.de is a private, non-commercial hobby project.
Controller
Dominik Weber
Mendelssohnstraße 12
67551 Worms
Germany
Email: info@freestylemusic.de
Hosting
This website is operated on a server of netcup GmbH, Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany. When the website is accessed, the server automatically processes technical access data. The legal basis is our legitimate interest in the secure and stable operation of the website (Art. 6 (1) (f) GDPR). A data processing agreement is in place with the provider.
Server log files
When you visit the website, information transmitted by your browser is automatically stored in server log files: IP address, date and time of access, the page requested, and the browser and operating system used. This data is used to ensure technical operation and security (Art. 6 (1) (f) GDPR) and is deleted after a short period.
Registration and user account
To register a user account we process the username you choose, your email address and your password (stored solely as a cryptographic hash, never in plain text). This data is required to provide the account (Art. 6 (1) (b) GDPR). Your email address is used to confirm registration, to send notifications and to reset your password. You can have your account deleted at any time.
Public profiles and community features
As a registered member you can create a public profile page. Publication is voluntary (opt-in): your profile only becomes visible after you actively publish it, and for each content block you decide individually whether it is public, visible to logged-in members only, or visible only to you. Content you post yourself (e.g. profile texts, interests, favourite CDs, guestbook entries, profile pictures) is processed to provide the community features (Art. 6 (1) (b) GDPR). Details such as location or date of birth are optional; the date of birth is used for the birthday note on the homepage. Uploaded profile pictures are reviewed by an administrator before publication; on upload we automatically remove metadata (e.g. EXIF/GPS data) from the images. Profile pages count their number of views without storing the visitors.
Member directory
On the "Members" page we maintain a public directory of active members. It shows the username, avatar, profile headline (if set), registration date and online status of members who have logged in at least once since the website relaunch. Imported legacy accounts that were never reactivated do not appear there. The legal basis is our legitimate interest in operating the community (Art. 6 (1) (f) GDPR).
Online status ("Who is online")
To show who is currently online, we briefly store a session identifier, for logged-in members the link to the user account, the time of the last page view and the path of the most recently visited page (without query parameters). This data is deleted after 15 minutes at the latest. Only the online status of logged-in members and the number of guests are publicly visible; the most recently visited page can be viewed by administrators only. The legal basis is our legitimate interest in the community features and in secure operation (Art. 6 (1) (f) GDPR).
Private messages and friendships
Registered members can send each other private messages and friend requests (Art. 6 (1) (b) GDPR). Private messages are visible only to the sender and the recipient; as with any online service they are technically accessible to the operator, but we do not read them unless this is necessary to investigate abuse or technical faults. If you delete a conversation, it disappears from your inbox; the other member's copy remains until they delete it as well. When a user account is deleted, its messages and friendships are removed completely. Your friends list is private — at most the number of your friends is publicly visible on your profile page.
Contact form
Registered members can send us requests via the contact form (Art. 6 (1) (b) GDPR). The request and our replies are stored as a conversation in your message inbox on this website and are accessible to our administration team so that they can handle the request. Once our team closes a request, it disappears from your inbox; it remains archived internally for accountability. When a user account is deleted, its contact requests are removed completely.
Material you send us
A separate form lets artists and supporters send us files — music, photos, scans, video or documents. We store the name you enter, the uploaded files together with their original file names, size and type, and the time of submission. An email address and an accompanying message are optional; without an address, however, we cannot get back to you. Please do not send us information you would rather not disclose — in particular no data about other people without their knowledge.
The legal basis is your consent, given by submitting the form (Art. 6 (1) (a) GDPR), together with our legitimate interest in reviewing and processing the submission (Art. 6 (1) (f) GDPR). A submission is visible only to our administration team; the files are not publicly available and cannot be reached through any public address. Sending us something does not mean we publish it: whether and where material appears on this website is settled beforehand — with any questions going to the address you provided.
To protect the form against abuse we store, with each submission, a non-reversible check value of your IP address (a cryptographic hash using a secret key). This lets us recognise that several submissions come from the same connection; the IP address itself is not stored for this purpose and cannot be derived from the check value. The legal basis is our legitimate interest in secure operation (Art. 6 (1) (f) GDPR).
We keep a submission for as long as we need it for processing and then delete it together with all its files. You may ask us to delete a submission at any time — a message through our contact form is enough, and we will remove it without requiring a reason.
Email delivery
Transactional emails (e.g. registration confirmation, password reset, notifications) are sent via the service provider Brevo (Sendinblue GmbH, Köthener Straße 65, 10963 Berlin, Germany) acting as a processor.
Internal notifications
For certain events (e.g. new content awaiting moderation, or technical errors) we send automatic notifications to a private channel on the Discord service (Discord Inc., USA) that is accessible to the operating team only. The affected username and the path of the affected page may be transmitted; content such as images is not transferred. The legal basis is our legitimate interest in moderation and secure operation (Art. 6 (1) (f) GDPR).
Push notifications
If you enable push notifications in your profile, we store the subscription data generated by your browser: the endpoint address at the push service, two associated cryptographic keys, your browser identification (user agent) and the time of setup and of the last successful delivery. A subscription belongs to a device; through your account it can be attributed to you.
Delivery happens through the push service of your browser vendor, depending on the browser for example Google (Firebase Cloud Messaging, Google Ireland Limited or Google LLC, USA), Mozilla (Mozilla Corporation, USA) or Apple (Apple Inc., USA). That service receives the endpoint address and the encrypted message; a transfer to the USA is therefore possible. The content is encrypted for your device and cannot be read by the push service. Only a short notice text (such as "Max sent you a message") and a link to the relevant page are transmitted — no message contents.
The legal basis is your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG), which you give by enabling the option in your profile and confirming it in your browser. You can withdraw it at any time: using the same switch in your profile, or in your browser notification settings. A subscription is deleted automatically as soon as the push service reports it as invalid, and in any case when your account is deleted.
Insta-Wall
On the Insta-Wall we curate selected, publicly accessible Instagram posts from the freestyle scene. For each post we store on our side: the post's short code, the name of the publishing account (handle), the publication date, the hashtags used in the post and the accounts mentioned in it (@ mentions), plus a note written by us. Handles and mentions may relate to natural persons.
We deliberately do not store the post's caption, nor its like and comment counts. We also do not store or mirror any images or videos: the content stays on Instagram and is delivered from there. We merely keep references to the original posts; the publishing account is named and linked on every card.
The post itself is displayed through the embedding function provided by Instagram and is only loaded after you click the respective card. No data is therefore transmitted to Instagram without your action; which data is transmitted once loading happens is described in the section on embedded third-party content.
The legal basis for storing the details listed above is our legitimate interest in documenting and promoting the freestyle music scene (Art. 6 (1) (f) GDPR). The posts were published publicly by the respective accounts themselves, and we store only references and our own commentary, not third-party works.
We check the listed posts automatically on a regular basis. If a post has been deleted or the account is no longer public, the entry is automatically hidden on our side. If you own one of the accounts named or appear in one of the posts and would like the entry removed, a message via our contact form is enough — we will remove it without asking for reasons. Independently of this, you have the right to object under Art. 21 GDPR.
Change log in the administration area
Operations in the non-public administration area of this website are logged so that it remains traceable who changed, approved or deleted which content. We store: the time, the account of the acting person, the administration function used, the affected object and the outcome of the operation. Automated maintenance runs are logged without a person, under the identifier "System". IP addresses are not stored.
If an operation concerns a member account or content submitted by a member (for example approving a profile picture, deleting a comment or blocking an account), the log entry contains the user name in plain text. This is necessary because otherwise the entry would lose its purpose precisely when it matters most — namely after the affected content has been deleted.
The legal basis is our legitimate interest in operating a secure and accountable service (Art. 6 (1) (f) GDPR). The log is visible to administrators only and is neither published nor passed on. Entries are deleted automatically after one year.
Cookies
Without your consent we use only technically necessary cookies required to operate the website – in particular to manage your session, for login ("stay signed in") and to protect against cross-site request forgery (CSRF). No consent is required for these cookies (§ 25 (2) TDDDG). We also store your chosen theme setting (light/dark mode) and your cookie decision locally in your browser. This local storage documents your consent decision or is required for the website to function and does not require separate consent. If you consent to audience measurement, Matomo's cookies are added (see "Audience measurement with Matomo").
Embedded third-party content
We embed content from external providers (see below). This content is only loaded after you have explicitly given your consent via our consent banner. Before that, no data is transmitted to the providers – instead you see a placeholder. After your consent, your IP address may be transmitted to the respective provider and cookies or comparable technologies may be set; data may be transferred to countries outside the EU (e.g. the USA). The legal basis is your consent (Art. 6 (1) (a) GDPR, § 25 (1) TDDDG). Your consent is voluntary and can be withdrawn at any time with effect for the future – via the "Cookie settings" link in the footer. Without consent the website remains fully usable; only the external content is not displayed automatically.
- YouTube (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland) – to display videos.
- Spotify (Spotify AB, Sweden) – for album links and the player.
- Instagram (Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland) – to display Instagram posts that members embed in their profile.
- Twitch (Twitch Interactive, Inc., 350 Bush Street, 2nd Floor, San Francisco, CA 94104, USA) – to display the livestream and its chat. Data is transferred to the USA in the process.
- laut.fm – for the embedded radio stream.
Audience measurement with Matomo
To understand how this website is used, we use Matomo — open source audience measurement software that we run on a server of our own. The data stays with us and is not shared with third parties. Measurement only takes place if you have given your consent via our consent banner: without your consent no measurement request is triggered and no Matomo cookies are set. We do not use any third-party advertising or profiling services.
The data processed includes in particular the pages you visit and when, the previously visited page (referrer), the time spent, the browser and device type you use, your screen resolution and your IP address, from which an approximate location is derived. After your consent, Matomo stores cookies in your browser so that repeat visits can be attributed to one session.
If you are signed in to your member account, we additionally transmit your internal user identifier to Matomo. This is a randomly generated string — neither your username nor your email address. It allows us to combine several devices or sessions belonging to the same account and thus to understand which member features are actually being used. No such identifier is transmitted for visitors who are not signed in.
The legal basis is your consent (Art. 6 (1) (a) GDPR, Section 25 (1) TDDDG). It is voluntary and can be withdrawn at any time with effect for the future — via the "Cookie settings" link in the page footer. On withdrawal we stop the measurement and delete the cookies set by Matomo. Without consent the website remains fully usable.
Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object (Art. 21). To exercise these rights, please contact the address above.
Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority.
SSL/TLS encryption
For security reasons this website uses SSL/TLS encryption. You can recognise an encrypted connection by the "https://" in your browser's address bar.