Privacy Policy
Privacy Policy
Last updated: 30 September 2026
This policy explains how DemoPool handles personal data. It has two parts: Part A covers you as a visitor or customer of demopoolbase.com. Part B covers music-industry professionals whose business contact details appear in the lists we sell.
Who we are
The controller is FloyaraMusic OÜ (registry code 16341789), Männimäe/1, Pudisoo küla, Kuusalu vald, Harju maakond, 74626, Estonia, trading as DemoPool ("DemoPool", "we", "us"). Privacy questions and requests: privacy@demopoolbase.com.
Part A. Customers and website visitors
A1. What we collect
- Account and order data: name, email address, billing address, company name and VAT number (if given), order history, subscription status.
- Payment data: processed by our payment providers. We receive the payment status and limited card details (such as card type and last four digits), never the full card number.
- Download and delivery data: download links issued, download times and IP addresses, used to deliver files and prevent abuse.
- Communications: emails you send us, refund or bounce-guarantee claims and the reports you attach.
- Free sample and waitlist sign-ups: your email address and the list you asked about.
- Technical and usage data: IP address, browser and device type, pages viewed, referring site, collected through cookies and similar technologies.
A2. Why we use it and our legal basis
- To process orders, deliver files, run subscriptions and handle support and guarantee claims: performance of our contract with you.
- To keep accounting and tax records and respond to lawful requests: legal obligation.
- To prevent fraud, enforce our licence terms and secure the store: our legitimate interests.
- To measure and improve the site with analytics: your consent where required for cookies, otherwise our legitimate interests.
- To send you the free sample you asked for, launch notices and occasional tips: your consent, which you can withdraw at any time using the unsubscribe link in every email.
- To send order-related messages (receipts, download links, renewal reminders): performance of our contract.
A3. Cookies
We use cookies that are strictly necessary for the cart, checkout and your account. Analytics and marketing cookies are only set where you have consented, where the law requires consent. You can change your choice at any time through the cookie banner or your browser settings. Shopify's own cookies are described in Shopify's cookie policy.
A4. Who we share it with (processors)
- Shopify: store hosting, checkout, customer accounts and order emails.
- Payment providers: Shopify Payments and PayPal.
- Subscription billing: Shopify Subscriptions.
- Analytics: Shopify Analytics, Google Analytics and Microsoft Clarity (session recordings and heatmaps with personal data masked). Clarity and Google Analytics load only after you allow analytics cookies.
- Advertising measurement: Meta (Facebook/Instagram) Pixel, only after you allow marketing cookies.
- Email delivery for marketing and transactional emails: Shopify Email.
- Professional advisers such as our accountant, and authorities where the law requires.
Processors act only on our instructions under data processing agreements. We do not sell customer data and do not share it for cross-context behavioural advertising.
A5. International transfers
Some providers process data outside the European Economic Area and the UK, including in the United States and Canada. Where the destination does not have an adequacy decision, transfers rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) or the EU-US Data Privacy Framework where the provider is certified.
A6. How long we keep it
- Orders, invoices and payment records: 7 years, as required by accounting law.
- Customer account: until you close it, then deleted or anonymised except for records we must keep.
- Download logs: 24 months.
- Marketing sign-ups: until you unsubscribe, after which we keep only a suppression record so we do not email you again.
- Analytics data: 14 months.
A7. Your rights
Under the GDPR and UK GDPR you have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. If you live in California or another US state with a consumer privacy law, you have the right to know what personal information we collect and why, to access and delete it, to correct it, and not to be discriminated against for using these rights. We do not sell or share customer personal information.
To use any right, email privacy@demopoolbase.com. We may ask you to confirm your identity. We answer within one month (GDPR, UK GDPR) or 45 days (US state laws), and tell you if we need an extension allowed by law. You may use an authorised agent where state law allows.
You can complain to a data protection authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee). In the UK you can complain to the Information Commissioner's Office (ico.org.uk), and in the EU to the authority where you live or work.
A8. Security
We use encrypted connections, restrict access to people who need it, and deliver files through expiring, account-bound download links. No system is perfectly secure; if a breach affects your data, we notify you and the authorities as the law requires.
Part B. Professionals listed in our contact lists
B1. What data we hold
We hold business contact data that music-industry professionals and organisations published themselves so that people can reach them about their work. Depending on the list, a record can include:
- name, artist, label, playlist or channel name, and the type of contact (for example label, curator, DJ or producer);
- a business or public contact email address, submission link or demo policy;
- public profile and website links, country and city;
- public professional information such as genres, audience or follower counts, track counts, last release and chart entries;
- the date and result of our last email verification.
We do not collect home addresses, private phone numbers, passwords, payment data, private messages or special category data such as health, religion or political opinions.
B2. Where it comes from
- Record labels' own websites, including contact and demo-submission pages.
- Public artist, curator and label profiles on music platforms, including contact fields that the profile owner chose to make public on SoundCloud and YouTube.
- Public playlist information and published curator contact details.
- Public chart listings, such as Beatport charts.
Our own data pipeline collects this information. We do not use data from breaches, closed groups, private messages or content behind a login. We check each email address with an SMTP verification that confirms the mailbox exists without sending a message.
B3. Why we process it and our legal basis
We compile these lists so that artists, labels, promoters and music businesses can contact the right professional about music work: demo submissions, playlist pitching, bookings, collaborations, sponsorships and similar B2B purposes. Our legal basis is legitimate interests (Article 6(1)(f) GDPR and UK GDPR): our interest and our customers' interest in professional networking in the music industry. We have weighed this against your interests and rights, taking into account that you published these details for professional contact, that we limit the data to professional information, and that you can object and be removed at any time.
B4. Who receives it
We license the lists to business customers worldwide. Each customer is bound by our Terms of Service and Acceptable Use Policy: they must use the data lawfully and only for relevant professional contact, identify themselves, include a working opt-out in every message, never resell or publish the data, and delete any contact we tell them has been removed. Customers act as independent controllers of the data they receive. Our hosting, storage and email-verification providers (our own SMTP verification system, Shopify, Vercel and Neon) process the data on our behalf. Some recipients are outside the EEA and UK; we use the transfer safeguards described in section A5 for our processors.
B5. How long we keep it
We keep a record while it remains publicly available and valid. Addresses that hard-bounce or are no longer published are removed at the next verification cycle, and each record is re-verified periodically and deleted once it fails verification or is no longer published. Removal requests are kept on a suppression list, described below.
B6. Your rights
You can ask to see the data we hold about you, correct it, have it deleted, restrict its use, or object to our processing at any time. When you object, we stop processing your data for our lists. You can also complain to the Estonian Data Protection Inspectorate (aki.ee), the UK ICO or your local authority.
California residents: selling your business contact information to our customers is a "sale" under the CCPA. You have the right to opt out of that sale, to know what we hold, and to request deletion. Use the removal procedure below, which also works as our "Do Not Sell or Share My Personal Information" request.
B7. How to be removed
- Use our Remove my data page, or email privacy@demopoolbase.com from the address you want removed, or include that address in your message.
- We may email that address once to confirm the request came from its owner or someone authorised to act for the organisation.
- We act without undue delay and within 30 days of receiving your request, and we confirm when it is done.
B8. What happens after removal
- We delete your record from every list we sell, including All Access and all genre and country files.
- We add a one-way hash of your email address to a permanent suppression list. Our pipeline checks every newly collected contact against it, so your address is not added back in any future file or monthly refresh, even if it is still public elsewhere.
- Your address is excluded from all future deliveries and refreshes to every customer.
- We notify customers who received your record in the last 12 months and require them, under our Terms, to delete it within 10 days.
Changes to this policy
We update this policy when our practices or the law change, and we change the date at the top. For material changes affecting customers, we also notify you by email.