Privacy Policy
Effective date: 22 May 2026
This Privacy Policy explains how MeSoft ("we", "us", "our") collects, uses, and protects personal information when you use Etto Music (the "Service"). It is intended to satisfy the requirements of the UK GDPR, the EU GDPR, the Australian Privacy Act 1988 (Australian Privacy Principles), and the Korean Personal Information Protection Act.
1. Data Controller
MeSoft is the data controller for personal information processed in connection with the Service. Contact: support@ettomusic.com.
2. Information We Collect
2.1 Account information
- Social-login identifier (e.g., Google sub), email address, name
- Venue information you provide (venue name, industry type, optional address)
2.2 Subscription and billing information
- Subscription status and history
- Billing records (we do not store full payment card numbers; payment is processed by Polar as our Merchant of Record)
2.3 Service usage information
- Playback logs (tracks played, timestamps, device identifiers)
- App and web analytics (page views, feature usage, crash reports)
- IP address, browser type, operating system, language preference
2.4 Customer-support communications
- Messages you send to support@ettomusic.com or via in-app chat
3. Why We Collect Information (Lawful Bases)
| Purpose | Lawful basis (GDPR) |
|---|---|
| Account creation, authentication, providing the Service | Performance of a contract |
| Subscription billing, fraud prevention, tax compliance | Performance of a contract / legal obligation |
| AI playlist curation tuned to your venue | Performance of a contract |
| Service-improvement analytics and aggregate reporting | Legitimate interest |
| Marketing communications (opt-in only) | Consent (withdrawable anytime) |
| Legal compliance, dispute resolution | Legal obligation |
4. How We Share Information
We share personal information only with the following categories of recipient:
- Polar — Merchant of Record. Processes subscription payments, tax remittance, and refunds for international customers.
- Amazon Web Services — cloud infrastructure provider for hosting and storage.
- Analytics providers — aggregated usage analytics (e.g., Google Analytics with IP anonymisation).
- Customer-support tools — email and ticketing platforms used to respond to your enquiries.
- Authorities — where required by law or to protect the safety of any person.
We do not sell your personal information.
5. International Transfers
MeSoft is based in the Republic of Korea. Some processors (e.g., Polar, AWS) operate internationally. Where personal data of UK/EU residents is transferred outside the UK/EEA, we rely on Standard Contractual Clauses, UK International Data Transfer Agreements, or adequacy decisions, as appropriate.
6. Retention
- Account information: retained while your account is active and for 1 year after closure.
- Billing records: retained for 7 years to satisfy tax and accounting obligations.
- Playback logs: retained in identified form for 12 months; longer in aggregated, anonymised form.
- Support communications: retained for 3 years.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal information:
- Access — request a copy of the data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete data we no longer need.
- Restriction or objection — limit certain uses of your data.
- Portability — receive your data in a machine-readable format.
- Withdraw consent — at any time, where processing is based on consent.
- Lodge a complaint with your data protection authority (e.g., the UK ICO at ico.org.uk, or the OAIC in Australia at oaic.gov.au).
To exercise any of these rights, email support@ettomusic.com. We respond within 30 days.
8. Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember your preferences, and measure site usage. Non-essential cookies (analytics, marketing) are set only with your consent where required by law. You can adjust cookie settings in your browser at any time.
9. Security
We implement technical and organisational measures including encryption in transit (HTTPS), access controls, regular backups, and least-privilege administration to protect personal information. No method of transmission or storage is 100% secure; we will notify affected users and authorities of any data breach as required by law.
10. Children
The Service is intended for business use by adults. We do not knowingly collect personal information from children under 16. If we become aware that we have collected such data, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via the Service or by email at least 30 days before they take effect.
12. Contact
For privacy questions or requests:
Email: support@ettomusic.com
Postal: MeSoft, Republic of Korea
