Privacy & Cookie Policy

Last Updated: 20/11/2025

Data Controller

Company: Jassonata OÜ

Registration No.: 17139860

Address: Harju maakond, Tallinn, Lasnamäe linnaosa, Peterburi tee 53, 11415

Email: info@bmln.app

Website: bmln.app

1. INTRODUCTION

BMLN ("we", "our", or "us") is committed to protecting your privacy and personal data. This Privacy & Cookie Policy explains how we collect, use, store, and protect your personal information when you use our Business Music Licensing Network service.

This policy applies to all users of the BMLN platform, including business administrators, managers, and members.

By using BMLN, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use our service.

2. DATA WE COLLECT

2.1. Account Information

  • Email address
  • First name and last name
  • Phone number
  • Password (encrypted)

2.2. Business Information

  • Business name and type
  • Business capacity (venue size)
  • Company registration details
  • VAT number (if applicable)
  • Business address and contact information
  • Venue details

2.3. Payment Information

  • Billing details (processed by Stripe)
  • Subscription tier and status
  • Payment history

Note: Credit card details are stored securely by Stripe. We do not store full credit card numbers.

2.4. Usage Data

  • Music listening history (tracks played, playlists accessed)
  • Login times and session duration
  • Device information (browser type, operating system)
  • IP address and approximate location
  • Feature usage and interaction data

2.5. Technical Data

  • Cookies and similar tracking technologies
  • Error logs and diagnostic data
  • Performance metrics
  • Service worker cache data

3. HOW WE USE YOUR DATA

3.1. Service Delivery: To provide and maintain the BMLN music streaming service, including authentication, playlist management, and music playback.

3.2. Account Management: To create and manage your account, process registrations, and handle business approvals.

3.3. Billing and Payments: To process subscriptions, handle payments, generate invoices, and manage billing cycles.

3.4. Analytics and Improvements: To analyze service usage, improve platform performance, and develop new features.

3.5. Customer Support: To respond to inquiries, troubleshoot issues, and provide technical assistance.

3.6. Legal Compliance: To comply with legal obligations, enforce our Terms of Service, and protect our rights and the rights of our users.

3.7. Communications: To send service-related notifications, subscription updates, and important announcements (we do not send marketing emails without consent).

4. COOKIES AND TRACKING TECHNOLOGIES

BMLN uses cookies and similar tracking technologies to enhance your experience and analyze service usage. You can manage your cookie preferences using our cookie banner.

4.1. Essential Cookies (Required)

These cookies are necessary for the service to function and cannot be disabled:

  • Authentication: Supabase session tokens for user authentication
  • Security: CSRF protection and session management
  • Preferences: Business selection, language preferences

4.2. Analytics Cookies (Optional)

These cookies help us understand how you use the service:

  • Vercel Analytics: Page views, user flows, feature usage
  • Vercel Speed Insights: Performance monitoring, load times

4.3. Preference Cookies (Optional)

  • Audio Player Settings: Volume level, playback preferences
  • UI Preferences: Layout choices, theme settings

4.4. Managing Cookies

You can control cookie preferences through:

  • Our cookie consent banner (appears on first visit)
  • Your browser settings (note: disabling essential cookies may affect functionality)

5. DATA SHARING AND THIRD PARTIES

We do not sell your personal data. We share data only with trusted service providers necessary for service delivery:

5.1. Service Providers

  • Supabase: Database hosting, authentication, file storage
  • Vercel: Web hosting, analytics, performance monitoring
  • Stripe: Payment processing and billing
  • AWS: Audio file storage and streaming (S3)

5.2. Legal Requirements

We may disclose your data if required by law, court order, or to:

  • Comply with legal obligations
  • Protect our rights and property
  • Prevent fraud or security threats
  • Protect user safety

5.3. Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.

6. DATA SECURITY

We implement industry-standard security measures to protect your personal data:

  • Encryption: HTTPS/TLS for data transmission, encrypted storage for sensitive data
  • Access Controls: Role-based access, multi-tenant isolation via Row Level Security (RLS)
  • Authentication: Secure password hashing, optional two-factor authentication
  • Monitoring: Regular security audits and vulnerability assessments
  • Infrastructure: Enterprise-grade cloud providers (Supabase, Vercel, AWS)

However, no method of transmission over the Internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. DATA RETENTION

7.1. Active Accounts: We retain your personal data as long as your account is active or as needed to provide services.

7.2. Inactive Accounts: Data from inactive accounts (no login for 24+ months) may be deleted after notification.

7.3. Closed Accounts: When you close your account, we delete or anonymize your personal data within 90 days, except:

  • Data required for legal compliance (billing records, transaction history)
  • Aggregated, anonymized analytics data
  • Data in backup systems (automatically purged within 30 days)

7.4. Legal Holds: We may retain data longer if required by law or for legal proceedings.

8. YOUR RIGHTS UNDER GDPR

Under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restriction: Limit how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for data processing at any time
  • Right to Lodge a Complaint: File a complaint with your data protection authority

To exercise these rights, contact us at privacy@bmln.app. We will respond within 30 days.

9. INTERNATIONAL DATA TRANSFERS

BMLN is based in Estonia (EU), but our service providers may process data in other countries:

  • Supabase: EU data centers (GDPR-compliant)
  • Vercel: Global CDN, EU data residency available
  • AWS: EU-North-1 region (Stockholm, Sweden)
  • Stripe: EU operations, GDPR-compliant

All data transfers comply with GDPR requirements through Standard Contractual Clauses (SCCs) or adequacy decisions.

10. CHILDREN'S PRIVACY

BMLN is a B2B service intended for business use only. We do not knowingly collect personal data from individuals under 16 years of age.

If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@bmln.app.

11. CHANGES TO THIS POLICY

We may update this Privacy & Cookie Policy from time to time to reflect:

  • Changes in our data practices
  • New features or services
  • Legal or regulatory requirements

We will notify you of material changes via:

  • Email notification to your registered email address
  • Prominent notice on our platform
  • Updated "Last Updated" date at the top of this policy

Your continued use of BMLN after changes take effect constitutes acceptance of the updated policy.

12. CONTACT US

For questions, concerns, or requests regarding this Privacy & Cookie Policy or your personal data, please contact us:

Email: privacy@bmln.app

General Inquiries: info@bmln.app

Postal Address:

Jassonata OÜ
Harju maakond, Tallinn
Lasnamäe linnaosa
Peterburi tee 53
11415 Estonia

We aim to respond to all inquiries within 5 business days.

By using BMLN, you acknowledge that you have read, understood, and agree to this Privacy & Cookie Policy.

Last Updated: 20/11/2025

BMLN - Baltic Music Licensing Network