Data protection in practice.
This overview explains the controls designed to support our obligations and our customers' data-protection work under UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. It does not make a customer compliant by itself.
Roles follow the purpose.
Music Intel is controller for its own sites and business administration. It may act as processor for customer-directed product activity. The order, DPA and collection notice define the role for each use.
Defined retention.
Raw visitor telemetry is currently capped at 30 days before aggregation, security logs at up to 90 days, and billing records follow statutory requirements. Product-specific periods belong in the applicable order, DPA or notice.
Optional tracking needs consent.
On our corporate and musician marketing sites, Groove, Google Analytics and Meta Pixel load only after the relevant Performance or Marketing choice. Withdrawal clears site-controlled identifiers and stops future loading.
UK / EU data sovereignty.
UK company, with UK and EU primary hosting. Where restricted transfers need safeguards, we use the UK IDTA or UK Addendum to the EU SCCs together with the required data-protection test or transfer risk assessment.
Detail
Data subject rights.
Access, rectification, erasure, restriction, objection and portability apply where the legal conditions are met. You may also withdraw consent. Submit a request or complaint to legal@musicintel.co.uk. We acknowledge data-protection complaints within 30 days, investigate without undue delay and communicate the outcome. You may complain directly to the ICO at any time.
Providers and recipients.
- IP-API Pro (geolocation)
- Brandfetch (logo resolution)
- People Data Labs (optional enrichment)
- Stripe (Musicata subscription payment processing)
- Xero (Industry invoicing and accounting records)
- Google Analytics (optional performance measurement)
- Meta (optional advertising measurement)
- TikTok (optional customer-configured campaign measurement)
- Google reCAPTCHA (form abuse prevention where shown)
- Spreadshirt / Spreadshop (merch shop and fulfilment)
- Cloud and CDN providers (UK / EU first; SCCs or IDTA for any third countries)
These organisations do not all have the same legal role. Service-specific roles and providers are confirmed during due diligence; some providers, such as payment or shop operators, may act as independent controllers for their own activity.
Security controls.
- TLS 1.2+ in transit, encrypted storage for customer data.
- Role-based access, least privilege, regular key rotation.
- Rate limiting and bot filtering on ingestion endpoints.
- Data minimisation by design; no unnecessary identifiers.
DPA and documentation.
Where Music Intel will act as processor, the required Article 28 terms must be agreed before that processing begins. Restricted transfers may use the UK IDTA or the UK Addendum to the EU SCCs where required. During due diligence we identify the security evidence, service-specific provider information and incident-response material currently available for the proposed scope.
Third-party platform integrations.
The Musicata platform allows users to connect their own social and streaming accounts via OAuth 2.0 to aggregate audience metrics. We comply with platform-specific data-use policies and apply the following safeguards:
- Meta (Facebook and Instagram): permissions and data depend on the connection selected. Unless expressly stated in the permission screen, we do not post on the user's behalf or access private messages.
- Google (YouTube and Search Console): read-only access to subscriber counts and search performance. No access to private videos or email.
- Spotify: public follower and listener counts only via the Web API.
Lawful basis and role: these depend on the user, customer relationship and purpose. Disconnection: use Dashboard Settings > Connected Accounts where available. Retention and deletion follow the product notice, customer agreement and verified platform obligations.
