Proyalties
Effective date: July 12, 2026 · Beta release
Proyalties (“we”, “us”, “our”) operates the royalty statement consolidation service available at proyalties.com. We are the data controller for personal data processed through this service.
Contact: [email protected]
Account data
Royalty statement data (parsed)
When you upload a statement file, we extract and store the structured royalty data it contains — work titles, royalty amounts, performance counts, periods, and the name of the collecting society. This is the core service: consolidating that data across societies into one view.
We do not store your original statement files. Files are read into memory, parsed, and immediately discarded. Only the extracted data fields are written to the database.
Contact form submissions
If you use the contact form at proyalties.com/contact, we collect your name, email address, subject, and message. This data is used solely to respond to your inquiry and is not added to any marketing list. We retain contact messages for as long as necessary to resolve the inquiry and comply with legal obligations, typically no longer than 12 months.
Usage data
pro-lang) storing your UI language choice (en/ja). No expiry set; cleared when you clear cookies.We process your data under the following legal bases:
Withdrawing analytics consent stops your data from being included in future aggregations. It does not alter aggregates already computed — but this is a privacy guarantee, not a limitation: once your data is merged into a statistic, your contribution is irreversibly combined with others' and can no longer be isolated or attributed to you. The merged result is anonymous statistical data, not personal data; there is nothing remaining to extract or remove.
We do not sell, rent, or share your data with third parties for their own purposes.
Your parsed statement data and account information are retained for as long as your account exists. You can permanently delete all your data at any time from Settings → Wipe all data, or by contacting us at [email protected] to request full account deletion.
Deletion removes all statements, placements, and your account record from our active systems immediately. However, your data may persist in encrypted offline backups for up to 12 months, after which backup snapshots containing your data are cycled out under our retention schedule (7 daily / 7 weekly / 12 four-weekly snapshots). Backup data is encrypted and not accessible for normal use — it exists solely for disaster recovery. We cannot selectively purge individual records from backup snapshots.
We protect your data with layered controls suited to each type of information we hold.
Identity data(your email and password) is stored on our EU infrastructure (see Section 9) and is encrypted at rest with AES-256. Passwords are hashed using bcrypt and can never be read or recovered, even by us.
Royalty data (the parsed figures behind your dashboard) is stored on our Canadian servers and is protected primarily by two controls: we parse and immediately discard your original statement files — so the most sensitive raw documents are never retained — and all offsite backups are encrypted. This royalty data is not additionally encrypted at the disk level; we have chosen data minimisation and encrypted backups as the protections here, rather than relying on at-rest disk encryption, which primarily guards against physical theft of a drive. Access is restricted and all connections are encrypted in transit.
All data is transmitted over HTTPS/TLS. Statement files are never written to disk — they are processed in memory only and discarded immediately after parsing.
We believe in telling you exactly how your data is protected, including where our approach differs from a one-size-fits-all “everything encrypted” claim.
This is a beta product. While we take security seriously, no system is perfectly secure. If you discover a vulnerability, please report it to [email protected] before public disclosure.
If you are in the UK or European Economic Area, you have the right to:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (UK: ICO at ico.org.uk; EU: your country's DPA).
We use two cookies:
No third-party cookies, analytics, or advertising are used.
We use the following third-party service providers, each acting as a data processor on our behalf. We have data processing agreements (or rely on their published DPAs) with each.
challenges.cloudflare.com and sends browser signals to Cloudflare for verification. Turnstile does not set cookies, does not track users across sites, and is not used for advertising. See Cloudflare's Turnstile privacy documentation for details.We do not use advertising networks, analytics services, or any other third-party trackers.
We use two separate databases, stored in different regions:
Canada holds an EU Commission adequacy decision for commercial-sector data transfers under PIPEDA, and a separate UK adequacy decision post-Brexit, meaning transfers of personal data from the EU or UK to our Canadian servers are generally covered without additional safeguards. If you have specific data-residency requirements, contact us at [email protected].
Proyalties is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We will notify registered users by email of material changes at least 14 days before they take effect. The effective date at the top of this page reflects the most recent update. Continued use after the effective date constitutes acceptance.
Data controller inquiries, right-to-erasure requests, and security reports can be sent via our contact form or directly to [email protected]. We aim to respond within 30 days.