Proyalties

Privacy Policy

Effective date: July 12, 2026 ·  Beta release

1. Who we are

Proyalties (“we”, “us”, “our”) operates the royalty statement consolidation service available at proyalties.com. We are the data controller for personal data processed through this service.

Contact: [email protected]

2. What data we collect and why

Account data

  • Email address — required to create and secure your account.
  • Password — stored as a salted cryptographic hash; we cannot read it.
  • Analytics consent preference — a boolean flag recording whether you have opted in to allow your royalty data to be included anonymously in platform-wide trend analysis. This is off by default. If you opt in, we also store the UTC timestamp of that consent. You can change this preference at any time from Settings → Data & privacy.

Royalty statement data (parsed)

When you upload a statement file, we extract and store the structured royalty data it contains — work titles, royalty amounts, performance counts, periods, and the name of the collecting society. This is the core service: consolidating that data across societies into one view.

We do not store your original statement files. Files are read into memory, parsed, and immediately discarded. Only the extracted data fields are written to the database.

Contact form submissions

If you use the contact form at proyalties.com/contact, we collect your name, email address, subject, and message. This data is used solely to respond to your inquiry and is not added to any marketing list. We retain contact messages for as long as necessary to resolve the inquiry and comply with legal obligations, typically no longer than 12 months.

Usage data

  • A language preference cookie (pro-lang) storing your UI language choice (en/ja). No expiry set; cleared when you clear cookies.
  • A session cookie used to keep you logged in. This is a strictly necessary cookie — the service cannot function without it.
  • We do not use analytics cookies, advertising cookies, or any third-party tracking.

3. Legal basis for processing (GDPR)

We process your data under the following legal bases:

  • Contract performance — processing your account data and uploaded statement data is necessary to provide the service you signed up for.
  • Legitimate interests — keeping server logs for security and debugging, and maintaining the integrity of your account.
  • Consent— storing your language preference cookie; and, where you have explicitly opted in, including your royalty data in anonymised platform-wide aggregations (Article 6(1)(a) GDPR). This consent is freely given, specific, and fully revocable at any time from Settings → Data & privacy.

4. How we use your data

  • To provide and display your royalty dashboard, tracks, networks, and statements views.
  • To authenticate your account and protect it from unauthorised access.
  • To send transactional emails — account verification and security notices only. No marketing without separate consent.
  • Where you have opted in to analytics: to produce anonymised, aggregated statistics about royalty trends across opted-in users — such as aggregate totals by collecting society or territory — and to display those statistics within the platform. No individual records, earnings, work titles, or identities are ever disclosed; aggregates are only produced and surfaced when the contributing group is large enough that no individual user can be identified from the result.

Withdrawing analytics consent stops your data from being included in future aggregations. It does not alter aggregates already computed — but this is a privacy guarantee, not a limitation: once your data is merged into a statistic, your contribution is irreversibly combined with others' and can no longer be isolated or attributed to you. The merged result is anonymous statistical data, not personal data; there is nothing remaining to extract or remove.

We do not sell, rent, or share your data with third parties for their own purposes.

5. Data retention

Your parsed statement data and account information are retained for as long as your account exists. You can permanently delete all your data at any time from Settings → Wipe all data, or by contacting us at [email protected] to request full account deletion.

Deletion removes all statements, placements, and your account record from our active systems immediately. However, your data may persist in encrypted offline backups for up to 12 months, after which backup snapshots containing your data are cycled out under our retention schedule (7 daily / 7 weekly / 12 four-weekly snapshots). Backup data is encrypted and not accessible for normal use — it exists solely for disaster recovery. We cannot selectively purge individual records from backup snapshots.

6. Security

We protect your data with layered controls suited to each type of information we hold.

Identity data(your email and password) is stored on our EU infrastructure (see Section 9) and is encrypted at rest with AES-256. Passwords are hashed using bcrypt and can never be read or recovered, even by us.

Royalty data (the parsed figures behind your dashboard) is stored on our Canadian servers and is protected primarily by two controls: we parse and immediately discard your original statement files — so the most sensitive raw documents are never retained — and all offsite backups are encrypted. This royalty data is not additionally encrypted at the disk level; we have chosen data minimisation and encrypted backups as the protections here, rather than relying on at-rest disk encryption, which primarily guards against physical theft of a drive. Access is restricted and all connections are encrypted in transit.

All data is transmitted over HTTPS/TLS. Statement files are never written to disk — they are processed in memory only and discarded immediately after parsing.

We believe in telling you exactly how your data is protected, including where our approach differs from a one-size-fits-all “everything encrypted” claim.

This is a beta product. While we take security seriously, no system is perfectly secure. If you discover a vulnerability, please report it to [email protected] before public disclosure.

7. Your rights (GDPR / UK GDPR)

If you are in the UK or European Economic Area, you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Erasure — delete all your data via Settings, or request deletion by email.
  • Rectification — correct inaccurate account data (email) via Settings or by contacting us.
  • Restriction — ask us to restrict processing while a complaint is resolved.
  • Portability — request your parsed royalty data in a machine-readable format.
  • Object — object to processing based on legitimate interests.
  • Withdraw consent — where processing is based on consent (e.g. analytics opt-in), you may withdraw it at any time from Settings → Data & privacy or by contacting us. Withdrawal does not affect the lawfulness of processing before the withdrawal.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (UK: ICO at ico.org.uk; EU: your country's DPA).

8. Cookies

We use two cookies:

  • Session cookie (strictly necessary) — keeps you logged in. Deleted when you sign out.
  • pro-lang (preference) — remembers your language setting. No tracking, no expiry.

No third-party cookies, analytics, or advertising are used.

9. Third-party processors

We use the following third-party service providers, each acting as a data processor on our behalf. We have data processing agreements (or rely on their published DPAs) with each.

  • Cloudflare (CDN and DDoS protection)— All web traffic to proyalties.com is routed through Cloudflare's network, which handles HTTPS termination, caching, and DDoS mitigation. Cloudflare processes request metadata (IP addresses, HTTP headers) as a necessary part of this. Cloudflare is subject to its own Privacy Policy and standard contractual clauses for EU/UK transfers.
  • Cloudflare Turnstile (bot protection) — Our login and registration forms use Cloudflare Turnstile to distinguish humans from automated bots. Turnstile loads a JavaScript challenge from challenges.cloudflare.com and sends browser signals to Cloudflare for verification. Turnstile does not set cookies, does not track users across sites, and is not used for advertising. See Cloudflare's Turnstile privacy documentation for details.
  • Neon (database infrastructure)— Our identity database (email and credentials) is hosted on Neon infrastructure in Frankfurt, EU. See Section 10.

We do not use advertising networks, analytics services, or any other third-party trackers.

10. Where your data is stored

We use two separate databases, stored in different regions:

  • Identity data (email address and hashed password) — stored on Neon infrastructure in Frankfurt, Germany (EU). AES-256 encrypted at rest.
  • Royalty statement data (parsed earnings, work titles, placements) — stored on servers in Montreal, Quebec, Canada. See Section 6 for encryption-at-rest status.
  • Encrypted offsite backups — held on a backup server also located in Canada. Backup data is encrypted before it leaves the source server and is not publicly accessible.

Canada holds an EU Commission adequacy decision for commercial-sector data transfers under PIPEDA, and a separate UK adequacy decision post-Brexit, meaning transfers of personal data from the EU or UK to our Canadian servers are generally covered without additional safeguards. If you have specific data-residency requirements, contact us at [email protected].

11. Children

Proyalties is not directed at children under 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to this policy

We will notify registered users by email of material changes at least 14 days before they take effect. The effective date at the top of this page reflects the most recent update. Continued use after the effective date constitutes acceptance.

13. Contact

Data controller inquiries, right-to-erasure requests, and security reports can be sent via our contact form or directly to [email protected]. We aim to respond within 30 days.