1. Controller and contact
Beyer Licensing’s billing operator, identified on the checkout receipt or invoice, is the controller for customer and licence records. Privacy requests can be sent to hello@deepbridgeadvisory.co.uk. We may ask for reasonable information to verify the requesting account before disclosing or changing records.
2. Information we use
- Google-verified email, display name and customer-session identifiers.
- Licence-holder, organisation, project, territory, intended use and consent records.
- The text and configuration facts you submit to the public Beyer Licence Advisor. This public assistant is not given customer-account records, private rights documents or payment credentials, and its conversation is not saved to your customer account.
- Orders, Stripe checkout identifiers, payment status, price and certificate records. Beyer does not store full card details.
- Player entitlements, registered device/session leases, station choices and operational playback records.
- Administration audit records, catalogue metadata, upload hashes and processing status.
- Cookie-free counts of landing visits, station previews, pricing views, checkout starts, completed purchases and contact submissions. These counts use approved categories and timestamps, not names, email addresses, account or Stripe identifiers, full URLs or referrers, IP addresses or user-agent strings.
- For the public station previews, which allow up to three 45-second starts per station and day, a one-way hash derived from the requesting IP address, the station, time window and granted seconds. The raw address is not stored in the preview-limit table.
- Technical security information such as timestamps, request metadata, error logs and approximate usage volumes.
3. Purposes and legal bases
We process account, order, delivery and licence data to perform a contract; protect the catalogue, prevent abuse and maintain service security for our legitimate interests; keep tax, payment and licence evidence where legally required; and use consent where the interface specifically asks for it. We do not sell personal data.
4. Service providers
Google provides customer identity verification; Stripe provides checkout and payment records; Cloudflare provides hosting, database and private media infrastructure; OpenAI processes the limited text submitted to the Licence Advisor when its AI extraction is enabled; and the configured email provider delivers receipts and licence PDFs. Each provider processes the data necessary for its role under its own terms and applicable data-processing commitments.
Some providers may process data outside the European Economic Area using legally recognised safeguards. Provider documentation gives further detail about their locations and transfer mechanisms. Do not enter private rights evidence, payment details or sensitive personal information into the public Licence Advisor.
5. Retention
Customer sessions normally expire after 30 days and admin sessions after 7 days unless renewed or ended earlier. OAuth request cookies expire after about 10 minutes. We keep transaction, licence and consent evidence for the period needed to perform the grant, answer rights disputes and meet accounting or legal obligations. Public-preview limit records reset after 24 hours and are scheduled for deletion within the following 24 hours during later preview processing. Cookie-free event occurrences use a 12-month retention window and expired rows are removed during subsequent event processing or permanent aggregation. Security and operational logs are kept only as long as reasonably necessary. Accounts may be retained while purchases or active entitlements remain associated with them.
6. Your data-protection rights
Depending on the circumstances, you may request information, access, correction, deletion, restriction, portability or objection, and you may withdraw consent without affecting earlier lawful processing. Some records must be retained for contractual, fraud-prevention, tax or legal reasons. Send a request from the account email to our contact address.
You may complain to the Spanish Data Protection Agency or the supervisory authority where you live. The European Data Protection Board provides an official overview of data-subject rights.