// Legal

Privacy Notice.

Last updated: 17 June 2026

1. Who we are

This Privacy Notice is issued by Andrea Chirivi, operator of PRESS-KIT.CLOUD (the "Service"). We act as the data controller for personal data we collect about you when you use the Service.

Contact: privacy@press-kit.cloud.

2. Data we collect

  • Account data: email address, password hash, authentication identifiers.
  • EPK content: artist name, bio, genre, location, links, photos and other content you upload.
  • Support data: messages and attachments you send to us.
  • Usage and telemetry: pages viewed, EPK views/downloads, approximate location, device and browser type.
  • Technical data: IP address, log files, cookie identifiers.

Payment data (card details, billing address) is collected directly by our Merchant of Record, Paddle, and is not stored by us.

3. Why we use your data and legal basis

  • Provide the Service (account creation, hosting your EPK, generating PDFs) — performance of a contract.
  • Process payments and subscriptions via Paddle — performance of a contract and legal obligation.
  • Security and fraud prevention — legitimate interests in protecting the Service.
  • Improve the product (analytics, debugging) — legitimate interests.
  • Customer support — performance of a contract.
  • Marketing emails (only if you opt in) — consent, which you can withdraw at any time.
  • Comply with legal obligations (tax, accounting, lawful requests) — legal obligation.

4. Who we share data with

  • Paddle.com — our Merchant of Record for sale of the product, subscription management, payments, tax compliance and invoicing.
  • Hosting and infrastructure providers (Cloudflare, Supabase) — to host the application, database and uploaded media.
  • Analytics and error-monitoring providers — to understand usage and diagnose issues.
  • Email providers — to send transactional and (with consent) marketing emails.
  • Professional advisers (legal, accounting) where necessary.
  • Public recipients of your EPK — anything you publish on a public EPK link is visible to anyone with the link.
  • Authorities where required by law.

5. International transfers

Some of our providers are based outside the UK/EEA (for example in the United States). Where personal data is transferred internationally we rely on appropriate safeguards such as the EU Standard Contractual Clauses or an applicable adequacy decision.

6. Retention

We keep your account and EPK data for as long as your account is active. If you delete your account, we delete or anonymise personal data within 30 days, except where we are required to keep certain records for legal or accounting purposes (typically up to 10 years for invoicing).

7. Your rights

Under the GDPR and equivalent laws you have the right to: access your data, request rectification or erasure, restrict or object to processing, data portability, and withdraw consent at any time. You may also lodge a complaint with your local data protection authority. To exercise your rights, email privacy@press-kit.cloud. We respond within one month.

8. Security

We use appropriate technical and organisational measures to protect your data, including TLS encryption in transit, encryption at rest for stored files, access controls and audit logging. No system is perfectly secure; please use a strong, unique password.

9. Cookies

We use a small number of essential cookies required to keep you signed in and to keep the Service secure. We may also use limited analytics cookies to understand aggregate usage. You can manage or block cookies in your browser settings; blocking essential cookies may break sign-in.

10. Changes to this notice

We may update this Privacy Notice from time to time. Material changes will be notified by email or in-product banner.

See also our Terms & Conditions and Refund Policy.