COLOSSAL

PRIVACY NOTICE

Effective from: 20 May 2025

This Privacy Notice (“Privacy Notice”) sets out how Colossal Sound Limited processes your personal data in connection with our Colossal platform and related business, including the provision of our websites and our web and mobile application(s) (collectively our “Platform(s)”) and the services we offer, including through our Platforms (our “Services”). It applies when you use or register on the Platform, and/or buy licenses from Colossal, and also in some circumstances when you buy a license directly from the Producer. See below for more on this.

We will update this Privacy Notice from time to time to reflect any changes or proposed changes to our use of your personal data, or to comply with changes in applicable law or regulatory requirements. We may notify you by email of any significant changes to this Privacy Notice, but we encourage you to review this Privacy Notice periodically to keep up to date on how we use your personal data.

1. PURPOSE OF THIS PRIVACY NOTICE

This Privacy Notice explains our approach to any personal data that we might collect from you or which we have obtained about you from a third party, and the purposes for which we process your personal data and how we share it with others. This Privacy Notice also sets out your rights in respect of our processing of your personal data.

When we talk about “personal data”, we mean any information which relates to an identified or identifiable living individual. Individuals might be identified by reference to a name, address, an identification number, location data, an online identifier (such as an IP address) or to other factors that are specific to them.

This Privacy Notice is intended to assist you in making informed decisions when using our Platform and our Services. Please take a moment to read and understand it. It should be read in conjunction with our Terms of Service, and our Cookie Policy.

This Privacy Notice only applies to the use of your personal data obtained by us, whether from you directly or from a third party. It does not apply to personal data collected by third parties during your communications with those third parties or your use of their products or services (for example, where you follow links to third party websites over which we have no control, or you purchase goods or services from those third parties).

2. ABOUT US

The Platform and our Services are made available by Colossal Sound Limited (known as “Colossal”, “we”, “us”, “our”). Colossal Sound Limited is the data controller responsible for your personal data.

Colossal Sound Limited is an English company number 15022256 and our registered office is 86-90 Paul Street, London, England, United Kingdom, EC2A 4NE.

3. HOW TO CONTACT US

If you have any questions about this Privacy Notice or want to exercise your rights as a data subject set out in this Privacy Notice, you can contact us using the following methods:

  • On site / platform: Contact us using our support chat in the lower-left hand side of the screen
  • Email: Send us an email at support@colossal.fm

4. WHAT PERSONAL DATA WE COLLECT

The types of personal data we collect depends on who you are and how you use our Platform and Services and may include the following:

  • Identity Data: First name; last name
  • Contact Data: Address; email address; telephone number; social media handle
  • Registration Data: First name; last name; date of birth; gender; country; nationality; username; any other personal data that you may provide, or we receive from single sign-on (“log in with @”) partners, when you register an account with us
  • Financial Data: Bank account details; payment card details
  • Transaction Data: Details about payments made; and details of items purchased (including from Colossal on the Platform and directly from Producers)
  • Profile Data: Account username; password; profile picture or avatar; purchase/order details; interests and preferences; contact preferences; data we receive from single sign-on (“log in with @”) partners; the content of any messaging you send using any Enquiry Form or Chat function on the Platform
  • Behavioural Data: Data relating to your browsing activity or interaction with the Platform, obtained through the use of cookies, pixel tags and other similar technologies; information about when your current or previous sessions started; details about any products you viewed or purchased through the Platform
  • Technical Data: IP address; browser type and operating system; geolocation, to ensure we’re showing you the correct notices and information; any other unique numbers assigned to a device
  • Marketing and Communications Data: Marketing preferences; service communication preferences

5. HOW WE COLLECT AND RECEIVE PERSONAL DATA

We collect and receive personal data using different methods:

  • Personal data you provide to us, including via the Platform during a direct Transaction with a Producer
    You may give us, or the Producer you are buying from directly, your personal data, for example, when you register or purchase on or via our Platform, contact us with enquiries, complete forms on our Platform, subscribe to receive our marketing communications or provide feedback to us.

  • Personal data we collect using cookies and other similar technologies
    When you access and use our Platform, we will collect certain Behavioural Data and Technical Data. We collect this personal data by using cookies and other similar technologies (see the “Insight, analysis and retargeting through Cookies” section below).

  • Personal data received from third parties
    We may receive personal data about you from third parties. Such third parties may include single sign-on (“log in with @”) partners, analytics providers, data brokers, third party directories and third parties that provide technical services to us (such as payment service providers) so that we can provide our Platform and our Services.

6. HOW WE USE YOUR PERSONAL DATA

We use your personal data for the purposes set out in this section.

Use of our Platform

If you register for an account on our Platform

You may be required to register an account with us in order to gain access to certain features and functionality of our Platform. Account holders will need to complete the registration form, providing all required Identity Data, Contact Data, Registration Data, Financial Data and Profile Data. We will use this data in order to process your registration.

Once the account is registered, we will process your Identity Data, Contact Data, Registration Data and Profile Data to identify you when you log in to your account and access secure areas of our Platform. We will also process certain Technical Data and Marketing and Communications Data so that we can administer your account and contact you about your account.

We will also collect and process Behavioural Data and Technical Data when you use certain features and functionality on our Platform. This data helps us understand how you use our Platform so that we can improve it.

We will also populate your account with any pre-existing Transaction Data, Identity Data and Contact Data, including in relation to purchases via the Platform directly from Producers, or otherwise use it in relation to features you may use that are of benefit to you.

Our legal basis for processing
It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you, or it is in our legitimate interest to use personal data in such a way to ensure that we provide access to the Platform and our Services in a secure and effective way and so that we can make improvements to our Platform.

If you purchase items via our Platform

We collect and maintain personal data that you submit to us or the Producer you are buying from directly, for the purpose of supplying items that you have requested via our Platform or from the Producer.

The personal data we process may include your Identity Data, Contact Data, Registration Data, Profile Data, Financial Data and Transaction Data (where applicable). We process this information so that we can fulfil the supply of Services, maintain our user databases and to keep a record of how our Services are being used.

We will also populate your account with any pre-existing Transaction Data, Identity Data and Contact Data, including in relation to purchases via the Platform directly from Producers, or otherwise use it in relation to features you may use that are of benefit to you.

Our legal basis for processing
It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Services, or it is in our legitimate interest or a third party’s legitimate interest to use personal data in such a way to ensure that we provide our Services in an effective, safe and efficient way.

If you browse our Platform

When you browse our Platform, we collect and process Behavioural Data and Technical Data to help us understand how you are using and navigating our Platform. We do this so that we can better understand which parts of our Platform are more or less popular and improve the structure and navigation of our Platform.

Our legal basis for processing
It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Services, or it is in our legitimate interest to use personal data in such a way to ensure that we provide access to our Platform in a secure and effective way and so that we can make improvements to our Platform.

If you use the interactive features on our Platform

We will collect and use personal data about you when you use certain features on our Platform. For example, depending on the nature of your enquiry, we may process your Identity Data, Contact Data, Registration Data, Profile Data and certain Behavioural Data and Technical Data when you use the Enquiry Form or Chat function to get in touch with us or other account holders.

Our legal basis for processing
It is necessary for us to use your personal data to perform our obligations in accordance with any contract that we may have with you for the Services, or it is in our legitimate interest to use personal data in such a way to ensure that we can respond to your enquiries, provide access to our Platform in a secure and effective way and make improvements to our Platform.

If you contribute to our Platform or post content on our Platform

If you submit any content to us, including via our Platform, we may process any personal data comprised within that content for the purposes of making available particular Services via our Platform.

Our legal basis for processing
Where we use your content in connection with Services that we provide via our Platform, it is in our legitimate interest to use any personal data that you provide to us to ensure that we provide the relevant Services in an effective way.

If you log in with or otherwise link to social media sites and interact with our social media pages

If you log in with or click on one of the social media links on our Platform or otherwise interact with our social media pages such as on Facebook or Instagram (including interacting with any ‘like’ or similar embedded features on our Platform or social media accounts), we and the relevant social media platform may receive information relating to such interaction and may share your personal data in connection with this purpose, such as certain Behavioural Data and Technical Data.

Our legal basis for processing
It is in our legitimate interest to use personal data in the ways described above to ensure that we provide the Platform in an effective way and to promote our Platform via social media.

Ensuring the proper functioning of our Platform and providing you with our Platform features and notifications

When you use our Platform and associated features and functionality, the provider of your device may collect certain Technical Data. The data is automatically collected and transmitted to us from your device during your use of the Platform (“Usage Data”) and includes:

  • Device name (e.g. “Apple iPhone”, “Samsung Galaxy”, or any other name you have given your device)
  • Operating system and version
  • System language
  • General device data such as voice and regional settings
  • IP address of the device
  • Date and time of use
  • Application ID to identify your installation

You may be asked for permission to receive push notifications. If you allow this feature, we may send you reminders, alerts, updates, or other messages.

Our legal basis for processing

  • Legitimate interest to ensure security, detect errors and cyberattacks
  • Consent for features like push notifications, location, microphone, camera, etc.

7. SHARING PERSONAL DATA

We only share personal data when legally permitted. We apply contractual and security safeguards to protect data we share with:

  • Producers: Only identity and transaction data from purchases via the Platform
  • Third-party suppliers: For IT, infrastructure, and analytics (see Cookie Policy)
  • Payment providers and banks
  • Advertising partners: To serve and measure advertising
  • CRM and email marketing providers
  • Promotion administrators
  • Professional advisers (lawyers, auditors, etc.)
  • Regulators or law enforcement when required

8. HOW WE OBTAIN YOUR CONSENT

Where consent is required for processing, it is gathered when you provide personal data or by contacting us directly (see Section 3 – How to Contact Us).

9. THIRD-PARTY LINKS

Our Platform may contain links to third-party websites and services. This Privacy Notice does not apply to:

  • Data collected by third parties
  • Use of third-party websites/services (even if accessed through our Platform)

We encourage you to review the privacy policies of those parties directly.

10. TRANSFERS OUTSIDE THE UK AND THE EUROPEAN ECONOMIC AREA (“EEA”)

We may transfer personal data to countries outside the UK or EEA. These countries may not offer the same level of protection.

When we transfer your personal data, we ensure:

  • A lawful basis for the transfer
  • Appropriate safeguards are in place
  • Security measures are applied in line with data protection law

11. HOW LONG WE KEEP YOUR PERSONAL DATA

  • We may retain personal data for up to six years for Service-related matters
  • Data used for short-term purposes (e.g. promotions) is deleted after use
  • If you opt out of marketing, your email is kept on a suppression list indefinitely

12. CONFIDENTIALITY AND SECURITY OF YOUR PERSONAL DATA

We apply security policies and technical measures to protect your data from:

  • Unauthorised access
  • Improper use or disclosure
  • Unlawful destruction or accidental loss

All personnel and data processors handling your data are bound by confidentiality obligations.

13. YOUR RIGHTS AS A DATA SUBJECT

You have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccuracies in your data
  • Erasure: Request deletion of your data in certain cases
  • Restrict Processing: Block or suppress further use
  • Data Portability: Receive your data in a machine-readable format
  • Object: Oppose processing, especially for marketing
  • Automated decision-making: Request human review if decisions significantly affect you
  • Withdraw consent: At any time (where processing is based on consent)
  • Complain: Contact the Information Commissioner’s Office (ICO) via https://ico.org.uk