ToplineBase
BrowseBriefsOrigin™
Log InGet Started

0:000:00
0:000:00
    Back to Home

    Privacy Policy

    Last updated: January 22, 2026

    This Privacy Policy explains how ToplineBase collects, uses, shares, and protects your personal data when you use our platform. We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

    1. Data Controller

    The data controller responsible for your personal data is:

    ToplineBase

    Chamber of Commerce (KvK): 87084562

    Country of establishment: The Netherlands

    Email: support@toplinebase.com

    ToplineBase is the data controller as defined under Article 4(7) of the GDPR, meaning we determine the purposes and means of processing your personal data.

    2. Personal Data We Collect

    2.1 Data You Provide Directly

    CategoryExamplesLegal Basis (Art. 6 GDPR)
    Account DataName, email, password, profile pictureContractual necessity (Art. 6(1)(b))
    Profile DataBio, location, social links, portfolioContractual necessity (Art. 6(1)(b))
    Identity Verification (KYC)Government ID, selfie, date of birthLegal obligation (Art. 6(1)(c))
    Payment DataBank account (IBAN), PayPal emailContractual necessity (Art. 6(1)(b))
    Audio ContentVocal recordings, stems, metadataContractual necessity (Art. 6(1)(b))
    CommunicationsSupport requests, feedback, messagesLegitimate interest (Art. 6(1)(f))

    2.2 Data Collected Automatically

    CategoryExamplesLegal Basis (Art. 6 GDPR)
    Device DataIP address, browser type, operating systemLegitimate interest (Art. 6(1)(f))
    Usage DataPages visited, features used, session durationLegitimate interest (Art. 6(1)(f))
    Transaction DataPurchase history, payout recordsContractual necessity / Legal obligation

    2.3 Special Category: Audio Data

    Important: Vocal recordings may contain biometric-adjacent data (voice characteristics). We process this data solely for the functional purpose of:

    • Hosting and streaming your content on the Platform
    • AI authenticity detection (Origin™ system)
    • Generating audio previews and watermarked samples

    We do not: Use your audio to train AI models, sell your audio data, or process voice biometrics for identification purposes.

    3. How We Use Your Personal Data

    3.1 Service Delivery

    Legal Basis: Contractual necessity (Art. 6(1)(b))

    • Create and manage your account
    • Process transactions and distribute payouts
    • Facilitate communication between users
    • Provide customer support

    3.2 AI Detection (Origin™)

    Legal Basis: Contractual necessity (Art. 6(1)(b)) & Legitimate interest (Art. 6(1)(f))

    • Analyze uploaded audio for AI-generated content
    • Extract spectral features for authenticity verification
    • Compare against trained detection models

    Note: Audio analysis data is processed temporarily and not stored beyond the detection result.

    3.3 Legal Compliance

    Legal Basis: Legal obligation (Art. 6(1)(c))

    • Identity verification (KYC/AML requirements)
    • Tax reporting and invoicing
    • Responding to legal requests

    3.4 Platform Security & Fraud Prevention

    Legal Basis: Legitimate interest (Art. 6(1)(f))

    • Detect and prevent fraudulent activity
    • Monitor for Terms of Service violations
    • Protect the rights and safety of users

    3.5 Marketing Communications

    Legal Basis: Consent (Art. 6(1)(a))

    • Newsletter and product updates
    • Promotional offers and campaigns
    • Feature announcements

    You can withdraw consent at any time via your account settings or by clicking "unsubscribe" in any email.

    3.6 Platform Improvement

    Legal Basis: Legitimate interest (Art. 6(1)(f))

    • Analyze usage patterns to improve features
    • Conduct research and analytics
    • Test new features and functionality

    4. Third-Party Data Processors

    We share your personal data with the following categories of third-party processors:

    Stripe, Inc. (Payment Processing)

    Data shared: Name, email, bank account details, transaction data, identity verification documents

    Purpose: Payment processing, identity verification (KYC), payout distribution

    Role: Stripe acts as an independent data controller for payment services

    Privacy Policy: stripe.com/privacy

    Note: ToplineBase does not store full credit card numbers or complete bank account details. This data is processed and stored directly by Stripe.

    Supabase, Inc. (Database & Authentication)

    Data shared: Account data, profile data, content metadata, transaction records

    Purpose: Database hosting, user authentication, file storage

    Privacy Policy: supabase.com/privacy

    Brevo (Email Services)

    Data shared: Email address, name, email content

    Purpose: Transactional emails, marketing communications

    Privacy Policy: brevo.com/legal/privacypolicy

    Vercel, Inc. (Hosting)

    Data shared: IP address, device data, usage data

    Purpose: Website hosting, content delivery, performance optimization

    Privacy Policy: vercel.com/legal/privacy-policy

    4.1 Other Disclosures

    We may also share your data:

    • With other users: Profile information and content as part of marketplace transactions
    • Legal requirements: When required by law, court order, or government request
    • Rights protection: To enforce our Terms of Service or protect our legal rights
    • Business transfers: In connection with a merger, acquisition, or sale of assets

    5. International Data Transfers

    Some of our third-party processors are located outside the European Economic Area (EEA), including in the United States. When we transfer your data outside the EEA, we ensure appropriate safeguards are in place:

    • EU-US Data Privacy Framework: Transfers to US companies certified under the Framework
    • Standard Contractual Clauses (SCCs): EU-approved contractual safeguards
    • Adequacy Decisions: Transfers to countries deemed adequate by the European Commission

    You may request a copy of the safeguards in place by contacting support@toplinebase.com.

    6. Data Retention

    We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

    Data TypeRetention Period
    Account dataDuration of account + 2 years after deletion
    Transaction records7 years (Dutch tax law requirement)
    Uploaded contentUntil you delete it or close your account
    AI detection analysisDetection result stored; raw analysis data deleted after processing
    Identity verification (KYC)Processed by Stripe; we store verification status only
    Marketing preferencesUntil you withdraw consent
    Support communications3 years after last interaction

    After the retention period, data is securely deleted or anonymized for statistical purposes.

    7. Cookies & Tracking Technologies

    7.1 What Are Cookies?

    Cookies are small text files stored on your device when you visit a website. They help us remember your preferences and improve your experience.

    7.2 Types of Cookies We Use

    CategoryPurposeLegal Basis
    Strictly NecessaryAuthentication, security, session managementLegitimate interest (exempt from consent)
    FunctionalPreferences, language, audio player stateConsent
    AnalyticsUsage statistics, performance monitoringConsent
    MarketingPersonalized ads, remarketing (if applicable)Consent

    7.3 Managing Cookies

    You can manage cookie preferences through:

    • Cookie banner: Select your preferences when you first visit the site
    • Browser settings: Block or delete cookies in your browser
    • Opt-out tools: Use industry opt-out tools like youronlinechoices.eu

    Note: Disabling strictly necessary cookies may prevent the Platform from functioning properly.

    8. Your Rights Under GDPR

    Under the General Data Protection Regulation, you have the following rights regarding your personal data:

    Right of Access (Art. 15)

    Request a copy of the personal data we hold about you.

    Right to Rectification (Art. 16)

    Request correction of inaccurate or incomplete personal data.

    Right to Erasure / "Right to be Forgotten" (Art. 17)

    Request deletion of your personal data (subject to legal retention requirements).

    Right to Restriction of Processing (Art. 18)

    Request that we limit how we use your data while a complaint or request is being resolved.

    Right to Data Portability (Art. 20)

    Request your data in a structured, machine-readable format for transfer to another service.

    Right to Object (Art. 21)

    Object to processing based on legitimate interest or for direct marketing purposes.

    Right to Withdraw Consent (Art. 7(3))

    Withdraw consent at any time where processing is based on your consent.

    Right to Not Be Subject to Automated Decisions (Art. 22)

    Not be subject to decisions based solely on automated processing that significantly affect you.

    8.1 How to Exercise Your Rights

    To exercise any of these rights, contact us at:

    • Email: support@toplinebase.com
    • Subject line: "GDPR Request - [Your Right]"

    We will respond to your request within 30 days (extendable by 60 days for complex requests). We may ask for verification of your identity before processing your request.

    8.2 Right to Lodge a Complaint

    If you believe we have violated your data protection rights, you have the right to lodge a complaint with your local Data Protection Authority.

    For the Netherlands, this is the Autoriteit Persoonsgegevens (AP):

    Autoriteit Persoonsgegevens

    Hoge Nieuwstraat 8

    2514 EL Den Haag

    Netherlands

    Website: autoriteitpersoonsgegevens.nl

    9. Data Security

    We implement appropriate technical and organizational measures to protect your personal data, including:

    • Encryption: Data encrypted in transit (TLS/SSL) and at rest
    • Access controls: Role-based access, multi-factor authentication for admin systems
    • Monitoring: Security monitoring and intrusion detection
    • Vendor security: Due diligence on third-party processor security practices
    • Regular audits: Periodic security assessments and updates

    While we strive to protect your data, no method of transmission or storage is 100% secure. If you become aware of any security incident, please contact us immediately at support@toplinebase.com.

    10. Children's Privacy

    ToplineBase is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at support@toplinebase.com, and we will delete such information.

    11. Changes to This Policy

    We may update this Privacy Policy from time to time. Material changes will be communicated via:

    • Email notification to registered users
    • Prominent notice on the Platform
    • Update to the "Last updated" date at the top of this Policy

    Your continued use of the Platform after changes take effect constitutes acceptance of the updated Policy.

    12. Contact Us

    For questions, concerns, or requests regarding this Privacy Policy or our data practices:

    ToplineBase

    KvK: 87084562

    Email: support@toplinebase.com

    ToplineBase

    The premium marketplace for exclusive toplines. Connect songwriters with producers worldwide.

    © 2026 ToplineBase. All rights reserved.

    Product

    • Browse Marketplace
    • Pricing
    • Stories
    • Contact

    Resources

    • Documentation
    • Origin™ AI Detection

    Legal

    • Terms of Service
    • Privacy Policy
    • License Agreement

    Company

    • About
    • Careers