Skip to content
Legal

Privacy Policy

This Privacy Policy applies to

1. Data Protection at a Glance

General Information

The following notes provide a simple overview of what happens to your personal data when you visit this website. Personal data is any data with which you can be personally identified. For detailed information on data protection, please refer to our privacy policy listed below this text.

Data collection on this website

Who is responsible for data collection on this website?

Data processing on this website is carried out by the website operator. You can find their contact details in the „Notice Regarding the Controller“ section of this privacy policy.

How do we collect your data?

Your data is collected, in part, by you providing it to us. This can include, for example, data that you enter into a contact form.

Other data is automatically collected by our IT systems or with your consent when you visit the website. This primarily includes technical data (e.g., internet browser, operating system, or time of page access). The collection of this data occurs automatically as soon as you access this website.

What do we use your data for?

Some of the data is collected to ensure the error-free provision of the website. Other data may be used to analyze your user behavior. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders, or other order inquiries.

What rights do you have regarding your data?

You have the right to receive information free of charge at any time about the origin, recipients, and purpose of your stored personal data. You also have the right to request the correction or deletion of this data. If you have given your consent for data processing, you can revoke this consent at any time with future effect. Furthermore, you have the right to request the restriction of the processing of your personal data under certain circumstances. You also have the right to lodge a complaint with the competent supervisory authority.

Please feel free to contact us at any time regarding this matter or any other questions you may have about data protection.

Analysis tools and third-party tools

When you visit this website, your browsing behavior may be analyzed for statistical purposes. This is primarily done using so-called analytics tools.

You can find detailed information about these analytics programs in the following privacy policy.

2. Hosting

We host our website's content with the following provider:

All-Inkl

Provider is ALL-INKL.COM - Neue Medien Münnich, Owner René Münnich, Hauptstraße 68, 02742 Friedersdorf (hereinafter referred to as All-Inkl). For details, please refer to the All-Inkl privacy policy: https://all-inkl.com/datenschutzinformationen/.

The use of All-Inkl is based on Art. 6 para. 1 lit. f GDPR. We have a legitimate interest in the most reliable presentation of our website possible. If the corresponding consent has been requested, the processing is carried out exclusively on the basis of Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TDDDG, insofar as the consent includes the storage of cookies or access to information in the user's terminal device (e.g., device fingerprinting) within the meaning of the TDDDG. Consent can be revoked at any time.

Order processing

We have entered into a Data Processing Agreement (DPA) for the use of the service mentioned above. This is a legally required data protection contract that ensures it will only process the personal data of our website visitors according to our instructions and in compliance with the GDPR.

3. General Information and Mandatory Disclosures

Data Privacy

The operators of these pages take the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with the statutory data protection regulations and this privacy policy.

By using this website, various personal data are collected. Personal data is data that can be used to personally identify you. This privacy policy explains what data we collect and how we use it. It also explains how and for what purpose this happens.

We would like to point out that data transmission on the internet (e.g., in email communication) may be subject to security vulnerabilities. It is not possible to guarantee complete protection of data against access by third parties.

Information on the responsible party

The entity responsible for data processing on this website is:

Both Music Syndicate GmbH
Bismarck St. 142
47057 Duisburg

Phone: +49 176 64190757
E-Mail: my@bms-music

The controller is the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data (e.g., names, email addresses, etc.).

Storage duration

Unless a more specific storage period is mentioned within this privacy policy, your personal data will remain with us until the purpose for data processing ceases to apply. If you assert a legitimate request for deletion or revoke consent for data processing, your data will be deleted, provided we have no other legally permissible reasons for storing your personal data (e.g., tax or commercial retention periods); in the latter case, deletion will occur after these reasons no longer apply.

General information on the legal basis for data processing on this website

If you have consented to data processing, we will process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, if special categories of data are processed according to Art. 9(1) GDPR. In the event of express consent to the transfer of personal data to third countries, data processing will also be carried out on the basis of Art. 49(1)(a) GDPR. If you have consented to the storage of cookies or to accessing information on your terminal device (e.g., via device fingerprinting), data processing will additionally be carried out on the basis of § 25(1) TDDDG. The consent can be revoked at any time. If your data is required for the performance of a contract or for the implementation of pre-contractual measures, we will process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, we will process your data if it is required for the fulfillment of a legal obligation on the basis of Art. 6(1)(c) GDPR. Data processing may also be carried out on the basis of our legitimate interest according to Art. 6(1)(f) GDPR. The specific legal bases applicable in each individual case are explained in the following paragraphs of this data protection declaration.

Notice regarding data transfer to third countries not considered safe from a data protection perspective, as well as data transfer to US companies not DPF-certified

Among other things, we use tools from companies based in third countries that are not considered data protection-safe, as well as US tools whose providers are not certified under the EU-US Data Privacy Framework (DPF). When these tools are active, your personal data may be transferred to and processed in these countries. We point out that a level of data protection comparable to that of the EU cannot be guaranteed in third countries that are not considered data protection-safe.

We would like to point out that the USA, as a safe third country, generally has a comparable level of data protection to the EU. Data transfer to the USA is therefore permissible if the recipient has a certification under the „EU-US Data Privacy Framework“ (DPF) or has suitable additional guarantees. Information on transfers to third countries, including data recipients, can be found in this privacy policy.

Recipients of personal data

As part of our business operations, we collaborate with various external entities. This sometimes requires the transfer of personal data to these external entities. We only disclose personal data to external entities when it is necessary for the performance of a contract, when we are legally obligated to do so (e.g., disclosure of data to tax authorities), when we have a legitimate interest in disclosure pursuant to Art. 6 para. 1 lit. f GDPR, or when another legal basis permits the data transfer. When using order processors, we only transfer our customers' personal data on the basis of a valid order processing agreement. In the case of joint processing, a joint processing agreement is concluded.

Withdrawal of Your Consent to Data Processing

Many data processing operations are only possible with your explicit consent. You may withdraw any consent you have already given at any time. The lawfulness of the data processing carried out prior to the withdrawal remains unaffected by the withdrawal.

Right to object to data collection in specific cases and to direct marketing (Art. 21 GDPR)

IF DATA PROCESSING IS BASED ON ART. 6(1)( E OR F OF THE GDPR, YOU HAVE THE RIGHT AT ANY TIME, FOR REASONS RELATED TO YOUR SPECIFIC SITUATION, to object to the processing of your personal data; this also applies to profiling based on these provisions. THE SPECIFIC LEGAL BASIS ON WHICH PROCESSING IS BASED CAN BE FOUND IN THIS PRIVACY POLICY. IF YOU OBJECT, WE WILL NO LONGER PROCESS YOUR PERSONAL DATA, UNLESS WE CAN DEMONSTRATE COMPELLING LEGITIMATE GROUNDS FOR THE PROCESSING THAT OUTWEIGH YOUR INTERESTS, RIGHTS, AND FREEDOMS, OR THE PROCESSING IS NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR DEFENSE OF LEGAL CLAIMS (OBJECTION PURSUANT TO ART. 21(1) OF THE GDPR).

IF YOUR PERSONAL DATA IS PROCESSED FOR DIRECT MARKETING PURPOSES, YOU HAVE THE RIGHT TO OBJECT AT ANY TIME TO THE PROCESSING OF YOUR PERSONAL DATA FOR SUCH MARKETING, INCLUDING PROFILING, INSOFAR AS IT IS RELATED TO SUCH DIRECT MARKETING. IF YOU OBJECT, YOUR PERSONAL DATA WILL NO LONGER BE PROCESSED FOR DIRECT MARKETING PURPOSES (OBJECTION PURSUANT TO ART. 21 (2) GDPR).

Right to File a Complaint with the Competent Supervisory Authority

In the event of violations of the GDPR, data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, their place of work, or the location of the alleged violation. The right to lodge a complaint is without prejudice to any other administrative or judicial remedies.

Right to Data Portability

You have the right to have data that we process automatically—based on your consent or in fulfillment of a contract—provided to you or to a third party in a commonly used, machine-readable format. If you request the direct transfer of the data to another data controller, this will be done only to the extent that it is technically feasible.

Information, correction, and deletion

You have the right at any time to free access to your stored personal data, its origin and recipients, and the purpose of data processing, and if applicable, a right to correction or deletion of this data, in accordance with applicable legal provisions. You can contact us at any time for this and for further questions on the subject of personal data.

Right to restrict processing

You have the right to request the restriction of the processing of your personal data. You can contact us at any time for this purpose. The right to restrict processing exists in the following cases:

  • If you dispute the accuracy of your personal data stored with us, we generally need time to verify it. During the verification period, you have the right to request the restriction of the processing of your personal data.
  • If the processing of your personal data was/is unlawful, you can request the restriction of data processing instead of erasure.
  • If we no longer need your personal data, but you require it for the establishment, exercise, or defense of legal claims, you have the right to request a restriction of the processing of your personal data instead of erasure.
  • If you have lodged an objection under Art. 21(1) GDPR, a balancing of your interests and ours must be carried out. As long as it has not yet been determined whose interests prevail, you have the right to demand the restriction of the processing of your personal data.

If you have restricted the processing of your personal data, these data may – apart from their storage – only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of an important public interest of the European Union or of a Member State.

SSL/TLS encryption

For security reasons and to protect the transmission of confidential content, such as orders or inquiries that you send to us as the site operator, this page uses SSL or TLS encryption. You can recognize an encrypted connection by the fact that the browser's address bar changes from „http://“ to „https://“ and by the padlock symbol in your browser bar.

When SSL or TLS encryption is enabled, the data you transmit to us cannot be read by third parties.

4. Data Collection on this Website

Server log files

The provider of the pages automatically collects and stores information in so-called server log files, which your browser automatically transmits to us. These are:

  • Browser type and browser version
  • Operating system used
  • Referrer URL
  • Hostname of accessing computer
  • Server request time
  • IP Address

This data will not be merged with other data sources.

The collection of this data is based on Art. 6(1)(f) GDPR. The website operator has a legitimate interest in the technically flawless presentation and optimization of its website – server log files must be collected for this purpose.

Contact Form

If you send us inquiries via the contact form, your details from the inquiry form, including the contact information you provide there, will be stored by us for the purpose of processing your inquiry and in case of follow-up questions. We will not pass on this data without your consent.

The processing of this data is based on Article 6(1)(b) GDPR, provided that your request relates to the fulfillment of a contract or is necessary for the performance of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), provided it has been requested; consent can be revoked at any time.

The data you enter in the contact form will remain with us until you ask us to delete it, revoke your consent to storage, or the purpose for data storage ceases to apply (e.g., after your request has been processed). Mandatory legal provisions, particularly retention periods, remain unaffected.

Inquiry by email, phone, or fax

If you contact us by email, phone, or fax, your inquiry, including all personal data arising from it (name, inquiry), will be stored and processed by us for the purpose of handling your request. We will not disclose this data without your consent.

The processing of this data is based on Article 6(1)(b) GDPR, provided that your request relates to the fulfillment of a contract or is necessary for the performance of pre-contractual measures. In all other cases, processing is based on our legitimate interest in the effective handling of inquiries addressed to us (Article 6(1)(f) GDPR) or on your consent (Article 6(1)(a) GDPR), provided it has been requested; consent can be revoked at any time.

The data you send us via contact inquiries will remain with us until you request its deletion, revoke your consent for storage, or when the purpose for data storage ceases to apply (e.g., after your request has been fully processed). Mandatory legal provisions, especially statutory retention periods, remain unaffected.

Communication via WhatsApp

We use the instant messaging service WhatsApp, among other things, for communication with our customers and other third parties. The provider is WhatsApp Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Communication takes place via end-to-end encryption (peer-to-peer), which prevents WhatsApp or any other third party from accessing the content of the communication. However, WhatsApp does gain access to metadata generated during the communication process (e.g., sender, recipient, and time). We also point out that WhatsApp, according to its own statements, shares personal data of its users with its parent company Meta, which is based in the USA. Further details on data processing can be found in WhatsApp's privacy policy at: https://www.whatsapp.com/legal/#privacy-policy.

The use of WhatsApp is based on our legitimate interest in the fastest and most effective communication possible with customers, prospects, and other business and contractual partners (Art. 6 Para. 1 lit. f GDPR). If appropriate consent has been requested, data processing will be carried out exclusively on the basis of that consent; this consent can be revoked at any time with effect for the future.

The communication content exchanged between you and us.

The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the US. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/7735.

We use the „WhatsApp Business“ version of WhatsApp.

Data transfers to the US are based on the standard contractual clauses of the EU Commission. Find details here: https://www.whatsapp.com/legal/business-data-transfer-addendum.

We have configured our WhatsApp accounts so that they do not automatically sync data with the address book on the smartphones in use.

We have concluded a contract for order processing (AVV) with the above-mentioned provider.

5. Analysis Tools and Advertising

TikTok Pixel

We have integrated the TikTok Pixel on this website. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (hereinafter TikTok).

Using the TikTok Pixel, we can show interest-based advertising on TikTok (TikTok Ads) to website visitors who have viewed our offers. At the same time, the TikTok Pixel allows us to determine the effectiveness of our advertising on TikTok. This enables the performance of TikTok ads to be evaluated for statistical and market research purposes and optimized for future advertising campaigns. Various usage data are processed, such as IP address, page views, duration of stay, operating systems used, and the user's origin, information about the ad a person clicked on TikTok, or an event that was triggered (timestamp). This data is aggregated into a user ID and assigned to the respective end device of the website visitor.

Use of this service is based on your consent according to Art. 6 para. 1 lit. a GDPR and § 25 para. 1 TTDSG. Your consent can be revoked at any time.

Data transfers to third countries are based on the EU Commission's Standard Contractual Clauses. Details can be found here: https://www.tiktok.com/legal/page/eea/privacy-policy/de-DE and https://ads.tiktok.com/i18n/official/policy/controller-to-controller.

Order processing

We have entered into a Data Processing Agreement (DPA) for the use of the service mentioned above. This is a legally required data protection contract that ensures it will only process the personal data of our website visitors according to our instructions and in compliance with the GDPR.

6. eCommerce and Payment Providers

Processing customer and contract data

We collect, process, and use personal customer and contract data to establish, define the terms of, and modify our contractual relationships. We collect, process, and use personal data regarding the use of this website (usage data) only to the extent necessary to enable the user to use the service or to bill the user. The legal basis for this is Article 6(1)(b) of the GDPR.

The customer data collected will be deleted after the order is completed or the business relationship is terminated, and after any applicable statutory retention periods have expired. Statutory retention periods remain unaffected.

7. Audio and Video Conferencing

Data processing

Among other things, we use online conference tools for communication with our customers. The specific tools we use are listed below. When you communicate with us via video or audio conference over the internet, your personal data will be collected and processed by us and the provider of the respective conference tool.

The conference tools collect all data that you provide/use for the tools (email address and/or your phone number). Furthermore, the conference tools process the duration of the conference, the start and end time of participation in the conference, the number of participants, and other „contextual information“ related to the communication process (metadata).

Furthermore, the tool provider processes all technical data necessary for the execution of online communication. This includes, in particular, IP addresses, MAC addresses, device IDs, device type, operating system type and version, client version, camera type, microphone or speaker, and connection type.

If content is exchanged, uploaded, or otherwise provided within the tool, it will also be stored on the servers of the tool provider. Such content includes, in particular, cloud recordings, chat/instant messages, voicemails, uploaded photos and videos, files, whiteboards, and other information shared during the use of the service.

Please note that we do not have full control over the data processing operations of the tools used. Our capabilities are primarily determined by the corporate policies of the respective provider. For further information on data processing by the conference tools, please refer to the privacy policies of the respective tools used, which we have listed below this text.

Purpose and Legal Basis

The conference tools are used to communicate with prospective or existing contractual partners or to offer specific services to our customers (Art. 6(1)(b) GDPR). Furthermore, the use of the tools serves to generally simplify and accelerate communication with us or our company (legitimate interest within the meaning of Art. 6(1)(f) GDPR). To the extent consent has been requested, the use of the relevant tools is based on this consent; consent can be revoked at any time with future effect.

Storage duration

The data we directly collect via video and conference tools is deleted by our systems as soon as you request its deletion, withdraw your consent to storage, or the purpose for data storage no longer applies. Stored cookies remain on your end device until you delete them. Mandatory legal retention periods remain unaffected.

We have no influence on the storage duration of your data, which is stored by the operators of the conference tools for their own purposes. For details, please inquire directly with the operators of the conference tools.

Conference Tools Used

We use the following conference tools:

Zoom

We use Zoom. The provider of this service is Zoom Communications Inc., San Jose, 55 Almaden Boulevard, 6th Floor, San Jose, CA 95113, USA. For details on data processing, please refer to Zoom's privacy policy: https://www.zoom.com/de/trust/privacy/privacy-statement/.

Data transfers to the US are based on the standard contractual clauses of the EU Commission. Find details here: https://www.zoom.com/de/trust/privacy/privacy-statement/.

The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the US. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5728.

Order processing

We have entered into a Data Processing Agreement (DPA) for the use of the service mentioned above. This is a legally required data protection contract that ensures it will only process the personal data of our website visitors according to our instructions and in compliance with the GDPR.

Microsoft Teams

We use Microsoft Teams. The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. For details on data processing, please refer to the Microsoft Teams Privacy Statement: https://privacy.microsoft.com/de-de/privacystatement.

The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the US. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/6474.

Order processing

We have entered into a Data Processing Agreement (DPA) for the use of the service mentioned above. This is a legally required data protection contract that ensures it will only process the personal data of our website visitors according to our instructions and in compliance with the GDPR.

Our social media presence

This privacy policy applies to the following social media presences

Data processing by social networks

We maintain publicly accessible profiles on social networks. You can find the social networks we use individually below.

Social networks like Facebook, X, etc. can usually analyze your user behavior comprehensively when you visit their website or a website with integrated social media content (e.g., like buttons or advertising banners). Visiting our social media presences triggers numerous data-privacy-related processing operations. Specifically:

If you are logged into your social media account and visit our social media presence, the operator of the social media portal can associate this visit with your user account. However, your personal data can also be collected under certain circumstances even if you are not logged in or do not have an account with the respective social media portal. In this case, this data collection occurs, for example, via cookies that are stored on your end device or by capturing your IP address.

Using the data collected in this way, social media portal operators can create user profiles that store your preferences and interests. This allows interest-based advertising to be displayed both within and outside of the respective social media presence. If you have an account with the respective social network, the interest-based advertising can be displayed on all devices on which you are logged in or have been logged in.

Please also note that we cannot track all processing activities on the social media portals. Depending on the provider, additional processing operations may be carried out by the operators of the social media portals. Please refer to the terms of use and data protection regulations of the respective social media portals for details.

Legal basis

Our social media presence is intended to ensure the most comprehensive presence on the internet possible. This constitutes a legitimate interest within the meaning of Art. 6(1)(f) GDPR. The analysis processes initiated by social networks are possibly based on different legal grounds, which are to be indicated by the operators of the social networks (e.g., consent within the meaning of Art. 6(1)(a) GDPR).

Responsible Party and Assertion of Rights

When you visit one of our social media presences (e.g., Facebook), we are jointly responsible with the social media platform operator for the data processing operations triggered by this visit. You can generally assert your rights (access, rectification, erasure, restriction of processing, data portability, and complaint) both towards us and towards the operator of the respective social media portal (e.g., towards Facebook).

Please note that despite our joint responsibility with the social media portal operators, we do not have full control over the data processing operations of the social media portals. Our options are largely dependent on the company policy of the respective provider.

Storage duration

The data we collect directly from you through our social media presence will be deleted by our systems as soon as you request deletion, revoke your consent for storage, or the purpose for data storage no longer applies. Stored cookies remain on your end device until you delete them. Mandatory legal provisions – including retention periods – remain unaffected.

We have no control over how long your data is stored by social media platform operators for their own purposes. For more details, please contact the social media platform operators directly (e.g., in their privacy policies; see below).

Your Rights

You have the right to receive free information at any time about the origin, recipients, and purpose of your stored personal data. You also have the right to object, data portability, and the right to lodge a complaint with.

Social networks in detail

Instagram

We have a profile on Instagram. The provider of this service is Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland.

Data transfers to the US are based on the standard contractual clauses of the EU Commission. Find details here: https://www.facebook.com/legal/EU_data_transfer_addendum and https://de-de.facebook.com/help/566994660333381.

Details on how they handle your personal data can be found in Instagram's Privacy Policy: https://privacycenter.instagram.com/policy/.

The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the US. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/4452

YouTube

We have a profile on YouTube. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. You can find details on how they handle your personal data in YouTube's privacy policy: https://policies.google.com/privacy?hl=de.

The company is certified under the „EU-US Data Privacy Framework“ (DPF). The DPF is an agreement between the European Union and the United States designed to ensure compliance with European data protection standards for data processing in the US. Any company certified under the DPF commits to adhering to these data protection standards. Further information on this can be obtained from the provider at the following link: https://www.dataprivacyframework.gov/participant/5780

TikTok

We have a profile on TikTok. The provider is TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. For details on how they handle your personal data, please refer to TikTok's privacy policy: https://www.tiktok.com/legal/privacy-policy?lang=de.

Data transfers to non-secure third countries are based on the European Commission's Standard Contractual Clauses. More details can be found here: https://www.tiktok.com/legal/privacy-policy?lang=de.

As of May 28, 2026