At Divzoon (“Divzoon”, “we”, “us”, or “our”), we are committed to safeguarding your privacy and ensuring the integrity of your personal and creative data. This Privacy Policy outlines our data governance practices when you interact with our websites (wearediv.com and divzoon.com), applications, application programming interfaces (APIs), digital distribution pipelines, AI Bundles, White Label solutions, and related services (collectively, the “Service”).
Please read this policy carefully. By accessing, registering for, or utilizing the Service, you acknowledge the collection, use, and sharing practices described herein. Where you interact with a branded platform powered by Divzoon’s White Label tenancy, please note that the tenant organization acts as the independent Data Controller for your relationship, and Divzoon processes your data as a Data Processor pursuant to our contractual agreements with that tenant.
1. Information We Collect
We collect personal data that you provide directly, data generated automatically through platform telemetry, and data received from authorized third-party partners. We organize the categories of collected information as follows:
A. Personal Data You Provide to Us:
• Account & Profile Information: When registering an account or updating your profile, we collect your legal name, artist or stage name, email address, hashed authentication credentials, account category (such as artist, record label, or creator), and profile images. If you choose to authenticate via single sign-on providers (such as Google OAuth), we receive your basic profile identifiers and verified email address as permitted by your third-party account authorizations.
• Identity Verification & Compliance Data: To satisfy statutory anti-money laundering (AML), sanctions screening, and intellectual property protection regulations, we may collect government-issued identification documents (such as national identity cards or passports). Document images captured through our verification workflows are encrypted upon receipt and stored in secured environments strictly for identity confirmation and statutory compliance. We do not use continuous facial recognition or biometric surveillance systems.
• Catalog Assets & Release Metadata: We collect audio master files, artwork assets, release titles, track listings, featured contributors, genres, release dates, lyrics, copyright notices, and international sound recording identifiers, including International Standard Recording Codes (ISRC) and Universal Product Codes (UPC).
• Publishing & Rights Documentation: Songwriter split agreements, performance rights organization (PRO) affiliations and membership identifiers, International Standard Musical Work Codes (ISWC), publisher designations, and synchronization licensing documentation necessary to protect and administer musical works.
• Financial, Billing & Tax Information: Payout routing information (including international bank account numbers or digital payment addresses) necessary to disburse catalog royalties. For platform subscriptions, transaction billing details and statutory tax forms (such as IRS Forms W-8BEN or W-9) are collected to ensure legal tax reporting. All payment card transactions are processed directly by our PCI-DSS certified payment processors; Divzoon never stores or has access to your full credit or debit card numbers.
• AI Inputs & Creative Prompts: When utilizing AI Bundles or our creative AI tools, we process your submitted input text, prompts, configuration settings, and associated token telemetry to generate the requested output.
• Commercial & Partnership Inquiries: Contact information, organization details, and business correspondence submitted through our enterprise contact channels, partnership applications, or customer support ticketing systems.
B. Personal Data Collected Automatically:
• Device & Telemetry Data: When accessing the Service, our servers log technical telemetry necessary to maintain service reliability, security, and performance. This includes IP addresses, browser specifications, operating system details, device type, approximate regional location, access timestamps, and error diagnostics.
• Cookies & Analytics: We use strictly necessary cookies, session tokens, and privacy-preserving first-party telemetry to authenticate sessions, maintain platform security, preserve user preferences, and measure system operational performance. Subject to your explicit prior consent, we also utilize Google Analytics 4 (provided by Google LLC) to analyze aggregate site traffic and interaction trends. Google Analytics is integrated with Google Consent Mode v2 and IP anonymization, ensuring no measurement cookies or personal identifiers are stored without your affirmative opt-in. You may update or withdraw your consent at any time through our or consult our Cookie Policy.
C. Information We Do Not Collect:
Divzoon does not collect sensitive personal data concerning racial or ethnic origin, political affiliations, philosophical beliefs, trade union memberships, genetic data, or health records. Furthermore, the Service is strictly intended for individuals aged 18 and older; we do not knowingly solicit or maintain data from minors.
2. Legal Basis for Processing
Under applicable global privacy regulations, including the General Data Protection Regulation (GDPR), we process your personal data under the following recognized legal bases:
• Performance of a Contract: Processing necessary to deliver the services you request, including ingesting and delivering musical catalogs to digital service providers, calculating and remitting royalties, hosting podcasts, executing AI gateway requests, providing customer support, and maintaining platform uptime.
• Compliance with Legal Obligations: Processing required to adhere to applicable laws and regulatory directives, including identity verification (KYC/AML compliance), statutory accounting requirements, tax filings, and lawful governmental or judicial requests.
• Legitimate Interests: Processing necessary to advance our legitimate operational interests, provided such interests are balanced against your fundamental rights. This includes defending against platform abuse, preventing artificial streaming fraud, auditing system security, issuing critical login notifications, and optimizing platform performance.
• Consent: Where required by law, we rely on your explicit consent for specific non-essential activities, such as optional analytics cookies or specialized notifications. You maintain the right to revoke consent at any time without retroactive effect.
3. How We Use Personal Data
We use collected data solely for legitimate operational, contractual, and technical purposes:
• Catalog Distribution & Administration: Ingesting digital audio masters, formatting release metadata according to industry delivery specifications, delivering releases to worldwide streaming platforms, and calculating automated royalty disbursements.
• AI Zero-Training Commitment: Divzoon strictly guarantees that your creative assets, audio recordings, musical compositions, lyrics, prompts, and generated outputs are never used to train or fine-tune artificial intelligence models. All AI-assisted features are provisioned through enterprise agreements with leading AI model providers that contractually prohibit using customer data for model training or evaluation. Your intellectual property remains exclusively your own.
• Platform Security & Fraud Prevention: Authenticating account access, verifying account ownership, detecting automated bot traffic, preventing unauthorized access, and identifying fraudulent or artificial streaming behavior.
• Service Communications: Providing critical transactional notices, release delivery confirmations, payout summaries, security alerts, and responding to customer support inquiries.
4. How We Share Personal Data
Divzoon does not sell your personal data. We do not disclose personal information to third parties for cross-context behavioral advertising. We share data only under strictly defined operational conditions:
• Digital Service Providers (DSPs): To distribute your music globally, catalog metadata (including artist names, release titles, cover art, contributor credits, and track metadata) and audio recordings are transmitted to digital streaming services, download stores, and social video platforms worldwide. Once published, release metadata is publicly displayed on destination stores to facilitate consumer discovery and streaming.
• Rights & Collective Management Organizations: Work registrations, songwriter split data, and international identifiers are shared with performing rights organizations, mechanical licensing agencies, and copyright collection societies to ensure accurate rights attribution and royalty administration.
• Financial & Payment Processors: Subscription billing and payment transactions are facilitated by industry-standard, PCI-DSS certified payment processors (including Stripe, Inc.). Payout instructions are securely routed to licensed banking and payment networks to fulfill royalty disbursements.
• Cloud Infrastructure & Enterprise Sub-processors: We partner with premier cloud and infrastructure providers (such as Amazon Web Services and Cloudflare) for hosting, distributed content delivery networks (CDN), secure data storage, and DDoS defense. All service providers operate under strict Data Processing Agreements requiring equivalent confidentiality and technical safeguards.
• White Label Tenancy Operations: For users accessing services through a branded White Label partner, Divzoon operates as a Data Processor under a formal Data Processing Agreement. The partner tenant functions as the independent Data Controller responsible for establishing their own privacy notices and governing end-user accounts.
• Analytics & Measurement Providers: Subject to your affirmative consent via our Cookie Preferences modal, pseudonymized site navigation telemetry and interaction metrics are processed by Google Analytics (Google LLC). Google acts as an independent processor or controller under EU Standard Contractual Clauses (SCCs) and GDPR Article 28 data processing commitments. You can adjust your consent at any time via our or install the official Google Analytics Opt-Out Browser Add-on.
• Legal Compliance & Protection: We may disclose information if required by applicable law, regulation, valid legal process, or governmental request, or when necessary to protect the legal rights, safety, and security of Divzoon, our users, or the general public.
4.A. AI Chat Logging & Conversation Data
When you interact with Divzoon’s artificial intelligence tools, AI Bundles, prompt interfaces, or automated creative assistants, we systematically log and store conversation telemetry within secured internal databases. This logged data includes transmission timestamps, prompt inputs, submitted contextual text, associated parameters, and generated model outputs.
We process conversation records strictly for service delivery, system reliability, product refinement, quality assurance, feature enhancement, and empirical feedback analysis. Divzoon does not sell your conversation history, nor do we disclose or license prompt telemetry to third parties for commercial advertising, cross-context behavioral marketing, or lead generation.
Conversation records are retained in raw text format for a defined operational window of twelve (12) months from the date of transmission. Following the conclusion of this retention window, records are either irrevocably pseudonymized, de-identified and aggregated into non-attributable performance benchmarks, or permanently expunged from production environments, unless continued preservation is mandated by applicable legal proceedings or statutory retention requirements.
To execute real-time model completions, input text and prompt instructions are transmitted through secured application programming interfaces (APIs) to authorized third-party artificial intelligence model providers. Your interaction with these features may additionally be governed by the service terms, acceptable use policies, and privacy notices of the designated inference provider.
In the event of an operational divergence or irreconcilable inconsistency between this Privacy Policy and the policies of an external AI provider, Divzoon will use commercially reasonable efforts to reconcile such discrepancies and will proactively inform you where any material conflict impacts the security or protection of your personal data. In all processing activities, Divzoon governs your data in accordance with the highest available standard of data protection and privacy safeguards, without asserting unilateral priority over external statutory obligations.
We process AI conversation data under the legal basis of Performance of a Contract (GDPR Article 6(1)(b)) to execute the generative outputs you request, and under Legitimate Interests (GDPR Article 6(1)(f)) to optimize algorithmic accuracy, maintain platform infrastructure, and prevent systemic abuse, balanced proportionately against your fundamental privacy rights. You maintain the statutory right to request access to or erasure of your dialogue history, subject only to narrow legal exemptions where preservation is strictly required to resolve active disputes or satisfy binding regulatory orders.
4.B. Device & Fingerprinting Data
When accessing or authenticating to the Service, our edge infrastructure and client-side security modules log technical, device-level parameters. This technical telemetry includes Internet Protocol (IP) addresses, display resolution and screen dimensions, audio input hardware specifications and microphone interface capabilities (such as hardware driver descriptors, available audio channels, and supported sampling rates, without recording or intercepting ambient sound or spoken audio), Internet Service Provider (ISP) network identifiers, operating system releases, browser user-agent tokens, and related hardware configuration flags. These technical attributes may be synthesized into a cryptographic device fingerprint (__div_fp).
Device-level identifiers and fingerprinting tokens are deployed exclusively to uphold platform security, enforce authorized rate limits, detect and prevent artificial streaming manipulation, identify unauthorized multi-account farming, and protect copyright royalties from automated fraud syndicates. Under no circumstances is device fingerprinting telemetry utilized for commercial surveillance, cross-site behavioral tracking, ad-tech targeting, or consumer profiling.
Divzoon explicitly confirms that device-level hardware metrics—including audio interface and microphone hardware specifications—are classified strictly as non-biometric technical telemetry. This data does not capture, measure, or process biological characteristics, physiological attributes, or unique biometric identifiers (such as voiceprints, acoustic vocal patterns, or facial geometry). It does not constitute biometric data under Article 9 of the GDPR, the Egyptian Data Protection Law No. 151 of 2020, or specialized biometric data statutes.
Device telemetry and fraud-prevention fingerprinting are processed under the lawful ground of Legitimate Interests (GDPR Article 6(1)(f) and applicable international legislation) to preserve platform integrity, protect digital service provider feeds, and maintain contractual trust across our global creator community. This processing is applied proportionately to satisfy security imperatives without constituting an absolute or mandatory requirement beyond verified risk mitigation.
Under applicable privacy legislation, including Article 21 of the General Data Protection Regulation, you have the right to object to the processing of your technical device telemetry on grounds relating to your particular situation. If you exercise this right, Divzoon will cease processing the disputed telemetry unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or where processing is required for the establishment, exercise, or defense of legal claims. Please note that exercising an objection to security fingerprinting may, by technical necessity, restrict or condition your access to sensitive, high-risk workflows—including catalog royalty withdrawals, high-volume batch distributions, and automated developer API provisioning—where alternative identity verification cannot be reliably established.
Technical device fingerprints and network identifiers are subjected to strictly restricted access controls (Strictly Restricted Access). Access is restricted exclusively to a designated cohort of authorized cybersecurity and platform engineering personnel on a verified need-to-know basis to investigate security incidents, audit fraud signals, or provide escalated infrastructure support. All administrative queries, modifications, and access events involving device telemetry are permanently logged in immutable internal audit trails subject to regular institutional compliance oversight.
5. Data Retention
We retain personal data only for the duration necessary to satisfy the purposes described in this policy, maintain active customer accounts, fulfill statutory accounting mandates, and enforce contractual commitments:
• Account Records: Retained throughout the duration of your active account. Following a verified account closure or deletion request, account records are purged from primary production databases within 30 days, with complete deletion from encrypted backup archives within 90 days.
• Catalog & Distribution Metadata: Retained for as long as your releases remain active across digital service providers. Upon receipt of a distribution takedown request, metadata and media assets are removed from delivery feeds and archived solely to verify historical royalty earnings.
• Identity Verification Records: Retained in encrypted form during the verification lifecycle and for the duration required under applicable financial audit and anti-money laundering regulations.
• Financial, Tax & Billing Records: Retained for up to seven (7) years following the conclusion of the relevant financial period, in strict accordance with statutory accounting, tax reporting, and corporate governance laws.
• Operational Logs & Telemetry: System diagnostics, security telemetry, and access logs are maintained on a rolling retention cycle (typically 30 days to 12 months) before automated purging.
6. Data Security
We maintain an enterprise-grade security program incorporating physical, organizational, and technical safeguards engineered to protect personal data from accidental loss, unauthorized access, destruction, misuse, or alteration:
• Cryptographic Controls: All platform communications and data transmissions are encrypted using modern Transport Layer Security (TLS) protocols. Sensitive information stored at rest is encrypted using industry-standard cryptographic mechanisms.
• Access Management: Access to production systems and customer data is strictly restricted according to the principle of least privilege, guarded by multi-factor authentication, and subjected to continuous administrative audit logging.
• Defense in Depth: We deploy edge-level DDoS mitigation, automated vulnerability scanning, secure credential management, and routine architecture reviews to preserve the ongoing confidentiality, integrity, and availability of our infrastructure.
7. Incident Response & Breach Notification
Divzoon maintains a formal security incident response framework. In the event of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data:
• Regulatory Notification: We will notify relevant supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of a qualifying breach, in compliance with GDPR Article 33.
• User Notification: Where an incident presents a high risk to individual rights and freedoms, we will promptly notify affected users directly via their registered account email address in accordance with GDPR Article 34, outlining the nature of the breach, likely implications, and recommended mitigating measures.
8. Automated Processing & Human Oversight
To maintain service speed and catalog security at global scale, Divzoon utilizes automated analytical mechanisms in specific operational contexts:
• Fraud & Abuse Prevention: Automated heuristics monitor streaming patterns and distribution ingestion queues to identify potential fraud, artificial streaming manipulation, or terms of service violations. Critical account actions are subject to qualified human review.
• Support Request Triage: Inbound technical and support inquiries may be initially evaluated by automated systems to ensure rapid routing to the appropriate specialist team.
In accordance with applicable privacy laws (including GDPR Article 22), you have the right to request human intervention regarding any automated decision that produces legal or similarly significant effects. To request human review or contest an automated evaluation, please contact [email protected].
9. International Data Transfers
As a global technology and distribution provider, Divzoon maintains infrastructure and engages service providers located across multiple jurisdictions, including the United States, the European Union, and the United Kingdom. As a result, your personal data may be transferred to, stored, or processed in jurisdictions with data protection frameworks differing from those of your home country.
When transferring personal data originating in the European Economic Area (EEA), the United Kingdom, or Switzerland to countries without an adequacy finding, we implement lawful cross-border transfer mechanisms, including European Commission-approved Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, supplemented by rigorous technical security measures.
10. Your Privacy Rights & Choices
Depending on your geographic residency and applicable data protection legislation (including the EU/UK GDPR, California Consumer Privacy Act as amended by the CPRA, and related global frameworks), you may exercise the following rights regarding your personal data:
• Right to Access & Know: Request confirmation of whether we process your personal data, along with access to specific data records, categories of information collected, purposes of processing, and recipient categories.
• Right to Rectification: Request correction of inaccurate, outdated, or incomplete personal data maintained within your profile or catalog records.
• Right to Erasure (“Right to be Forgotten”): Request the permanent deletion of your personal data, subject to lawful retention exceptions such as statutory tax, accounting, and anti-fraud compliance mandates.
• Right to Data Portability: Obtain a structured, commonly used, and machine-readable copy of your personal data and creative catalog records, or request transmission to a designated third party where technically feasible.
• Right to Restrict or Object to Processing: Request temporary restriction of data processing or object to processing conducted under our legitimate interests.
• Right to Opt-Out of Sale or Sharing: Divzoon does not sell personal data, nor do we share personal information for cross-context behavioral advertising. Our default platform architecture operates under a strict no-sale framework.
• Cookie Management: You may modify or withdraw your non-essential cookie preferences at any time by accessing our settings.
• Right to Lodge a Complaint: You possess the right to submit a complaint regarding our data handling practices to a competent data protection supervisory authority in your country or region of residence.
To submit a privacy inquiry or exercise any statutory right, please contact our Data Protection Office at [email protected]. We acknowledge verified requests within 72 hours and provide substantive responses within thirty (30) calendar days without charge or discriminatory treatment.
11. Children's Privacy
The Service is strictly intended for individuals aged eighteen (18) years and older. We do not knowingly collect, solicit, or maintain personal data from individuals under the age of 18 without verifiable written consent from a parent or legal guardian who accepts contractual responsibility for the account.
If we discover that personal data has been submitted by an unauthorized minor, we will take prompt steps to terminate the associated account and permanently erase the collected data. If you believe a minor has provided us with personal data without required legal authorization, please notify us immediately at [email protected].
12. Regional Privacy Frameworks
Divzoon provides services to creators and enterprise partners globally. In addition to compliance with the EU/UK GDPR and California privacy legislation, we are dedicated to respecting applicable international privacy frameworks across all operating regions, including:
• Brazil (LGPD): Lei Geral de Proteção de Dados Pessoais.
• South Africa (POPIA): Protection of Personal Information Act.
• Thailand (PDPA): Personal Data Protection Act.
• United Kingdom (UK GDPR): Data Protection Act 2018.
Where local privacy laws grant additional statutory entitlements or specific legal remedies, Divzoon ensures that eligible residents may fully exercise their regional rights.
13. Changes to This Privacy Policy
We may periodically update this Privacy Policy to reflect platform enhancements, operational modifications, or emerging regulatory standards. When material revisions occur, we will provide advance notice via email or a prominent notification within the platform dashboard prior to the changes taking effect. The revised policy will be posted on this page with an updated effective date. Your continued use of the Service following such updates constitutes your acknowledgment of the amended policy.
14. Contact Information
If you have questions, feedback, or concerns regarding this Privacy Policy, or if you wish to exercise your data protection rights, please contact our Data Protection Office:
Privacy & Data Protection Office: [email protected]
Customer Support: [email protected]
Corporate Inquiries: Divzoon — Global Music Distribution & Platform Operations
Response Commitment: All verified privacy inquiries are acknowledged within 72 hours and resolved within 30 calendar days.