Privacy Policy
1. Who we are and scope of this Policy
1.1. This Privacy Policy explains how iradio S.R.L., a Romanian company registered with the Trade Register under no. J2024003934236, fiscal registration code (CUI) 50155192, with its registered office at Str. Emil Racoviță nr. 29, Bl. A4, Sc. 1, Ap. 1, Bucharest, Romania ("Daily Radio", "we", "us"), processes personal data as a data controller when you visit the Website, listen to our free stations, create an account, use the Daily Radio service (the "Service"), purchase subscriptions or add-ons, or contact us.
1.2. We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR"), Romanian Law no. 190/2018 on implementing measures for the GDPR, and Law no. 506/2004 on the processing of personal data and the protection of private life in the electronic communications sector.
1.3. Contact for data protection matters: gdpr@dailyradio.com (or by post at the registered office address above, marked "Data Protection"). We have designated this dedicated contact point for all privacy matters; a formal Data Protection Officer within the meaning of art. 37 GDPR has not been appointed, as the conditions that make appointment mandatory are not met. Should this change, this Policy will be updated.
1.4. This Policy does not cover processing performed by our business customers themselves (for example, an account holder deciding which of its employees receive sub-user access acts as a controller for its own decisions regarding its staff).
2. Categories of personal data we process
2.1. Account and registration data: first name, last name, e-mail address, password (stored only in salted/hashed form), country, preferred language, time zone derived from country, account role (account holder / sub-user), account status and settings.
2.2. Billing and transaction data: company/billing name, billing address, VAT/tax identification number, subscription plan, add-on orders, invoices and payment history, complimentary subscription grants. Payment card data is collected and processed directly by our payment processor Stripe; we never receive or store full card numbers. We receive from Stripe only limited information (e.g., payment status, card brand, last four digits, expiry) needed to manage billing.
2.3. Sub-user data: name/identifier, e-mail address, per-station access rights, status — provided to us by the account holder that creates the sub-user.
2.4. Contact and lead data: data submitted through the contact form (name, first name, e-mail address, telephone number, message content, request type — e.g., custom-plan requests) and the status of the request in our internal follow-up.
2.5. Content and production data: brand information, briefs, scripts, lyrics, voice/style/language selections, logos and other materials you provide or approve for jingles, ad campaigns and branded player pages.
2.6. Usage and technical data: IP address, date and time of access, requested resources, browser type and version, operating system and device type, session identifiers, authentication and session-management events (including enforcement of the single-active-session rule and last-seen timestamps), listening/playback sessions and heartbeats (station listened to, duration), API token usage, error and security logs, and audit logs of administrative actions (including support access to accounts, which is recorded).
2.7. Communications: e-mails and messages exchanged with us, password-reset requests, notifications and their delivery status.
2.8. Cookie and similar-technology data: as described in our separate Cookie Policy.
2.9. We do not intentionally process special categories of personal data (art. 9 GDPR) and we ask you not to include such data in briefs, scripts or messages. The Service is not addressed to children; see Section 10.
3. Purposes and legal bases of processing
We process personal data for the following purposes, on the following legal bases:
| Purpose | Data categories | Legal basis |
|---|---|---|
| Creating and administering accounts; providing the Service (streaming, stations, team/sub-users, player pages, API access); enforcing session limits | 2.1, 2.3, 2.6 | Art. 6(1)(b) GDPR — performance of the contract (for sub-users: art. 6(1)(f) — legitimate interest in providing the contracted service to the account holder) |
| Processing subscriptions, payments, invoicing, payment-failure handling | 2.1, 2.2 | Art. 6(1)(b) GDPR; art. 6(1)(c) — legal obligations (accounting and fiscal law) |
| Producing jingles, ad spots and branded content on your instructions (including via AI providers) | 2.5, 2.1 | Art. 6(1)(b) GDPR |
| Responding to contact-form requests and custom-plan enquiries; pre-contractual steps | 2.4 | Art. 6(1)(b) GDPR (steps prior to entering a contract); art. 6(1)(f) — legitimate interest in responding to enquiries |
| Security of the Service: authentication, fraud and abuse prevention, logging, audit trails, blocking of attacks, hotlink protection | 2.6 | Art. 6(1)(f) GDPR — legitimate interest in securing the Service and preventing abuse |
| Service analytics and improvement: listening statistics, feature usage, quality and performance monitoring | 2.6 (aggregated wherever possible) | Art. 6(1)(f) GDPR — legitimate interest in operating and improving the Service |
| Sending service communications (renewal, payment, security, changes to terms) | 2.1 | Art. 6(1)(b) and (c) GDPR |
| Sending marketing/newsletter communications, where you opted in | 2.1 | Art. 6(1)(a) GDPR — consent (withdrawable at any time) |
| Compliance with legal obligations: accounting, tax, consumer protection, responses to authorities, music-licensing reporting (playlist/usage reports to collective management organisations do not normally contain listener personal data) | 2.2, 2.6, 2.7 | Art. 6(1)(c) GDPR |
| Establishment, exercise or defence of legal claims; enforcement of our terms | all, as strictly necessary | Art. 6(1)(f) GDPR — legitimate interest |
Where we rely on legitimate interest, we have balanced our interests against your rights and freedoms; you may object as described in Section 8.
4. Sources of data
We collect data directly from you (registration, checkout, forms, uploads), automatically through your use of the Website and Service (logs, playback telemetry, cookies), from the account holder (for sub-user data), and from our payment processor (payment status information).
5. Recipients of personal data
5.1. Access to personal data within the Company is limited to authorized personnel bound by confidentiality.
5.2. We share personal data with the following categories of recipients, only to the extent necessary:
- Stripe (Stripe Payments Europe, Ltd., Ireland, and its affiliates, including Stripe, Inc., USA) — payment processing, subscription billing, fraud prevention and tax/invoice data handling; Stripe acts as an independent controller and/or processor for payment services under its own privacy policy;
- Cloudflare (Cloudflare, Inc., USA / Cloudflare EMEA) — content delivery network, DNS, TLS and security services (traffic filtering, bot management), which involves processing of IP addresses and technical logs;
- Hosting provider — the servers hosting the Website, application and databases;
- OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd) — processing of texts submitted for jingle/ad script suggestions, text-to-speech generation and audio-file metadata cleanup; we submit only the content necessary (briefs, scripts, brand names, file names) and instruct you not to include personal data in such content;
- Suno / sunoapi.org — generation of musical jingles from scripts/lyrics, where this feature is enabled;
- E-mail delivery infrastructure — for transactional e-mails (account, password reset, billing);
- Professional advisers and service providers — accountants, auditors, legal counsel, IT support, under confidentiality obligations;
- Public authorities and courts — where disclosure is required by law (e.g., ANAF, ANPC, ANSPDCP, law enforcement) or necessary for the defence of legal claims;
- Successors in business — in the event of a merger, acquisition or transfer of assets, subject to appropriate safeguards and, where required, notice.
5.3. We do not sell personal data and we do not disclose it to third parties for their own advertising purposes.
6. International transfers
Some of the providers listed above (in particular Stripe, Cloudflare, OpenAI and Suno) may process personal data in countries outside the European Economic Area, including the United States. Where this happens, transfers are carried out on the basis of an adequacy decision of the European Commission (including, for certified US organisations, the EU–US Data Privacy Framework) and/or the European Commission's Standard Contractual Clauses (art. 46(2)(c) GDPR), supplemented where necessary by additional technical and organisational measures. You may request further information about the safeguards applied at gdpr@dailyradio.com.
7. Retention periods
We keep personal data only as long as necessary for the purposes described above:
- Account data: for the duration of the account and up to 3 years after its closure (the general limitation period for legal claims), unless a longer period is required by law;
- Billing, invoicing and accounting records: the periods required by Romanian fiscal and accounting legislation (as a rule, 5 years from the end of the relevant fiscal year, or the longer period specifically required for certain records);
- Contact/lead requests: up to 2 years from the last interaction, unless a contract is concluded;
- Technical logs, security logs and playback telemetry: as a rule up to 12 months; station play history is retained for 90 days; short-lived operational data (e.g., session heartbeats) is deleted or aggregated on shorter cycles;
- Marketing consents and preferences: until consent is withdrawn or the purpose ceases;
- Data relating to disputes or investigations: until final resolution and expiry of applicable limitation periods.
When retention ends, data is deleted or irreversibly anonymised; anonymised, aggregated statistics may be kept indefinitely.
8. Your rights
8.1. Under the GDPR you have the following rights, under the conditions and within the limits of the law: the right of access (art. 15), the right to rectification (art. 16), the right to erasure ("right to be forgotten", art. 17), the right to restriction of processing (art. 18), the right to data portability (art. 20), the right to object to processing based on legitimate interest, including profiling based on that ground, and to object at any time to direct marketing (art. 21), the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal (art. 7(3)), and the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (art. 22). We do not carry out such automated decision-making; playlist curation and scheduling are automated processes concerning music, not evaluations of listeners.
8.2. You may exercise these rights by writing to gdpr@dailyradio.com or by post to the registered office. We may request information necessary to confirm your identity. We will respond without undue delay and in any event within one month of receipt of the request; this period may be extended by two further months where necessary for complex or numerous requests, in which case you will be informed of the extension and its reasons. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests, in accordance with art. 12 GDPR.
8.3. Complaints. If you consider that the processing of your personal data infringes the law, you have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, Romania, telephone +40 318 059 211, e-mail anspdcp@dataprotection.ro, website https://www.dataprotection.ro — as well as the right to an effective judicial remedy. We would, however, appreciate the chance to address your concerns first at gdpr@dailyradio.com.
9. Security of processing
We implement appropriate technical and organisational measures pursuant to art. 32 GDPR, taking into account the state of the art and the risks, including: encrypted transport (HTTPS/TLS across the Website and streams), salted password hashing, role-based access control and per-account authorization of media streaming, protection of stored media and application files from direct web access, CSRF protection, session management with single-active-session enforcement, audit logging of administrative actions (including support access to customer accounts), webhook signature verification for payment events, network-level protection through Cloudflare, backups, and the principle of least privilege for internal access. No system can be guaranteed 100% secure; in the event of a personal data breach likely to result in a risk to your rights, we will notify the ANSPDCP within 72 hours of becoming aware of it and, where the breach is likely to result in a high risk, we will also inform the affected data subjects, in accordance with art. 33–34 GDPR.
10. Children
The Website's free listening features are not directed at children under 16, and accounts may be created only by persons aged 18 or over. We do not knowingly collect personal data from children under 16 without verifiable parental consent; if you believe a child has provided us personal data, please contact gdpr@dailyradio.com and we will delete it.
11. Cookies and similar technologies
The Website uses cookies and similar technologies (including local storage used by the audio player). Details about the technologies used, their purposes, durations and how to manage your preferences are set out in our Cookie Policy, available on the Website, which forms part of this Policy.
12. Third-party websites
The Website may contain links to third-party websites (for example, the policies of our providers). We are not responsible for the privacy practices of such third parties; please review their own privacy notices.
13. Changes to this Policy
We may update this Policy from time to time to reflect legal, technical or business developments. The current version, with its effective date, is always published on the Website. Material changes will be announced by e-mail or through the Website/Service before they take effect. We encourage you to review this Policy periodically.
14. Contact
iradio S.R.L. — Str. Emil Racoviță nr. 29, Bl. A4, Sc. 1, Ap. 1, Bucharest, Romania · Trade Register no. J2024003934236 · CUI 50155192 · Data protection contact: gdpr@dailyradio.com · Website: https://dailyradio.com
DailyRadio