Version 1.0, 2026-10-07
In short: when you send audio or data of your own users to the Songbrain API, you decide what happens with it and we process it only to produce your result. This addendum is part of the Terms (§17) for everyone who uses the API, so there is nothing to sign. Need a countersigned copy for your records? Email support@songbrain.ai.
This Data Processing Addendum ("DPA") is concluded between the customer who uses the Songbrain Developer API at api.songbrain.ai, including its MCP endpoint ("Customer", controller), and
Leon Ulicnik
songbrain ai / Smoke-Oh Studios
Liebrütistrasse 44, 4303 Kaiseraugst, Switzerland
Email: info [at] songbrain [dot] ai
("Songbrain", processor). It applies whenever Songbrain processes personal data on the Customer's behalf through the API ("Customer Personal Data"). It is incorporated by reference into the Terms of Serviceand becomes binding when the Customer first uses an API key. It does not cover data for which Songbrain is itself the controller, such as the Customer's own account and billing data; that is described in the Privacy Policy.
It implements Art. 28 of the EU General Data Protection Regulation ("GDPR") and Art. 9 of the Swiss Federal Act on Data Protection ("FADP"), as far as each applies. Terms defined in the GDPR have the same meaning here.
| Description | |
|---|---|
| Subject matter | Analysis of audio submitted through the API and delivery of the result. |
| Duration | As long as the Customer uses the API, plus the deletion periods in section 10. |
| Nature | Receiving, storing, transcribing, analysing, transmitting (API responses, webhooks) and deleting. |
| Purpose | Producing and delivering the analysis, story and shot plan the Customer requested. No other purpose. |
| Types of data | Audio recordings (which may contain voices), lyrics transcribed from them, metadata the Customer sends (title, artist name, external reference) and webhook URLs. |
| Data subjects | Performers and artists heard in the audio, and the Customer's end users whose data the Customer submits. |
| Special categories | Not intended. The Customer must not submit special categories of data (Art. 9 GDPR) beyond what may be inherent in a voice recording. |
Songbrain processes Customer Personal Data only on the Customer's documented instructions. The Customer's instructions are the API requests it makes, the settings it chooses, the Terms and this DPA. Songbrain will tell the Customer if it believes an instruction infringes data protection law, unless the law forbids it. If law requires Songbrain to process data otherwise, it will tell the Customer first, unless the law forbids that on important grounds of public interest.
Everyone at Songbrain who can access Customer Personal Data is bound to confidentiality. Access is limited to what is needed to run and support the service.
Songbrain implements appropriate technical and organisational measures under Art. 32 GDPR, listed in Annex 1, and keeps them up to date with the state of the art. Songbrain may change the measures as long as the overall level of protection does not go down.
The Customer gives general authorisation for Songbrain to engage sub-processors. The current list is published at songbrain.ai/security#subprocessors and forms Annex 2.
Songbrain notifies the Customer at least 30 days before it adds or replaces a sub-processor, by email to the address of every account that holds an active API key, and by updating the list. The Customer may object in writing within that period on reasonable data-protection grounds. If the parties cannot resolve the objection, the Customer may stop using the API and close its account without penalty.
Songbrain imposes on each sub-processor, by written contract, data protection obligations that offer at least the same protection as this DPA, and remains responsible to the Customer for its sub-processors' performance.
Songbrain is established in Switzerland, which the European Commission recognises as providing an adequate level of data protection. Customer Personal Data is hosted in Germany (EU). Where sub-processors process it in the United States or other countries without an adequacy decision, the transfer is protected by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, module 3, processor to processor) with the amendments required for Switzerland, or by the EU-U.S. Data Privacy Framework and its Swiss-U.S. extension where the recipient is certified. The safeguard used per provider is named in the Privacy Policy, section 5.
Taking into account the nature of the processing, Songbrain assists the Customer with appropriate measures in answering requests from data subjects (access, deletion and the other rights in Chapter III GDPR) and with its obligations under Art. 32 to 36 GDPR (security, breach notification, data protection impact assessments, prior consultation). The API already lets the Customer fetch and delete each song (GET and DELETE /v1/songs/{id}). If a data subject contacts Songbrain directly about data submitted by the Customer, Songbrain refers them to the Customer and does not answer on its own, unless the law requires it.
Songbrain notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay and no later than 72 hours after becoming aware of it, by email to the account address. The notice includes, as far as known at that time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. Information that is not yet available is provided as soon as it is. Songbrain takes reasonable steps to contain the breach and limit its effects.
During the term, Songbrain deletes uploaded audio files within 24 hours and compressed previews after 30 days. Analysis results are kept until the Customer deletes them through the API or closes its account. The Customer can retrieve all results through the API at any time before deletion; this is the return of data.
When the Customer closes its account or the API service ends, Songbrain deletes all remaining Customer Personal Data within 30 days, including copies held by sub-processors under their own deletion schedules, unless the law requires Songbrain to keep it. On request, Songbrain confirms the deletion in writing.
Songbrain makes available all information necessary to demonstrate compliance with this DPA. In the first place this is done through documentation: this DPA, the security page, the sub-processor list, the Privacy Policy and written answers to a reasonable security questionnaire, once per year or after a breach.
If that documentation is not enough to show compliance, or a supervisory authority requires it, the Customer may carry out an audit itself or through an independent auditor bound to confidentiality, with at least 30 days' notice, during business hours, without access to other customers' data and at the Customer's own cost.
Liability under this DPA follows the Terms of Service, except where mandatory law provides otherwise. If this DPA conflicts with the Terms on the protection of personal data, this DPA prevails. Where Standard Contractual Clauses apply, they prevail over both. This DPA is governed by the same law as the Terms (section 15), unless the Standard Contractual Clauses require otherwise. It lasts as long as Songbrain processes Customer Personal Data.
Songbrain may update this DPA, for example when a law or a sub-processor changes. Changes that reduce the protection of Customer Personal Data are announced by email at least 30 days in advance. The current version and its date are always on this page.
The list at songbrain.ai/security#subprocessors, in its current version.
This addendum was drafted in-house by the operator and has not yet been reviewed by qualified legal counsel. Where it conflicts with mandatory data protection law, that law prevails.