Data Protection / GDPR
Version 1.0 Effective: 30 August 2026 Last Updated: 30 August 2026
1. Overview
This Data Protection notice explains how EuroRadios handles personal data in accordance with EU data protection principles, including the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). It should be read together with our Privacy Policy.
2. Data Controller
The data controller is [LEGAL ENTITY NAME — to be configured], with registered address at [REGISTERED ADDRESS — to be configured].
EuroRadios has not appointed a Data Protection Officer (DPO) as it is not required to do so under Article 37 GDPR. For data protection matters, contact [LEGAL CONTACT EMAIL — to be configured] via the Contact page.
3. GDPR Principles
EuroRadios processes personal data in accordance with the following GDPR principles (Article 5):
- Lawfulness, fairness, and transparency: data is processed lawfully, fairly, and transparently.
- Purpose limitation: data is collected for specified, explicit, and legitimate purposes.
- Data minimisation: data is limited to what is necessary for the purposes.
- Accuracy: data is kept accurate and up to date.
- Storage limitation: data is kept only as long as necessary.
- Integrity and confidentiality: data is processed securely with appropriate protection.
4. Lawful Bases (Article 6)
We rely on the following lawful bases:
- Article 6(1)(b) — Contractual necessity: processing necessary for the performance of a contract (account creation, streaming, station management, Premium subscription).
- Article 6(1)(c) — Legal obligation: processing required to comply with legal obligations (tax records, fraud prevention).
- Article 6(1)(f) — Legitimate interests: platform security, rate-limiting, preventing abuse, and fraud detection.
- Article 6(1)(a) — Consent: optional analytics, optional data sharing for recommendations, and non-essential cookies/tracking.
5. Data Subject Rights
Under Articles 12–22 GDPR, you have the following rights:
- Right of access (Article 15): request a copy of your personal data.
- Right to rectification (Article 16): request correction of inaccurate personal data.
- Right to erasure / "right to be forgotten" (Article 17): request deletion of your personal data.
- Right to restriction of processing (Article 18): request that we limit processing of your data.
- Right to data portability (Article 20): receive your data in a structured, machine-readable format and transmit it to another controller.
- Right to object (Article 21): object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent (Article 7(3)): withdraw consent at any time without affecting prior lawful processing.
To exercise these rights, contact [LEGAL CONTACT EMAIL — to be configured] or use the Contact page (Privacy category).
6. Automated Decision-Making
EuroRadios does not engage in automated decision-making that produces legal or similarly significant effects on individuals (Article 22). Ad frequency capping and station ranking algorithms do not produce such effects.
7. Processors
EuroRadios uses the following processors (Article 28):
- Base44 platform — hosting, infrastructure, and database services.
- PayPal — payment processing for Premium subscriptions.
- Stripe — payment processing for Premium subscriptions.
- Google AdSense — advertising (where enabled).
- Google Analytics — usage analytics (where enabled and consented).
Each processor processes data under appropriate data processing agreements.
8. International Transfers (Chapter V)
EuroRadios is hosted on the Base44 platform, which may process data outside the European Economic Area (EEA). Where personal data is transferred to a third country, appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) adopted by the European Commission.
- Where applicable, adequacy decisions for the destination country.
Payment providers (PayPal, Stripe) may also transfer data outside the EEA under their own safeguards.
9. Security (Article 32)
EuroRadios implements appropriate technical and organisational measures, including:
- Encrypted data transmission (HTTPS/TLS).
- Access controls and authentication.
- Regular security reviews and monitoring.
- Data minimisation in ad analytics (no PII sent to advertising providers).
10. Data Retention
Personal data is retained only as long as necessary for the purposes for which it was collected. See the Privacy Policy §7 for specific retention periods.
11. Data Breach Handling
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, EuroRadios will notify the competent supervisory authority within 72 hours of becoming aware of the breach, where required by Article 33. Where the breach is likely to result in a high risk to data subjects, we will also communicate the breach to affected individuals (Article 34).
12. Complaints
You have the right to lodge a complaint with your local supervisory authority if you believe that our processing of your personal data infringes applicable data protection law. You may also contact us first at [LEGAL CONTACT EMAIL — to be configured].
13. Important
This notice describes actual EuroRadios practices. The existence of this page does not, by itself, constitute legal compliance certification. Legal content should be reviewed by qualified legal counsel before publication.
See also: Privacy Policy, Cookie Policy, Terms of Use.