Skip to content

Launch offer · Labelmate is free for the first 10 independent labels that join us.Free for the first 10 labels.

Contact us

Data processing agreement

Last updated: 21 September 2026

This agreement forms part of Labelmate's terms of use. It applies as soon as a label uses Labelmate, and governs the processing we carry out on its behalf, within the meaning of Article 28 GDPR.

1. The parties

The label using Labelmate is the controller. Labelmate's publisher, Tom Nsengiyumva (sole proprietor, BE 1022.549.155), is the processor.

2. What we do for the label

ProcessingDataDuration
Keeping the label's computers in sync through the relaySealed copies of the label's database, which we cannot read; identifiers and public keys of the computers; IP addressesWhile the label uses Labelmate, then one month at most
Having a document read by the AI, if the label turns it onThe document's text, with IBANs, card and social security numbers maskedThe time of the reading, then under Anthropic's terms
Helping the label, at its requestWhat the label chooses to show usThe time of the request

Data subjects: the label's artists and rights holders, its contacts and correspondents, the members of its team. Data: identity and contact details, contract terms, amounts and statements, the content of emails and documents. Labelmate needs no special-category data within the meaning of Article 9 GDPR, and the label must not knowingly give it any.

3. Our commitments

  • Process the data only on the label's instructions (what the app does when the label uses it), and tell the label if an instruction seems to us to breach the GDPR.
  • Make sure everyone authorised to process the data is bound by confidentiality.
  • Apply the security measures described in Annex 2.
  • Help the label answer requests to exercise rights, carry out an impact assessment where one is needed, and meet its security obligations.
  • Make available the information needed to show compliance with this agreement, and allow audits under the conditions of section 7.

4. Sub-processors

The label authorises us to use the sub-processors listed in Annex 1. We tell it at least thirty days before adding or replacing one; if it objects on reasonable data protection grounds, it may end the Service. We impose on each sub-processor protection obligations at least equivalent to those of this agreement.

5. Transfers outside the EEA

Anthropic processes texts in the United States. This transfer relies on a mechanism the GDPR recognises: an adequacy decision or the European Commission's Standard Contractual Clauses.

6. Data breaches

If we become aware of a personal data breach affecting the label, we tell it without undue delay, and no later than 48 hours after becoming aware of it, with what we know of its nature, its likely consequences and the measures taken.

7. Audits

Once a year and with thirty days' notice, the label may ask us for the information needed to check compliance with this agreement, or have an audit carried out at its own cost by an auditor bound by confidentiality. These limits do not apply after a data breach.

8. End of processing

The label's data stays on its computers: it has nothing to retrieve from us. When it stops using Labelmate, we delete its sealed copies from the relay no later than one month after its request, and confirm it in writing if it wishes.

9. Duration and liability

This agreement lasts as long as the label uses Labelmate. Each party's liability follows the terms of use and Article 82 GDPR.

10. Labels outside the European Union

This agreement applies to every label, wherever it is established, and we keep our commitments in the same way.

For a label established in the United States, we also act as its service provider within the meaning of the California Consumer Privacy Act (CCPA) and similar laws in other states: we process personal information only to provide Labelmate to the label, we do not sell or share it, we do not retain, use or disclose it for any other purpose or outside our direct relationship with the label, and we do not combine it with personal information from other sources, except as those laws allow.

If another country's law asks for specific commitments, write to us: we add them.

Annex 1: Sub-processors

Sub-processorRoleLocation
Supabase, Inc.Hosting the relay: sealed copies, computer identifiers, IP addressesEuropean Union (Ireland)
Anthropic, PBCReading documents with the AI, if the label turns it on: masked textUnited States

Annex 2: Security measures

  • The label's database is encrypted on each computer (SQLCipher); its key is kept in the system's secure keychain.
  • Copies sent to the relay are sealed on the computer, with keys that never leave it; we cannot read them.
  • Every request to the relay is signed with the computer's key, time-stamped and single-use: an old, replayed or wrongly signed request is refused.
  • The list of the label's computers is a signed chain; removing a computer changes the label's keys.
  • Traffic goes over encrypted connections (TLS).
  • Before any reading by the AI, IBANs, card numbers and social security numbers are masked.
  • The app's logs hold no content: identifiers, counts and durations, never a subject, a name, an amount or a body of text.
  • Backups are encrypted, with a fresh key for each file.
  • Only the publisher has access to the relay's database.

Apply for early access

Early access is free for the first 10 labels. Tell us about yours: we read every application and get back to you very soon.

We only use this information to reply to you. Privacy policy.

Labelmate in one minute

The app itself, on the made-up label Exemple Records.