Legal

Privacy Policy

Last updated 9 August 2026

The short version: I collect the minimum needed to run your membership, I do not sell anything to anyone, and there are no advertising trackers on this site.

01Who is responsible for your data

The data controller is Constantinos Tsiolis, trading as Flow Room Music, Nicosia, Cyprus. If you have any question about your data, or want to exercise any of the rights in section 7, write to info@flowroommusic.com.

Email: info@flowroommusic.com
Address: Nicosia, Cyprus
Business / tax ID (ΑΦΜ / VAT): to be added

02What I collect and why

DataWhyLegal basis
Name and email address To create your account, issue your licence certificate in your name, and send service messages such as receipts and renewal notices. Performance of our contract
Password To secure your account. It is stored hashed — I cannot read it and neither can anyone else. Performance of our contract
Subscription and payment status To know whether your membership is active. Card details are handled entirely by Stripe and never reach Flow Room Music servers. Contract, and legal obligation for tax records
Studio photo, if you upload one To display it back to you inside your own account. Your consent, withdrawable at any time by deleting it
Playlists, saved classes and downloads To remember your work between sessions. Today these are stored in your own browser, not on a server. Performance of our contract
Technical logs — IP address, browser, pages requested Security, fraud prevention and diagnosing faults. Generated automatically by the hosting provider. My legitimate interest in keeping the service working and secure

I do not collect health data, and I do not ask for anything about your clients. Please do not send me client information.

03Cookies and local storage

There are no advertising or analytics trackers on this site. No Google Analytics, no Meta pixel, no third-party ad cookies.

The library uses your browser's local storage to keep you signed in and to remember your playlists, filters and downloads. This stays on your device, is not transmitted to me, and clearing your browser data removes it. Stripe sets its own cookies during checkout for fraud prevention; that is covered by Stripe's privacy policy.

04Who else sees your data

Only the companies I need to run the service. Each one processes your data on my instructions, under a contract, and none of them may use it for their own purposes.

  • Stripe — payment processing, invoices, subscription management and (when enabled) tax calculation.
  • Firebase (Google) — account authentication (email and password).
  • Cloudflare — hosting and the billing worker that records membership status after Stripe confirms payment.
  • Cloudflare — website hosting, file delivery and protection against attacks.
  • My email provider — to send you receipts and service notices.

I do not sell your data, rent it, or share it with advertisers. I will only disclose it otherwise if the law requires it.

05Transfers outside the EEA

Some of these providers are based in the United States or operate global infrastructure, so your data may be processed outside the European Economic Area. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent approved safeguard.

06How long it is kept

  • Account data — for as long as your membership is active, and for 12 months afterwards in case you come back. Ask me to delete it sooner and I will.
  • Invoices and payment records — kept for as long as Cypriot tax law requires, currently six years. I cannot delete these earlier even if you ask.
  • Studio photo — until you delete it or close your account.
  • Technical logs — a short rolling period set by the hosting provider, typically under 30 days.

07Your rights

Under the GDPR you can ask me to:

  • give you a copy of the data I hold about you;
  • correct anything that is wrong;
  • delete your data, where I am not legally required to keep it;
  • restrict or object to how I use it;
  • send it to you, or to another provider, in a portable format;
  • withdraw consent you gave earlier, without affecting what was done before.

Email me and I will respond within one month. There is no charge.

If you think I have handled your data badly, you can complain to the Office of the Commissioner for Personal Data Protection of Cyprus at dataprotection.gov.cy, or to the supervisory authority in your own country. I would appreciate the chance to fix it first.

08Security

Traffic to this site is encrypted. Passwords are stored hashed. Card details never touch my systems. That said, no online service is perfectly secure — if a breach ever affects your data, I will tell you and the supervisory authority as the law requires.

09Children

This service is for professionals and is not intended for anyone under 18. I do not knowingly collect data from children.

10Changes to this policy

If I change anything meaningful, I will update the date at the top and email active members. Older versions are available on request.