01Who is responsible for your data
The data controller is Constantinos Tsiolis, trading as Flow Room Music, Nicosia, Cyprus. If you have any question about your data, or want to exercise any of the rights in section 7, write to info@flowroommusic.com.
02What I collect and why
| Data | Why | Legal basis |
|---|---|---|
| Name and email address | To create your account, issue your licence certificate in your name, and send service messages such as receipts and renewal notices. | Performance of our contract |
| Password | To secure your account. It is stored hashed — I cannot read it and neither can anyone else. | Performance of our contract |
| Subscription and payment status | To know whether your membership is active. Card details are handled entirely by Stripe and never reach Flow Room Music servers. | Contract, and legal obligation for tax records |
| Studio photo, if you upload one | To display it back to you inside your own account. | Your consent, withdrawable at any time by deleting it |
| Playlists, saved classes and downloads | To remember your work between sessions. Today these are stored in your own browser, not on a server. | Performance of our contract |
| Technical logs — IP address, browser, pages requested | Security, fraud prevention and diagnosing faults. Generated automatically by the hosting provider. | My legitimate interest in keeping the service working and secure |
I do not collect health data, and I do not ask for anything about your clients. Please do not send me client information.
05Transfers outside the EEA
Some of these providers are based in the United States or operate global infrastructure, so your data may be processed outside the European Economic Area. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent approved safeguard.
06How long it is kept
- Account data — for as long as your membership is active, and for 12 months afterwards in case you come back. Ask me to delete it sooner and I will.
- Invoices and payment records — kept for as long as Cypriot tax law requires, currently six years. I cannot delete these earlier even if you ask.
- Studio photo — until you delete it or close your account.
- Technical logs — a short rolling period set by the hosting provider, typically under 30 days.
07Your rights
Under the GDPR you can ask me to:
- give you a copy of the data I hold about you;
- correct anything that is wrong;
- delete your data, where I am not legally required to keep it;
- restrict or object to how I use it;
- send it to you, or to another provider, in a portable format;
- withdraw consent you gave earlier, without affecting what was done before.
Email me and I will respond within one month. There is no charge.
If you think I have handled your data badly, you can complain to the Office of the Commissioner for Personal Data Protection of Cyprus at dataprotection.gov.cy, or to the supervisory authority in your own country. I would appreciate the chance to fix it first.
08Security
Traffic to this site is encrypted. Passwords are stored hashed. Card details never touch my systems. That said, no online service is perfectly secure — if a breach ever affects your data, I will tell you and the supervisory authority as the law requires.
09Children
This service is for professionals and is not intended for anyone under 18. I do not knowingly collect data from children.
10Changes to this policy
If I change anything meaningful, I will update the date at the top and email active members. Older versions are available on request.