← SSPUpdated 2026-06-09
§ SSP—LEGAL

Privacy Policy.

Who we are

Sovereign Sign Prortocall, operating Sovereign Sign Protocol ("SSP"), is the data controller for personal data processed in the application. Contact: privacy@ssp.invalid. EU representative: rep@ssp.invalid.

Data we process

  • Account: email, display name, hashed password (managed by our auth provider).
  • Masters: audio files you upload to a private bucket, plus SHA-256 hash, ISRC, ISWC, title, artist, duration.
  • Splits: contributor names, roles, Polygon wallet addresses, basis-point shares.
  • Wallet attestations: the signed EIP-191 message and signature proving you control a wallet.
  • Sanctions screening: cached boolean result from the Chainalysis OFAC oracle for each wallet you use.
  • Billing: name, billing address, and payment method details are collected and processed directly by Paddle (see Sub-processors). SSP stores only your Paddle customer/subscription IDs and subscription status.
  • Consent ledger: which cookie / policy versions you accepted, when, with a salted-hash of your IP and your user agent.

Legal bases (GDPR Art. 6)

Contract (running the service you asked for, including processing payments through Paddle), legal obligation (sanctions screening, tax/audit), and consent (analytics cookies, optional marketing). You can withdraw consent any time.

On-chain data

Anything written to Polygon (track hashes, splits, payments) is public and permanent. We cannot delete it. Don't include personal data in fields that get written on-chain.

Your rights

Under GDPR / UK GDPR / CCPA you can request access, rectification, portability, restriction, objection, and erasure. Use the self-service tools at /account/data or email privacy@ssp.invalid. We respond within 30 days.

Retention

Account data until you delete the account. Consent records 6 years (audit). Storage: deleted with the account. Billing records retained by Paddle per their retention policy and applicable tax law. On-chain records: permanent.

International transfers

Data is hosted in the EU. Sub-processors outside the EEA are bound by Standard Contractual Clauses.

Sub-processors & data sharing

We share personal data only with the following categories of recipients, each bound by contract:

  • Paddle.com Market Ltd. (Merchant of Record) — processes all payments, subscriptions, invoicing, sales tax/VAT, refunds, and chargebacks on our behalf. Paddle is an independent controller for the payment data it collects at checkout. See the Paddle Privacy Notice.
  • Auth & database hosting — session, profile, and application data storage.
  • Polygon RPC providers — broadcast on-chain transactions.
  • Chainalysis — sanctions screening oracle for wallet addresses.
  • Professional advisers & authorities — legal, accounting, or where required by law.

Full sub-processor list on request: subprocessors@ssp.invalid.

Security

We use appropriate technical and organisational measures — encryption in transit and at rest, access controls, least-privilege database policies — to protect personal data.

Complaints

You may lodge a complaint with your local supervisory authority (e.g. CNIL in France, ICO in the UK).