Privacy Policy

Last updated

1. Introduction

At Fragments.fm ("we," "us," "our"), operated by A08 Consulting, we are committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our music storytelling platform and related services (the "Services").

This Privacy Policy applies to all users of Fragments.fm, including visitors, registered users, and subscribers.

Data Controller

A08 Consulting is the data controller responsible for your personal data:

A08 Consulting
Ratakatu 9 B 11
00120 Helsinki, Finland
Business ID: 3446829-3
VAT ID: FI34468293
Email: legal@fragments.fm

For questions about this Privacy Policy or our data practices, contact us at legal@fragments.fm.


2. Information We Collect

We collect information in the following ways:

2.1 Information You Provide Directly

Account Information

  • Name and display name
  • Email address
  • Password (stored in encrypted form)
  • Profile information (biography, profile picture, links)

User Content

  • Stories you create about your music
  • Text, images, and media you upload
  • Comments and interactions with other users' content

Payment Information

  • Billing name and address
  • Payment card details (processed and stored by our payment processor, not stored by us)
  • Transaction history

Communications

  • Messages you send to us (support requests, feedback)
  • Survey responses
  • Email correspondence

Connected Services

  • Information from music platforms you choose to connect (e.g., Spotify, Apple Music) to display your music in stories
  • We only access the specific data needed to provide features you request

2.2 Information Collected Automatically

Usage Data

  • Pages and features you access
  • Actions you take within the Services
  • Time, frequency, and duration of your activities

Device and Technical Information

  • IP address
  • Browser type and version
  • Operating system
  • Device type and identifiers
  • Screen resolution and language preferences

Cookies and Similar Technologies

  • We use cookies and similar technologies as described in Section 8 below

Log Data

  • Server logs recording your interactions with the Services
  • Error reports and performance data

2.3 Information from Third Parties

  • Authentication providers: If you sign in using a third-party service (e.g., Google), we receive basic profile information from that service
  • Payment processors: Confirmation of successful payments and basic transaction data
  • Analytics providers: Aggregated usage statistics

3. How We Use Your Information

We use your personal data for the following purposes and legal bases:

PurposeLegal Basis (GDPR Art. 6)
Providing the Services – Creating and managing your account, enabling you to create and share stories, processing transactionsPerformance of contract
Communication – Sending service-related messages, responding to your inquiries, providing customer supportPerformance of contract
Payment processing – Processing subscriptions and purchases, sending invoices and receiptsPerformance of contract
Service improvement – Analyzing usage patterns, fixing bugs, developing new featuresLegitimate interests
Security – Detecting and preventing fraud, abuse, and security incidents; enforcing our termsLegitimate interests
Personalization – Customizing your experience based on your preferences and usageLegitimate interests
Marketing – Sending promotional communications about new features and offers (with your consent)Consent
Legal compliance – Complying with legal obligations, responding to legal requestsLegal obligation

Legitimate Interests: Where we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms. You may object to processing based on legitimate interests as described in Section 5.


4. How We Share Your Information

We do not sell your personal data. We share your information only in the following circumstances:

4.1 With Your Consent

When you choose to share your stories publicly or with specific users, that content is visible to those audiences.

4.2 Service Providers

We share data with third-party service providers who help us operate the Services, including:

Provider TypePurposeData Shared
Cloud hostingInfrastructure and storageAll data processed through Services
Payment processorsPayment processingPayment and billing information
Email servicesTransactional and marketing emailsEmail address, name
AnalyticsUsage analysis and improvementUsage data, device information
Customer supportHelp desk and support ticketsContact information, support communications

All service providers are contractually obligated to protect your data and may only use it for the purposes we specify.

4.3 Legal Requirements

We may disclose your information if required to do so by law or if we believe in good faith that such disclosure is necessary to:

  • Comply with legal obligations or valid legal process
  • Protect and defend our rights or property
  • Prevent fraud or abuse of the Services
  • Protect the safety of users or the public

4.4 Business Transfers

If A08 Consulting is involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have.

4.5 Aggregated or Anonymized Data

We may share aggregated or anonymized data that cannot reasonably be used to identify you for any purpose, including research and analytics.


5. Your Privacy Rights

Under the General Data Protection Regulation (GDPR) and Finnish data protection law, you have the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

You have the right to request correction of inaccurate personal data and to have incomplete data completed.

Right to Erasure ("Right to Be Forgotten")

You have the right to request deletion of your personal data in certain circumstances, including when:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent (where processing is based on consent)
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed

Right to Restriction of Processing

You have the right to request that we restrict processing of your data in certain circumstances, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing purposes. If you object to direct marketing, we will stop processing your data for that purpose.

Right to Withdraw Consent

Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. In Finland, the relevant authority is:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
Lintulahdenkuja 4, 00530 Helsinki, Finland
Website: www.tietosuoja.fi
Email: tietosuoja@om.fi

How to Exercise Your Rights

To exercise any of these rights, contact us at legal@fragments.fm. We will respond to your request within one month. If your request is complex or we receive many requests, we may extend this period by up to two additional months, in which case we will inform you.

We may need to verify your identity before processing your request. We will not charge a fee for most requests, but we may charge a reasonable fee or refuse to act on requests that are manifestly unfounded or excessive.


6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.

Data TypeRetention Period
Account informationDuration of account plus 30 days after deletion request
User ContentDuration of account plus 30 days after deletion (unless shared with other users who retain access)
Payment records7 years (Finnish accounting law requirement)
Support communications3 years after resolution
Usage and analytics data26 months
Server logs90 days
Marketing consent recordsDuration of consent plus 3 years

After the retention period expires, we will securely delete or anonymize your data. Some data may be retained longer if required by law or for legitimate business purposes (e.g., defending legal claims).


7. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA), including countries that may not provide the same level of data protection as Finland or the EU.

When we transfer data outside the EEA, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs): We use EU-approved standard contractual clauses with our service providers
  • Adequacy decisions: We transfer data to countries that the European Commission has determined provide adequate protection

You may request information about the safeguards we use for international transfers by contacting us at legal@fragments.fm.


8. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve the Services.

Types of Cookies We Use

Cookie TypePurposeDuration
Strictly NecessaryEssential for the Services to function (e.g., authentication, security)Session or persistent
FunctionalRemember your preferences and settingsUp to 1 year
AnalyticsUnderstand how users interact with the ServicesUp to 2 years
MarketingDeliver relevant advertisements (only with consent)Up to 1 year

Your Cookie Choices

When you first visit Fragments.fm, we will ask for your consent to use non-essential cookies. You can change your preferences at any time through our cookie settings or your browser settings. Blocking certain cookies may affect functionality.


9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

Technical Measures

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure password hashing
  • Regular security assessments and penetration testing
  • Access controls and authentication requirements
  • Firewalls and intrusion detection systems

Organizational Measures

  • Staff training on data protection
  • Access limited to personnel who need it
  • Confidentiality agreements with employees and contractors
  • Incident response procedures

Beta Notice: While we implement reasonable security measures, please be aware that the Services are in beta. No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your data.

If you become aware of any security breach or unauthorized access to your account, please notify us immediately at support@fragments.fm.


10. Children's Privacy

Fragments.fm is not intended for children under 18 years of age. We do not knowingly collect personal data from children under 18.

If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information as quickly as possible. If you believe we may have collected data from a child under 18, please contact us at legal@fragments.fm.


11. Third-Party Links and Services

The Services may contain links to third-party websites or integrate with third-party services (such as music streaming platforms). This Privacy Policy does not apply to those third-party services.

We encourage you to read the privacy policies of any third-party services you access through Fragments.fm. We are not responsible for the privacy practices of third parties.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors.

How We Notify You:

  • We will post the updated Privacy Policy on this page with a new "Last Updated" date
  • For material changes, we will notify you by email or by a prominent notice on the Services before the changes take effect

Your Continued Use: Your continued use of the Services after any changes indicates your acceptance of the updated Privacy Policy. If you do not agree to the changes, you should stop using the Services and may request deletion of your account.


13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

A08 Consulting
Ratakatu 9 B 11
00120 Helsinki, Finland

General inquiries and support: support@fragments.fm
Privacy, legal, and data protection matters: legal@fragments.fm

We aim to respond to all privacy-related inquiries within one month.


By using Fragments.fm, you acknowledge that you have read and understood this Privacy Policy.