Versione italiana in preparazione. Fino alla pubblicazione della traduzione ufficiale, fa fede la versione inglese qui sotto.
Legal

Privacy Policy

Choral Network is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store and safeguard your information in compliance with the EU General Data Protection Regulation (GDPR).

Last updated: 17 June 2026

Data Controller

The data controller for the Choral Network platform is the legal entity operating the service, responsible for determining the purposes and means of processing your personal data.

Choral Network

Email: support@choral.network

If you have any questions about how your data is handled, or wish to exercise any of your rights under the GDPR, please contact us using the details above.

Categories of Collected Personal Data

We collect and process the following categories of personal data, depending on how you use the platform:

  • Identity Data

    Name, email address, profile photo, date of birth (optional), and public profile information.

  • Authentication Data

    Encrypted password hashes and session tokens managed by Supabase Auth.

  • Musical Identity Data

    Vocal family (e.g., soprano, alto, tenor, bass), vocal sections, singing experience level, and repertoire preferences. This data is optional and user-controlled.

  • Choir & Membership Data

    Choir profiles you create or join, your role within a choir (singer, director, admin), official titles, and membership status.

  • Communication Data

    Messages sent through the platform, notification preferences, and email correspondence.

  • Activity Data

    Event applications, opportunity postings, file uploads (scores, recordings), and discovery/matching interactions.

  • Technical Data

    IP address, browser type, device information, and cookies used for security and analytics (see below).

Purpose of Processing

We process your personal data for the following purposes:

  • Account Provision & Management

    To create and maintain your user account, authenticate your identity, and provide platform access.

  • Choir Operations

    To enable choir profile management, member directories, invitation workflows, and role-based access within choirs.

  • Matching & Discovery

    To power the intelligent matching system that connects singers with choirs and opportunities based on musical identity and preferences.

  • Communication

    To send platform notifications, email alerts, and enable direct messaging between users and choirs.

  • Event & Opportunity Management

    To process event applications, manage opportunity postings, and coordinate participation.

  • Security & Fraud Prevention

    To protect the platform against spam, abuse, and unauthorized access using Cloudflare Turnstile and security monitoring.

  • Platform Improvement

    To analyse aggregate usage patterns and improve the platform experience. We do not use personal data for automated profiling that produces legal or similarly significant effects.

Data Retention Periods

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • Account Data

    Retained for the duration of your active account. You may initiate self-service account deletion at any time from /settings/account. See the Right to Erasure section below for details on what happens when your account is deleted.

  • Choir Data

    Retained while the choir is active. When a choir is deactivated, data is preserved in an archived state and excluded from public discovery. Choir owners may request complete deletion.

  • Communication Data

    Messages and other user-generated content linked to your account are removed when your account is deleted, through cascade deletion. Certain non-personal or anonymised records may be retained where necessary for legal or integrity purposes.

  • Security Logs

    We do not currently maintain a separate security log system beyond standard server access logs managed by our hosting provider.

  • Backup Data

    Our infrastructure provider manages automated backups as part of their standard service. We do not directly control backup schedules or retention periods.

Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights:

  • Right of Access (Art. 15)

    You have the right to obtain confirmation of whether your personal data is being processed, and if so, access to that data and information about how it is used.

  • Right to Rectification (Art. 16)

    You have the right to request the correction of inaccurate personal data and to have incomplete data completed.

  • Right to Erasure (Art. 17)

    You have the right to request deletion of your personal data in certain circumstances. See the Right to Erasure section below for details.

  • Right to Restriction (Art. 18)

    You have the right to request that we restrict processing of your personal data where certain conditions apply.

  • Right to Data Portability (Art. 20)

    You have the right to receive your personal data in a structured, commonly used, and machine-readable format. See the Data Portability section below.

  • Right to Object (Art. 21)

    You have the right to object to processing based on legitimate interests or for direct marketing purposes.

  • Right to Withdraw Consent

    Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

  • Right to Lodge a Complaint

    You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

To exercise any of these rights, please contact us at support@choral.network. We will respond within 30 days of receiving your request.

Data Portability

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.

Future capability: We plan to introduce a self-service data export feature that will include your profile information, choir memberships, musical identity data, and activity history in JSON format. Until this feature is available, you may request a copy of your personal data by emailing us at support@choral.network. We will respond to all requests in accordance with GDPR timeframes.

Right to Erasure

You have the right to request the deletion of your personal data ("right to be forgotten") in the following circumstances:

  • The data is no longer necessary for the purposes it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • The data must be erased for compliance with a legal obligation

Limitations: The right to erasure does not apply where processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest, or for the establishment, exercise or defence of legal claims.

Self-service account deletion: You can initiate permanent deletion of your account and associated personal data at any time by visiting /settings/account. The process includes the following safeguards and consequences:

  • Password confirmation

    You must enter your current password to verify your identity before the deletion request is accepted.

  • Explicit confirmation

    You must type "DELETE" as an explicit confirmation of your intent to permanently delete your account.

  • Choir ownership check

    If you currently own one or more choirs, deletion is blocked. You must first transfer ownership of each choir to another member, or delete or deactivate the choir, before you can delete your account.

  • Profile anonymisation

    Your public profile is anonymised so that any content that must remain visible on the platform is no longer linked to your identity.

  • Avatar removal

    Your uploaded avatar image is removed from storage where applicable.

  • Authentication account deletion

    Your authentication account is permanently deleted, which revokes all active sessions and prevents future login.

  • Cascade data removal

    Data linked to your user record through cascade deletion (such as memberships, messages, and applications) is removed together with your account.

  • Preserved records

    Certain non-personal, anonymised, legal, security, or integrity records may be preserved where necessary to comply with legal obligations, protect the rights of others, or maintain platform integrity.

Deletion is initiated immediately upon successful confirmation. You may also request deletion by emailing support@choral.network.

Right to Object

You have the right to object at any time to processing of your personal data which is based on legitimate interests (Article 6(1)(f) GDPR) or for direct marketing purposes.

If you object to processing for direct marketing, we will cease processing your personal data for that purpose immediately. For other objections based on legitimate interests, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.

You can manage your notification preferences in your account settings, or submit an objection by emailing support@choral.network.

Third-Party Service Providers

We engage the following categories of third-party processors to provide our services. All processors are bound by data processing agreements compliant with Article 28 GDPR:

  • Supabase (PostgreSQL, Auth, Storage)

    Cloud infrastructure provider for database hosting, authentication, and file storage. Data is stored in the European Union.

  • Vercel

    Hosting and edge network provider for the Choral Network application. Vercel processes technical data (IP addresses, request logs) as a data processor.

  • Resend

    Transactional email delivery service for account verification, password resets, notifications, and choir invitations.

  • Cloudflare (Turnstile)

    Anti-spam and bot protection service. Turnstile processes minimal technical data to verify human users without displaying traditional CAPTCHA challenges.

  • Google Maps Platform

    Address autocomplete and place lookup for choir locations and rehearsal venues. Google receives the search text you type and returns suggested places; no account data or user identifiers are sent. Subject to Google's privacy policy.

We do not sell your personal data to third parties. We do not share your data with advertisers or data brokers.

International Data Transfers

Choral Network is designed for users in Europe. Your personal data is primarily stored and processed within the European Union.

Where we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with Chapter V GDPR, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries recognised by the European Commission as providing adequate data protection
  • Binding Corporate Rules (where applicable) for intra-group transfers

If you would like more information about the specific safeguards applied to international transfers, please contact us at support@choral.network.

Security Measures

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:

  • Encryption in Transit

    All data transmitted between your browser and our servers is protected using TLS 1.3 encryption.

  • Encryption at Rest

    Database contents and file storage are encrypted at rest using AES-256 encryption.

  • Row-Level Security (RLS)

    Database access is strictly controlled through Row-Level Security policies, ensuring users can only access data they are authorised to view.

  • Secure Authentication

    Passwords are hashed by Supabase Auth using bcrypt. Session tokens are managed securely with industry-standard practices.

  • Access Control

    Role-based access control (RBAC) ensures that choir members, directors, and admins can only perform actions appropriate to their role.

  • Anti-Spam Protection

    Cloudflare Turnstile protects registration and public forms from automated abuse without compromising user privacy.

  • Security Monitoring

    We monitor for suspicious activity and maintain audit logs of administrative actions.

Despite our efforts, no internet transmission or electronic storage is completely secure. We encourage you to use strong, unique passwords and enable all available security features.

Contact Information for Privacy Requests

For all privacy-related inquiries, data subject access requests, GDPR requests, support requests, data access requests, data deletion requests, or general inquiries, please contact us at:

Choral Network

Email: support@choral.network

Response time: within 30 days for all formal requests

If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. In Italy, this is the Garante per la Protezione dei Dati Personali.