Data Controller
The data controller for the Choral Network platform is the legal entity operating the service, responsible for determining the purposes and means of processing your personal data.
Choral Network
Email: support@choral.network
If you have any questions about how your data is handled, or wish to exercise any of your rights under the GDPR, please contact us using the details above.
Categories of Collected Personal Data
We collect and process the following categories of personal data, depending on how you use the platform:
Identity Data
Name, email address, profile photo, date of birth (optional), and public profile information.
Authentication Data
Encrypted password hashes and session tokens managed by Supabase Auth.
Musical Identity Data
Vocal family (e.g., soprano, alto, tenor, bass), vocal sections, singing experience level, and repertoire preferences. This data is optional and user-controlled.
Choir & Membership Data
Choir profiles you create or join, your role within a choir (singer, director, admin), official titles, and membership status.
Communication Data
Messages sent through the platform, notification preferences, and email correspondence.
Activity Data
Event applications, opportunity postings, file uploads (scores, recordings), and discovery/matching interactions.
Technical Data
IP address, browser type, device information, and cookies used for security and analytics (see below).
Purpose of Processing
We process your personal data for the following purposes:
Account Provision & Management
To create and maintain your user account, authenticate your identity, and provide platform access.
Choir Operations
To enable choir profile management, member directories, invitation workflows, and role-based access within choirs.
Matching & Discovery
To power the intelligent matching system that connects singers with choirs and opportunities based on musical identity and preferences.
Communication
To send platform notifications, email alerts, and enable direct messaging between users and choirs.
Event & Opportunity Management
To process event applications, manage opportunity postings, and coordinate participation.
Security & Fraud Prevention
To protect the platform against spam, abuse, and unauthorized access using Cloudflare Turnstile and security monitoring.
Platform Improvement
To analyse aggregate usage patterns and improve the platform experience. We do not use personal data for automated profiling that produces legal or similarly significant effects.
Legal Basis of Processing
Under Article 6 of the GDPR, we rely on the following legal bases for processing your personal data:
Performance of a Contract (Art. 6(1)(b))
Processing necessary to provide the Choral Network service to you, including account management, choir operations, and matching functionality.
Consent (Art. 6(1)(a))
Processing based on your explicit consent, such as optional profile fields, marketing communications, and certain analytics cookies. You may withdraw consent at any time.
Legitimate Interests (Art. 6(1)(f))
Processing necessary for our legitimate interests in maintaining platform security, preventing fraud, and improving the service, provided these interests do not override your fundamental rights and freedoms.
Legal Obligation (Art. 6(1)(c))
Processing required to comply with applicable law, such as tax regulations or responding to lawful requests from public authorities.
Data Retention Periods
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
Account Data
Retained for the duration of your active account. You may initiate self-service account deletion at any time from /settings/account. See the Right to Erasure section below for details on what happens when your account is deleted.
Choir Data
Retained while the choir is active. When a choir is deactivated, data is preserved in an archived state and excluded from public discovery. Choir owners may request complete deletion.
Communication Data
Messages and other user-generated content linked to your account are removed when your account is deleted, through cascade deletion. Certain non-personal or anonymised records may be retained where necessary for legal or integrity purposes.
Security Logs
We do not currently maintain a separate security log system beyond standard server access logs managed by our hosting provider.
Backup Data
Our infrastructure provider manages automated backups as part of their standard service. We do not directly control backup schedules or retention periods.
Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights:
Right of Access (Art. 15)
You have the right to obtain confirmation of whether your personal data is being processed, and if so, access to that data and information about how it is used.
Right to Rectification (Art. 16)
You have the right to request the correction of inaccurate personal data and to have incomplete data completed.
Right to Erasure (Art. 17)
You have the right to request deletion of your personal data in certain circumstances. See the Right to Erasure section below for details.
Right to Restriction (Art. 18)
You have the right to request that we restrict processing of your personal data where certain conditions apply.
Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format. See the Data Portability section below.
Right to Object (Art. 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
To exercise any of these rights, please contact us at support@choral.network. We will respond within 30 days of receiving your request.
Data Portability
You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance.
Future capability: We plan to introduce a self-service data export feature that will include your profile information, choir memberships, musical identity data, and activity history in JSON format. Until this feature is available, you may request a copy of your personal data by emailing us at support@choral.network. We will respond to all requests in accordance with GDPR timeframes.
Right to Erasure
You have the right to request the deletion of your personal data ("right to be forgotten") in the following circumstances:
- The data is no longer necessary for the purposes it was collected
- You withdraw consent and there is no other legal basis for processing
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
- The data must be erased for compliance with a legal obligation
Limitations: The right to erasure does not apply where processing is necessary for exercising the right of freedom of expression and information, for compliance with a legal obligation, for the performance of a task carried out in the public interest, or for the establishment, exercise or defence of legal claims.
Self-service account deletion: You can initiate permanent deletion of your account and associated personal data at any time by visiting /settings/account. The process includes the following safeguards and consequences:
Password confirmation
You must enter your current password to verify your identity before the deletion request is accepted.
Explicit confirmation
You must type "DELETE" as an explicit confirmation of your intent to permanently delete your account.
Choir ownership check
If you currently own one or more choirs, deletion is blocked. You must first transfer ownership of each choir to another member, or delete or deactivate the choir, before you can delete your account.
Profile anonymisation
Your public profile is anonymised so that any content that must remain visible on the platform is no longer linked to your identity.
Avatar removal
Your uploaded avatar image is removed from storage where applicable.
Authentication account deletion
Your authentication account is permanently deleted, which revokes all active sessions and prevents future login.
Cascade data removal
Data linked to your user record through cascade deletion (such as memberships, messages, and applications) is removed together with your account.
Preserved records
Certain non-personal, anonymised, legal, security, or integrity records may be preserved where necessary to comply with legal obligations, protect the rights of others, or maintain platform integrity.
Deletion is initiated immediately upon successful confirmation. You may also request deletion by emailing support@choral.network.
Right to Object
You have the right to object at any time to processing of your personal data which is based on legitimate interests (Article 6(1)(f) GDPR) or for direct marketing purposes.
If you object to processing for direct marketing, we will cease processing your personal data for that purpose immediately. For other objections based on legitimate interests, we will stop processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
You can manage your notification preferences in your account settings, or submit an objection by emailing support@choral.network.
Third-Party Service Providers
We engage the following categories of third-party processors to provide our services. All processors are bound by data processing agreements compliant with Article 28 GDPR:
Supabase (PostgreSQL, Auth, Storage)
Cloud infrastructure provider for database hosting, authentication, and file storage. Data is stored in the European Union.
Vercel
Hosting and edge network provider for the Choral Network application. Vercel processes technical data (IP addresses, request logs) as a data processor.
Resend
Transactional email delivery service for account verification, password resets, notifications, and choir invitations.
Cloudflare (Turnstile)
Anti-spam and bot protection service. Turnstile processes minimal technical data to verify human users without displaying traditional CAPTCHA challenges.
Google Maps Platform
Address autocomplete and place lookup for choir locations and rehearsal venues. Google receives the search text you type and returns suggested places; no account data or user identifiers are sent. Subject to Google's privacy policy.
We do not sell your personal data to third parties. We do not share your data with advertisers or data brokers.
International Data Transfers
Choral Network is designed for users in Europe. Your personal data is primarily stored and processed within the European Union.
Where we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with Chapter V GDPR, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions for countries recognised by the European Commission as providing adequate data protection
- Binding Corporate Rules (where applicable) for intra-group transfers
If you would like more information about the specific safeguards applied to international transfers, please contact us at support@choral.network.
Security Measures
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction:
Encryption in Transit
All data transmitted between your browser and our servers is protected using TLS 1.3 encryption.
Encryption at Rest
Database contents and file storage are encrypted at rest using AES-256 encryption.
Row-Level Security (RLS)
Database access is strictly controlled through Row-Level Security policies, ensuring users can only access data they are authorised to view.
Secure Authentication
Passwords are hashed by Supabase Auth using bcrypt. Session tokens are managed securely with industry-standard practices.
Access Control
Role-based access control (RBAC) ensures that choir members, directors, and admins can only perform actions appropriate to their role.
Anti-Spam Protection
Cloudflare Turnstile protects registration and public forms from automated abuse without compromising user privacy.
Security Monitoring
We monitor for suspicious activity and maintain audit logs of administrative actions.
Despite our efforts, no internet transmission or electronic storage is completely secure. We encourage you to use strong, unique passwords and enable all available security features.
Contact Information for Privacy Requests
For all privacy-related inquiries, data subject access requests, GDPR requests, support requests, data access requests, data deletion requests, or general inquiries, please contact us at:
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. In Italy, this is the Garante per la Protezione dei Dati Personali.