Privacy Policy
How HyperPulse International Company Limited, the company operating Spilix, collects, uses, shares, and protects your personal data.
1. Who We Are and Scope
Spilix (spilix.co) is operated by HyperPulse International Company Limited (Co., Ltd.), trading as HyperPulse Group, a company incorporated in Vietnam ("Spilix", "we"). We are the data controller responsible for the personal data described in this Policy.
This Policy applies to the Spilix website, dashboard, and related services, and should be read together with our Terms of Service and Cookie Policy. If you sign up on behalf of a label or company, it also covers the personal data you give us about your artists and contributors — you are responsible for having the right to share that data with us.
2. Information We Collect
Information you give us:
• Account: email, name, username, password (stored only as a bcrypt hash), country, preferred language, and your confirmation that you are at least 18 years old.
• Sign-in security: if you enable them, passkey public keys (WebAuthn) and the secret used to generate multi-factor authentication codes. Biometric data never leaves your device and is never sent to Spilix.
• Artist and label profile: stage name, bio, avatar, social links, and identifiers such as Spotify ID, Apple Music ID, and IPI/CAE.
• Content: master recordings, cover art, metadata, lyrics, songwriter splits, and contributor details.
• Billing: the payment method type and your transaction history. Card details are entered directly in the Dodo Payments checkout and tokenized by Dodo — Spilix never receives or stores full card numbers.
• Payout details: beneficiary name, address, bank account number or IBAN, SWIFT/BIC, and the other bank details needed to pay your royalties.
• Invoice details: the name, address, and email shown on the VAT invoice issued for each payment.
• Agreement records: when you accept our Terms, we record your name, email, IP address, device, the time, and the version accepted, and generate a PDF Agreement Record that Spilix digitally signs (possibly after the time of acceptance).
• Tax details: tax identification number and proof of tax residence, only where the law or a DSP requires it (Terms, Section 22).
• Support: the messages you send us and any contact details you include.
Information collected automatically:
• Usage and device data: IP address and the approximate country derived from it, browser and operating system, pages visited, dashboard actions, and access timestamps.
• Analytics data through Google Analytics, and ad click and conversion data through Google Ads and Meta, only if you choose "Accept all" in the cookie notice (see Section 9).
Information from third parties: delivery, streaming, and payment status from DSPs and from our payment and payout providers; public catalog data (for example artist and track statistics) from music data providers.
3. How We Use Information and Legal Bases
We process your personal data for the purposes below. Where the GDPR or a similar law applies, the legal basis is shown in brackets.
• Provide the service — create your account, distribute your releases, show analytics, and collect and pay your royalties [performance of a contract].
• Process payments and payouts through our providers, and issue the invoices the law requires [contract; legal obligation].
• Keep records of the agreements you accept and countersign them digitally [contract; legal obligation].
• Send transactional emails — release status, payout statements, security alerts, and support replies [contract].
• Send marketing emails about Spilix products, features and offers to users who registered an account and accepted the Terms (Section 2); every such email includes an unsubscribe link, and you can turn them off in your account settings [consent; legitimate interest in existing customers].
• Keep the service secure — session management, fraud prevention, abuse detection, and the geographic availability check based on your IP address described in Section 16 of the Terms [legitimate interests; legal obligation].
• Understand how the site is used and improve it, using Google Analytics only if you accept analytics cookies [consent].
• Measure which of our Google Ads and Meta ads lead to sign-ups and purchases, and show Spilix ads to people who have visited our site, using Google Ads and Meta only if you accept advertising cookies [consent].
• Check copyright and prevent content fraud, by generating an audio fingerprint of the recordings you upload and matching it against the ACRCloud music recognition database to detect matches with recordings owned by others [contract; legitimate interests].
• Comply with tax, accounting, anti-money-laundering, and other legal obligations, and respond to lawful requests from authorities [legal obligation].
We do not make automated decisions that have legal or similarly significant effects on you. The geographic availability check is automated, but it only determines whether Spilix is offered in your country.
4. Who We Share Information With
We share personal data only with the parties below, and only the data each one needs:
• Digital service providers (Spotify, Apple Music, YouTube, Zing MP3, JOOX, Boomplay, and the other stores you select): release metadata, audio, cover art, and the artist details required for distribution.
• Performing and mechanical rights organizations (BMI, ASCAP, GEMA, VCPMC, and others): work information and songwriter splits, if you subscribe to Publishing Admin.
• Dodo Payments (payment processor): checkout and subscription data. Card data goes directly to Dodo and is never seen by Spilix.
• Airwallex (payout provider): beneficiary name, address, and bank details, so that your royalty payouts can be sent.
• MISA (Vietnam): MISA MeInvoice receives the name, address, and email shown on each VAT invoice we are required to issue; MISA eSign receives the agreement PDF (containing your name, email, IP address, and acceptance time) so that our digital signature can be applied.
• Amazon Web Services: database (Aurora PostgreSQL), file storage (S3), content delivery (CloudFront), and transactional email (SES).
• ACRCloud (audio recognition): the audio file or audio fingerprint of the recordings you upload, with basic release metadata (title, artist name), to check copyright before distribution. ACRCloud does not receive your account, contact or payment details.
• Google: Google Analytics and Google Ads, only if you choose "Accept all" in the cookie notice. See the Cookie Policy.
• Meta: Meta Pixel and Meta Conversions API, only if you choose "Accept all" in the cookie notice, including your email address in hashed form, IP address and browser details. See the Cookie Policy.
• Music data providers (Soundcharts): we look up public artist and track identifiers to show streaming trends. No account data is sent.
• Internal tooling: operational alerts sent to our team through Discord may include account identifiers and invoice references.
• Authorities, advisers, and successors: when required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets (in which case you will be notified).
Spilix does not sell your personal data and does not share it with third parties for their own marketing.
5. International Transfers
Spilix is operated from Vietnam, and our team accesses data from there. Our infrastructure runs on Amazon Web Services in the United States and in Sydney, Australia. The providers listed in Section 4 may process data in other countries, including Vietnam (MISA) and the countries in which Dodo Payments, Airwallex, ACRCloud, and Google operate.
When we transfer personal data out of the EEA, the United Kingdom, or Switzerland, we rely on adequacy decisions where available and otherwise on Standard Contractual Clauses or the UK Addendum, together with encryption and access controls. Transfers of personal data out of Vietnam are made in accordance with Vietnam's personal data protection laws.
6. Storage and Security
Data is stored on AWS with encryption at rest and TLS encryption in transit. Passwords are stored only as bcrypt hashes. Audio and image files are stored on S3 with server-side encryption and delivered through CloudFront. Sessions use HttpOnly, Secure cookies, and you can add passkeys and multi-factor authentication to your account.
Access to production data is limited to staff who need it for their role. No system is completely secure and we cannot guarantee absolute security, but we apply these safeguards to protect your data from unauthorized access, loss, or alteration.
7. Data Retention
We keep personal data only for as long as it is needed for the purposes in Section 3. In practice:
• Account, profile, and content data: for as long as your account exists. Distribution is a continuing relationship — your releases stay on DSPs, royalties keep arriving, and we must be able to match them to you — so we do not delete this data on a fixed schedule while your catalog is live or royalties are still owed to you.
• Financial records (invoices, payments, payout statements, and agreement records): for the period required by Vietnamese accounting and tax law, generally ten years, even after your account is closed.
• Security and access logs: for the limited period needed for fraud prevention and incident investigation.
When you close your account and ask us to delete your data, we delete or anonymise the personal data we no longer need once your releases have been taken down and any outstanding royalties have been paid. We keep only the records the law requires us to keep, as described above. See Section 8 for how to make a request.
8. Your Rights
Depending on where you live, you have the rights below over your personal data. We honour them for all users regardless of location, subject to the legal limits described in this Policy.
• Access: obtain a copy of the personal data we hold about you.
• Rectification: correct inaccurate or incomplete data. Most account and profile data can be edited directly in your dashboard.
• Erasure: ask us to delete your account and personal data. Releases already delivered may remain on DSPs under your artist name according to the distribution agreements, and we keep the records the law requires (Section 7).
• Restriction and objection: ask us to limit certain processing, or object to processing based on our legitimate interests.
• Portability: receive your account data in a structured, machine-readable format (JSON or CSV), prepared on request.
• Withdraw consent: at any time, for processing based on consent — for example by clearing this site's data in your browser so that the cookie notice appears again, or by using the unsubscribe link in a marketing email.
• Complain: lodge a complaint with your data protection authority. In Vietnam this is the Department of Cybersecurity and Hi-tech Crime Prevention (A05) of the Ministry of Public Security; in the EEA or the UK, your national supervisory authority.
• California residents (CCPA/CPRA): the rights to know, delete, and correct personal data, to opt out of its sale or sharing (we do not sell or share it), and not to be discriminated against for exercising these rights.
• Vietnam (Decree 13/2023/ND-CP and the Law on Personal Data Protection): the rights to be informed, to give and withdraw consent, to access, correct, delete, restrict, and object to processing, to request the provision of your data, to complain, to claim damages, and to self-protect, as provided by those laws.
To exercise any right, email privacy@spilix.co from the address on your account. We may ask you to verify your identity. We respond within 30 days, or sooner where the law requires a shorter period (for example 72 hours for certain requests under Vietnamese law), and we will tell you if a complex request needs more time.
9. Cookies, Analytics and Advertising
Spilix sets one essential cookie (spilix_session) to keep you signed in. With your consent, we also use Google Analytics 4, which sets analytics cookies and sends usage data — pages viewed, events such as sign-ups and purchases, device and browser information, and a truncated IP address — to Google, and Google Ads and the Meta Pixel, which set advertising cookies that record whether you reached Spilix from one of our ads on Google, Facebook, or Instagram, so we can measure which ads lead to sign-ups and purchases and show Spilix ads to people who visited the site. None of these are loaded until you choose "Accept all" in the cookie notice. To change your choice later, clear this site's cookies and site data in your browser settings: the cookie notice will appear again on your next visit.
We do not sell your personal data. Full details — cookie names, purposes, durations, and the browser storage we use — are in our Cookie Policy.
10. Children
You must be at least 18 to use Spilix, as set out in the Terms. We do not knowingly collect personal data from anyone under 18. If you believe an under-age person has registered, contact privacy@spilix.co and we will delete the account.
11. Data Breaches
If a personal data breach is likely to put your rights at risk, we will notify you and the competent authority without undue delay and within the timeframes required by applicable law, and tell you what we are doing about it.
12. Changes to This Policy
We may update this Policy from time to time. For material changes — new purposes, new categories of third parties, or reduced rights — we will notify you by email and by an in-app notice at least 30 days before they take effect. Minor changes take effect when posted, with the "Last updated" date revised.
13. Contact
For questions about this Policy or to exercise your rights, contact privacy@spilix.co.
Data controller: HyperPulse International Company Limited (Co., Ltd.) — trading as HyperPulse Group — a company incorporated in Vietnam. Tax code: 4401107251. Registered address: Hoa Nghia, Van Hoa, Dak Lak, Vietnam.