Privacy Policy

Last updated: 30 July 2026. This policy covers the Sampularity website and the Sampularity application. In short: this site sets no cookies and runs no analytics, your samples never leave your machine, and the personal data we hold is what a purchase and a licence require.

1. Controller

Luca Zidane Bartl (zidArts), Mohnweg 2, 67346 Speyer, Deutschland.
Email: support@sampularity.com

2. Hosting and server logs

This website is delivered by Cloudflare Germany GmbH (Rosental 7, 80331 München) and its group companies, including Cloudflare, Inc. in the United States, acting as our processor under Art. 28 GDPR. Downloads are served from the same provider’s object storage (dl.sampularity.com). Delivering a page necessarily processes technical connection data (IP address, requested URL, timestamp, user agent). Legal basis: Art. 6 (1)(f) GDPR, our legitimate interest in operating the site securely and defending it against attack.

Because this provider operates a global network, that data may be processed outside the EU, including in the United States. The transfer is covered by the European Commission’s Standard Contractual Clauses agreed with the provider, supplemented by its own technical and organisational measures. We do not enable per-request access logging of our own and keep no access logs ourselves; the provider processes connection data for the duration of the request and for its own security purposes under its retention rules. See Cloudflare’s privacy policy.

3. Cookies and analytics

This website sets no cookies and uses no analytics or tracking services. It loads no fonts, scripts or images from third-party servers: everything the page needs is served from this domain. The only third party involved is the payment provider, and only after you open the checkout yourself (section 4).

4. Payment processing (Paddle)

Purchases are processed by Paddle.com Market Ltd. (Judd House, 18-29 Mora Street, London EC1V 8BT, United Kingdom) as our merchant of record. The Paddle checkout is loaded only when you click a buy button. Until then, no connection to Paddle is made: the price you see on our pages is a fixed value stored in this website, not a live lookup. When you open the checkout, Paddle loads its own software into the page, may store data on your device for that purpose, and processes the data required to complete the purchase (e.g. name, email address, country, payment details) under its own responsibility. See Paddle’s privacy policy.

After a completed purchase, we receive your order details (name, email, product, order id) from Paddle in order to issue and deliver your license (Art. 6 (1)(b) GDPR: performance of contract).

5. Our own records (licence database)

Issuing, delivering and re-sending a licence requires us to keep records of our own. They live in a database on a virtual private server rented from netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe) and located in Germany; there is no transfer outside the EU. We hold:

CustomerName and email address, as received from the payment provider
OrderOrder id, amount, currency, provider, the purchased price id, refund flag
LicenceThe signed licence itself, which contains your name and email address; plus the times it was re-sent or revoked
ActivationHardware identifier, first and last contact, app version
DeliveryRecipient address and time of each licence email
Payment eventsProvider, event id, event type and time. The provider’s message itself is not stored.

Legal basis: Art. 6 (1)(b) GDPR (performance of the contract). The first five are kept for as long as your licence exists, because they are what lets us re-send it, verify it and enforce the number of seats you bought. Invoices are issued and retained by the payment provider as merchant of record, not by us.

When the payment provider notifies us of a purchase or a refund, its message contains far more than we need, including the cardholder name and the last four digits and expiry date of the card. We read the handful of fields required to issue your licence and discard the message; only the fact that an event was received and handled is recorded, so that the same notification cannot be processed twice. Your payment details are therefore never stored by us. (Until 30 July 2026 the full message was kept for 90 days. It was never read by anything, so it has been removed and existing copies were erased.)

6. License delivery and support email

If you contact us by email or receive your license by email, we process your email address and message content to handle your request and deliver the product (Art. 6 (1)(b) GDPR). Our mailboxes are hosted by netcup GmbH in Germany.

7. The Sampularity application

No audio content, file name or library data ever leaves your machine. Analysis, tagging, similarity and the Nebula map are computed locally; the app does not upload your collection anywhere and has no account system.

If your license requires online activation, the app contacts our activation server (same server and location as section 5) to manage licence seats (Art. 6 (1)(b) GDPR). On the first activation it sends the complete signed licence, which includes your name and email address, together with a hardware identifier and the app version. Every later check sends only the licence id, the hardware identifier and the activation id. The hardware identifier is a value derived from characteristics of your computer; it exists so that a licence can count how many machines use it, and it does not tell us anything about your machine beyond distinguishing it from another one. The activation server keeps no access log.

The desktop app also checks once a day whether a newer version has been released. It requests a single static file, sampularity.com/latest.json, and reads nothing from it but the version number. No licence data, no hardware identifier and no usage data are sent; as with any web request, the connection data described in section 2 is processed by our hosting provider, and this request goes to the same provider as the website itself. Nothing is downloaded or installed automatically: if a newer version exists, the app shows a dismissible note linking to the download page. You can switch the check off at any time under Settings → Updates; the plug-in never performs it. Legal basis: our legitimate interest in supplying you with a current, secure version (Art. 6 (1)(f) GDPR).

8. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21 GDPR). You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). For us that is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, but you may also contact the authority where you live.

Write to support@sampularity.com from the address you bought with, and we will answer within one month (Art. 12 (3) GDPR). We only ask for further proof of identity if we have real doubts that the request is yours, and we will not ask for an identity document when the purchase address already answers the question.

Three things worth knowing before you ask for erasure. Your licence carries your name and email address inside its signature, so they cannot be stripped out of it: erasing the record means deleting the licence, after which we can no longer re-send or verify it, and you should keep your own copy first. Your payment and invoice data sit with Paddle as merchant of record, which is a separate controller, so a request about those goes to them. And backups run on their own cycle: they cannot be edited, they are used for nothing but restoring a failure, and the deleted data disappears from them as they expire.

9. Changes

We will update this policy when the website or product changes in ways that affect data processing. The current version is always available at this address.