Skip to content

Legal

Data processing and UK GDPR notice

Roles, legal bases, transfers and the rights of data subjects under the UK GDPR and the Data Protection Act 2018.

Last updated 8 September 2026

Roles

For applicants, account holders and their team members, Hovnect is the controller. For the personal data of the artists, songwriters and other contributors you enter into the platform, you are the controller and Hovnect is the processor acting on your documented instructions under Article 28 of the UK GDPR: we deliver that data to stores and use it to pay you, and for nothing else. These terms, together with the distribution agreement, form the processing terms between us.

Legal bases

  • Contract: applications, accounts, deliveries, royalties, payouts, agreements, support.
  • Legal obligation: accounting records, tax, responding to lawful requests.
  • Legitimate interests: security, fraud prevention, service notifications, audit trails.
  • Consent: marketing email, which you can withdraw at any time.

Processors we use

Hosting and functions, database hosting, object storage for artwork and audio, transactional email, our distribution partner for deliveries and reports, and payment providers for payouts. Each is bound by a written agreement, processes data only on our instructions and applies appropriate technical and organisational measures. A current list is available on request.

International transfers

Data may be processed in the United Kingdom, the European Economic Area and the United States. Transfers out of the UK rely on the UK's adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses, with a transfer risk assessment where one is required.

Retention

Rejected applications 12 months; account and catalogue data for the life of the account and the royalty tail; financial records six years after the end of the relevant financial year; logs 90 days. Backups roll over within 35 days.

Rights of data subjects

Under the UK GDPR you may ask to access your personal data, have it corrected or erased, restrict or object to its processing, receive it in a portable form and not be subject to a decision based solely on automated processing that has legal or similarly significant effects. Hovnect makes no such automated decisions. Requests go to hello@northsongs.com and are answered within one month at no cost; where we act as processor we pass the request to the controller and help them answer it. You may also complain to the Information Commissioner's Office.

Security measures

Encryption in transit, hashed passwords, optional two-factor authentication with recovery codes, private storage with signed links, role-based access inside organisations, an audit log of significant actions and least-privilege access for staff.

Sub-processor changes and breaches

We announce new processors in the platform before they handle your data, and you may object on reasonable grounds. Personal data breaches that are likely to result in a risk to you are reported to the Information Commissioner's Office within 72 hours of our becoming aware of them and to you without undue delay; where we act as processor we notify the controller without undue delay.

Data processing and UK GDPR notice · Hovnect