Privacy Policy

Last updated on June 5 2026

1. General information, Controller

Protection of your personal data is very important to us. We process your data exclusively in compliance with the legal provisions (GDPR, Austrian Data Protection Act (DSG), Telecommunication Act (TKG 2021)). In this privacy policy, we inform you about the most important aspects of data processing.

In order to provide our online platform and services, we process information about you, known as personal data – or "data" for short. The term "processing" refers to any handling of data, such as the collection, storage, use, and erasure of personal data.

We are happy to inform you in this privacy policy about the processing of your personal data and the claims and rights to which you are entitled under data protection regulations.

The entity responsible for processing your personal data (“controller”) is:

Beat Shaper FlexCo  
Ottakringer Straße 242/8/35  
1160 Vienna  
Austria  
Email: info@beatshaper.ai

If you have any questions about how your data is processed or would like to exercise your rights (see below), please contact us at this address.

2. Data processing when using our website

2.1. General information

We process data that you provide to us (e.g., when contacting us, creating a user account, and using our services), data that is generated when using our website and services, server logs, and cookies.

2.2. Cookies

Cookies are small text files that are stored on your device containing information that can be retrieved by us or third parties, depending on the type of cookie. Our website uses technically necessary cookies and similar technologies and, with your consent, analytics cookies.

In particular, we may use:

  • Technically necessary cookies and similar technologies to provide the website and platform, enable login and account functions, maintain security, process payments, and remember cookie preferences. These are provided by Beat Shaper and its service providers and are session-based or stored until expiry or deletion.
  • Analytics cookies to measure website usage and improve our website and services. These are only used with your consent and may be provided by Google Analytics / Google. They are stored according to our analytics settings or until you withdraw your consent or delete the cookies.

You can refuse some or all cookies or delete cookies that have already been set via your browser settings. Please note that certain functions of the website or platform may not be available if you disable technically necessary cookies.

To prevent third-party cookies from being set, you can block third-party cookies in your browser.

2.3. Data processing for the operation and security of our website

Purpose of processing: When you visit our website, the web server processes usage data and stores such data in server logs. Collecting this data is necessary to enable the connection to our server and the use of the website. In addition, this data is used to defend our website against cyberattacks.

The following data is stored in server logs: The host name and IP address of the accessing device, together with the date, time of the request, identification data of your web browser and your operating system, and the referrer URL.

Legal basis for processing: Your data is processed on the basis of our legitimate interest (Art. 6 (1) (f) GDPR) in ensuring the operation of the service and security of our systems.

Recipients of the data: The web server for the operation of our website is operated by Webflow, Inc., San Francisco, USA, as a data processor. The servers may be operated outside the EU. Webflow, Inc. has adopted an adequate level of data protection through certification under the EU-US Data Privacy Framework (for more information, see https://webflow.com/legal/eu-privacy-policy). The data collected will not be passed on to third parties. Only in the unlikely event of a hacker attack we may transmit data to law enforcement authorities.

Further information: Server logs are stored for a maximum of 6 weeks. The IP address is stored in order to assist the relevant authorities in investigating and prosecuting security incidents (hacking, data breaches, etc.).

2.4. Data processing when contacting us

Purpose of processing: When you contact us via the contact form or by email, we collect and store all the data you provide us with.

Legal basis for processing: Your data is processed in order to take steps prior to entering into a contract with you, or for the performance of a contract (Art. 6 (1) (b) GDPR), or is based on our legitimate interest in providing a response to your inquiry (Art. 6 (1) (f) GDPR).

Recipients of the data: We only pass on the data to third parties if this is necessary to respond to the inquiry.

Further information: We store the data for the time necessary to process your inquiry and for any follow-up questions. In addition, we keep your inquiries for up to six months so that you can refer to an older inquiry later.

2.5. Data processing when registering for a user account

Purpose of processing: When you register for a user account, we store all data that you provide to us in this context. This includes master data (first and last name, email address), login data (user, password hash, login timestamps, account creation date), and transaction and billing data (invoices). We also store communication data and personal settings for the account.

The data required in the registration form is mandatory. If you do not provide this data, you will not be able to create an account on our platform. We use this data to manage your account (e.g., for authentication and password recovery), to enable you to use our platform, and to send service notifications.

Legal basis for processing: The legal basis for processing your data is the performance of the contract entered into with you (Art. 6 (1) (b) GDPR) or a legal obligation (Art. 6 (1) (c) GDPR).

Recipients of the data: In general, this data will not be transferred to third parties. We may only transfer your data if we are required to do so and to the extent necessary, to the following categories of recipients:

  • Legal representatives
  • Accountants, auditors, and tax advisors
  • Courts
  • Administrative authorities
  • Debt collection agencies

Further information: We store all this data until you delete your user account, but in any case until the expiry of the period for asserting warranty and damage claims arising from the contract (usually three years). Statutory data retention obligations (e.g. according to accounting regulations) remain unaffected.

2.6. Data processing when using Beat Shaper

Purpose of processing: When you use Beat Shaper, we collect and process all related data (master data, content data, communication data) such as prompts, generation parameters, generated musical content, saved projects, arrangements, exports, manual edits, playback, download and export events, and technical log data. Depending on the type of plan you are subscribed to, we also process billing data (invoices).

Legal basis for processing: The legal basis is the performance of the contract entered into with you (Art. 6 (1) (b) GDPR).

Recipients of the data: In general, this data will not be transferred to third parties. We may only transfer your data if we are required to do so and to the extent necessary, to the following categories of recipients:

  • Legal representatives
  • Accountants, auditors, and tax advisors
  • Courts
  • Administrative authorities
  • Debt collection agencies

Further information: We store this data until you delete it or until you delete your user account.

2.7. Data processing in connection with our newsletter

Purpose of processing: When you subscribe to our newsletter, you will regularly receive emails about our company, our offers, and our services. We evaluate your use of our mailings anonymously in order to determine how many users read our emails so that we can better tailor the newsletter to the interests of our subscribers.

Legal basis for processing: Your data is processed for mailing purposes on the basis of your consent (Art. 6 (1) (a) GDPR). You can revoke your consent to receive the newsletter at any time. A link to do so is included in all mailings. You can also revoke your consent using the contact options provided. Revoking your consent does not affect the lawfulness of processing based on your consent before its withdrawal.

Recipients of the data: For sending our newsletters we use the services of MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland (“MailerLite”). MailerLite acts as a data processor for us. When providing the newsletter service, your personal data may be processed outside Europe. MailerLite committed to complying with the requirements of the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list), so that adequate protection is provided for the transfer and processing of your data, even in non-EU countries. For more information see https://www.mailerlite.com/gdpr-compliance

Further information: Your personal data will be stored until you unsubscribe from the newsletter.

3. Data transfers

Your personal data will be used exclusively by Beat Shaper and will not be passed on to third parties without your consent, a legal obligation, or a decision by a court or an administrative body.

If we use third parties ("data processors") to process your data, we ensure that they process your data within the scope of the data processing agreement concluded with them, on documented instructions, and in compliance with data protection regulations.

Our internet provider, Webflow, Inc., operates its servers outside the EU. We have concluded a data processing agreement with this service provider. It has committed to complying with the requirements of the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list), so that adequate protection is provided for the transfer and processing of your data, even in non-EU countries.

4. Other service providers

  • 4.1 Our data models are processed on servers provided by Amazon Web Services (AWS), a service delivered by Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855, Luxembourg (“AWS”). All the servers used by Beat Shaper are located within the EU.
  • 4.2 Your prompts are processed with the support of the OpenAI API, provided by OpenAI Ireland Ltd, 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland (“OpenAI”). We ensure that all the prompts are processed within the EU and are not stored by OpenAI.
  • 4.3 We use the Google OAuth authentication tool from Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. This tool allows you to register or log in to our website with your Google account. Data is stored and processed when you use the tool. When using Google OAuth, your data is transferred to Google. While Google has a subsidiary in Ireland, Google Ireland Limited Gordon House, Barrow Street Dublin 4, your data may also be transferred to its headquarters in the USA. Google has committed to complying with the requirements of the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov/list), so that adequate protection is provided for the transfer and processing of your data, even in non-EU countries. Further information on data processing can be found in Google's privacy policy.
  • 4.4 Your payments are processed by Stripe, Inc., 354 Oyster Point Boulevard, South San Francisco, California, 94080, USA ("Stripe"). Stripe processes payments and acts partly as an independent data controller and partly as a data processor on our behalf. Stripe is certified under the EU-US Data Privacy Framework, ensuring an adequate level of protection in the event of personal data being transferred to the US (https://stripe.com/at/legal/data-privacy-framework).

5. Your rights

5.1. Right to information about stored data in accordance with Art. 15 GDPR

You have the right to request information about whether we process your personal data. If this is the case, you have the right to information about this personal data and other information related to the processing.

5.2. Right to rectification of inaccurate data in accordance with Art. 16 GDPR

If personal data that we process about you is no longer accurate or is incomplete, you can request that this data be corrected and, if necessary, completed.

5.3. Right to erasure of data in accordance with Art. 17 GDPR

If the legal requirements are met, you can request the erasure of your personal data.

5.4. Right to restriction of data pursuant to Art. 18 GDPR

If the legal requirements are met, you can request the restriction of the processing of data concerning you.

5.5. Right to data portability pursuant to Art. 20 GDPR

If the legal requirements are met, you may request the transfer of your data in a structured, commonly used, and machine-readable format.

5.6. Right to object to unreasonable data processing in accordance with Art. 21 GDPR

For reasons arising from your particular situation, you may object at any time to the processing of personal data that we process on the basis of a legitimate interest pursuant to Art. 6 (1) (f) GDPR.

5.7. Right to withdraw consent

If our data processing is based on your consent, you have the option of revoking this consent at any time without affecting the legality of the processing carried out on the basis of the consent until its revocation.

5.8. Right to lodge a complaint with the data protection authority

If you believe that our processing of your personal data violates applicable data protection law or that your data protection rights have been violated in any other way, you have the option of lodging a complaint with the competent supervisory authority (Austrian Data Protection Authority). The address is:

Österreichische Datenschutzbehörde  
Barichgasse 40-42  
1030 Vienna  
Phone: +43 1 52 152-0  
Email: dsb@dsb.gv.at

6. Further information

There is no automated decision-making, and no profiling.

If we process your personal data for a purpose other than that for which we collected it, we will notify you of this fact and inform you of this other purpose.

We reserve the right to amend or supplement this privacy policy as necessary to reflect changes in our services and customer feedback. The date of the last amendment can be found at the top of this document. Please visit this website regularly to stay informed about the current status of the privacy policy.