1. Overview
This Privacy Policy explains the account, license, purchase and application data handled by Arctisoft Studio ("we", "us", "our") when you use our desktop applications and connected services. It also explains your rights under the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applicable Austrian law.
This policy applies to all Arctisoft Studio products and services, including Arctisoft Studio Hub, Medio, WaveShaper, MetaEdit Plus, and Sonaris (collectively, the "Software").
2. Data Controller
The data controller within the meaning of Article 4(7) GDPR is:
Arctisoft Studio / Bernd Julian Hagen
Austria
Email:
support@arctisoft-studio.com
For data protection inquiries and requests about your account data, contact us at the address above.
3. Legal Basis for Processing
We process personal data exclusively on lawful grounds as defined in Article 6(1) GDPR:
- Performance of a contract (Art. 6(1)(b)) – Processing your email address, account data, and license information is necessary to provide the services you have contracted for, including account creation, license activation, cloud synchronisation, software updates, and purchase fulfilment.
- Legitimate interest (Art. 6(1)(f)) – We process limited data for fraud prevention, detecting unauthorised license sharing, maintaining service security, and ensuring system integrity. Our legitimate interests do not override your fundamental rights and freedoms.
- Consent (Art. 6(1)(a)) – Where you voluntarily provide optional data such as a profile avatar, your name or your country, or opt into non-essential features. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Legal obligation (Art. 6(1)(c)) – Processing necessary to comply with tax, accounting, and regulatory obligations under Austrian and EU law, including retention of purchase records pursuant to the Austrian Federal Fiscal Code (Bundesabgabenordnung, "BAO").
4. Categories of Personal Data
4.1 Data We Collect
- Account data – Email address (serves as your unique account identifier) and account creation date.
- Profile data – Profile avatar image, first name, last name and country of residence, each only if voluntarily provided by the user. None of these is required to use an account. They are stored on our servers and can be changed or removed at any time in Account & Security.
- License data – License keys, activation status, linked account information, product type, and purchase date.
- Application preferences – Configuration settings, UI preferences, and feature selections synced via Arctisoft Studio Hub.
- Download history – Medio stores a record of completed downloads (URL, title, format, timestamp). This data is stored locally and optionally synced to the cloud when signed in. No actual downloaded files or their contents are transmitted.
- Transaction data – Customer name (as provided to the payment processor), purchase amount, currency, invoice number, transaction date, and payment status. This data is generated by our payment processor and stored for invoice and tax compliance purposes.
- Authentication activity – Records of security-relevant events including sign-in and sign-out timestamps, password changes, email address changes, and two-factor authentication enrollment or removal. This data is used for account security monitoring and is viewable by the account holder in Settings.
- Account usage metrics – Aggregate counters of media processed through Arctisoft applications (number of items processed and data volume). These counters are used solely for the account progression system and do not identify specific files or content.
- Technical data – Device identifiers (derived from hardware attributes such as network adapter addresses and volume serial numbers), device hostname, IP address recorded at the time of device registration, and application version. This data is collected during license activation and device heartbeat requests.
4.2 Local Files and Connected Features
- Media processing and local library workflows do not require uploading your media files to Arctisoft Studio Hub.
- Connected features can send the information needed for your request to their service providers. For example, media downloads use the URL you supply, and online metadata or artwork searches use search terms or media identifiers. Those providers apply their own privacy policies.
- Payment details are entered with the checkout provider. Hub purchase records contain order and license information rather than complete payment-card credentials.
- Information you include in a support request, screenshot or diagnostic report is shared when you send that request. Review it before sending.
5. Data Processing Purposes
| Purpose | Data Involved | Legal Basis |
|---|---|---|
| Account creation and authentication | Email address | Contract (Art. 6(1)(b)) |
| License activation and validation | License key, email, device identifier | Contract (Art. 6(1)(b)) |
| Cloud synchronisation of preferences | Application settings, download history | Contract (Art. 6(1)(b)) |
| Purchase fulfilment and invoicing | Email, customer name, transaction data, license key | Contract (Art. 6(1)(b)) |
| Transactional email delivery | Email address, purchase details | Contract (Art. 6(1)(b)) |
| Fraud prevention and license abuse detection | License activation patterns, device identifiers, IP address | Legitimate interest (Art. 6(1)(f)) |
| Account security monitoring | Authentication activity log (sign-in, sign-out, security changes) | Legitimate interest (Art. 6(1)(f)) |
| Profile personalisation | Avatar image, first name, last name, country | Consent (Art. 6(1)(a)) |
| Account progression system | Aggregate processing counters (item counts, data volume) | Contract (Art. 6(1)(b)) |
| Tax and accounting compliance | Transaction records, invoice data | Legal obligation (Art. 6(1)(c)) |
| Software update delivery | Application version, operating system | Contract (Art. 6(1)(b)) |
6. Sub-Processors and Third-Party Services
The Hub uses the following services for account access, purchases and software delivery. The information involved depends on the feature you use. A provider may also act as an independent controller for parts of its service, such as payment processing.
| Provider | Purpose | Data Processed |
|---|---|---|
| Supabase, Inc. | Authentication, database, storage, and serverless functions | Email, account data, license records, preferences, device records, avatar images |
| Stripe, Inc. | Payment processing | Email, customer name, transaction amount, currency |
| Resend, Inc. | Transactional email delivery | Email address, email content |
| GitHub, Inc. | Content delivery and software distribution | IP address (server logs) |
Provider privacy notices explain their own processing. Contact us if you need information about the provider or processing relevant to a particular account request.
7. International Data Transfers
Service providers may process account, payment or delivery data in countries outside your country of residence, including outside the European Economic Area.
Transfers of personal data outside the European Economic Area are subject to the safeguards required by applicable data protection law, such as an adequacy decision or standard contractual clauses where applicable. Contact us for information about a specific transfer.
8. Data Security
The Hub uses authenticated account access and encrypted HTTPS connections for connected services. You can add an authenticator to your account, review registered devices and manage your credentials in Account & Security. No system can promise absolute security.
9. Data Retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Local application data | Until you clear the records or remove the stored user data | User-controlled |
| Cloud-synced preferences | Duration of active account | Contract |
| Account data | Duration of active account; deleted when you delete your account unless statutory retention applies | Contract |
| Purchase and invoice records | For applicable accounting and tax retention periods | Legal obligation |
| License records | Duration of account link; unlinked on account deletion and retained where needed for purchase records, support, fraud prevention, or legal obligations | Contract / legitimate interest / legal obligation |
| Transactional email logs | For email delivery and troubleshooting needs | Legitimate interest |
| Authentication activity log | Duration of active account | Legitimate interest |
| Device registration records | For account access, license history and security review needs | Legitimate interest |
Account deletion removes Hub account data, profile data, cloud-synced preferences, avatar data and account-linked activity from your account. Licenses linked to the deleted account are unlinked rather than destroyed. Purchase records subject to statutory retention obligations are retained for the legally required period and minimised where possible.
10. Automated Decision-Making
License checks can automatically allow or refuse an activation based on the license status and its device limit. If you believe an account restriction or license decision is incorrect, contact support to request a review. Your rights under Article 22 GDPR apply where the conditions of that article are met.
11. Your Rights Under GDPR
As a data subject, you have the following rights. To exercise any of these rights, please contact us at support@arctisoft-studio.com . We will respond within one month of receipt (extendable by two months for complex requests, per Article 12(3) GDPR).
- Right of access (Art. 15) – Request a copy of all personal data we hold about you, along with information about how it is processed.
- Right to rectification (Art. 16) – Request correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17) – Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, you withdraw consent, or there is no overriding legitimate ground for processing. Statutory retention obligations may limit this right.
- Right to restriction of processing (Art. 18) – Request restriction of processing where the accuracy of data is contested, processing is unlawful, or we no longer need the data but you require it for legal claims.
- Right to data portability (Art. 20) – Receive your personal data in a structured, commonly used, and machine-readable format (JSON), and request transmission to another controller where technically feasible.
- Right to object (Art. 21) – Object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent (Art. 7(3)) – Withdraw consent at any time for processing based on consent. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
12. Right to Lodge a Complaint
In accordance with Article 77 GDPR, you have the right to lodge a complaint with a competent data protection supervisory authority if you believe that the processing of your personal data infringes applicable data protection law. You may contact the supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement.
13. Your Controls
- Delete individual download history entries via context menus within the application
- Manage or clear local records using the application's controls; uninstalling may leave user data or preferences on your computer
- Manage cloud sync settings within Arctisoft Studio Hub
- Export available Hub account records in Account & Security, or contact us for a data request
- Delete your Arctisoft account to remove cloud-synced account data and unlink licenses from that account
14. Children's Privacy
Our Software (Arctisoft Studio Hub, Medio, WaveShaper, MetaEdit Plus, and Sonaris) offer local features that can be used without an account. Connected features and software delivery may still involve technical request data, such as an IP address.
Account creation involves the processing of personal data (email address) and is subject to GDPR Article 8 and the Austrian Data Protection Act (DSG §4(4)). In Austria, the digital age of consent is 14. Users aged 14 and above may create an Arctisoft Studio account independently. Users under 14 require verifiable consent from a parent or legal guardian before creating an account.
We do not knowingly collect personal data from children under 14 without parental consent. If we become aware that personal data has been collected from a child under 14 without appropriate consent, we will take prompt steps to delete that data. If you believe a child under 14 has created an account without parental consent, please contact us immediately.
15. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Austrian Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR). Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify affected individuals directly (Article 34 GDPR).
16. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or service offerings. Material changes will be communicated through our Software or website. The "Last updated" date at the top of this page indicates when the policy was last revised. Any processing that requires consent remains subject to that consent.
17. Contact
For all privacy-related inquiries, data subject access requests, or concerns about our data processing practices, please contact us at support@arctisoft-studio.com .
This Website
The Privacy Policy above applies to this website as it does to our Software. The following points describe what is specific to arctisoft-studio.com.
- No tracking. This website sets no advertising or analytics cookies, embeds no third-party trackers and loads its fonts and scripts from its own domain.
- Sign-in storage. When you sign in, your session is kept in your browser's local storage so that you stay signed in. It is strictly necessary for the account area and is removed when you sign out.
- Server logs. The hosting provider processes technical request data such as your IP address, the requested page and the time of the request in order to deliver the site and protect it against misuse (Art. 6(1)(f) GDPR).
- Account, releases and purchases. The account area and the release journal communicate with our account services at Supabase. A purchase continues on a checkout page operated by Stripe. Both are described in section 6 above.
- Email. If you write to us, we process your message and address in order to answer you.