BEAT/SCROLL
Legal center
Legal noticePrivacyTermsAcceptable useRefundsWithdrawalCancelContact

BS / LEGAL SIGNAL

Clear terms.
No fine-print fog.

Information about using BeatScroll, your rights, and how to contact us. German is the controlling version; this translation is provided for convenience.

Status: Accounts and sign-in are available. Paid subscriptions and Gig Passes are not yet on sale. The paid-plan policies describe the intended conditions for those offers; creating an account alone does not create a paid contract.

02 / DATA PATH

Privacy

Current + Draft

Last updated: 13 September 2026

1. Controller

Marvin Jerome Stephan, IT-Consulting and Design Jerome Stephan
Dieselstr. 20, 14482 Potsdam, Germany
[email protected]

Sections 1 to 10 describe the current personal beta. Section 11 describes planned processing for the paid service, which has not launched.

2. Website Access and Security Logs

When you access the site, data such as IP address, time, requested address, HTTP method, response status, and technical browser details is processed transiently to deliver the site, diagnose errors, and prevent abuse. The legal basis is Article 6(1)(f) GDPR; the legitimate interests are secure and reliable operation. Fastify and Caddy are currently configured not to write routine access logs. Technical error and security events may appear in size-limited container logs without form data or message bodies. Metadata needed for a specific security incident may be preserved until the incident is resolved. The hosting provider may additionally process its own infrastructure metadata under its contractual retention periods.

3. Messages and Reactions in the Personal Beta

Message text is required to send a message. A display name is optional; “anon” is shown if you leave it blank. Messages are transmitted to the locally connected DJ app and shown on the selected display. People at the venue may therefore see them. Reactions do not require a name.

The server keeps a message in memory only while delivering it and awaiting confirmation from the DJ app; there is currently no server-side message history. After confirmation, the content remains temporarily in the connected desktop app's volatile queue until shown, dismissed, or cleared. Rejected message bodies are not retained as messages. The legal basis is Article 6(1)(f) GDPR; the interests are the requested live communication and protection of the service.

4. Device ID, Browser Storage, and Drafts

  • A random device ID is stored in the browser for rate limiting and abuse prevention and is sent with messages or reactions. It expires and is replaced after 30 days. Local storage access is based on Section 25(2)(2) TDDDG and subsequent processing on Article 6(1)(f) GDPR.
  • A display name is not stored as a browser preference. It is processed only as part of the current message transmission.
  • Only the text of an unsent message draft is held in the tab's session storage so it survives a connection interruption. The display name is not included in the draft. The draft ends with the browser session or is erased after confirmed delivery.

BeatScroll uses no advertising or analytics cookies in the current beta.

5. Accounts, Sign-in, and Sessions

When account functions are enabled, Clerk, Inc. provides signup, sign-in, verification, recovery, and browser sessions. Depending on the sign-in methods enabled in Clerk, it may process identifiers such as an email address or telephone number, verification and security data, technical request data, and the browser data needed to maintain a session. BeatScroll receives the stable Clerk user ID and verified session state. BeatScroll does not receive or store your password.

After account setup, BeatScroll stores the stable Clerk user ID, account status, DJ display name, language, and timezone. These fields are required to provide and secure the account and Deck. The legal basis is Article 6(1)(b) GDPR for steps requested by you and performance of the service, and Article 6(1)(f) GDPR for account and session security. Clerk's strictly necessary session storage is used under Section 25(2)(2) TDDDG. No account data is used for advertising by BeatScroll.

Deleting the Clerk identity disables the mapped BeatScroll account after receipt of Clerk's signed deletion event. Profile and mapping data is then retained only while needed to complete erasure or export requests and meet security or legal obligations. The final automated erasure/export process and exact period are launch gates; until they are complete, requests are handled through [email protected]. Clerk is an external identity provider and may involve processing outside the EEA. Its data-processing agreement, locations, transfer safeguards, and configured retention must be verified before public production activation.

6. Contact Form and Content Reports

When the contact page shows the server form as available, BeatScroll processes the submission type, language, optional name, email address, subject, and free text. Content reports additionally include the content location, an optional copy of the reported content, and the accuracy declaration. Email is required for ordinary contact; a content report may be possible without contact details where a lawful exception applies. The IP address is used only in the transient abuse-prevention rate limit and is not stored with the submission.

Purposes are handling and replying to requests, establishment or defence of legal claims, and assessment of allegedly illegal content. Depending on the request, the legal bases are Article 6(1)(b), (c), or (f) GDPR. Submissions are generally erased 365 days after recording; a documented statutory retention or evidence-preservation duty may place an individual case on hold. Deleted data may remain in encrypted backups for up to 28 additional days. A notification goes to the operator address configured by the server. Before public activation, this notice will name the email service actually used, its locations, and the contractual basis. An on-screen reference confirms storage only, not email delivery or a substantive decision. The email notification contains only the reference, type, and recording time, not the submitted free text or contact details.

If you use email, the mailbox service processes the sender address, technical email headers, subject, content, and any attachments. The purposes, legal bases, and general 365-day retention period are the same as for the server form; statutory duties or necessary preservation of evidence may apply for longer in an individual case. The mailbox service actually used will be named here before public deployment.

7. Recipients and Hosting

Hetzner Online GmbH in the European Union is intended to host a publicly deployed beta; local personal tests run on the controller's development systems. When account functions are enabled, Clerk, Inc. receives the identity, verification, session, and technical data needed to provide them. The message and optional display name also go to the connected DJ app and may appear on its output display. Service providers receive data only as needed for their task and under an appropriate contractual basis.

8. No Analytics or AI Training

BeatScroll does not use messages for personalized advertising or AI-model training. Security filters and rate limits may operate automatically, but they do not make a decision with legal or similarly significant effects about a person.

9. Your Rights

Subject to the GDPR, you may have rights of access, rectification, erasure, restriction, portability, and objection. Consent can be withdrawn for the future. Send requests to [email protected]. You can also complain to a data protection authority, particularly the Brandenburg Commissioner for Data Protection and Access to Information, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany, lda.brandenburg.de.

10. Children

BeatScroll is not directed at children under 16. Paid accounts are intended to be available only to people aged 18 or older.

11. Planned Paid Service – Advance Information

The following functions are not active. Before launch, this notice will be updated with the providers, locations, and transfer safeguards actually selected.

Data/functionPurpose and intended durationIntended recipients
Payment and invoice dataPurchase, tax, invoice, and refunds for statutory retention periodsThe Merchant of Record named at checkout; selection is still open
Message historyAccount holder's choice: off, 24 hours, 7 or 30 days; default 7 daysBeatScroll as processor and the DJ/organizer as controller
Security dataAbuse prevention; device IDs generally 30 days; log periods will be set from the actual configuration before launchBeatScroll and the hosting and security services named before activation
BackupsRecovery; deleted data may remain encrypted for up to 28 additional daysPlanned Hetzner Storage Box in the EU

For guest content, the DJ, agency, or venue is intended to act as controller and BeatScroll as processor. Before a channel is activated, account holders must therefore provide their legal identity and privacy contact and enter into a data processing agreement. BeatScroll remains an independent controller for account, security, billing, and abuse data.

If a selected provider processes data outside the EEA, transfers are intended to rely on an adequacy decision or safeguards such as the EU Standard Contractual Clauses. Providers and specific safeguards will be completed before activation.

BEAT/SCROLL

Live crowd relay for the DJ booth.

Legal noticePrivacyTermsWithdrawalCancelContact
Language
EnglishEN
  • DEDeutsch
  • ENEnglish