DPIA Summary

Data Protection Impact Assessment — Summary

Public summary of BRMUSIC-DPIA-2026-001. Last updated 2026-09-05. Full DPIA prepared; external counsel review on hold pending funding.

What is this?

A DPIA is a document required under GDPR Article 35 before launching new processing of personal data. We did one for BananaRat Studio before EU testers joined.

What did we assess?

How we collect, use, and protect data on the platform — covering 10 data categories including your account info, your compositions, the Witness Log of your editorial actions, and analytics.

What did we find?

Residual risk: Medium-Low. No risk reaches the threshold that requires prior consultation with a Data Protection Authority. The biggest design decision: our cryptographic Witness Log uses a "forward-only redaction" approach — if you ask us to delete your account, your linkable identifying fields are erased, but the underlying cryptographic chain continues to verify (preserving authorship-evidence for any compositions you exported and kept).

Key technical safeguards

  • Anthropic LLM calls run under their zero-retention API setting
  • Audio file URLs are HMAC-signed, path-bound, and expire after 8 hours
  • AuthorMark = C2PA content credentials + AudioSeal watermark (machine-readable AI disclosure per EU AI Act Article 50)
  • Sealed audio masters carry an OpenTimestamps proof anchored to the Bitcoin blockchain, so the file can be shown to have existed before a given block
  • 30-day SLA on right-to-erasure requests, with Day-25 alerting if not on track
  • Audit log uses a signing key separate from all other application secrets
  • The Witness Log is a hash chain — every entry commits to the SHA-256 of the one before it, so an altered or reordered entry fails verification

What we don't do

  • We do not train AI models on your compositions
  • We do not sell your data
  • We do not embed your identity in the audio files you export

Subprocessors

We keep one list, in one place, so it cannot drift: Subprocessor List — every subprocessor, what it processes, where it sits, and the transfer safeguard for each. Our Privacy Policy §7 covers how we use them.

International transfers

EU/UK data may transit through Canada (where our backend runs). Canada has an EU adequacy decision under PIPEDA (renewed 15 January 2024), so no Standard Contractual Clauses are required for EU→Canada transfers. US subprocessors operate under either the EU-US Data Privacy Framework or SCCs Module 2.

Counsel review

An external counsel review of the full DPIA is prepared and is on hold pending funding; it has not taken place. We would rather say that plainly than carry a date we have passed. Updates will land in this summary as the document evolves.

Questions

Email feedback@bananarat.com with subject "Privacy" or "DPIA".