AAVIRO ONE
INDEPENDENT MUSIC
AVIRO ONE / PRIVACY

Privacy
notice.

This notice explains how personal data is handled on the AVIRO ONE website under the EU General Data Protection Regulation (GDPR).

Updated 8 October 2026

1. Who is responsible

The controller for this website is Mario Essl, AVIRO ONE / NightPulse Music, Kleinzell im Mühlkreis 74, 4115 Kleinzell im Mühlkreis, Upper Austria, Austria. For privacy questions or requests about data held by this website, email nightpulse-music@gmx.at.

Operator and editorial information is available in the legal notice.

This notice covers the website’s own features. OpenAI, Spotify, Apple and your email provider also explain their processing in their own privacy notices, linked below.

2. Contact messages

When you use the contact form, we save your name, email address, subject, message, ChatGPT account identifier and submission date. These details let AVIRO ONE read and answer your enquiry, follow up and prevent repeated or abusive submissions. Contact messages are accessible through the owner’s private Studio, rather than displayed in the community.

For enquiries about entering or performing a contract, the legal basis is Article 6(1)(b) GDPR. For other enquiries, it is Article 6(1)(f): our legitimate interest in communicating with people who contact us and protecting the form against misuse.

Submitting the form saves your message on the website. It does not automatically send an email. Choosing “Send by email” opens your own email app; sending is a separate action. If you email nightpulse-music@gmx.at, your message and email metadata also pass through your email provider and the recipient’s GMX service.

Providing these details is voluntary. The form needs the requested fields and a signed-in identity to save a message; without them, use the email link instead. Please do not include sensitive personal information that is unnecessary for your enquiry.

3. Community posts and replies

We save the display name you choose, topic title, post or reply text, category, date, relationship to a topic and your ChatGPT account identifier. This connects contributions to their author, enables replies and deletion, and allows the owner to moderate the forum and limit spam.

Your display name, contribution, category and date are visible to everyone who has access to the website. The community is not a private message channel. Your contact-form email address is not displayed in community posts. Choose a nickname if you prefer, and avoid posting private details about yourself or other people.

The website is publicly accessible. Community content can be read by visitors without signing in and may also be processed by search engines.

The legal basis is Article 6(1)(f) GDPR: our legitimate interest in providing the requested music community, maintaining conversations and protecting participants against abuse. Posting is voluntary; an author name and contribution are needed to participate.

You can remove your own contributions. The owner can also remove them. Removing a topic removes its replies. For correction or other privacy requests, contact nightpulse-music@gmx.at.

4. Sign in with ChatGPT

OpenAI Sites handles sign-in and provides the website with your account identifier, email address and, when available, profile name. The site uses your identifier to check access, associate submissions with you and protect owner-only features. A profile name may be used to suggest a community display name. The website does not receive or store your ChatGPT password.

Your account identifier is stored with posts and contact messages; the owner’s identifier is also stored for Studio access. The sign-in email and profile name are otherwise read with your signed-in requests, rather than kept in a separate visitor account database. An email address you enter in the contact form is stored with that message.

The website relies on Article 6(1)(f) GDPR for these access and security checks. Without sign-in you cannot submit a contact message or contribute to the forum. OpenAI’s own account processing and retention are described in its Europe privacy policy.

5. Hosting, access and cookies

The website is hosted through OpenAI Sites and uses Cloudflare infrastructure for its database and uploaded files. Hosting services process requests and stored submissions to deliver the website. Technical request information can include IP address, browser and device information, requested pages, date and time, and error or security information.

For an operator based in Austria, the hosting agreement is with OpenAI Ireland Ltd. The ChatGPT Sites Terms cover this service. For individual plans such as Plus and Pro, the Sites Data Processing Addendum governs visitor data hosted on the operator’s behalf. It distinguishes hosted website data from information supplied in ChatGPT conversations.

The processing agreement is incorporated into the hosting terms and applies through the operator’s use of Sites to publish and host a website that collects personal data.

The basis for the website’s necessary delivery, access controls and abuse prevention is Article 6(1)(f) GDPR: our legitimate interest in operating a reliable, secure website. Hosting providers and their technical service providers receive data needed to deliver those services. The owner can access submissions for the purposes explained above.

Sites also automatically records website traffic and provides visitor and page-view statistics. This website does not add a separate advertising or analytics tool. Platform sign-in and external music services can use cookies or similar storage; this is not a promise that the entire hosting platform is cookie-free. See OpenAI’s privacy information and Cloudflare’s privacy information.

OpenAI may use providers for hosting, infrastructure, content moderation and support. Its sub-processor list also describes processing for Plus and Pro Sites and the providers’ locations. This is a list of potential service providers, rather than a claim that every listed provider processes every visit.

The official OpenAI documentation states that Sites does not currently support data residency, including for database and file storage and logs. Processing is therefore not guaranteed to remain in the EEA.

The website is publicly accessible at aviro-one.com; Studio and contact messages remain restricted to the owner. Exact retention for additional Sites platform logs, traffic analytics and backup copies is not established by the published information reviewed. The operator has a prepared request for those details. This notice will be updated when a provider answer establishes them; no specific unverified hosting period is promised here.

easyname manages the registration and DNS for aviro-one.com; website content, contact messages and community records are hosted through Sites. Domain resolution also involves DNS services. See easyname’s privacy policy for its processing information.

6. Spotify, Apple Music / iTunes, Amazon Music and covers

Your choice to load a player

Embedded music players stay disabled until you choose “Load Spotify player” or “Load Apple Music player”. Loading is optional and based on your consent under Article 6(1)(a) GDPR. Your browser then connects directly to the selected provider, which receives your IP address, browser or device information and information about player use. Cookies or similar storage may be used, and data may be processed outside the European Economic Area, including in the United States.

You can choose “Disable player” to stop loading it here. Closing the song or switching services also removes the player and requires a new choice. The choice is not saved across visits. Withdrawal does not affect processing that already occurred or remove data or cookies held by the provider; use its privacy controls for that. You can also open a song directly on the provider’s website.

Spotify

Spotify AB, Sweden, handles Spotify service data under its own privacy policy. This can include technical identifiers, playback and usage information, and account-related data if you use a Spotify account. Spotify determines its service purposes and retention; its policy explains the criteria, privacy controls and international transfers. AVIRO ONE does not receive your Spotify password or personal listening history through these embeds.

Apple Music / iTunes

For EEA users, Apple’s privacy policy identifies Apple Distribution International Limited, Ireland, as the controller. Apple’s web-player notice describes browser, approximate location, embedding-domain and player-activity data. Player identifiers reset after one day; web-player activity information may be stored for up to two years. Signed-in playback can be associated with your Apple Account and follows the Apple Music notice. AVIRO ONE does not receive your Apple password or personal music library.

Amazon Music

Amazon Music is provided as a direct external link to the artist or individual released song. This website does not load an Amazon player, script, image or cookie. Your browser connects to Amazon when you choose that link; the link does not send a referrer from this website. On Amazon’s service, Amazon may process your IP address, device information, cookies, account and listening activity for service delivery, security and personalisation under its Privacy Notice. Its notice explains retention criteria, international processing and privacy controls. AVIRO ONE does not receive your Amazon password or listening history.

Instagram and TikTok

Instagram and TikTok are linked as external artist profiles. This website does not embed their feeds or load their tracking scripts. Your browser connects to the selected service when you open its profile link; no referrer from this website is sent. The service’s own privacy and account settings apply there.

Cover images and external links

Some release covers load directly from Apple’s image service or Spotify’s image service when the cover is displayed, even if you have not loaded a player. Those image requests disclose your IP address and browser request information to the image host. The purpose is to show the released artwork alongside the music; the website relies on Article 6(1)(f) GDPR for this catalog presentation. Covers stored on this website are served by its hosting provider.

Opening Spotify, Apple Music / iTunes, Amazon Music, Instagram, TikTok or another external link takes you to that provider’s service, where its own privacy and account settings apply. The weekly catalog update reads public music-release information; it does not send contact messages or forum contributions to the music providers.

7. How long data stays

  • Contact messages: for form submissions and email correspondence, the retention criterion is the time needed to resolve the enquiry and any necessary follow-up. Longer retention may be needed for a specific legal obligation or an actual legal claim. There is no automatic timed deletion in this app; the owner removes messages manually in Studio or the mailbox. You can request deletion by email.
  • Community contributions: stored while they remain part of an active or useful conversation, until the author or owner removes them, or the community is closed. There is no automatic expiry. The linked account identifier remains with the contribution for ownership and moderation.
  • Sign-in: account details are read during signed-in requests. Identifiers attached to submissions follow the retention of those records. OpenAI manages its own account and session retention.
  • Player choice: kept only while that player is open, with no consent preference stored in a cookie or browser storage by this website.
  • Provider records: hosting logs, backups, email and music-service records have separate provider retention arrangements. Deleting a record here does not itself delete a provider’s logs, backups, cookies or account records.

Cloudflare documents database recovery history of 7 or 30 days depending on its plan, and Workers Logs retention of 3 or 7 days. These product limits do not confirm the configuration of this managed Site or the retention of any additional OpenAI copies.

The Sites processing agreement provides for return or deletion on the operator’s instruction after the agreement ends, with an exception for legally required retention. It does not give a single fixed deletion deadline for all hosted records.

Where retention is required by a specific legal obligation, Article 6(1)(c) GDPR applies. Where necessary to establish, exercise or defend an actual legal claim, Article 6(1)(f) applies. This is not a blanket reason to keep every submission indefinitely.

8. International transfers

Section 4.1 of the Sites Data Processing Addendum provides for EEA transfers using EU Standard Contractual Clauses or a European Commission adequacy decision. For information about the applicable safeguards or a copy, contact nightpulse-music@gmx.at; OpenAI’s privacy contact is privacy@openai.com.

Spotify describes adequacy decisions and EU Standard Contractual Clauses for its transfers. Apple’s privacy policy describes international processing, including US storage and Standard Contractual Clauses for EEA data; it explains how to request a copy. Their policies are linked in this notice. These mechanisms do not amount to an EEA-only storage promise or an independent audit of the providers.

9. Your rights

Subject to the conditions in the GDPR, you may request access to your personal data, correction, erasure or restriction of processing. You may object to processing based on legitimate interests for reasons relating to your particular situation. You also have a right to data portability where processing is automated and based on consent or a contract.

You may withdraw consent at any time. For embedded players, use “Disable player”; you can also contact us. Withdrawal does not make earlier processing unlawful. This website does not use your submissions for automated decisions with legal or similarly significant effects, or for that kind of profiling.

Send requests to nightpulse-music@gmx.at, preferably identifying the message or contribution concerned. We may need proportionate information to verify that the data belongs to you. Under the GDPR, the usual response period is one month; an extension of up to two further months is possible for complex or numerous requests, with notice and reasons within the first month. Requests are normally free of charge.

You can lodge a complaint with a supervisory authority, including in the EU country where you live, work or where the alleged infringement took place. In Austria, contact the Austrian Data Protection Authority (Datenschutzbehörde). You do not have to contact AVIRO ONE first.

For data held independently by OpenAI, Spotify, Apple or your email provider, their privacy contacts and account controls can also help. AVIRO ONE remains your contact for this website’s own processing.