Skip to main content

Legal

Privacy Policy

Last updated:

1. Overview

Legal Disclaimer: Nothing in this Privacy Policy constitutes legal advice. This policy is provided for informational purposes only. For legal advice, please consult a qualified attorney.

Noiz ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, store, and safeguard your information when you use our service at noiz.bio (the "Service").

This policy applies to all users worldwide, with enhanced rights for residents of the European Economic Area (EEA), United Kingdom, Switzerland, and California. We comply with:

  • General Data Protection Regulation (GDPR) - EU Regulation 2016/679
  • UK Data Protection Act 2018 and UK GDPR
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • German Federal Data Protection Act (BDSG)
  • ePrivacy Directive (Cookie Law)

This policy should be read together with our Terms of Service and Section 11, on what we store on your device.

2. Data Controller

For the purposes of the GDPR and other applicable data protection laws, the data controller responsible for your personal data is:

Noiz

Inhaber: Fabian Schneidruck

Leopoldplatz 13

76437 Rastatt

Germany

USt-IdNr.: DE367705746

Data Protection Contact

For all privacy and data protection inquiries, please contact our designated data protection representative:

Email: privacy@noiz.bio

Legal matters: legal@noiz.bio

Response timeframe: We aim to respond to all data protection inquiries within 30 days.

3. Legal Basis for Processing (GDPR Article 6)

We process your personal data only when we have a valid legal basis under the GDPR. The table below explains the legal bases we rely on for different processing activities:

Processing ActivityLegal BasisGDPR Article
Account creation and managementPerformance of contractArt. 6(1)(b)
Payment processingPerformance of contractArt. 6(1)(b)
Profile hosting and displayPerformance of contractArt. 6(1)(b)
Analytics and service improvementLegitimate interestArt. 6(1)(f)
Security and fraud preventionLegitimate interestArt. 6(1)(f)
Analytics measurement (see Section 11)Legitimate interest, with opt-outArt. 6(1)(f)
Marketing communicationsConsentArt. 6(1)(a)
Tax and financial recordsLegal obligationArt. 6(1)(c)
Responding to legal requestsLegal obligationArt. 6(1)(c)

Legitimate Interest Assessment

Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights. Our legitimate interests include:

  • Improving and optimizing our services
  • Preventing fraud and ensuring platform security
  • Understanding how users interact with our service

You may object to processing based on legitimate interests at any time by contacting us.

Consent Withdrawal: Where we rely on consent, you have the right to withdraw your consent at any time by contacting us at privacy@noiz.bio or using the provided mechanisms (e.g., Privacy choices in the footer, unsubscribe links). Withdrawal does not affect the lawfulness of processing before withdrawal.

4. Categories of Personal Data

We collect and process the following categories of personal data, organized according to GDPR-compliant categories:

Identity Data

  • Username (publicly displayed)
  • Display name (optional, publicly displayed)
  • Email address (used for authentication and communication)
  • Password (hashed and encrypted, never stored in plaintext)

Contact Data

  • Email address
  • Contact form submissions

Profile Data

  • Biography (optional, publicly displayed)
  • Profile picture/avatar (optional, publicly displayed)
  • Banner image (optional, publicly displayed)
  • Social media links (optional, publicly displayed)
  • Custom links and their order
  • Pages and the widgets on them — the text, labels, values and links you put in them, and any Spotify or YouTube item you add (publicly displayed once published)
  • Theme and appearance preferences
  • Premium status and badge information
  • Connected Discord account details, if you connect one — your Discord id, handle, a copy of your avatar, and the invite code of a server you chose to feature (Section 8)

Technical Data

  • IP address — kept in full for 30 days in sign-in security logs, so we can investigate attacks on your account; stored only as a one-way digest everywhere else, for at most 12 months (see the retention table below)
  • Browser type and version
  • Device type (desktop, mobile, tablet)
  • Operating system
  • Time zone setting
  • Referring website/source

Usage Data

  • Profile view counts and statistics
  • Link click analytics
  • Pages visited within the Service
  • Features used and interaction patterns
  • Time spent on pages

Privacy-First Profile Analytics

We use privacy-friendly first-party analytics to count profile views and link clicks. This helps profile owners understand how their noiz.bio page performs. We do not use third-party tracking pixels for this analytics system, do not store raw IP addresses, and do not sell analytics data. To keep these numbers trustworthy, we filter duplicate refreshes, obvious bots, social-preview crawlers and suspicious repeated activity — this helps reduce artificial traffic, though no system prevents every fake view or click.

  • No cookies or persistent device identifiers are set for this analytics.
  • Visitors are counted using a daily-rotating, one-way hash that cannot be reversed to an IP address or used to track you across other websites or from one day to the next.
  • We record only aggregate signals: traffic source/referrer, UTM tags, coarse device/browser/OS, and country (only when the visitor's platform safely provides it).
  • Bots, social-preview crawlers, duplicate refreshes and suspicious repeated clicks are filtered out of the counted totals. Analytics are private to the profile owner (and platform administrators).
  • Deleting your profile or account also deletes its analytics data.

Transaction Data

  • Purchase history
  • Premium subscription status
  • Payment timestamps
  • Stripe customer ID (we do not store full card details)

Security Data

  • Two-Factor Authentication (2FA) enrollment status
  • Encrypted 2FA backup codes
  • Login attempt records
  • Authentication events and timestamps

Content Data

  • Uploaded images (avatar, banner)
  • Background music files (if uploaded)
  • Custom icons and media

Special Categories of Data: We do NOT intentionally collect special categories of personal data as defined in GDPR Article 9 (e.g., racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, sexual orientation). If you voluntarily include such information in your profile, you do so at your own discretion.

5. How We Collect Your Data

We collect personal data through the following methods:

5.1 Direct Interactions

Data you provide when you:

  • Create an account or register for our Service
  • Complete your profile information
  • Make a purchase or upgrade to Premium
  • Subscribe to newsletters or marketing communications
  • Contact us via email, support form, or social media
  • Report a problem or provide feedback
  • Participate in surveys or promotions

5.2 Automated Technologies

Data collected automatically when you interact with our Service:

  • Local storage on your device, all of it listed in Section 11 (we set no cookies)
  • Server logs recording requests to our infrastructure
  • Our own server-side analytics, which stores nothing on your device (Section 11.2)
  • Security monitoring systems

5.3 Third Parties

Data we may receive from third parties:

  • Payment Processors: Transaction confirmation and status from Stripe
  • OAuth Providers: Basic profile information if you sign up or connect using Google or Discord (we receive only what you authorize — Section 8 lists exactly what Discord gives us)
  • Analytics Partners: Aggregated usage insights

6. Purposes of Processing

We use your personal data for the following purposes:

PurposeData UsedLegal Basis
Provide and maintain the ServiceIdentity, Profile, TechnicalContract
Process payments and subscriptionsIdentity, Contact, TransactionContract
Manage your account and authenticationIdentity, SecurityContract
Send service-related communicationsIdentity, ContactContract
Provide customer supportIdentity, Contact, TechnicalContract/Legitimate Interest
Improve and personalize the ServiceUsage, TechnicalLegitimate Interest
Detect and prevent fraudTechnical, SecurityLegitimate Interest
Comply with legal obligationsAll relevant categoriesLegal Obligation
Send marketing communicationsIdentity, ContactConsent

7. Data Sharing and Recipients

We may share your personal data with the following categories of recipients:

  • Service Providers: Third parties that help us operate the Service, including hosting, payment processing, analytics, and customer support providers. These parties process data only on our behalf and under our instructions.
  • Professional Advisers: Lawyers, accountants, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services.
  • Law Enforcement and Regulators: When required by law, court order, or governmental authority, or to protect our legal rights.
  • Business Transfers: In connection with any merger, acquisition, reorganization, sale of assets, or bankruptcy proceeding. We will notify you of any such transfer and your options.
  • With Your Consent: Any other third parties when you have given us explicit consent to share your information.

We NEVER Sell Your Personal Data

Noiz does not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not participate in data broker transactions. Your data is never monetized through third-party advertising networks.

8. Sub-Processors and Third-Party Services

We use the following sub-processors and third-party services to operate Noiz. Each has been reviewed for GDPR compliance and appropriate data protection measures. Where a service does not meet that bar, its row says so plainly and the notes below explain what we do about it:

ServicePurposeLocationSafeguards
StripePayment processingUSAEU-US DPF, SCCs
Lovable Cloud (Supabase)Database, authentication, file storage, edge functionsEU (Frankfurt)EU-based processing, Art. 28 DPA
CloudflareWebsite hosting, CDN, edge compute, DDoS protectionGlobal edge (EU for European visitors)EU-US DPF, SCCs, Art. 28 DPA
ResendTransactional email (sign-in links, confirmation, password reset)USASCCs, Art. 28 DPA
Fontshare (Indian Type Foundry)Webfont delivery, for five optional profile fonts onlyGlobal CDNIP address only, no cookies — see note below
Google (OAuth)Social authentication (optional)USAEU-US DPF, SCCs
Discord (discord.com, cdn.discordapp.com)Social authentication (optional), and reading the public details of a server a creator chooses to show on their pageUSASign-in and server details are requested by our servers; avatars, server icons and badges are loaded by your browser from Discord's CDN — see note below
Spotify (open.spotify.com)Playing a track, album or playlist a creator has added to their page or to one of their pagesUSAContacted as the page renders, before you interact with anything. Players below the fold are not loaded until you scroll near them
YouTube (youtube-nocookie.com)Playing a video or playlist a creator has added to their page or to one of their pagesUSAContacted as the page renders, before you interact with anything; the no-cookie player is used. Players below the fold are not loaded until you scroll near them

A note on fonts

Nearly all typefaces on Noiz are served from our own servers, so loading a page does not reveal your IP address to any font provider. That is a deliberate choice: most websites load fonts from a third party, and we do not.

Five optional typefaces are the exception — Satoshi, Array, Panchang, Technor and Chillox. Their licence does not permit us to host the files ourselves, so when a creator has chosen one of them for their page, your browser requests that font from Fontshare and Fontshare receives your IP address and browser user agent. No cookie is set and no account is involved. Every other page, and every profile using any other font, contacts nobody.

A note on Discord and live status

The Discord row above describes requests made by our servers, not by yours, with one exception we would rather state than bury.

The exception is Discord's images. If a creator shows a Discord server or their Discord profile on their page, the server's icon and the creator's Discord avatar are loaded by your browser directly from Discord's content delivery network (cdn.discordapp.com). Discord therefore receives your IP address and the usual headers your browser sends — including, depending on your browser's settings, the address of the page you are on — as the page loads, before you interact with anything. No account information of yours is sent, and you do not need a Discord account for this to happen.

Live status is still fetched inside an edge function and cached before it reaches a page, and link icons are still copied into our own storage rather than hotlinked. But embeds changed on 27 August 2026: a YouTube or Spotify player used to sit behind a click and now loads with the page, so if a creator has added one, that provider is contacted as the page renders rather than when you press play. Players further down a page are not loaded until you scroll near them.

Discord is not a processor acting on our instructions. It is its own controller for the account you sign in with.

Live status has been removed

Noiz used to show a creator’s live Discord status (online, idle, do not disturb) using a community-run service called Lanyard. That service is gone from Noiz entirely: we no longer contact it, send it anything, or depend on it. The status dot and the “on mobile” indicator no longer exist, because Discord does not make another user’s status available except through a permanently-connected bot, which we do not run.

What remains, for creators who switch their Discord card on, is the account’s badges — HypeSquad, Early Supporter and so on. Those are read from Discord’s own API by our server, using our credentials, once per cache interval rather than once per visitor. The only thing sent is that creator’s own Discord user id. No visitor data is involved: not your IP address, not your user agent, not which profile you were looking at.

What connecting Discord stores

If you connect Discord to your Noiz account, we write four fields to your profile — three read from the OAuth identity you authorised, and one you type in yourself:

  • discord_user_id — your Discord account's numeric id
  • discord_username — your Discord handle, as Discord reports it
  • discord_avatar — our own address for our copy of your Discord avatar, held in our storage bucket. It is not a link to Discord's CDN.
  • discord_server_id — the invite code of a server you chose to feature, if you featured one. Despite the column's name it holds an invite code, not a server id; we use it to ask Discord for that invite's public details (the server's name, its icon and the member counts Discord attaches to it), and the icon is mirrored into our storage like the avatar.

We ask Discord only for your identity — id, handle, avatar and email address. We cannot read your messages, your friends, or the list of servers you are in, because we never request the permission to.

Storing is not showing. Live status is off until you enable it, and so is the server card; connecting your account publishes nothing on its own. Disconnecting Discord clears the id, the handle and the mirrored avatar from your profile and sets both display switches back to off — so reconnecting later cannot quietly republish something you had turned off. Deleting your account deletes all of it, on the schedule in Section 10.

Links to sub-processor privacy policies:

9. International Data Transfers

Your personal data may be transferred to, stored, and processed in countries outside the European Economic Area (EEA). Our primary data processing occurs in the European Union (Frankfurt, Germany), but some sub-processors operate globally.

9.1 Transfer Mechanisms

When we transfer your data outside the EEA, we ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework (DPF): For transfers to US companies certified under the EU-US Data Privacy Framework (e.g., Stripe, Google).
  • Standard Contractual Clauses (SCCs): EU Commission-approved contractual clauses that provide adequate protection for data transfers.
  • Adequacy Decisions: Transfers to countries that the European Commission has determined provide an adequate level of data protection.
  • Binding Corporate Rules: Where applicable for multinational service providers.

9.2 Supplementary Measures

In addition to the above safeguards, we implement:

  • End-to-end encryption for sensitive data in transit
  • Data minimization - we only transfer data necessary for the specific purpose
  • Regular reviews of our sub-processors' data protection practices
  • Contractual requirements for sub-processors to notify us of government access requests

You may request a copy of the safeguards we use for international transfers by contacting privacy@noiz.bio

10. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. The table below outlines our retention periods:

Data TypeRetention PeriodBasis
Account and profile dataUntil account deletion + 30 daysContract performance
Analytics data (anonymized)90 daysLegitimate interest
IP address in sign-in logs (full address)30 daysLegitimate interest / Security
IP digests in abuse limiters24 hours to 7 daysLegitimate interest / Security
Payment and transaction records10 yearsLegal obligation (§ 147 AO, § 257 HGB)
Sign-in attempts30 daysLegitimate interest / Security
Admin access logs1 yearLegitimate interest / Security
Cookie consent records12 months from consentLegal compliance (ePrivacy)
Support inquiries3 years from receiptLegitimate interest (§ 195 BGB)
Backup data30 days after deletion from productionBusiness continuity

10.1 Retention Criteria

When determining retention periods, we consider:

  • The nature and sensitivity of the personal data
  • The potential risk of harm from unauthorized use or disclosure
  • The purposes for which we process the data
  • Whether we can achieve those purposes through other means
  • Applicable legal, regulatory, tax, accounting, or other requirements

10.2 Deletion Procedures

When data reaches the end of its retention period, or upon valid deletion request, we securely delete or anonymize the data. Anonymized data (which can no longer identify you) may be retained indefinitely for statistical purposes.

11. Cookies, Local Storage and Analytics

noiz.bio does not set any cookies. Not for analytics, not for advertising, and not for sign-in. This is a claim you can check yourself: no response from noiz.bio contains aSet-Cookieheader, and your browser's cookie list for this site stays empty.

What we do use is your browser's local storage — a small amount of data kept on your own device and never automatically sent anywhere. Everything in it is listed below. Local storage is covered by the same rules as cookies, so we treat it the same way: each item is either strictly necessary to run the service you asked for, or you can switch it off.

11.1 What We Store on Your Device

KeyWhat it doesCreated whenKept untilCategory
noiz-cookie-consentRemembers the choice you made on the privacy banner, so you are not asked againYou choose on the banner12 months, then we ask againStrictly necessary
noiz-session-idA random ID stored alongside your consent record, so we can show which choice belongs to which browser if you ever query it. Not used to track you and not attached to analytics.You choose on the bannerYou clear site dataStrictly necessary
sb-<project>-auth-tokenKeeps you signed in to your account (issued by Supabase, our database provider)You sign inYou sign out, or it expiresStrictly necessary
auth_rate_limit
forgot_password_rate_limit
email_change_rate_limit
password_change_rate_limit
contact_form_rate_limit
Counts recent attempts so sign-in, password resets and the contact form can be throttled against abuseYou use one of those formsThe limit window passes, or you sign outSecurity
dismissed_announcementsRemembers which in-app notices you have closed, so they stay closedYou close a noticeYou sign outFunctional

All of the above is first-party: it is written by noiz.bio, read only by noiz.bio, and never sold, shared, or used to build an advertising profile. There are no third-party trackers, tag managers, or advertising pixels on any noiz.bio page, including creator profiles.

The record of your choice, kept on our side

One thing is not stored on your device: the record of the choice itself. When you answer the banner we write it down on our server, whether or not you have an account. We have to be able to show that you were asked and what you answered, and a record that exists only in your own browser is not evidence of anything — you can clear it, and so could we.

Here is that record in full. It contains:

  • Which choice you made — accept, reject, or the switches you set yourself
  • The version of this notice you were shown (currently 1.0), so a later revision can re-ask you
  • When you chose, taken from our clock rather than yours, and the date it expires 12 months later
  • The random noiz-session-idfrom the table above — and, only if you were signed in at the time, your account ID
  • Whether you have since withdrawn it

That is the entire record. No IP address, no user-agent string, no fingerprint of any kind — the database itself refuses a consent record carrying an IP, so this is a property of the system and not only a promise about it. If you were not signed in, the record holds nothing that identifies you beyond a random ID your own browser generated. We keep it for 12 months, the same period as the choice.

These records are readable only by you (when signed in) and by our administrators. Withdrawing via Privacy choices in the footer marks this browser's record as withdrawn rather than deleting it, because when you withdrew is part of the same evidence.

11.2 Analytics Stores Nothing on Your Device

Creators can see how their profile is performing. That measurement is deliberately built so that visiting a profile leaves nothing behind on your device — no cookie, no local storage entry, no identifier of any kind. A view is counted server-side, at the moment of the request, and then the request is over.

What is recorded for a profile view or link click:

  • A hashed IP address — hashed before storage, so it cannot be read back or reversed to your address
  • The referring site, if your browser sent one, and any campaign parameters in the link you followed
  • A coarse device category (mobile, tablet, desktop) derived from your browser's user-agent string
  • Which profile or link was viewed, and when

Creators only ever see totals and trends, never individual visitors. Because nothing is stored on your device and nothing follows you to another site, this cannot identify you or track you across the web. Our lawful basis is legitimate interest (GDPR Article 6(1)(f)): creators need to know whether their page works. You can still switch it off — see below, and we honour it.

11.3 Your Choices

The privacy banner shown on your first visit gives you three options:

  • Accept: analytics measurement stays on
  • Reject: analytics measurement is switched off for this browser; only strictly necessary storage remains
  • Customize: set analytics on or off yourself

You can change your mind at any time using Privacy choices in the site footer. Turning analytics off takes effect immediately for every page you load afterwards, including creator profiles.

The strictly necessary and security items in the table above cannot be switched off, because without them you could not stay signed in and we could not protect accounts against automated attacks. They are exempt from the consent requirement for exactly that reason.

11.4 How to Clear It Yourself

Signing out removes the app's own entries. To remove everything, clear this site's data in your browser — the same control that clears cookies also clears local storage:

Clearing site data also removes your saved privacy choice, so the banner will appear again on your next visit.

12. Data Security

We implement appropriate technical and organizational security measures to protect your personal information in accordance with GDPR Article 32:

12.1 Technical Measures

  • Encryption in Transit: All data transmitted to and from our servers uses TLS 1.3 encryption
  • Encryption at Rest: Sensitive data is encrypted using AES-256 encryption
  • Password Security: Passwords are hashed using industry-standard algorithms (never stored in plaintext)
  • Two-Factor Authentication: Optional 2FA for enhanced account security
  • Secure Payment Processing: Payments handled by Stripe (PCI-DSS Level 1 compliant)
  • IP Hashing: Visitor IP addresses are hashed for privacy before storage

12.2 Organizational Measures

  • Access Controls: Strict access controls and role-based permissions
  • Security Audits: Regular security assessments and monitoring
  • Incident Response: Documented procedures for handling security incidents
  • Data Minimization: We only collect and retain data necessary for our purposes

12.3 Privacy by Design and Default

In accordance with GDPR Article 25, we implement data protection principles from the design phase of our services:

  • Privacy-preserving defaults for all new features
  • Data minimization in all collection processes
  • Pseudonymization where possible (e.g., IP hashing)
  • Regular privacy impact assessments for new processing activities

However, no method of transmission over the Internet or electronic storage is 100% secure, and we cannot guarantee absolute security. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately.

13. Data Breach Notification

In accordance with GDPR Articles 33 and 34, we have procedures in place to detect, report, and investigate personal data breaches.

13.1 Notification to Supervisory Authority

If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach
  • Document the breach, its effects, and remedial actions taken
  • Provide the authority with all required information as per GDPR Article 33(3)

13.2 Notification to Affected Individuals

If a breach is likely to result in a high risk to your rights and freedoms, we will:

  • Notify you without undue delay
  • Describe the nature of the breach in clear and plain language
  • Provide the name and contact details of our data protection contact
  • Describe the likely consequences of the breach
  • Describe the measures taken or proposed to address the breach
  • Provide recommendations for you to mitigate potential adverse effects

13.3 Our Commitment

We take data security seriously and continuously work to prevent breaches. However, if an incident occurs, we are committed to transparent and timely communication with both authorities and affected users.

14. Your Data Subject Rights (GDPR)

If you are in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under data protection law:

Right of Access (Art. 15)

Request a copy of your personal data we hold. We will provide this in a commonly used electronic format.

Right to Rectification (Art. 16)

Request correction of inaccurate or incomplete personal data. You can also update most information directly through your account settings.

Right to Erasure (Art. 17)

Request deletion of your personal data ("right to be forgotten"). This applies when the data is no longer necessary, you withdraw consent, or you object to processing.

Right to Restriction (Art. 18)

Request restriction of processing while we verify the accuracy of your data or the legitimacy of our processing.

Right to Data Portability (Art. 20)

Request transfer of your data in a structured, commonly used, machine-readable format (e.g., JSON, CSV) to another service provider.

Right to Object (Art. 21)

Object to processing based on legitimate interests or direct marketing. We will stop processing unless we have compelling legitimate grounds.

Right to Withdraw Consent (Art. 7)

Withdraw consent at any time where processing is based on consent. This does not affect the lawfulness of processing before withdrawal.

Right Not to be Subject to Automated Decisions (Art. 22)

Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects (see Section 15).

14.1 How to Exercise Your Rights

To submit a data subject request:

  1. Email us at privacy@noiz.bio with your request
  2. Include your account email address for identification
  3. Specify which right(s) you wish to exercise
  4. We may ask for additional information to verify your identity

14.2 Response Timeframe

  • We will respond to your request within 30 days
  • For complex requests, we may extend this by up to 60 additional days (we will inform you)
  • Requests are processed free of charge, except for manifestly unfounded or excessive requests

14.3 Right to Lodge a Complaint

If you are not satisfied with how we handle your request, you have the right to lodge a complaint with a supervisory authority (see Section 17).

15. Automated Decision-Making

In accordance with GDPR Article 22, we inform you about any automated decision-making processes that may affect you:

Our Position

Noiz does NOT use automated decision-making, including profiling, that produces legal effects or similarly significantly affects you. All decisions that materially impact your account or access are made with human oversight.

15.1 Automated Processing We Do Use

We use automated processing for the following non-consequential purposes:

  • Content Filtering: Automated checks for prohibited content in profile text (human review for any actions)
  • Spam Detection: Automated detection of suspicious activity patterns (human review before account restrictions)
  • Analytics: Automated aggregation of usage statistics (no individual decisions made)

15.2 Your Rights

If you believe any automated processing has unfairly affected you, you have the right to:

  • Request human intervention in any decision
  • Express your point of view
  • Contest any decision made

16. Children's Privacy

The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13.

16.1 Age Requirements

  • Minimum Age: 13 years old (worldwide)
  • EU Users: In certain EU member states, users between 13-16 may require parental consent
  • COPPA Compliance: We comply with the Children's Online Privacy Protection Act for US users

16.2 If We Discover Underage Users

If we become aware that we have collected personal information from a child under the applicable minimum age without proper consent:

  • We will promptly delete that information
  • We will terminate the associated account
  • We will notify the parent or guardian if contact information is available

If you believe a child has provided us with personal information, please contact us immediately at privacy@noiz.bio

17. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

17.1 Your California Rights

  • Right to Know: Request information about the categories and specific pieces of personal information we have collected
  • Right to Delete: Request deletion of your personal information (subject to certain exceptions)
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising your rights
  • Right to Limit Use: Limit the use and disclosure of sensitive personal information

17.2 "Do Not Sell My Personal Information"

Noiz does NOT sell your personal information. We do not sell, rent, or trade your personal data to third parties for monetary or other valuable consideration. We do not share your information for cross-context behavioral advertising.

17.3 Shine the Light

California Civil Code Section 1798.83 permits California residents to request information regarding disclosure of personal information to third parties for direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.

17.4 Removal of Content Posted as a Minor

If you are a California resident under 18 and have publicly posted content on our Service, you may request removal of that content by contacting us. Note that removal may not ensure complete removal if the content has been reposted by others.

18. Supervisory Authority

If you are located in the European Economic Area and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.

18.1 German Supervisory Authority

As we are based in Baden-Württemberg, Germany, our lead supervisory authority is:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg

Lautenschlagerstraße 20

70173 Stuttgart

Germany

Phone: +49 711 615541-0

Website: www.baden-wuerttemberg.datenschutz.de

18.2 Other EU/EEA Authorities

You may also lodge a complaint with the supervisory authority in your country of residence. A list of EU data protection authorities can be found at: European Data Protection Board

We encourage you to contact us first at privacy@noiz.bio so we can try to resolve your concerns directly before you escalate to a supervisory authority.

19. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

19.1 How We Communicate Changes

  • We will post the updated policy on this page with a new "Last updated" date
  • For material changes, we will provide at least 30 days' advance notice via email to your registered address
  • Material changes include: new categories of data collection, new processing purposes, changes to data sharing practices, or changes to your rights

19.2 Your Continued Use

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you should discontinue use of the Service and delete your account.

We encourage you to review this Privacy Policy periodically to stay informed about our data practices.

20. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Noiz

Inhaber: Fabian Schneidruck

Leopoldplatz 13

76437 Rastatt

Germany

USt-IdNr.: DE367705746

Contact Channels

Privacy Inquiries: privacy@noiz.bio

Data Subject Requests: privacy@noiz.bio

Legal Matters: legal@noiz.bio

General Support: support@noiz.bio

Response Timeframe: We aim to respond to all privacy-related inquiries within 30 days. For data subject requests, we will respond within the timeframes required by applicable law.