Privacy

Privacy Policy

This policy explains what personal data Marisonus processes, why it is processed, how uploads are handled across account and demo flows, and how support, verification, and retention controls currently operate.

Last updated

June 23, 2026

This Privacy Policy is provided by MB Marisonus and describes how we handle personal data in compliance with GDPR and applicable data protection laws. For privacy inquiries or data subject requests, contact info@marisonus.com with sufficient detail to identify the data subject and request type (e.g., access, deletion, correction).

Account raw files are temporary

For signed-in uploads, the original source audio is deleted after analysis finishes. The retained account record is the analysis history and related metadata.

Demo raw files are temporary

Chunk files and queued raw demo files are deleted after analysis completes or fails. Derived results and limited job metadata can remain temporarily in operational storage.

Improvement retention is opt-in

Demo uploads are not supposed to be retained for service-improvement or reference-development purposes unless the user explicitly opts in.

1. Data controller and policy scope

This policy applies to the Marisonus website, analyzer workspace, account registration, demo upload flow, billing-related account fields, and support or security operations tied to the service.

Data Controller: MB Marisonus, info@marisonus.com. This policy describes how the service handles data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. All personal data processing is conducted with the understanding that audio uploads are for analysis purposes only and will not be retained or shared without explicit user consent.

2. Categories of data we process

We may process account identity data such as name, email address, company name, and profile preferences when you register or update your account.

We may process authentication and security data such as password changes, session identifiers, access tokens, IP-derived security signals, admin audit events, incident records, rate-limit state, and brute-force protection metadata.

We may process upload-related data such as filenames, file size, duration, format, temporary chunk identifiers, upload/session identifiers, analyzer mode, improvement-consent flags, and derived analysis results.

If paid billing is enabled later, we may also process billing contact fields, subscription state, processor IDs, and plan metadata necessary to operate recurring access.

3. How we use personal data

We use personal data to create and manage accounts, authenticate users, deliver audio analysis, enforce plan limits, secure the platform, investigate failures, prevent abuse, and operate support, billing, and infrastructure workflows.

We also use operational data to monitor availability, troubleshoot analysis failures, review security incidents, and improve reliability of the upload and analysis pipeline.

4. Legal bases for processing (GDPR)

Where applicable data protection law requires a legal basis, Marisonus generally relies on: (a) contract necessity to provide the requested service (GDPR Article 6(1)(b)); (b) legitimate interests in securing and operating the platform (Article 6(1)(f)); (c) consent where optional demo-retention or marketing preferences are offered (Article 6(1)(a)); and (d) legal obligations where records must be retained by law (Article 6(1)(c)). Audio analysis for service delivery is based on contract necessity. Optional improvement consent uses explicit opt-in. Security and abuse prevention rely on legitimate interests.

5. Audio uploads and analysis data

For signed-in users, the service processes the uploaded source audio, creates the analysis record, and then deletes the stored source file after the analysis completes or terminally fails. The retained account history consists of metadata, timestamps, metrics, and recommendations rather than a downloadable copy of the original upload.

For demo uploads, temporary chunk files are stored only long enough to reassemble and validate the upload. When async processing is used, the queued raw file is stored in processing storage during analysis and is then deleted after completion or terminal failure. A temporary session copy of analysis output may be stored to hand the result back to the demo user.

Derived analysis payloads, incident records, and minimal async job metadata may remain in the operational database for reliability, abuse prevention, and troubleshooting even after the raw demo file has been deleted.

6. Optional improvement consent

Demo users must confirm they accept the governing terms and that they have the right to upload the audio. Signed-in members may also be shown a separate optional improvement-consent prompt before upload.

Declining that optional improvement consent does not block the ordinary analysis flow.

If that optional consent is not selected, the upload should be handled for the requested analysis flow only. If it is selected, Marisonus may retain the material or associated outputs longer for service improvement, calibration work, or future reference-model development, subject to internal review and security controls.

The current codebase keeps that consent separate from the core analysis flow and can route opted-in member uploads into an internal genre-based reference-library import folder. It does not automatically publish uploads into any public library, expose them to other customers, or automatically add them into a customer-visible shared reference corpus.

Opted-in internal reference imports are intended to remain stored until the uploader submits a deletion request through support or Marisonus removes them internally.

7. Sharing and processors

We may share data with hosting, storage, queue, cache, security, authentication, and payment infrastructure providers that process data on our behalf and under our instructions.

We may also disclose data where reasonably necessary to investigate abuse, protect the platform, comply with law, respond to valid legal process, or enforce our rights.

We do not describe customer audio as public or community-visible content. Access is intended to be restricted to the uploader, authorized staff, and infrastructure processors needed to run the service.

8. Retention

Account profile data is typically retained while the account remains active and for a reasonable period afterward where needed for security, billing, or legal recordkeeping.

For signed-in workspace uploads, the original source audio is not intended to remain in long-term storage after analysis. The retained account history is the analysis record and associated metadata until deleted by the user, removed through account deletion handling, or aged out under the currently configured member-history retention window.

The current launch configuration is set up for these initial windows: completed demo-derived job records for 24 hours, failed demo jobs for 72 hours, abuse and security event records for 30 days, and signed-in member analysis history for 7 days. Production should run the purge command on a scheduler and can change those windows later if infrastructure capacity or public policy commitments change.

9. Your choices and rights (GDPR Data Subject Rights)

You may be able to access, correct, update, or delete parts of your data through the product interface or by using the public support workflow on the contact page. For signed-in analysis history, the repository now supports self-service deletion of individual entries and full history removal.

You have the right to request access to your personal data (GDPR Article 15), correction of inaccurate data (Article 16), and erasure of your data ('right to be forgotten', Article 17). You may also request restriction of processing (Article 18), data portability (Article 20), and object to processing (Article 21). To exercise these rights, contact info@marisonus.com with sufficient detail to process the request. We aim to respond within 30 days.

Anonymous demo users who want manual deletion review should submit the request promptly through the same support path, because the normal demo-retention windows are intentionally short.

You also have the right to lodge a complaint with your local data protection supervisory authority (e.g., your country's Data Protection Authority) if you believe your rights have been violated.

10. Security

Marisonus uses technical and organizational measures intended to reduce unauthorized access, including authentication controls, admin restrictions, rate limiting, tokenized analyzer access, security logging, and infrastructure security settings.

No internet service is absolutely secure. You should upload only through trusted devices and networks and should not share account credentials or analyzer access tokens.

11. International hosting and transfers

The service may rely on cloud providers or infrastructure located in more than one jurisdiction. If personal data is transferred across borders, Marisonus expects to rely on appropriate contractual, organizational, or statutory safeguards where required by law.

12. Children

The service is not intended for children and should not be used by anyone who is not old enough to form a binding agreement under applicable law.

13. Policy changes

We may update this policy as the product, infrastructure, legal setup, or billing model changes. Material updates should be reflected on this page with a revised effective date.