Privacy
Privacy statement
Last updated: 26 April 2026
Musicdott is a working environment for music schools and the teachers and students who use it. This statement explains exactly which personal data we hold, why we hold it, and what you can do to control it. We are a small company; this is not a 30-page legal document — it is the maker explaining how things work.
Where this statement and the General Data Protection Regulation (AVG/GDPR) say different things, the law wins. If you spot something inconsistent, mail mail@musicdott.app and we fix it.
Who is responsible for your data?
The data controller is:
- Musicdott — a trading name of Bèta Development VOF (KvK 71344233). Partners: Stefan van de Brug and Oscar Knijff.
- Aalbessenstraat 6, 's-Gravenhage, the Netherlands
- mail@musicdott.app
What personal data do we hold?
Different data per role. Only what we need to make the platform work.
School owners
- Name, e-mail, username, hashed password.
- School name, address, phone, website (optional).
- Stripe customer ID and subscription ID once you subscribe — payment card details are held by Stripe, not by us.
- Login history (last login timestamp + IP for security alerts).
Teachers
- Name, e-mail, hashed password, instruments taught.
- Lessons created and the content blocks within them.
Students
- Name, e-mail, optional phone and birthdate, optional parent e-mail.
- Lesson assignments, practice logs, progress notes from the teacher.
- Lesson attendance and the time spent in lesson sessions.
Minors: Many drum and band students are under 16. Their accounts are created by their music school owner under their own legal basis as service provider; the parent e-mail (if provided) is used only for billing and lesson reminders. Parents can request access, correction, or deletion via the school owner or directly via mail@musicdott.app.
Why do we hold this data?
Strictly to operate the service:
- Authenticate users and protect accounts (legal basis: contract).
- Show students their lesson material and track their progress (legal basis: contract).
- Bill the school owner via Stripe (legal basis: contract + legal obligation for invoicing).
- Send transactional e-mails (signup, password reset, invitation, lesson reminders) (legal basis: contract).
We do not use your data for marketing, profiling or any kind of automated decision-making.
Who do we share data with?
Only with sub-processors that are strictly required to deliver the service. They each have their own DPA.
- Stripe — Payment processing. Receives the payer’s name, e-mail and card details directly (we never see the card number).
- Hostinger — Outgoing transactional e-mail. Receives recipient e-mail address + the message.
- Railway — Hosting and database (PostgreSQL) within the EU. Holds the entire Musicdott database.
- Sentry — Error tracking. Receives stack traces and request paths when something breaks; PII is filtered as much as possible.
We do not sell or trade personal data with third parties under any circumstance.
How long do we keep your data?
- Active accounts: as long as the school subscription is active.
- After cancellation: 90 days during which the school owner can re-activate; then permanently deleted, except invoice records.
- Invoices and payment records: 7 years (Dutch tax law).
- Auth tokens (password reset, email verify, invitations): expire after 1 hour to 14 days respectively, then auto-purged.
Your rights under the AVG/GDPR
You can exercise the following rights at any time. Most are self-service inside the app:
- Access — See what we hold about you in your account settings, or request a full copy via mail@musicdott.app.
- Data portability — Use the "Export my data" button in account settings (calls /api/user/export). You get a JSON download with all of your records.
- Correction — Edit your profile in account settings, or mail us if a correction needs special handling.
- Erasure ("right to be forgotten") — Use "Delete my account" in account settings. We anonymise the linked student records first, then permanently delete your user record. Invoices are kept for 7 years (legal obligation).
- Objection — Object to a particular processing activity by emailing us. Since we don't do marketing or profiling, this rarely applies.
- Complaint — Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl. We hope you talk to us first; we read every email.
How do we protect your data?
Passwords are scrypt-hashed (or bcrypt for legacy accounts). Sessions use HTTP-only secure cookies. The database lives on Railway in the EU with daily backups. All traffic is over HTTPS. Auth tokens are sha256-hashed at rest. We follow OWASP Top 10 in our code reviews. We are honest about what we do not have yet: a formal SOC2 audit, third-party pentest reports, or a 24/7 SOC. If those are blockers for your school, Musicdott is probably not the right fit.
Cookies
We only use functional cookies: a session cookie to keep you logged in, and a CSRF cookie. No marketing or analytics cookies. We do not use Google Analytics, Facebook Pixel, Hotjar, or any tracker that profiles you.
Changes to this statement
If we change something material we'll email all account holders. Smaller changes are reflected on this page with a new "last updated" date. Significant policy changes require explicit re-consent before they take effect.
Contact
Questions about your data, or about this statement: mail@musicdott.app. We answer within one working day during the beta. After the beta, within five working days.