Last updated July 8, 2026
Privacy Notice
This notice is provided by Unsigned Now LLC (“Unsigned”, “we”, “us”, “our”), operator of the Unsigned platform and website (the “Service”). It forms part of, and should be read alongside, our Terms of Service, our Cookie Notice and our Data Processing Addendum.
Who we are and how to contact us
Data controller: Unsigned Now LLC, 1021 E Lincolnway, Suite #10234, Cheyenne, Wyoming 82001, USA.
Privacy contact: info@unsigned.now.
Data Protection Officer: No Data Protection Officer has been appointed.
The personal data roles in the Service
The Service involves two distinct groups of people, and our data-protection role differs for each. It is important to understand this split because it determines who is responsible for what.
If you are a user (a musician or artist). When you create an account, upload music and use the Service, we act as the controller of your account and User Content data. We decide how that information is handled in order to provide the Service to you.
If you are a recipient (an industry contact).We maintain a database of professional, business-role contact details for music-industry recipients (such as labels, A&R staff, DJs, curators and distributors) and we transmit user-initiated communications to them. In respect of that recipient data, we act as a controller, because we determine the sourcing, selection, matching and retention of those details. Our lawful basis and safeguards for this are set out below.
The user’s own role in outreach. When you review, edit and send a communication from your own account, you determine the content and the decision to make contact. To that extent you act as an independent controller of your own outreach. We are not your processor for that activity, and you are responsible for your communications as set out in the Terms of Service (clauses 7.2–7.4, 7.7).
What personal data we collect
Data about users.
- Account data: name, email address, password credentials, and profile details you provide.
- User Content: music, audio, artwork and related material you upload, and derived data such as audio analysis and generated pitch/metadata content.
- Usage and outreach data: records of the drafts generated for you, the communications you choose to send, and recipients you contact.
- Billing data: subscription status and payment information processed by our payment provider.
- Technical data: IP address, device/browser information, and cookie or similar-technology data (see our Cookie Notice).
Data about recipients.For recipients, we hold business and professional-role contact information only — for example a professional or role-based email address (such as a submissions, demo or A&R address), the associated organisation or project, and any public submission link. We do not knowingly collect or use recipients’ personal (private, non-professional) email addresses, because outreach to individuals in a personal capacity is subject to stricter rules in the UK and most EU/EEA countries than outreach to business contacts.
Source of recipient data. Consistent with clause 7.1 of the Terms, recipient contact information is sourced from publicly available sources — including recipients’ own official websites, social-media and link-in-bio pages, public submission pages, and publicly indexed search results. We do not scrape or reproduce any third-party platform’s private member directory, and we do not store private contact data. The fact that information is publicly available does not by itself exempt it from data-protection law, which is why we set out our lawful basis and safeguards below and provide the transparency information required when data is obtained indirectly.
How we use personal data and our lawful bases
The tables below set out, for each purpose, the personal data used and the lawful basis under UK GDPR / EU GDPR Article 6. Where we rely on legitimate interests, you may ask us for a summary of the balancing assessment.
Users
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and administering your account; providing the Service | Account data, usage data | Performance of a contract (Art. 6(1)(b)) |
| Storing and analysing your User Content and generating draft pitch/metadata content | User Content, derived data | Performance of a contract (Art. 6(1)(b)) |
| Processing payments, trials and renewals | Billing data | Performance of a contract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c)) |
| Securing the Service, preventing abuse and enforcing the No-Spam policy | Account, usage, technical data | Legitimate interests (Art. 6(1)(f)) — protecting the Service and third parties |
| Service-related communications (e.g. transactional and account emails) | Account data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Optional product-marketing to you (if offered) | Account data | Consent (Art. 6(1)(a)) and PECR consent where required |
| User behaviour analytics for product improvement | Pseudonymous user identifiers, click events, scroll events, session start and end timestamps, device type data, OS data, IP address | Consent (Art. 6(1)(a)) and PECR consent where required |
Recipients
| Purpose | Data used | Lawful basis |
|---|---|---|
| Maintaining a database of professional recipients so users can identify relevant industry contacts | Business-role contact data | Legitimate interests (Art. 6(1)(f)) — connecting artists with relevant professionals |
| Transmitting user-initiated context-sharing communications to recipients | Business-role contact data | Legitimate interests (Art. 6(1)(f)); see the section on PECR below |
| Handling recipient objections, removal requests and suppression | Business-role contact data | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
More about our legitimate interests
Where we rely on legitimate interests, we have weighed our interests, and those of our users, against the rights and reasonable expectations of the people concerned. In summary: our interest is in operating a service that connects independent artists with industry professionals in their professional capacity; we use only business/professional-role contact details; recipients who publish a professional submission or contact address can reasonably expect to receive relevant, individually-directed submissions; and we provide an easy way to object and be suppressed at any time.
Contacting recipients — PECR and the ePrivacy Directive
Separately from UK/EU GDPR (which governs the use of personal data), the Privacy and Electronic Communications Regulations 2003 (PECR) in the UK, and national laws implementing the ePrivacy Directive 2002/58/EC across the EU/EEA, govern electronic communications. Our approach is as follows.
Nature of the communications. Communications transmitted through the Service are user-initiated music context-sharing and outreach: an artist asks us to pass on their music and submission details to a relevant professional recipient. These communications are not sent to advertise or promote Unsigned’s own goods or services, and we do not include Unsigned product-marketing within them. On that basis we consider that they do not constitute “direct marketing” within the meaning of Regulation 22 of PECR.
Business recipients only. We direct communications to professional, business-role recipients, not to individuals in a personal capacity. Under PECR, the prior-consent rule in Regulation 22 applies to “individual subscribers”; communications to corporate subscribers fall outside it. We do not send communications to recipients who are individual subscribers (such as sole traders or private individuals) without an appropriate basis.
Sender identification and opt-out (Regulation 23). Every communication sent through the Service identifies the sender and includes a valid, cost-free means for the recipient to opt out of further contact, consistent with Regulation 23 of PECR. When a recipient opts out or asks to be removed, we suppress their details across the Service so they are not contacted again.
Who we share data with, and international transfers
Service providers (processors). We share personal data with third parties that provide services to us, under written data-processing terms that require them to protect it and act only on our instructions. Our current sub-processors, by function, are:
- Hosting and infrastructure — application hosting and database.
- Payment processing.
- Email delivery and validation — transactional and outreach email, and email-address validation.
- AI processing — audio analysis and generation of draft pitch and metadata content.
- Monitoring and product analytics.
A full list of our sub-processors is available on request. We keep it current and update it when our sub-processors change.
AI and model training. We use third-party AI processing services to analyse audio and generate draft pitch, metadata and related content. We use these providers through their APIs on no-training terms: your User Content and personal data are used only to provide the Service to you, and not to train or fine-tune their models. Our signed data-processing agreements with these providers back this up.
Recipients. When you send a communication, the content you approve (including your name, music links and message) is disclosed to the recipient you are contacting. Recipients are independent third parties.
International transfers. Unsigned is established in the United States, and personal data of UK and EU/EEA individuals is transferred to and processed in the US. Where we transfer personal data outside the UK or EEA, we rely on appropriate safeguards under Article 46 UK/EU GDPR. In practice this means one of two mechanisms per provider: where a provider is certified under the EU-US Data Privacy Framework and its UK Extension, the transfer is covered by the corresponding UK and EU adequacy decisions; where a provider is not certified, we rely on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum or IDTA. We retain these safeguards even where a provider is separately certified. You may request information about the safeguard applying to a particular transfer using the contact details above.
Your rights
Under UK GDPR and EU GDPR, individuals (both users and recipients) have the following rights, subject to conditions and exemptions:
- Access — a copy of your personal data.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion in certain circumstances.
- Restriction — to limit processing in certain circumstances.
- Portability — to receive certain data in a portable format.
- Object — in particular, an absolute right to object to direct marketing, and a right to object to processing based on legitimate interests (Art. 21).
- Rights relating to automated decision-making.
- Withdraw consent — where processing is based on consent, at any time.
Recipients: you can object to our processing of your details or ask to be removed at any time using the opt-out in any message we send, or by contacting our privacy contact above. We will action removal and add you to our suppression list within 30 days.
To exercise any right, contact us at info@unsigned.now. You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner’s Office (ICO), ico.org.uk; in the EU/EEA, your local Data Protection Authority.
How long we keep personal data
We keep personal data only as long as necessary for the purposes described, then delete or anonymise it.
- User account and User Content: for the life of your account; the User Content licence ends when you delete the content or close your account (see Terms). We delete or anonymise this data within 30 days of account closure.
- Billing records: retained for 7 years to meet tax and accounting obligations.
- Recipient data: kept while it remains relevant to the Service and re-verified on an ongoing basis (bounce and validity checks). It is removed on request or when found invalid, and reviewed at least every 12 months.
- Suppression list: retained as long as necessary to honour opt-outs (this is a lawful reason to keep minimal data indefinitely).
Children
The Service is not directed to children. The minimum age of use is 18 years.
Security
We take appropriate technical and organisational measures to protect personal data, and we choose service providers that do the same. These measures include encryption of data in transit and at rest, access controls limiting who can access personal data, and due-diligence and written data-protection terms with our sub-processors. No system is completely secure, but we work to protect personal data proportionately to the risk.
Changes to this notice
We may update this notice from time to time. Where changes are material, we will take reasonable steps to notify you. The “Last updated” date at the top shows when it was last revised.
