Underground Platform — Privacy Policy
Status: pre-launch draft for legal review
Effective date: to be set before public beta
Last updated: 25 July 2026
This document is an operational draft and does not replace advice from qualified Italian/EU counsel.
1. Data controller
Underground Platform is operated by Gianluca Pizzamiglio, acting as Data Controller.
The operator postal or elected service address must be completed before public beta.
Privacy contact: privacy@undergroundplatform.com
General support: support@undergroundplatform.com
Legal contact: legal@undergroundplatform.com
2. Scope
This policy explains how Underground Platform processes personal data when users create accounts, manage bands, publish content, listen to music, communicate, interact with community features, contact support or exercise data-protection rights.
3. Categories of personal data
Depending on the features used, Underground may process:
- account and identity data, including email address, display name, account type and authentication records;
- profile and band data, including biographies, locations, roles, images, social links and public credits;
- user content and related metadata, including music, artwork, release data, comments and messages;
- usage and technical data, including session identifiers, IP addresses, security logs, device/browser information and request metadata;
- communication and support data;
- moderation, abuse, copyright, legal-hold and dispute records;
- privacy-request identity-verification, correspondence and response records;
- consent and legal-document acceptance evidence when implemented.
Underground does not intentionally request special-category data. Users should avoid submitting unnecessary sensitive information through profiles, messages or support requests.
4. Purposes and lawful bases
Personal data may be processed to:
- provide accounts, authentication, band administration, publishing, playback, discovery and communication features;
- perform the contract with users and take requested pre-contractual steps;
- maintain security, prevent abuse, investigate incidents and protect platform integrity based on legitimate interests and legal obligations;
- comply with GDPR requests, copyright notices, court orders, legal holds and statutory duties;
- send essential service communications;
- send optional communications only where a valid lawful basis or consent exists;
- produce privacy-preserving aggregate product metrics without cross-site tracking or user fingerprinting.
The detailed processing inventory and lawful-base mapping are maintained in `PROCESSING_ACTIVITIES.md`.
5. Public information
Information intentionally published on public profiles, releases, credits, recruitment listings, comments or similar areas may be visible to anyone and may be indexed or shared outside Underground. Users must have authority to publish information about other people.
Private messages and unpublished drafts are not public, but may be accessed where strictly necessary for security, moderation, support, legal compliance or the investigation of substantiated reports.
6. Recipients and processors
Personal data may be processed by infrastructure, storage, email, monitoring, content-delivery, playback, security and support providers acting under contractual safeguards.
The current provider inventory, locations and transfer safeguards are maintained in `PROCESSOR_AND_DATA_LOCATION_REGISTER.md`. Production vendors and Article 28 data-processing agreements must be finalised before public beta.
Underground does not sell personal data.
Playback Providers
Underground Platform uses a provider-agnostic playback architecture. Multiple playback providers may be integrated depending on the implementation available at a given time.
Current playback provider
The public beta uses YouTube (operated by Google Ireland Limited) as the active embedded playback provider for recordings that have a YouTube playback source configured.
When a user initiates playback of a YouTube-sourced recording, the Platform loads the YouTube IFrame Player API. Google may independently process:
- IP address;
- device and browser information;
- playback interactions;
- data linked to a Google account if the user is signed in.
This processing is performed by Google as an independent controller under its own Privacy Policy: https://policies.google.com/privacy.
Underground Platform does not receive personal data from Google as a result of this integration. The Platform records only aggregated, anonymous playback metrics (start, completion, skip) without user identification.
Self-hosted playback
The Platform architecture supports self-hosted audio delivery through its own object storage infrastructure. When self-hosted playback is available for a given recording, no third-party provider is involved in the delivery.
Future providers
Additional playback providers may be integrated in the future. Each provider and its data processing implications will be documented in this Privacy Policy when activated.
7. International transfers
Where data is processed outside the European Economic Area, Underground will use an applicable adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism and will complete any required transfer-impact assessment.
8. Retention
Personal data is retained only for as long as needed for the stated purposes, security, disputes, legal obligations and legitimate operational needs.
Retention periods, deletion rules, backup handling, anonymisation and legal-hold exceptions are defined in `RETENTION_POLICY.md`. Production deletion and backup-propagation procedures must be tested before public beta.
9. User rights
Subject to applicable law, users may request:
- access to personal data;
- correction of inaccurate data;
- deletion;
- restriction of processing;
- objection to processing based on legitimate interests;
- portability of eligible data;
- withdrawal of consent without affecting earlier lawful processing;
- information about safeguards for international transfers;
- review of qualifying automated decisions, if introduced.
Requests may be submitted to privacy@undergroundplatform.com. Underground may request proportionate identity verification. Operational handling is defined in `DSAR_PROCEDURE.md`.
Users may also lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority in their country of residence or work.
10. Account deletion and content relationships
Deleting an account does not necessarily delete content jointly administered by a band, public credits that must remain accurate, dispute records, security logs or records subject to a legal hold. Underground will distinguish between personal account data, shared band assets, public attribution and legally required records.
Public content will be removed or de-identified where appropriate and technically feasible, subject to rights, contractual and legal requirements.
11. Cookies and local storage
Essential session, authentication, security and preference technologies may be used without consent where legally permitted. Non-essential analytics, advertising or similar technologies will remain disabled until valid consent is obtained.
Details are provided in `COOKIE_POLICY.md`.
12. Security
Underground applies technical and organisational measures appropriate to the service and risk, including access controls, credential protection, secure transport, logging, backup controls, vulnerability management and incident response.
No online service can guarantee absolute security. Security concerns should be reported to security@undergroundplatform.com.
13. Personal-data breaches
Suspected personal-data breaches are assessed, documented and handled under the incident-response procedure, including the GDPR 72-hour supervisory-authority assessment where applicable.
14. Children
The minimum age and parental-authorisation rules must be finalised before public beta following review under Italian law and Article 8 GDPR. Underground does not knowingly permit registration below the final applicable threshold.
15. Automated systems and AI
Underground may use automation for security, spam prevention, moderation support, search, accessibility, transcription, tagging and requested product functions.
User content and personal data will not be used to train general-purpose generative AI systems without specific, informed and explicit prior consent where required. Further rules are defined in `AI_POLICY.md`.
16. Changes to this policy
Material changes will be versioned and dated. Renewed notice or consent will be requested where legally required. Acceptance evidence will be retained once the legal-document versioning workflow is implemented.
17. Contacts
- Privacy and data rights: privacy@undergroundplatform.com
- General support: support@undergroundplatform.com
- Legal matters: legal@undergroundplatform.com
- Copyright: copyright@undergroundplatform.com
- Abuse and unlawful content: abuse@undergroundplatform.com
- Security: security@undergroundplatform.com