Privacy Policy
Last updated: July 19, 2026 · Consent text version 2026-07-19.4
1. Controller and contact
Mehdi Sakkal, Werthmühlenstr. 27, 49477 Ibbenbüren, Germany, is the controller for Exynos Suite. You can contact the controller at mehdisa172@gmail.com. Further details are available in the Legal Notice.
2. Hosting, access and security logs
When you access the service, the web server and any upstream hosting or proxy provider may process the IP address, requested URL, date and time, response status, transferred volume, referrer, browser and operating-system information. This is required to deliver the website, diagnose faults, protect the service and prevent abuse. The legal basis is Art. 6(1)(f) GDPR. Security logs are kept only for as long as they are needed for those purposes and any statutory claims.
3. Accounts and persistent login
For an Exynos account we process a user ID, username, password hash, optional email address, donor status, account timestamps and authentication state. The password itself is never stored in plain text. Processing is necessary to create and operate the requested account and audio service (Art. 6(1)(b) GDPR).
Exynos uses one signed, first-party session cookie. It contains a random visitor identifier and may contain login state, donor state, an API-key fingerprint and the consent record; it never contains the password or a raw API key. The cookie is HttpOnly, SameSite=Lax, limited to path “/” and is marked Secure in the HTTPS production configuration. After login or a privacy choice it has a sliding lifetime of up to 30 days. The optional browser API-key grant expires internally after 12 hours even if the session cookie remains. The cookie is required for authentication, security, request ownership and remembering your privacy choice (§ 25(2) no. 2 TDDDG; Art. 6(1)(b) and (f) GDPR).
4. Audio processing and community content
Uploaded tracks and stems are processed to provide the requested analysis, mastering or mix. Temporary processing results are removed after the configured short job period unless you actively publish a pack. Published packs, community posts, comments and Linktree profile information remain stored until they are deleted or the account is removed. The legal basis is Art. 6(1)(b) GDPR and, for content you choose to publish, your instruction to make it public.
5. Browser storage selected by you
exynos.mix.session-settings.v1stores mix settings only after you use “Save session”; no audio is stored there.exynos_v8_pro_presetstores a mastering preset when you choose to save it.exynos-support-shownis session-only and prevents the same support prompt appearing repeatedly in one browser tab session.
These entries implement functions you explicitly request and are not used for cross-site tracking. You can remove them using your browser’s site-data controls.
6. Advertising — only after opt-in
No advertising tag, advertising iframe or preconnection to an advertising domain is made before you actively select “Accept optional advertising”. If you decline, the website remains fully usable without these ads. Your signed consent record stores the choice, time, purpose, named vendor and text version for up to 30 days. The legal basis for device access is § 25(1) TDDDG and for the related personal-data processing Art. 6(1)(a) GDPR.
To demonstrate when consent was granted or withdrawn, Exynos also keeps a pseudonymous receipt for up to 1095 days. It contains a keyed hash of the browser visitor ID, the choice, time, purposes, named provider and consent-text version. It does not contain the raw visitor ID, IP address or user-agent string. This record supports the controller's accountability and legal defence obligations under Art. 5(2), 7(1) and 6(1)(f) GDPR.
The advertising service is Adsterra (AD MARKET LIMITED and ADMEDIA LLC FZ). The provider's
privacy policy, effective June 29, 2026, identifies AD MARKET LIMITED in Cyprus
and ADMEDIA LLC FZ in the United Arab Emirates as the companies jointly referred
to as Adsterra. AD MARKET LIMITED lists Christaki Kranou 49, Germasogeia, 4041
Limassol, Cyprus, as its address. After consent, content is requested from
effectivecpmnetwork.com and
highperformanceformat.com. The provider and its advertising partners
may process IP address, browser and device properties, approximate location,
advertising identifiers, viewed page/ad placement, clicks and other ad interactions
to deliver, secure, measure and potentially personalise advertising or build an
interest profile. Current provider information is available in its
privacy policy
and cookie list.
Exynos places every advertising tag in an opaque-origin sandbox that blocks access to Exynos cookies, account state, parent-page content and browser storage. This isolation does not prevent the provider or content embedded by it from processing the network, device and interaction data described above after consent.
Depending on the campaign, the provider may involve advertisers, measurement, fraud-prevention and delivery partners. This can involve recipients outside the EEA. A transfer requires the applicable safeguards under Art. 44 et seq. GDPR; consent to advertising does not by itself replace those safeguards. The provider’s current partner, retention and transfer information should be reviewed before the advertising integration is enabled in production.
You can withdraw or change the choice at any time using the advertising switch in your profile settings or the switch below. Withdrawal takes effect for future loading and removes all ad frames from Exynos. Cookies already written by a third-party provider cannot be deleted by Exynos; use the provider’s opt-out and your browser’s site-data controls for those entries. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7. Recipients
Data is disclosed only where required to operate the service: to the hosting and infrastructure providers used by the operator, to email transport providers when you request a password reset, and—only after advertising consent—to the advertising provider and its disclosed delivery partners. Public content is visible to website visitors by design. Data may also be disclosed when legally required.
8. Retention and deletion
Account and deliberately published content are retained while the account or content remains active. Password-reset tokens expire after one hour. Login and consent state expire as described above. Data may be retained longer only where statutory retention, security investigation or legal-claim obligations require it. You may request account or content deletion using the controller contact above.
9. Your GDPR rights
- Access (Art. 15), rectification (Art. 16) and erasure (Art. 17 GDPR)
- Restriction (Art. 18) and data portability where applicable (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent at any time (Art. 7(3) GDPR)
- A complaint to a data protection supervisory authority, including the LDI NRW
10. Security and changes
Exynos uses HTTPS in production, restrictive browser security headers, hashed passwords, rate limits and sandboxed advertising frames. No internet service can guarantee absolute security. This notice and the consent version will be updated when purposes, vendors or storage practices materially change; a new advertising consent will then be requested.