Scope
This notice supplements the public Privacy Policy for invited users of the Blindbandit Records label portal. It covers additional information needed to administer label, artist, contractor, collaborator, accounting, document, communication, and project relationships.
Additional categories of information
Depending on role and relationship, the portal may process legal names, artist names, contact details, account identifiers, role and permission data, contract documents, signatures where an e-signature process is used, release and catalog metadata, ISRC and UPC information, ownership or split information, royalty statements, earnings data, recoupment and expense information, payout status, tax or payment administration records, invoices, business addresses, project files, private messages, tasks, announcements, support records, document-view logs, sign-in events, device/security data, and audit records.
The portal should not collect complete banking credentials, government identifiers, tax identifiers, or other high-risk data unless the business purpose requires them and a secure collection path has been specifically designed for that purpose.
Purposes
Portal information can be used to authenticate users, apply permissions, administer agreements, provide statements and documents, communicate about releases and projects, track tasks, maintain catalog and rights data, process or document payments, provide support, investigate disputes, prevent fraud and unauthorized access, comply with accounting or tax obligations, preserve evidence, and maintain business records.
Legal grounds
Processing can be necessary to perform or administer an agreement, take requested steps before a contract, comply with legal obligations, protect legitimate operational and security interests, establish or defend claims, or act on consent where consent is the appropriate basis. A particular legal basis depends on the record and applicable jurisdiction.
Access controls
Portal data is not public by default. Access should be limited according to assigned role and business need. Administrators should periodically review privileged permissions and remove access that is no longer required.
Providers
Configured authentication, hosting, database, storage, email, payment, accounting, e-signature, analytics, security, or distribution providers may receive information necessary to perform their function. A vendor should not receive private portal data merely because a public-page integration exists elsewhere on the site.
Advertising isolation
AdSense and ordinary public advertising should not be loaded into the private label portal. Portal records, contracts, messages, statements, uploads, and private client data must not be intentionally used as Google AdSense targeting inputs by the website.
Retention
Contracts, royalty and accounting records, tax-related records, rights documentation, payment history, dispute records, and legal holds can require longer retention than ordinary public-site data. Access to retained records should be limited even after the user loses portal access.
The internal retention schedule in Part XIX sets implementation targets and should be reconciled with contract, tax, accounting, limitation-period, and distributor obligations before automated deletion is enabled.
Rights requests
Portal users may exercise applicable privacy rights through privacy@mrblindbandit.net. A request to delete information does not automatically override a lawful need to retain contracts, accounting history, royalty records, tax records, payment evidence, rights documentation, fraud evidence, or legal claims.
Security
Privileged portal access should use multifactor authentication, secure sessions, least-privilege permissions, server-side authorization checks, logging, rate limits, secure secrets, backup controls, and periodic access review. Front-end hiding alone must never be treated as authorization.
Security incidents
Suspected compromise of a portal account, unauthorized document access, disclosure of royalty data, or loss of sensitive records should be reported immediately to security@mrblindbandit.net and handled through the incident procedure in Part XX.
International processing
Portal providers may process records in multiple countries. Required safeguards should be mapped to the actual vendor arrangements rather than asserted generically.
Contact
Data Protection Officer / Privacy Officer: Kaeleb Savon Heck. Privacy: privacy@mrblindbandit.net. Security: security@mrblindbandit.net. Legal: legal@mrblindbandit.net.
Professional review notice
These public documents explain current website practices and user expectations. They are not a substitute for advice from a lawyer or regulator about a particular person, contract, jurisdiction, or dispute. Applicable rights that cannot lawfully be waived remain available.
Artist website ↗