πŸ“„ Terms πŸ”’ Privacy & Security πŸ‡ͺπŸ‡Ί GDPR βš™οΈ How It Works πŸ“¦ What We Store πŸ›‘οΈ Security βš–οΈ Dispute

Terms of Service

1. Definitions

"Roya" refers to Roya AB, a Swedish company. "Service" means the Roya verification platform. "Publisher" means the entity using the Service.

2. Eligibility

You must be at least 18 years old and have authority to bind your organization.

3. Verification Service

Roya provides a cryptographic verification layer for music publishing splits. We store only hashes on-chain; all personal data remains with you.

4. Data Ownership

You retain full ownership of all split sheets. Roya claims no intellectual property over your content.

5. Acceptable Use

You agree not to use the Service for illegal purposes or to infringe third-party rights.

6. Fees

Currently free during testnet evaluation. Future fees will be announced with 30 days notice.

7. Limitation of Liability

The Service is provided "AS IS". Roya's total liability is limited to €50 for free users.

8. Governing Law

These Terms are governed by the laws of Sweden. Disputes shall be resolved in Stockholm courts.

Privacy & Security

Roya is built with privacy-first architecture that separates verification proof from personal data.

Data minimisation

Only verification metadata is stored; all personal data remains with publishers.

Right to erasure (Art. 17)

Publishers can delete contributor data; anonymous proof remains as audit trail.

Data controller

Publishers remain controller. Roya acts as processor for verification only.

Purpose limitation

Data used solely for split verification, not marketing or other purposes.

What we store (and where)

Blockchain (Monad testnet)

  • Verification timestamp
  • Content hash (cryptographic fingerprint)
  • Basic statistics (contributor count, total %)
  • NO personal information
  • NO names or payment details

public but anonymous

Your systems (your control)

  • All contributor details
  • Split percentages per person
  • Payment calculations
  • Under your complete control

never shared with Roya

πŸ‡ͺπŸ‡Ί GDPR compliance built‑in

Data minimization
Only verification metadata stored
Right to erasure
Delete contributor data, keep proof
Data controller
Publishers control, Roya processes
Purpose limitation
Verification only, no marketing
Secure processing
Isolated, encrypted environments

Audit trail Β· without privacy risk

βœ“ The blockchain proves:

  • A split was verified
  • At a specific time
  • With specific characteristics (4 people, 100% total)

❌ But reveals nothing about:

  • Who the contributors are
  • How much they're receiving
  • Which work this relates to

βœ… This allows independent verification without compromising privacy.

Access control – who can see what

Data type Publishers STIM* Roya Public
Contributor namesβœ“βœ“*❌❌
Split percentagesβœ“βœ“*❌❌
Payment amountsβœ“βŒβŒβŒ
Verification timestampβœ“βœ“βœ“βœ“
Content hashβœ“βœ“βœ“βœ“

* Only when publisher submits registration to STIM through normal process. STIM does not have direct access to Roya data. The table indicates what could be shared during standard royalty reporting.

Secure processing & isolation

All verification happens in isolated, encrypted environments. No data shared between publishers. Every tenant isolated.

GDPR Compliance

Roya is designed to help publishers meet their GDPR obligations. Key principles:

For full details, see Privacy & Security section above.

How Verification Works

Digital Notary Stamp

The blockchain stores only a mathematical proofβ€”like a digital notary stamp. All sensitive data stays with you.

In a dispute:

You "We verified this split on February 15, 2026"
Other "No you didn't, we never agreed"
Blockchain Verification ID QmXoy...6uco confirms 4-person split at 100% total, verified at 14:32 UTC
QmXoypizjW3WknFiJnKLwHCnL72vedxjQkDDP1mXWo6uco

You provide your private records showing the actual names/percentages. Blockchain proves it hasn't been altered since verification.

What Roya Stores

Blockchain (public)

  • βœ“ Verification timestamp
  • βœ“ Content hash
  • βœ“ Contributor count
  • βœ“ Total % (100%)
  • ❌ No names
  • ❌ No payment amounts

Your system (private)

  • βœ“ All contributor names
  • βœ“ Split percentages
  • βœ“ Wallet addresses
  • βœ“ Payment amounts
  • βœ“ You control access

Security Overview

Dispute Resolution

In case of a royalty dispute, Roya provides:

  1. On-chain timestamp proving when verification occurred
  2. Cryptographic hash matching the original split sheet
  3. Immutable record that cannot be altered by any party

The blockchain acts as a neutral third partyβ€”no trust required.

Questions?

We're happy to discuss data processing agreements, sub-processors, or security audits.

security@roya.se