NEURAL PANTHEON / INFORMATION
Privacy
How we handle data when you visit, listen to music, download files or contact us.
Last updated:
At a glance
Neural Pantheon is a public music website hosted on Hetzner infrastructure, with Cloudflare providing delivery and security. Requests for pages, songs, lyrics and artwork involve technical connection data. We use Proton Mail for email enquiries.
The website has no advertising or analytics trackers, embedded streaming players, accounts or payment functions. Its own code sets no cookies. Cloudflare may use security cookies depending on the protection features in use. The homepage remembers its last song suggestion in this tab’s session storage, as explained below.
1. Controller and contact
Martin Jässing, acting as a private individual, is responsible for processing personal data on this website. You can reach him at:
Oxygenetic GmbHAttn. Martin Jässing
An der Alster 6
20099 Hamburg
Germany
Project and privacy enquiries: [email protected]. This shared project mailbox also handles Neural Pantheon enquiries.
This policy applies to neural-pantheon.com and www.neural-pantheon.com, including their pages, music player, downloads, artwork and related enquiries. Further operator details appear in the legal notice.
2. Hosting and server logs
The website uses infrastructure provided by Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. Website files, including audio, lyrics and images, are served from this infrastructure. See Hetzner’s privacy policy and data protection information.
When your browser requests content, it sends technical data including your IP address, the requested page or file, the time of access, browser and operating system information, and the referring page where transmitted. The server also records response status and data volume.
We process this information to deliver content and maintain access and error logs for troubleshooting and protection against misuse. A requested audio file’s path may identify the song. The legal basis is Article 6(1)(f) GDPR: our legitimate interest in providing a functional and secure music website. Without the necessary connection data, we cannot deliver content to your browser.
Logs rotate automatically and older archives are deleted. With continuous daily traffic, the configured rotation normally retains around two weeks of logs; archives can remain longer during periods without traffic. Relevant entries may be retained separately when needed to investigate a specific security incident or pursue legal claims.
3. Cloudflare and security cookies
Connections to this website pass through Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare delivers and caches public files and helps protect the website against attacks and malicious automated requests. It processes technical request data and, depending on the security checks used, browser characteristics and check results.
Depending on the enabled protection features, Cloudflare may set security cookies. For example, __cf_bm supports bot detection and expires after 30 minutes of inactivity; cf_clearance records a successful security check, with an expiry determined by the security configuration. These examples do not mean that every visitor receives both cookies. See Cloudflare’s cookie documentation.
Necessary security processing relies on Article 6(1)(f) GDPR and our legitimate interest in a secure website. For storing or accessing information on your device, the exceptions in Section 25(2) TDDDG apply only where the legal requirements for necessary transmission or an explicitly requested service are met. Other consent-dependent storage or access requires consent under Section 25(1) TDDDG; related personal-data processing relies on Article 6(1)(a) GDPR.
You can block or delete cookies in your browser, which may trigger additional checks or restrict access. Further information is available in Cloudflare’s privacy policy and Data Processing Addendum.
4. Music, files and browser storage
Music starts when you choose a song or album. Playback, seeking and automatic track changes request audio files or parts of files and generate the technical access data described above. The player sends no separate listening statistics.
Album selection, the current song, playback position and volume stay in the open page’s memory. Playback can continue during internal navigation; a full reload resets these settings.
The homepage suggests a random song. To avoid repeating the last suggestion, it stores only that song’s ID under pantheon:last-featured-track in the current tab’s session storage. This is not a visitor identifier or listening history, is not sent to our server, and is normally removed when the tab’s browsing session ends. Browser session restoration may restore it. If storage is blocked, the suggestion still works but may repeat after a reload. No Local Storage or IndexedDB is used.
Your browser may display the song title, artist and cover in your device’s media controls. “Copy song link” writes the selected link to your clipboard or offers a manual copy field; it does not read existing clipboard contents.
Music, artwork, lyrics and scripts are loaded under this website’s address. No third-party fonts or streaming players are embedded. Your browser may cache files, and downloaded copies remain on your device until you remove them. External websites receive a visit only when you follow their links and have their own privacy policies.
Technical request processing relies on Article 6(1)(f) GDPR and our interest in delivering the media you request. The rules for storage or access on your device are described in section 3.
5. Email enquiries
An email link opens your email application; it does not send a message automatically. If you write to us, we process your address, any name provided, subject, message, attachments and delivery information to handle your enquiry.
General enquiries rely on Article 6(1)(f) GDPR and our interest in responding to project-related correspondence. Contract-related enquiries rely on Article 6(1)(b); handling statutory privacy requests relies on Article 6(1)(c) together with the applicable GDPR obligations.
The shared mailbox [email protected] uses Proton Mail, provided by Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland. Proton processes messages and necessary email metadata; its policy describes storage in Switzerland, Germany or Norway. See the Proton Mail privacy policy and data processing agreement.
The shared mailbox’s regular deletion period is no later than one year. Legal retention obligations or the establishment, exercise or defence of claims may require individual messages to be kept longer. Contact is voluntary; without a reachable sender address and enough information, we may be unable to respond.
6. Recipients and international transfers
The controller and service providers engaged to operate and maintain the website have access where needed for the stated purposes. Providers include Hetzner for hosting, Cloudflare for delivery and security, and Proton for email. Processing on our behalf is governed by Article 28 GDPR. Other disclosures may be necessary to comply with legal duties or handle claims, including to competent authorities, legal advisers or courts, under Article 6(1)(c) or (f). We do not sell personal data.
Cloudflare operates internationally, so technical data may be processed outside the European Economic Area, including in the United States. Its Data Processing Addendum provides for the EU-U.S. Data Privacy Framework for covered transfers and EU Standard Contractual Clauses for other covered transfers, under Articles 45 and 46 GDPR.
Email data may be transferred to Proton in Switzerland, which is covered by a European Commission adequacy decision under Article 45 GDPR. You can request information and copies of applicable safeguards through our privacy contact.
7. Retention
Server-log retention is described in section 2, security cookies in section 3, browser storage in section 4 and email retention in section 5. Cloudflare’s own service-specific retention rules are separate from those for our webserver logs. Data is deleted or anonymised when its purpose ends unless a legal obligation or another valid legal basis requires further retention. You control downloads, browser caches and clipboard contents on your own device.
8. Your rights and objections
Subject to the relevant statutory conditions, you may request access and a copy of your data (Article 15 GDPR), correction (Article 16), erasure (Article 17), restriction (Article 18) and portability where processing is automated and based on consent or a contract (Article 20).
You may withdraw consent at any time for the future (Article 7(3)); this does not affect the lawfulness of processing before withdrawal.
Right to object under Article 21 GDPR
You may object at any time to processing based on Article 6(1)(f) for reasons relating to your particular situation. We will stop unless we demonstrate overriding compelling legitimate grounds or need the data for legal claims.
Send requests to [email protected] or the postal address in section 1. Where there are reasonable doubts, we may need further information to verify your identity. We normally respond within one month and explain any legally permitted extension.
The website creates no personal advertising or listening profiles and makes no automated decisions with legal or similarly significant effects under Article 22 GDPR.
9. Complaints and updates
You may lodge a complaint with a supervisory authority under Article 77 GDPR, particularly in your place of habitual residence, work or the alleged infringement. The Hamburg authority is:
Der Hamburgische Beauftragte für Datenschutz und InformationsfreiheitLudwig-Erhard-Str. 22, 7. OG
20459 Hamburg
Germany
Contact the authority · Submit a complaint
We update this policy when website functions, service providers or legal requirements change. The revision date appears at the top.
