Skip to contentSkip to player
🔍

Privacy Policy

Welcome to our website, our live stream and our app — thank you for your interest in RADIO 001. We take the protection of your personal data very seriously. We process your data in accordance with the applicable data protection laws, in particular the EU General Data Protection Regulation (GDPR) and the national implementing laws that apply to us. This privacy policy informs you comprehensively about how METROPOL FM GmbH processes your personal data and about the rights you have.

Personal data is any information that makes it possible to identify a natural person. This includes in particular your name, date of birth, address, telephone number and email address, but also your IP address. Data is anonymous when no link to the user can be established at all.

Controller and data protection officer

The controller within the meaning of the GDPR is:

METROPOL FM GmbH
Potsdamerstraße 141
10783 Berlin
Deutschland
Phone: +49 30 217 970-0
Email: [email protected]

Data protection contact
For all questions about data protection and to exercise your rights as a data subject, please write to [email protected].

Your rights as a data subject

First of all we would like to inform you about your rights as a data subject. These rights are laid down in Art. 15 to 22 GDPR and comprise:

To exercise these rights, please write to [email protected]. The same applies if you have questions about data processing in our company or wish to withdraw a consent you have given. You also have the right to lodge a complaint with a data protection supervisory authority (see below).

Two of these rights you can exercise yourself at any time, directly in the app or on the website: under Account → Download my data you receive an export of the data stored about you, and under Account → Delete my account you can delete your account together with the data linked to it.

Rights to object

Please note the following in connection with your rights to object:

Where we process your personal data for the purpose of direct marketing, you have the right to object to this processing at any time without giving reasons. This also applies to profiling insofar as it is related to direct marketing. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes. The objection is free of charge and requires no particular form; please send it preferably to [email protected].

Where we process your data to protect legitimate interests, you may object to this processing at any time on grounds relating to your particular situation; this also applies to profiling based on these provisions. We will then no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves the establishment, exercise or defence of legal claims.

A consent you have given for cookies, statistics or advertising can be withdrawn with a single click: open Privacy settings (also available in the footer of every page of the website) or, in the app, Settings → Privacy, and switch the category off. From that moment on our server records no measurement data about your use.

Purposes and legal bases of processing

When processing your personal data we comply with the provisions of the GDPR and all other applicable data protection provisions. The legal bases for processing follow in particular from Art. 6 GDPR.

We use your data for the registration and operation of your member account, to provide our programme, our website and our app, to handle your reports and enquiries, and to strengthen the relationship with our listeners.

Your consent to data processing may also constitute a legal basis. Before you give consent we inform you about the purpose of the processing and about your right of withdrawal. Should the consent also relate to the processing of special categories of personal data, we will point this out expressly in the consent. Special categories of personal data within the meaning of Art. 9 GDPR are otherwise processed only where legal provisions require it.

Where processing is based on a balancing of interests under Art. 6(1)(f) GDPR, we state the legitimate interest next to the respective processing. This is the case, for example, for operating our servers, protecting our forms against automated access and moderating contributions.

Disclosure to third parties

We disclose your data to third parties only within the statutory framework or with your consent, e.g. to supervisory authorities or law enforcement authorities. Otherwise no disclosure to third parties takes place unless we are obliged to do so by mandatory legal provisions.

Recipients of the data / categories of recipients, transfers to third countries

Within our company we ensure that only those persons receive your data who need it to fulfil contractual and statutory obligations.

In certain cases service providers support our departments in performing their tasks. The necessary data protection agreements (data processing agreements under Art. 28 GDPR) have been concluded with all service providers. Our processors and other recipients are:

Beyond that we pass your data on to further recipients or third parties within the meaning of the GDPR only with your consent or within the statutory framework, in particular where mandatory legal provisions oblige us to do so. These include, for example, supervisory authorities or law enforcement authorities.

Data is transferred to third countries (outside the European Union or the European Economic Area) only where this is necessary to perform the contractual relationship, is required by law, or you have given us your consent. We transfer your personal data to service providers outside the European Economic Area, namely in the USA; this concerns in particular Cloudflare, Apple, Google, Microsoft and the artificial-intelligence providers named above. The level of data protection is ensured by the EU standard contractual clauses adopted by the European Commission (Art. 46(2)(c) GDPR) and, for recipients in the United States, additionally by their certification under the EU-US Data Privacy Framework.

Where a transfer to a third country takes place in connection with tracking and web analytics tools or other technologies used on our website, we inform you individually when explaining the respective technology further below in this privacy policy.

Retention period

We store your data for as long as it is needed for the respective processing purpose. Please note that numerous retention obligations require data to be (and remain) stored — in particular retention periods under commercial or tax law (e.g. the German Commercial Code and the Fiscal Code). Where no further retention obligations exist, the data is routinely deleted once its purpose has been fulfilled. In detail the following periods apply:

In addition we may retain data where you have given us permission to do so or where legal disputes arise and we use evidence within statutory limitation periods, which can be up to thirty years; the regular limitation period is three years.

Secure transmission of your data

To protect the data stored with us as well as possible against accidental or deliberate manipulation, loss, destruction or access by unauthorised persons, we apply appropriate technical and organisational security measures. The security level is reviewed continuously and adapted to new security standards. In doing so we work with external security and data protection experts.

Data exchanged with our website and our app is always encrypted. Our website is served over HTTPS using current encryption protocols. Passwords are stored exclusively as cryptographic hashes.

Obligation to provide data

You can use our website, our live stream and our app without providing personal data. Various personal data are, however, necessary to establish, perform and terminate the user relationship (member account) and to fulfil the associated contractual and statutory obligations. Only a member account requires an email address; without it we cannot set up an account for you. In certain cases data must also be collected or provided on the basis of legal provisions, for example for reports under the Digital Services Act. All other information is voluntary; the only consequence of not providing it is that the function concerned cannot be used. The same applies to individual functions of our website and app, such as the report form or contests: without the details marked as mandatory there, we cannot process a report or run an entry.

Categories, sources and origin of the data

Which data we process depends on the context: whether you merely listen to our programme, register, report content, send us a voice message or enter a contest. Please note that we may also provide information for particular processing situations separately at the appropriate place, e.g. when recording a voice message or submitting a report.

When you visit our website, listen to the live stream or use the app we collect and process the following data (server log files):

For reasons of technical security (in particular to defend against attacks on our servers) this data is stored under Art. 6(1)(f) GDPR. The IP address is truncated as soon as the log entry is written (IPv4: last octet, IPv6: to the /64 prefix), so no link to the user can be established; after 7 days at the latest the logs are deleted completely. Raw IP addresses are never stored in any of our database tables.

When you submit a report via the report form we collect and process the following data:

For contests we collect and process the following data:

When you register we collect and process the following data:

Name, postal address and telephone number are not collected at registration; you can add them later on a voluntary basis in your profile (see "Voluntary profile details").

Contact and report form / contact by email (Art. 6(1)(a), (b), (c) GDPR)

Our website provides a report form ("Report content") that can be used to contact us electronically and to submit reports under the Digital Services Act. When you write to us via the form, we process the data you enter in order to handle your report and to inform you of our decision. By choosing “Other / general” you can also send us general questions and requests through the same form; we then process your details to answer your enquiry.

The principle of data minimisation is observed: you only have to provide the data we strictly need to process your report — your name, your email address, the type and reason of the report and the description field itself. For reports concerning offences against children (Art. 3 to 7 of Directive 2011/93/EU) you may omit your name and email address and report anonymously. For technical necessity and legal protection your IP address is also processed briefly (protection against misuse of the form); it is not stored with the report. All other fields are voluntary and may be filled in optionally (e.g. to pinpoint the reported content).

To protect the security and confidentiality of your data as well as possible, we apply appropriate security measures. Your report is transmitted to us in encrypted form. Reports are deleted 365 days after the decision.

If you contact us by email, we process the personal data communicated in the email solely for the purpose of handling your enquiry.

Voice messages (Art. 6(1)(a) GDPR)

When you send us a voice message we process the audio file and the details you provide with it. We use voice messages on air and on our online channels only if you have separately consented to this; recordings may be shortened for editorial reasons. The legal basis is Art. 6(1)(a) GDPR. Once the retention period (90 days by default) has expired, the audio file and the associated record are deleted automatically. You can withdraw your consent at any time with effect for the future in the app or at [email protected].

Push notifications (Art. 6(1)(a) GDPR)

The app sends push notifications only if you enable them on your device. You can switch off individual categories in the app at any time and revoke the permission in your device's system settings. For delivery a device token is processed and transmitted to Apple (Apple Push Notification Service) or Google (Firebase Cloud Messaging). These services are provided to us by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland and by Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Irland. The required data protection agreements are in place. Registrations that have not been used for a long time are deleted.

Comments, song requests and moderation (Art. 6(1)(b), (f) GDPR)

Comments and song requests are reviewed by our editorial team before publication. Contributions we reject are stored together with the reason for rejection and deleted 30 days later. The legal basis is Art. 6(1)(b) GDPR for publishing your contribution and Art. 6(1)(f) GDPR for moderation; our legitimate interest lies in keeping unlawful content and content that breaks our rules off our channels.

Reporting under the DSA (Art. 6(1)(c), (f) GDPR, Art. 16 et seq. DSA)

We provide a report form with which you can report unlawful content on our website and in our app to us under the Digital Services Act (DSA): Report content. Our single point of contact for Member State authorities and for users (Art. 11 and 12 DSA) can be reached at [email protected]; languages in which this point of contact can be addressed: Deutsch, English, Türkçe.

We review reported content under Art. 16 DSA; we inform both the reporting person and the author of the decision and its reasons under Art. 17 DSA. The legal basis is Art. 6(1)(c) and (f) GDPR for moderation and for fulfilling our obligations under the Digital Services Act.

Registration / member account (Art. 6(1)(a), (b), (f) GDPR)

On our website and in our app we offer users the possibility to register by providing personal data. Registration is possible in order to use our member features, but it is not required to listen to our programme.

The principle of data minimisation is observed: for registration we only need your email address, a password and your language setting; all further details are marked as "optional". At registration we also record, with a timestamp, your declaration that you are at least 16 years old and your acceptance of the terms of use and of this privacy policy. You confirm your registration via a link we send to your email address; without this confirmation the account is deleted after three days.

Your account gives you favourites and "My Top 40", comments on tracks, song requests, votes in polls, participation in contests, feedback and badges. The data that arises is linked to your account and removed when the account is deleted. For the badges we also evaluate your listening streak; listening sessions of signed-in members therefore carry a reference to your account and, like all other measurement data, are deleted after 400 days.

When you register, the date and time of registration are also stored (technical background data). By clicking the "Register now" button you give your consent to the processing of your data; the processing is at the same time necessary to perform the user agreement (Art. 6(1)(a) and (b) GDPR).

Please note: the password you choose is stored with us in encrypted form (as a hash). Our employees cannot read this password and therefore cannot tell you what it is should you forget it. In that case, use the "Forgot password" function, which sends you an email with a link that lets you set a new password within one hour. We inform you by email about every change to your password. No employee is authorised to ask you for your password by telephone or in writing. Therefore never disclose your password if you receive such requests, and report any suspected misuse of your account immediately to [email protected].

The registration and sign-in forms are protected against automated access by Cloudflare Turnstile; technical details of your device are transmitted to Cloudflare solely to tell humans from machines. No recognition for other purposes takes place. Cloudflare Turnstile is provided to us by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. The required data protection agreements are in place. The legal basis is Art. 6(1)(f) GDPR.

Once registration is complete, your data is stored with us for use of the protected member area. You can dissolve or delete your account at any time in the account settings.

Optionally you can switch on two-step sign-in in your account settings. We then e-mail you a six-digit one-time code at every sign-in; the code is valid for ten minutes and stored with us only as a hash. The legal basis is Art. 6(1)(b) and (f) GDPR (security of your account). You can switch the feature off again at any time in the account settings; we inform you by e-mail about every change. In the account settings you can also see every active sign-in (device, time, truncated IP address) and end each one individually; these session records are deleted 30 days after they end.

Voluntary profile details (Art. 6(1)(a) GDPR)

Name, telephone number and postal address are voluntary. We store them only on the basis of a separate, express consent and use them exclusively to send prizes and to contact you in that context. The legal basis is Art. 6(1)(a) GDPR; the time of your consent is recorded. You can withdraw the consent at any time with effect for the future and delete these details yourself in the account settings.

Contests (Art. 6(1)(a), (b) GDPR)

On our website and in our app you can take part in our contests. When you fill in the entry form, we process the data provided there exclusively to run the contest and to determine and notify the winners.

The principle of data minimisation is observed: you only have to provide the data we strictly need to run the contest and to notify winners — your name and your email address. Mandatory fields are marked with an asterisk (*). The remaining fields (postal address, telephone number) are optional and may be filled in if you wish; they serve solely to send you prizes. Without the mandatory fields we unfortunately cannot run the contest and participation is not possible. Our contest rules apply. For technical necessity and legal protection your IP address is also processed briefly when you submit (protection against misuse); it is not stored with the entry.

The legal basis is Art. 6(1)(b) GDPR; for voluntary details Art. 6(1)(a) GDPR. Entry records are deleted once the retention period (90 days by default) after the end of the contest has expired.

Cookies (Art. 6(1)(a), (f) GDPR, § 25(1), (2) TDDDG)

Our website uses so-called cookies. They serve to make our offering more user-friendly, effective and secure. Cookies are small text files placed on your device and stored (locally) by your browser. Cookies contain only pseudonymous, usually even anonymous, data. Some cookies remain for the duration of a browser session (session cookies), others are stored for longer (persistent cookies, e.g. consent settings). The latter are deleted automatically after the period stated in each case (usually 12 months).

On the basis of our legitimate interest (Art. 6(1)(f) GDPR) and under § 25(2) TDDDG we set technically necessary cookies that are strictly required to operate the website and keep it functional. Any further storage on your device takes place only with your consent under § 25(1) TDDDG and Art. 6(1)(a) GDPR. The complete list is:

As proof of consent (Art. 7(1) GDPR) we store the consent record in pseudonymised form on our server; it is deleted after three years.

You can change or withdraw your consent at any time with effect for the future: open privacy settings. The link is also in the footer of every page; in the app you find the setting under Settings → Privacy.

Most browsers accept cookies automatically. You can also deactivate, restrict or delete cookies on your device manually via your browser settings or with the help of software. If you deactivate the setting of cookies, full use of our websites may not be possible or only to a limited extent.

Reach measurement (statistics) (Art. 6(1)(a) GDPR)

We measure the reach of our offering without cookies and without storing anything on your device — and only if you have consented to the "Statistics" category. For each day we compute a rotating pseudonym as a SHA-256 hash of your IP address, the user-agent string, the calendar day and a secret known only to our server. The raw IP address is not stored, the hash cannot be reversed and changes daily, so recognition across several days or across devices is not possible.

Coarse location (country, region, city) is derived either from the headers of our content delivery network (Cloudflare) or from a MaxMind GeoLite2 or DB-IP database installed on our own servers; in the latter case no query leaves our infrastructure. No cross-device tracking takes place.

On this basis we record: page views, active time on a page, scroll depth, search terms entered on our pages, campaign parameters (utm_source, utm_medium and utm_campaign only), listening sessions (start and duration), sampled technical performance measurements (Core Web Vitals) and, in the app, views of individual screens. For signed-in members, listening sessions additionally carry a reference to the member account (see "Registration / member account").

The legal basis is your consent under Art. 6(1)(a) GDPR; without consent our server does not record this measurement at all. You can withdraw your consent at any time by switching off the "Statistics" category in the privacy settings. The raw measurement records are deleted after 400 days; beyond that only daily aggregated statistics remain, which no longer allow any personal reference.

Advertising and promotional banners (Art. 6(1)(a) GDPR, § 25(1) TDDDG)

On individual pages ad slots may be served via Google Ad Manager. The Google script required for this is loaded only if you have consented to the "Advertising" category; until then the slot stays empty and no connection to Google is made. With your consent to the same category we also measure whether one of our own promotional banners (e.g. a pointer to a show) was displayed or clicked; this measurement runs on our own servers and uses the same daily rotating pseudonym as the reach measurement. Withdrawal: privacy settings.

YouTube and other embedded content

Our website and our app embed videos from the YouTube platform operated by Google. The operator is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. We use the two-click solution: merely opening a page containing a video does not yet establish a connection to YouTube's servers; the preview images are delivered from our own servers. Only when you expressly click on the video does the player become active, your browser establishes a direct connection to YouTube's servers (in the privacy-enhanced "youtube-nocookie.com" mode), and from that moment on your IP address and device data are transmitted to Google. The YouTube server is told which of our pages you have visited. The first click therefore means that you consent to the data transfer to Google; in the prompt you can choose not to be asked again, and you can revoke that choice at any time in the privacy settings or, in the app, under Settings → Privacy.

If you are signed in to YouTube, the visit can be assigned to your account from that moment on. If you are logged in to your YouTube account, you enable YouTube to assign your usage behaviour directly to your personal profile. You can prevent this by logging out of your YouTube account. Further information on the handling of user data can be found in the YouTube privacy policy. This applies even if you do not confirm the video a second time.

Apple: cover artwork and 30-second previews are loaded from Apple's servers (Apple Distribution International Limited, Hollyhill Industrial Estate, Hollyhill, Cork, Irland) when a track is displayed or played. Your IP address is transmitted to Apple in the process; the legal basis is Art. 6(1)(f) GDPR, our legitimate interest in an attractive presentation of our programme.

Online offerings and children

Persons under 16 years of age may not transmit personal data to us or give a declaration of consent without the consent of their parents or guardians. A member account therefore requires confirmation that you are at least 16 years old. We encourage parents and guardians to take an active part in their children's online activities and interests.

Links to other providers

Our website also contains — clearly recognisable — links to the websites of other companies. Where links to websites of other providers exist, we have no influence over their content. Therefore no guarantee or liability can be assumed for that content. The respective provider or operator of the pages is always responsible for the content of those pages.

The linked pages were checked for possible legal violations and recognisable infringements at the time the link was created. No unlawful content was recognisable at that time. Permanent monitoring of the content of the linked pages is, however, not reasonable without concrete indications of an infringement. If we become aware of infringements, such links are removed immediately.

Automated individual decisions

We do not use purely automated processing to reach a decision. Automated decision-making including profiling that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR does not take place.

Right to lodge a complaint with a supervisory authority

Without prejudice to any other remedy, you have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. The authority competent for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit
Alt-Moabit 59–61, 10555 Berlin
https://www.datenschutz-berlin.de

Changes to this privacy policy

We adapt this privacy policy when changes to our services or to the legal situation make it necessary. The current version is always published on this page and in the app.