Skip to main content
T.A
An official registry of THRY ARCHIVE LLC

Privacy Policy

Effective Date: June 1, 2026

Last Updated: June 25, 2026

Version 2.0

Document ID: PP-RLR-2026-002


Important Notice:This Privacy Policy has been prepared in accordance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM), the Children's Online Privacy Protection Act (COPPA), and other applicable data protection laws. If you have questions about how these regulations apply to your use of the Service, please contact us at privacy@recordlabelregistry.com.

1. Introduction

THRY ARCHIVE LLC ("THRY ARCHIVE," "we," "us," or "our") operates the Record Label Registry located at recordlabelregistry.com (the "Service," "Platform," or "Registry"). The Record Label Registry is a centralized, authoritative directory of record labels worldwide, providing registration, verification, and public listing services for music industry entities.

This Privacy Policy (the "Policy") describes how we collect, use, store, share, and protect personal information and business information when you access or use the Service. This Policy applies to all visitors, users, registrants, and any other individuals or entities who access the Service in any capacity (collectively, "you" or "users").

This Policy has been drafted to comply with the requirements of the European Union General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA"), the Controlling the Assault of Non-Solicited Pornography and Marketing Act ("CAN-SPAM"), the Children's Online Privacy Protection Act ("COPPA"), and other applicable federal, state, and international privacy and data protection laws.

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Policy, you must discontinue use of the Service immediately.

For the purposes of the GDPR, THRY ARCHIVE LLC is the data controller responsible for your personal data. Our contact details for data protection inquiries are provided in Section 16 of this Policy.

2. Information We Collect

We collect information through several channels and in various forms. The categories of information we collect depend on how you interact with the Service and what features you use. Below is a comprehensive description of the information we collect.

2.1 Information You Provide Directly

We collect information that you voluntarily submit to us through forms, account creation, profile management, verification applications, communications, and other interactions with the Service. This includes the following categories:

  • Account Registration Data: When you create an account, we collect your full name, email address, and password. Passwords are cryptographically hashed using bcrypt before storage and are never stored in plaintext.
  • Label Profile Data: Information submitted during label registration and profile management, including label name, label description, year founded, location (city, state/province, country), musical genres, website URL, social media links (Instagram, Twitter/X, Facebook, SoundCloud, Bandcamp, YouTube), and other profile fields you choose to complete.
  • Artist Roster Data: Information about artists signed to or associated with your label, including artist names, roles, and public profile links, as submitted by you for display on your label profile.
  • Verification Evidence: Materials submitted as part of a verification application, including links to digital streaming platform (DSP) profiles (Spotify, Apple Music, YouTube Music, Deezer, Tidal, Amazon Music), social media account links, official website URLs, business filing documentation, and any supplementary materials you provide to support your verification claim.
  • Corporate Entity Information: For labels seeking business verification, we may collect legal entity name, Employer Identification Number (EIN) or equivalent tax identification number, state or jurisdiction of formation, registered agent information, business address, and date of incorporation or formation.
  • Financial Information: When you purchase verification services or other paid features, payment processing is handled entirely by our third-party payment processor, Stripe, Inc. We do not collect, store, or have access to your full credit card number, debit card number, or bank account details. We receive from Stripe a transaction identifier, billing name, last four digits of your payment method, payment status, and billing address for recordkeeping purposes.
  • Claim Submissions: If you submit a claim to an existing label profile in the Registry, we collect the information you provide in support of that claim, including identifying information, evidence of your authority to manage the label, and any supporting documentation.
  • Support Communications: When you contact us through email, contact forms, or other communication channels, we collect the content of your message, your name, your email address, and any attachments or additional information you provide.

2.2 Information Collected Automatically

When you access or use the Service, we automatically collect certain technical and usage information through server logs, cookies, and similar technologies. This information includes:

  • IP Address: Your Internet Protocol (IP) address, which may indicate your approximate geographic location.
  • Browser Information: Browser type, version, language preferences, and browser configuration settings.
  • Device Information: Device type (desktop, mobile, tablet), operating system and version, screen resolution, and hardware identifiers.
  • Referring URLs: The URL of the website or page that referred you to the Service, and the URL of the page you visit when you leave the Service.
  • Usage Data: Pages visited within the Service, features accessed, time spent on each page, click patterns, search queries performed within the Registry, and navigation paths.
  • API Usage Data: If you access our API, we log API endpoint requests, request timestamps, response codes, request frequency, authentication token usage (but not the tokens themselves), and data volumes transmitted.
  • Cookies and Similar Technologies: We use cookies, local storage, and session storage to maintain session state, authenticate users, remember preferences, and collect usage analytics. See Section 7 for detailed information about our cookie practices.

2.3 Information from Third Parties

We receive information from third-party sources in connection with operating the Service, verifying label identities, and enriching label profile data. These sources include:

  • Streaming Platform Data: We access publicly available data from digital streaming platforms and music databases, including Spotify, YouTube, Deezer, Last.fm, MusicBrainz, and Genius. This data may include label presence on the platform, associated artist catalogs, release metadata, follower counts, and other publicly available metrics. This data is used for verification scoring and profile enrichment.
  • Payment Processor Data: We receive transaction confirmations, payment status updates, billing information, and dispute or chargeback notifications from Stripe in connection with your purchases.
  • Email Delivery Data: We receive delivery status information from Resend, our email service provider, including whether transactional emails were delivered, opened, or bounced. This data is used for service reliability monitoring and is not used for marketing purposes.
  • Business Registry Data: For the purpose of verifying label legitimacy, we may access publicly available business filing records from state and federal business registries, including entity status, formation date, registered agent information, and principal office address.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: To provide, operate, and maintain the Record Label Registry, including label registration, profile management, directory listings, search functionality, and API services.
  • Account Management: To create and manage your account, authenticate your identity, process login requests, and maintain account security.
  • Verification Processing: To evaluate verification applications, perform automated and manual verification checks, assign verification scores, process verification payments, and communicate verification decisions.
  • Streaming Analytics Aggregation: To collect, aggregate, and display publicly available streaming platform data associated with registered labels, providing users with enriched label profiles and industry insights.
  • Compliance and Fraud Prevention: To detect, investigate, and prevent fraudulent, unauthorized, or illegal activity, including impersonation of labels, submission of false verification evidence, and abuse of the Service.
  • Claim Processing: To evaluate claims submitted against existing label profiles, verify claimant authority, and facilitate the resolution of ownership disputes.
  • Communications: To send transactional emails related to your account and use of the Service, including registration confirmations, verification status updates, payment receipts, security alerts, and service announcements. We do not send unsolicited marketing emails.
  • Service Improvement: To analyze usage patterns, monitor Service performance, diagnose technical issues, develop new features, and improve the overall user experience.
  • Legal Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests, and to establish, exercise, or defend legal claims.
  • Aggregate Analytics: To generate anonymized, aggregated statistical data about Registry usage, label demographics, and industry trends. Aggregated data does not identify individual users and may be used for research, reporting, and business purposes.

4. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data only when we have a valid legal basis under the GDPR. The following table identifies the legal basis for each category of processing activity.

Processing ActivityLegal BasisDetails
Account creation and managementPerformance of a contractNecessary to perform our contractual obligations under the Terms of Service when you register for an account.
Label registration and profile displayPerformance of a contractNecessary to provide the core registry listing service you have requested.
Verification processingPerformance of a contractNecessary to fulfill verification services purchased or requested by you.
Payment processingPerformance of a contractNecessary to process transactions for paid services.
Transactional email communicationsPerformance of a contract; legitimate interestsNecessary to deliver service-related notifications and updates you expect to receive.
Fraud prevention and security monitoringLegitimate interestsWe have a legitimate interest in protecting the Service, our users, and the integrity of the Registry from fraud, abuse, and unauthorized access.
Service improvement and analyticsLegitimate interestsWe have a legitimate interest in understanding how users interact with the Service to improve functionality and user experience.
Streaming data aggregationLegitimate interestsWe have a legitimate interest in enriching label profiles with publicly available data to provide a comprehensive registry experience.
Cookie-based analytics (non-essential)ConsentWhere required by law, we obtain your consent before placing non-essential cookies on your device.
Compliance with legal obligationsLegal obligationNecessary to comply with applicable laws, including tax reporting, anti-money laundering, and regulatory requirements.
Response to legal processesLegal obligationNecessary to respond to court orders, subpoenas, and valid regulatory inquiries.

Where we rely on legitimate interests as the legal basis for processing, we have conducted a balancing test to ensure that your interests, rights, and freedoms do not override our legitimate interests. You may contact us at any time to obtain information about our balancing assessments or to object to processing based on legitimate interests.

5. Data Storage and Security

5.1 Data Storage Infrastructure

Your data is stored in PostgreSQL databases hosted by Neon (neon.tech) in data center facilities located in the United States. The Service application is hosted on Vercel's global edge network, with primary compute functions executing in the United States. All data processing infrastructure is located within the United States unless otherwise specified.

5.2 Security Measures

We implement a range of technical and organizational security measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption at Rest: Data stored in our databases is encrypted at rest using AES-256 encryption, as provided by our database hosting provider.
  • Encryption in Transit: All data transmitted between your browser and our servers, and between our servers and third-party service providers, is encrypted using Transport Layer Security (TLS) version 1.2 or higher.
  • Password Security: User passwords are cryptographically hashed using the bcrypt algorithm with appropriate cost factors before storage. We never store passwords in plaintext and cannot recover your original password.
  • Role-Based Access Controls: Access to personal data within our systems is restricted to authorized personnel on a need-to-know basis through role-based access control mechanisms. Administrative access requires separate authentication.
  • Audit Logging: We maintain audit logs of administrative actions, data access events, and security-relevant system events to facilitate monitoring and incident investigation.
  • Regular Security Assessments: We conduct periodic reviews of our security practices, infrastructure configurations, and access controls to identify and address potential vulnerabilities.
  • Secure Development Practices: Our development process incorporates security best practices, including input validation, parameterized database queries, protection against cross-site scripting (XSS), and cross-site request forgery (CSRF) prevention.

5.3 Limitations

While we implement industry-standard security protections, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security of your data. In the event of a security incident, we will take appropriate measures in accordance with applicable law and our Data Breach Notification procedures described in Section 13 of this Policy.

6. Data Sharing and Disclosure

We share your information only in the circumstances described below. We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

6.1 Service Providers (Sub-Processors)

We engage the following third-party service providers ("sub-processors") to assist in operating the Service. Each sub-processor is contractually obligated to process your data only as necessary to provide services to us and in accordance with applicable data protection laws.

  • Neon (Neon Inc.): PostgreSQL database hosting and management. Neon stores all persistent Service data, including account information, label profiles, and verification records. Data is hosted in US-based data centers. Neon Privacy Policy.
  • Vercel (Vercel Inc.): Application hosting, deployment, and content delivery. Vercel processes request data, server logs, and performance metrics in connection with hosting the Service. Vercel Privacy Policy.
  • Stripe (Stripe, Inc.): Payment processing and financial transaction management. Stripe collects and processes payment card data directly; we do not receive or store full payment card numbers. Stripe Privacy Policy.
  • Resend (Resend, Inc.): Transactional email delivery. Resend processes recipient email addresses and email content in order to deliver service-related communications on our behalf. Resend Privacy Policy.

6.2 Public Registry Data

The Record Label Registry is, by its nature, a public directory. The following information associated with registered labels is publicly visible and searchable through the Registry directory and may be indexed by search engines:

  • Label name
  • Registry ID (unique identifier assigned upon registration)
  • Registration status (Registered, Verified, Suspended)
  • Location (city, state/province, country)
  • Musical genres
  • Year founded
  • Website URL
  • Verification status and verification tier
  • Label description (if provided)
  • Social media links (if provided)
  • Artist roster (if provided)

Your personal account information (name, email address, password) is not publicly displayed. By registering a label with the Service, you acknowledge and consent to the public display of the label profile information listed above.

6.3 API Access

We provide application programming interface (API) access to authorized third-party consumers. Authorized API consumers receive label profile data, Registry IDs, verification statuses, and other publicly available registry information in accordance with their subscription tier and the terms of their API access agreement. API consumers are contractually prohibited from using the data for purposes inconsistent with this Privacy Policy.

6.4 Legal Requirements

We may disclose your information if we believe in good faith that such disclosure is necessary to: (a) comply with applicable law, regulation, or legal process, including court orders, subpoenas, and valid government requests; (b) enforce our Terms of Service or other agreements; (c) protect the rights, property, or safety of THRY ARCHIVE LLC, our users, or the public; or (d) investigate or prevent suspected fraud, security breaches, or other illegal activity.

6.5 Business Transfers

In the event that THRY ARCHIVE LLC undergoes a merger, acquisition, reorganization, dissolution, sale of all or substantially all of its assets, or similar business transaction, your personal information may be transferred as part of that transaction. In such an event, we will notify you via email or through a prominent notice on the Service before your personal information is transferred and becomes subject to a different privacy policy.

6.6 No Sale of Personal Data

We do NOT sell personal data to third parties. We have not sold personal data in the preceding twelve (12) months and have no plans to do so. This applies to the sale of personal information as defined under the CCPA/CPRA and the sale or sharing of personal data as understood under the GDPR and other applicable data protection laws.

7. Cookies and Tracking Technologies

We use cookies and similar technologies to facilitate the operation of the Service, maintain user sessions, and analyze usage patterns. This section describes the types of cookies we use, their purposes, and your options for managing them.

7.1 Types of Cookies We Use

  • Essential Cookies (Strictly Necessary): These cookies are required for the basic operation of the Service. They enable core functionality such as session management, user authentication, security token validation, and CSRF protection. The Service cannot function properly without these cookies. These cookies do not require consent under applicable law, as they are strictly necessary for the provision of the service you have requested.
  • Functional Cookies: These cookies enable the Service to remember choices you have made, such as display preferences, search filters, and other user-configurable settings. Functional cookies improve your experience but are not strictly required for the Service to operate.
  • Analytics Cookies: If applicable, we may use analytics cookies to collect aggregated, anonymized information about how users interact with the Service, including pages visited, features used, and general usage patterns. This data helps us understand user behavior and improve the Service.

7.2 Third-Party Advertising and Cookies

We use Google AdSense to display advertisements on the Service. Google AdSense uses cookies, including the DoubleClick cookie, to serve ads based on your prior visits to this website and other websites on the internet. Google's use of advertising cookies enables it and its partners to serve ads to you based on your browsing patterns. You may opt out of personalized advertising by visiting Google Ads Settings. For more information about how Google uses data when you use our site, please visit Google's Privacy & Terms.

Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website or other websites. You may opt out of third-party vendor cookies for personalized advertising by visiting www.aboutads.info.

7.3 Managing Cookies

You can control and manage cookies through your browser settings. Most browsers allow you to view, delete, and block cookies from websites. Please note that disabling essential cookies may impair the functionality of the Service, including the ability to log in and maintain an authenticated session. Cookie consent is managed in accordance with the requirements of applicable law, including the GDPR and the ePrivacy Directive.

8. Data Retention

We retain your information only for as long as necessary to fulfill the purposes for which it was collected, comply with our legal obligations, resolve disputes, and enforce our agreements. Our complete data retention schedule is set forth in our Document Retention Policy. The following table summarizes retention periods for major categories of data.

Data CategoryRetention PeriodBasis for Retention
Account data (name, email, credentials)Duration of account + 3 yearsContractual and legal requirements; statute of limitations for potential claims.
Label profiles and registry dataDuration of registration + 5 yearsHistorical registry integrity; contractual obligations; potential dispute resolution.
Verification records and evidence7 years from verification decisionRegulatory compliance; evidence preservation for potential disputes or audits.
Financial and transaction records7 years from transaction dateTax reporting requirements (IRS); financial recordkeeping obligations.
Audit logs3 yearsSecurity monitoring; incident investigation; compliance verification.
API access logs12 monthsUsage monitoring; abuse detection; billing reconciliation.
Streaming analytics data24 monthsService functionality; trend analysis; profile enrichment.
Support communications3 years from resolutionQuality assurance; dispute resolution; training.

Upon expiration of the applicable retention period, personal data is securely deleted or anonymized such that it can no longer be associated with an identifiable individual. We may retain anonymized, aggregated data indefinitely for statistical and analytical purposes, as such data does not constitute personal data under applicable law.

9. Your Rights

Depending on your jurisdiction, you may have specific rights regarding your personal information. We are committed to facilitating the exercise of these rights in a timely and transparent manner.

9.1 Rights Under the GDPR (EEA, UK, and Swiss Residents)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the GDPR and equivalent local legislation:

  • Right of Access (Article 15): You have the right to obtain confirmation as to whether your personal data is being processed by us and, if so, to access that personal data and receive a copy in a commonly used electronic format.
  • Right to Rectification (Article 16): You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data.
  • Right to Erasure (Article 17): You have the right to request the deletion of your personal data in certain circumstances, including when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when the data has been unlawfully processed.
  • Right to Restriction of Processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances, including while we verify the accuracy of your data following a rectification request, or when you have objected to processing pending verification of our legitimate interests.
  • Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, where processing is based on consent or contract performance and is carried out by automated means.
  • Right to Object (Article 21): You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. Upon receiving an objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
  • Right to Withdraw Consent (Article 7(3)): Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work, or place of the alleged infringement, if you believe that our processing of your personal data infringes the GDPR.

9.2 Rights Under the CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

  • Right to Know (Cal. Civ. Code 1798.100): You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which that information was collected, the business or commercial purposes for collection, and the categories of third parties with whom we share that information.
  • Right to Delete (Cal. Civ. Code 1798.105): You have the right to request the deletion of your personal information, subject to certain exceptions permitted by law (including, for example, where retention is necessary to complete a transaction, comply with a legal obligation, or detect security incidents).
  • Right to Correct (Cal. Civ. Code 1798.106): You have the right to request the correction of inaccurate personal information that we maintain about you.
  • Right to Opt-Out of Sale or Sharing (Cal. Civ. Code 1798.120): You have the right to opt out of the sale or sharing of your personal information. As stated in Section 6.6 of this Policy, we do not sell or share personal information as those terms are defined under the CCPA/CPRA.
  • Right to Non-Discrimination (Cal. Civ. Code 1798.125): We will not discriminate against you for exercising any of your CCPA/CPRA rights, including by denying you services, charging different prices, providing a different quality of service, or suggesting that you will receive a different level of service.
  • Right to Limit Use of Sensitive Personal Information (Cal. Civ. Code 1798.121): You have the right to limit our use of sensitive personal information (as defined under the CPRA) to purposes necessary to perform the services you have requested. We use sensitive personal information only as necessary to provide the Service and do not use it for purposes beyond what is reasonably expected.

9.3 How to Exercise Your Rights

You may exercise any of the rights described above by:

  • Emailing us at privacy@recordlabelregistry.com with a detailed description of your request.
  • Using the data export feature available in your account dashboard settings, where applicable.

When submitting a request, we may need to verify your identity before processing your request. Verification measures may include confirming your email address, account credentials, or other identifying information reasonably necessary to confirm your identity.

We will acknowledge receipt of your request within five (5) business days and will respond substantively within thirty (30) days of receiving a verified request. If additional time is required, we will notify you of the extension and the reasons for it. Extensions will not exceed an additional sixty (60) days beyond the initial thirty-day period.

10. International Data Transfers

The Service is operated from the United States, and your personal data is primarily processed and stored in data centers located in the United States. If you access the Service from outside the United States, please be aware that your personal data will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States or other countries outside those regions, we rely on the following transfer mechanisms as applicable:

  • Standard Contractual Clauses (SCCs):We use the European Commission's Standard Contractual Clauses (as adopted under Commission Implementing Decision (EU) 2021/914) to provide appropriate safeguards for transfers of personal data to our sub-processors located outside the EEA.
  • Adequacy Decisions: Where the European Commission has issued an adequacy decision for the recipient country, we may rely on that decision as the basis for the transfer.
  • UK International Data Transfer Agreement: For transfers from the United Kingdom, we use the UK International Data Transfer Agreement or the UK Addendum to the EU SCCs as appropriate.

You may obtain a copy of the relevant transfer safeguards by contacting us at privacy@recordlabelregistry.com.

11. Children's Privacy

The Service is designed for use by businesses and professionals in the music industry and is not directed at children under the age of sixteen (16). We do not knowingly collect, solicit, or maintain personal information from anyone under the age of 16. If we learn that personal information from a child under 16 has been collected through the Service without verifiable parental consent, we will take immediate steps to delete that information from our records.

If you are a parent, guardian, or other individual who believes that a child under the age of 16 has provided personal information to us through the Service, please contact us immediately at privacy@recordlabelregistry.com so that we can take appropriate action. We will investigate all such reports promptly and will delete any confirmed personal information of a child under 16 within a reasonable timeframe.

12. Third-Party Links

The Service may contain links to third-party websites, services, and resources that are not operated or controlled by us. These links include, but are not limited to, links to label websites, social media profiles, streaming platforms, business registries, and the websites of our service providers. These links are provided for your convenience and informational purposes only.

We are not responsible for the privacy practices, content, or security of any third-party websites or services. The inclusion of a link on the Service does not imply endorsement of, or affiliation with, the linked website or its operator. We encourage you to review the privacy policy of every third-party website you visit.

This Privacy Policy applies solely to information collected through the Service and does not extend to information collected by third parties through their own websites or services, even if accessed via a link from the Service.

13. Data Breach Notification

In the event that we become aware of a security breach that results in the unauthorized access, disclosure, alteration, or destruction of personal data, we will take the following steps:

  • Supervisory Authority Notification: In accordance with GDPR Article 33, we will notify the competent supervisory authority without undue delay and, where feasible, within seventy-two (72) hours of confirming a breach involving personal data, unless the breach is unlikely to result in a risk to the rights and freedoms of affected individuals.
  • Affected Individual Notification: In accordance with GDPR Article 34, where a breach is likely to result in a high risk to the rights and freedoms of affected individuals, we will notify those individuals without undue delay. Notification will be made via the email address associated with the affected account, as well as through a prominent notice on the Service.
  • Content of Notification: Breach notifications will include, at a minimum, the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences of the breach, the measures taken or proposed to address the breach, and contact information for our Data Protection Lead.
  • State Law Compliance: We will also comply with all applicable state data breach notification laws in the United States, including notification to state attorneys general where required.

We maintain an incident response plan and conduct periodic exercises to ensure our readiness to respond to security incidents effectively and in compliance with applicable legal requirements.

14. Automated Decision-Making

The Service uses automated processing as part of the label verification process. Our auto-verification system evaluates verification applications by analyzing publicly available data from streaming platforms, social media accounts, official websites, and business registries to generate a verification score. This scoring process is automated and considers factors such as the presence and consistency of the label across platforms, the volume and recency of releases, the number and quality of associated artist profiles, and the validity of business registration information.

The automated verification score may influence whether a label receives a verification designation. However, automated scoring does not constitute the sole basis for decisions that produce legal effects or similarly significantly affect you.

In accordance with GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. You may exercise this right by:

  • Requesting human review of any automated verification decision by contacting us at privacy@recordlabelregistry.com.
  • Expressing your point of view and providing additional evidence to support your verification application.
  • Contesting the outcome of an automated decision by submitting a written explanation of the basis for your objection.

Additional details about our verification methodology and scoring criteria are available in our verification documentation. We regularly review our automated processing systems for accuracy, fairness, and bias.

15. Changes to This Policy

We may update or modify this Privacy Policy from time to time to reflect changes in our data practices, the Service, applicable laws, or industry standards. When we make changes to this Policy, we will update the "Last Updated" date and version number at the top of this page.

For material changes to this Policy (including changes that affect how we collect, use, or share your personal information, or changes that reduce your rights under this Policy), we will provide you with at least thirty (30) days' advance notice before the changes take effect. Notice of material changes will be provided via email to the address associated with your account and through a prominent notice on the Service.

Your continued use of the Service after the effective date of a revised Privacy Policy constitutes your acceptance of the revised terms. If you do not agree to the changes, you must stop using the Service and may request deletion of your account and personal data in accordance with Section 9 of this Policy.

Prior versions of this Privacy Policy are available upon request. To obtain a copy of a previous version, please contact us at privacy@recordlabelregistry.com.

16. Contact Information

If you have questions, concerns, or requests regarding this Privacy Policy, our data practices, or your rights under applicable data protection laws, please contact us using the information below.

THRY ARCHIVE LLC

Privacy Inquiries: privacy@recordlabelregistry.com

General Inquiries: contact@thryarchive.com

Website: thryarchive.com

GDPR Data Protection Lead

For inquiries related to the GDPR, the processing of personal data of EEA, UK, or Swiss residents, or to exercise your rights under applicable European data protection law, please contact our Data Protection Lead:

Email: privacy@recordlabelregistry.com

Subject Line:"GDPR Inquiry"

We will acknowledge receipt of all privacy-related inquiries within five (5) business days and will provide a substantive response within thirty (30) days.


Related Legal Documents

This Privacy Policy should be read in conjunction with the following legal documents, which together govern your use of the Service:


Document ID: PP-RLR-2026-002 | Version 2.0

Copyright 2026 THRY ARCHIVE LLC. All rights reserved.

This document constitutes a legally binding privacy policy. It does not create an attorney-client relationship. If you require legal advice regarding your rights, please consult a qualified attorney in your jurisdiction.