This English translation is provided for convenience only. The German version is the legally binding version. Read the German version.
Privacy Policy
Last updated: 14 July 2026 · Version 4
1. Controller
clubjam FlexCo, Göstling 170, 3345 Göstling an der Ybbs, Österreich (Austria)
Managing Director: Martin Käfer
Data protection inquiries: datenschutz@clubjam.co · General: support@clubjam.co
2. Principles
taktjam is an administration tool for music teachers. All application data is processed on servers in the European Union. We do not sell data, show no advertising and use no advertising-related tracking; we send our newsletter (section 12) only after explicit sign-up using a double opt-in procedure. We set statistics cookies exclusively with your explicit consent (see sections 6–7). In the practice space for students and parents (section 5), we use no analytics tools at all.
3. Account and contract data (teachers)
When you register, we process your e-mail address, password (encrypted/hashed) and the business data you enter (name, address, bank details for your invoices, tax mode). Legal basis: performance of the contract (Art. 6(1)(b) GDPR) and statutory retention obligations (Art. 6(1)(c) GDPR). For subscription billing we use Stripe Payments Europe Ltd. (Ireland); payment data is processed directly by Stripe.
4. Student data — processing on your behalf
For the personal data of your students (master data, appointments, notes, recordings), YOU as the teacher are the controller under data protection law; we process this data exclusively on your behalf (Art. 28 GDPR). The Data Processing Agreement (DPA) is part of the user agreement and contains the list of subprocessors as well as the technical and organizational measures. Subprocessors: Supabase (database/storage, region Frankfurt am Main, EU), Vercel (hosting, region Frankfurt), optionally Resend (e-mail delivery of lesson notes). For photo, audio and video recordings of students, taktjam provides consent management; obtaining the (for minors, parental, revocable at any time) consent is the teacher’s responsibility.
5. Practice area (portal) for students and parents
The practice space is reachable via a personal address and protected by a password assigned by the teacher (stored encrypted; login via a signed session cookie valid for 30 days). Messages between student/parents and teacher are stored on EU servers as part of the processing carried out on the teacher’s behalf (section 4) and are accessible only to the two sides of the conversation. Files are delivered via short-lived, signed links (1 hour). In the practice space we use no analytics or marketing tools and no cookie banners — only technically essential data (server logs, section 8) is processed. Recordings are deliberately not sent as e-mail attachments; they are made available only via the protected practice space.
6. Cookies & local storage (cookie policy)
We distinguish strictly between essential cookies and cookies that require consent:
| Name | Purpose | Type | Duration |
|---|---|---|---|
| sb-*-auth-token | Login/session (Supabase Auth) | Essential | Session / until logout |
| taktjam-cookie-consent | Stores your cookie decision (localStorage) | Essential | Until revoked |
| taktjam-portal | Login to the practice space (signed session) | Essential | 30 days |
| crisp-client/* | Live chat session (Crisp) — only set once you start the chat | Essential (functional) | 6 months |
| _ga | Google Analytics: distinguishing visitors | Statistics (only with consent) | 2 years |
| _ga_* | Google Analytics: session state | Statistics (only with consent) | 2 years |
You can change or revoke your consent at any time with effect for the future:
7. Google Analytics 4 (only with consent)
Only after you have given consent (Art. 6(1)(a) GDPR, § 165 Abs. 3 TKG 2021 (Austrian Telecommunications Act)) do we load Google Analytics 4 (Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4). We use Google Consent Mode v2; advertising features remain disabled (ad_storage, ad_user_data, ad_personalization: denied), and GA4 does not log IP addresses by default. Any transfer to Google LLC (USA) is based on the adequacy decision for the EU-US Data Privacy Framework, under which Google is certified. Without consent, no Google script is loaded. Revocation: section 6.
8. Server logs
When you access the application, our hosting providers process technically necessary access data (IP address, time, requested resource) for delivery, stability and abuse prevention (Art. 6(1)(f) GDPR); the data is deleted after a short period.
9. Retention & deletion
We store account data until the account is deleted; you can carry out the deletion (including all student data, appointments, notes and files) yourself in the settings at any time — irrevocably. Invoice-related data may be subject to statutory retention obligations (e.g. § 132 BAO (Austrian Federal Fiscal Code): 7 years); the data export is available for this purpose. All ways to delete your account (including without logging in): taktjam.app/en/konto-loeschen.
10. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to withdraw consent you have given. Self-service: complete data export (JSON) and account deletion in the settings. Inquiries: datenschutz@clubjam.co. Complaints: Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Wien (dsb.gv.at). Users in Switzerland may additionally, under the revised Swiss Federal Act on Data Protection (revDSG), contact the Federal Data Protection and Information Commissioner (FDPIC/ EDÖB, edoeb.admin.ch).
11. AI features (Mistral AI)
For AI features (practice plans, note drafts, progress reports for teachers, and the practice assistant “Takti” in the practice space) we use Mistral AI (Mistral AI SAS, Paris, France — processing in the EU). Only the content required for this is transmitted: first name, instrument and excerpts from lesson notes or homework — no contact, payment or health data. Under the data processing agreement, Mistral does not use inputs to train models. We do not store Takti conversations (only daily usage counters); the conversation history exists only in your browser. Teachers can disable Takti for their practice space at any time in the settings. AI outputs are drafts — responsibility for the content lies with the teacher. For the public AI support chat on the website, section 13 additionally applies.
12. Newsletter (Brevo, double opt-in)
On the website and in the app you can sign up for our newsletter (tips for music teaching and product news, max. 1–2 e-mails per month). Sign-up uses a double opt-in procedure: after entering your e-mail address you receive a confirmation e-mail; only once you click the link it contains are you added to the recipient list. The legal basis is your consent (Art. 6(1)(a) GDPR); signing up is voluntary and not a prerequisite for using taktjam.
For sending, we use Brevo (Sendinblue SAS, 106 boulevard Haussmann, 75008 Paris, France — processing in the EU, data processing agreement pursuant to Art. 28 GDPR) as a processor. To document your consent (Art. 7(1) GDPR), we log your e-mail address, the time, the source (website or app), the language you selected (LANGUAGE attribute), your IP address and browser identifier (user agent) at sign-up; confirmation of the double opt-in is documented at Brevo. We retain this evidence for up to three years after you unsubscribe (limitation period) and delete it afterwards.
You can withdraw your consent at any time with effect for the future — via the unsubscribe link contained in every newsletter e-mail, or by e-mail to datenschutz@clubjam.co. After unsubscribing you will not receive any further newsletters.
13. AI support chat (anonymous)
On the website (home page and help section) and in the app we offer a support assistant (“Takti”), labeled as AI, that answers questions about taktjam based on our FAQ. The chat can be used anonymously: no account is required, and the conversation history is not linked to an account. Your question and the current session history are transmitted to Mistral AI (Mistral AI SAS, Paris, France — processing in the EU, no use for model training, see section 11) to generate the answer. We do not store chat histories — they exist only in your browser or in the app while the session is open. No profiling takes place.
To protect against abuse, we limit the number of requests per day; for this purpose we store only a hashed (non-reversible) value of your IP address as a daily counter — no plain-text IP addresses and no content. The legal basis is our legitimate interest in an efficient support offering and in preventing abuse (Art. 6(1)(f) GDPR). Please do not enter personal data in the chat (in particular no names or data of your students) — for individual matters you can reach us at support@clubjam.co.
14. Live chat (Crisp)
For personal support we offer a live chat on the website and in the app. The service provider is Crisp IM SAS (Nantes, France — a European provider, data processing agreement pursuant to Art. 28 GDPR); processing takes place on servers in the EU (Netherlands/Germany). The chat is strictly opt-in: the Crisp script is only loaded once you actively open the chat — before that, no data is transmitted to Crisp and no Crisp cookies are set. In the practice space (/portal) the chat is never loaded.
We process your chat messages, contact details you provide (e.g. an e-mail address for replies), for logged-in teachers the name and e-mail address of the account, and technical metadata (e.g. browser, page visited). The legal basis is the provision of the support you requested (Art. 6(1)(b) GDPR) or our legitimate interest in an efficient support offering (Art. 6(1)(f) GDPR). We delete chat histories as soon as they are no longer needed for support. Please do not share sensitive data about your students in the chat — for such matters you can reach us at datenschutz@clubjam.co.
15. Push notifications
If you wish, you can enable push notifications (e.g. for new messages or lesson reminders) — both on the web (teacher app and practice space) and in the mobile app. Enabling them is voluntary and can be revoked at any time in the settings or in your device’s system settings. The legal basis is your consent (Art. 6(1)(a) GDPR). To deliver notifications we store the necessary device identifier (web push endpoint or device token) in our EU database.
Web push is triggered by our own server (VAPID procedure). For technical reasons, delivery goes through the push service of your browser or operating system (e.g. Google, Mozilla, Apple); under the Web Push standard the content is end-to-end encrypted (RFC 8291), so the push service only forwards the encrypted data and cannot read it. In the mobile app we use Firebase Cloud Messaging (Google Ireland Ltd. or Google LLC, USA) for delivery; this processes a device token and the notification content (which may contain a student’s first name). Any transfer to Google (USA) is based on the adequacy decision for the EU-US Data Privacy Framework or on EU Standard Contractual Clauses. Without notifications enabled, no such data is processed.
16. Mobile app: crash reports & usage statistics
The mobile app (iOS/Android) uses Firebase Crashlytics and Firebase Analytics (Google Ireland Ltd. or Google LLC, USA) to diagnose crashes and understand app usage in aggregated form (e.g. which features are used). This processes device and diagnostic data (device model, operating system version, app version, crash stack traces, pseudonymous instance IDs and events such as app launches) — no lesson content, no student data and no advertising IDs. The legal basis is our legitimate interest in a stable, working app (Art. 6(1)(f) GDPR). Any transfer to Google (USA) is based on the adequacy decision for the EU-US Data Privacy Framework or on EU Standard Contractual Clauses. The website is not affected — there, statistics run only with consent (section 8).
Last updated: 14 July 2026.