Rhyto Rhyto Studio

Privacy & data protection

Privacy Policy

How Rhyto Studio handles information across the web service and Rhyto Studio apps while artists and their teams manage profiles, music, lyrics, catalogue requests and account security.

Effective 5 September 2026 · Last updated 5 September 2026

1. About Rhyto Studio

Rhyto Studio is a product and service operated by Boda Dudu Technologies Limited. It is built for artist and catalogue management, giving artists and authorised team members one workspace to claim and manage artist profiles, manage team access, submit music and albums, upload artwork and audio, add or correct lyrics, request catalogue or profile changes, follow review activity and manage account security.

This Privacy Policy applies to the Rhyto Studio website, desktop and mobile applications, application programming interfaces, and related account, notification and support services. In this policy, “Rhyto Studio”, “Rhyto”, “we”, “us” and “our” refer to the Rhyto Studio service operated by Boda Dudu Technologies Limited.

For personal data processed to operate Rhyto Studio, Boda Dudu Technologies Limited acts as the data controller where applicable.

2. Information we process

Account and identity information

  • Name, email address, account identifiers and account status.
  • Password credentials in protected form, email-verification state and password-reset/security state.
  • Profile avatar and other account settings you choose to provide.

Artist, profile and team information

  • Artist stage name, full name, biography, country, label, social-profile information and date of birth where you choose or are required to provide it for a Studio workflow.
  • Artist catalogue identifiers, artist memberships, team roles, permissions, invitations and access history.
  • Information submitted when requesting a new artist profile or claiming authority to manage an existing artist.

Claim and verification material

  • Claim messages, proof links and proof documents you choose to submit to demonstrate your relationship to or authority over an artist.
  • Original file names, file size/type and internal storage references associated with submitted proof material.

Music, catalogue and creator content

  • Song and album titles, release information, genres, labels, featured artists, contributors, writers, producers and other catalogue metadata.
  • Audio files, album or single artwork, artist/profile images, lyrics and other creator content you intentionally upload or submit.
  • Requests to create, update or correct songs, albums, lyrics and artist profiles, together with review status, history and related comments.

Device, session and technical information

  • Device/platform type, operating environment, app version and installation identifiers used by the app.
  • Internet Protocol (IP) address, browser/user-agent information, session identifiers in protected or hashed form, first/last activity times and session revocation state.
  • Technical and diagnostic information needed to operate, secure, troubleshoot and improve Rhyto Studio.

Security and administration records

  • Security events such as sign-ins, password changes, two-factor authentication activity, passkey-related account state, session revocations and security alerts.
  • Administrative audit records for protected Studio actions. The service is designed to redact sensitive request fields such as passwords, secrets, tokens, proof documents, audio and file paths from administrative audit payloads where those fields are classified as sensitive.
Passkeys and device biometrics. If you use a passkey, biometric or device-PIN verification used to unlock that passkey is performed by your device or platform. Rhyto Studio receives the cryptographic authentication result/credential needed for sign-in; it does not receive your fingerprint or face template from the device.

3. Where information comes from

We receive information from:

  • You, when you create an account, update your profile, submit music or files, make an artist claim, manage a team, contact us or otherwise use Studio.
  • Authorised members of an artist team, when they invite you, manage permissions or participate in collaborative Studio workflows.
  • Your device and browser, when necessary for sessions, security, app operation and notifications.
  • Rhyto catalogue and related Rhyto services, when Studio needs existing artist, song, album or lyrics information to display or process a request.
  • Service providers used for security, notification delivery, hosting, email delivery and other infrastructure functions.

4. Why we use information

We process information to:

  • Create, authenticate and maintain Rhyto Studio accounts.
  • Provide artist claims, team access, artist-profile management, music and album submissions, lyrics tools and catalogue-change workflows.
  • Store and process files and creator content that you intentionally submit.
  • Route requests to the correct artist, team member, reviewer or Studio account.
  • Send transactional emails, security messages, workflow updates and push notifications.
  • Protect accounts, enforce permissions, detect abuse, revoke compromised sessions and investigate security incidents.
  • Maintain audit trails needed for accountability, security and administration.
  • Diagnose faults, maintain performance and improve the reliability of the service.
  • Comply with legal obligations and establish, exercise or defend legal rights.

We do not sell personal data. We also do not use Rhyto Studio creator submissions as advertising inventory simply because they were uploaded to a private Studio workflow.

5. Lawful bases for processing

Depending on the activity and applicable law, our lawful basis may include:

  • Performance of a contract or steps at your request — for example, creating and operating your Studio account and processing a submission or artist-management request.
  • Legitimate interests — for example, securing Studio, preventing abuse, maintaining auditability, supporting users and improving reliability, where those interests are not overridden by your rights.
  • Consent — where a particular feature or law requires consent, including permissions you choose to grant on your device.
  • Legal obligation — where we must process or retain information to comply with applicable law, regulation or a lawful request.

6. Account security and authentication

Rhyto Studio supports security features including password authentication, email verification where enabled, two-factor authentication, passkeys, session controls and device/session revocation.

We use reasonable administrative, technical and organisational measures designed to protect information against unauthorised access, alteration, loss, misuse or disclosure. These measures include authenticated application programming interfaces, access controls, protected session/token handling and server-side storage of service credentials that should not be embedded in public app packages.

No online service can guarantee absolute security. You should protect your account credentials, recovery information and devices and notify us if you suspect unauthorised access.

7. Push notifications

If notifications are enabled, Rhyto Studio may register your device with a platform notification service. Current supported flows can include Firebase Cloud Messaging for supported mobile platforms and Microsoft Windows Push Notification Services (WNS) for Windows.

To deliver notifications, Studio may process a push token or WNS channel URI, a hashed channel reference, installation identifier, platform, app version, channel expiry time, notification-enabled state and last-seen time. A notification may also contain routing information needed to open the correct Studio activity or account.

You can control notification permission through your operating-system settings. Studio may remove or replace push registrations when your app unregisters a device, a channel changes, a session ends or the registration is otherwise no longer required.

8. Cookies, local storage and security technologies

The Studio website uses technologies that are necessary for sign-in, security and user preferences. These can include:

  • Session and security cookies used by the Laravel web application to keep you signed in and protect requests.
  • Browser local storage for your Rhyto Studio appearance preference (system, light or dark).
  • Cloudflare Turnstile on protected authentication actions such as registration, sign-in or password/verification flows when that protection is enabled. Turnstile may process device, browser and network information necessary to distinguish legitimate users from automated abuse.

These technologies are used for service operation, security or preferences rather than behavioural advertising by Rhyto Studio.

9. When information may be shared

We may disclose information only as reasonably necessary to:

  • Authorised members of the relevant artist/team workspace, where the Studio feature is designed for collaboration and their permissions allow access.
  • Rhyto administrators and reviewers who need information to review claims, submissions, profile changes, catalogue requests, security incidents or support matters.
  • Infrastructure and service providers that help us host, secure, deliver email, store content or operate Rhyto Studio.
  • Cloudflare for Turnstile security verification where enabled.
  • Google/Firebase or Apple platform services where required to deliver supported mobile notifications, and Microsoft WNS for Windows notifications.
  • Professional advisers, regulators, courts, law-enforcement bodies or other authorities where disclosure is required by law or reasonably necessary to protect rights, users or the service.
  • A successor organisation in connection with a lawful merger, acquisition, restructuring or transfer of all or part of the business, subject to appropriate protections.

Service providers are expected to process information for the functions they provide and subject to appropriate contractual, confidentiality or security obligations.

10. How long we keep information

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing Studio, maintaining catalogue and request history, protecting users, resolving disputes, satisfying legal obligations and maintaining appropriate business/security records.

Retention periods therefore vary by data type. For example, active account and artist-management records may be needed while the account or relationship remains active; submission and approval history may need to remain with the catalogue workflow; and security/audit records may be kept for a reasonable period to investigate incidents or demonstrate accountability.

When a Studio account deletion is completed, the live account is closed, active artist/team access is revoked, direct authentication and device credentials are removed, and the account name/email are anonymised. The artist catalogue itself is not deleted merely because one team member closes an account. Claim or verification evidence, artist-access history, approved or published submissions, catalogue/request history, and limited fraud, security or audit records may be retained where reasonably necessary to establish previous authority, protect catalogue integrity, investigate impersonation or fraud, resolve rights disputes, demonstrate accountability or comply with law.

When information is no longer required, we may delete it, anonymise it or retain it only where continued retention is permitted or required by law.

11. International processing

Rhyto Studio is operated from Nigeria, but our infrastructure or service providers may process information in other countries. Where applicable law requires safeguards for cross-border transfers, we take appropriate steps designed to protect personal data and use providers or arrangements that support those obligations.

12. Your privacy rights

Subject to the Nigeria Data Protection Act 2023 and any other law that applies to you, you may have rights including the right to:

  • Be informed about how your personal data is processed.
  • Request access to personal data we hold about you.
  • Request correction of inaccurate or incomplete personal data.
  • Object to or request restriction of certain processing.
  • Request erasure where the legal requirements for erasure are met.
  • Request data portability where applicable.
  • Withdraw consent where processing is based on consent, without affecting processing that was lawful before withdrawal.
  • Raise concerns about qualifying automated decision-making and request appropriate human involvement where applicable.
  • Lodge a complaint with the Nigeria Data Protection Commission or another competent supervisory authority.

Some information can be updated directly in Studio. You can initiate deletion of your Studio account from our Account Deletion page or through a supported Studio app. For personal-data access, correction, portability or other privacy requests, contact us using the details below. We may need to verify your identity or authority before providing account information or acting on a request, especially where artist/team information involves other people.

A right may be limited where an applicable law allows or requires us to retain information, protect another person’s rights, preserve catalogue/verification history or security evidence, or refuse a request for another lawful reason.

13. Children’s privacy

Rhyto Studio is designed for artists, creators, representatives and authorised team members rather than as a service directed to children. Where a user is not legally able to consent to the relevant processing in their jurisdiction, any required parent or guardian authorisation must be obtained before using the service.

If you believe a child’s personal data has been provided to Rhyto Studio contrary to applicable law, please contact us so we can review the matter.

14. Changes to this Privacy Policy

We may update this policy when Rhyto Studio features, data practices, service providers or legal requirements change. We will update the “Last updated” date on this page. Where a change is material, we may provide additional notice through Studio or another appropriate communication channel.

15. Contact and privacy requests

Boda Dudu Technologies Limited
Rhyto Studio Privacy & Support
Nigeria

Email: support@bodadudu.com

Rhyto Studio: https://studio.rhyto.com

If your concern is not resolved, you may also contact the Nigeria Data Protection Commission through its official complaint and contact channels.