1. About Rhyto Studio
Rhyto Studio is a product and service operated by Boda Dudu Technologies Limited. It is built for artist and catalogue management, giving artists and authorised team members one workspace to claim and manage artist profiles, manage team access, submit music and albums, upload artwork and audio, add or correct lyrics, request catalogue or profile changes, follow review activity and manage account security.
This Privacy Policy applies to the Rhyto Studio website, desktop and mobile applications, application programming interfaces, and related account, notification and support services. In this policy, “Rhyto Studio”, “Rhyto”, “we”, “us” and “our” refer to the Rhyto Studio service operated by Boda Dudu Technologies Limited.
For personal data processed to operate Rhyto Studio, Boda Dudu Technologies Limited acts as the data controller where applicable.
2. Information we process
Account and identity information
- Name, email address, account identifiers and account status.
- Password credentials in protected form, email-verification state and password-reset/security state.
- Profile avatar and other account settings you choose to provide.
Artist, profile and team information
- Artist stage name, full name, biography, country, label, social-profile information and date of birth where you choose or are required to provide it for a Studio workflow.
- Artist catalogue identifiers, artist memberships, team roles, permissions, invitations and access history.
- Information submitted when requesting a new artist profile or claiming authority to manage an existing artist.
Claim and verification material
- Claim messages, proof links and proof documents you choose to submit to demonstrate your relationship to or authority over an artist.
- Original file names, file size/type and internal storage references associated with submitted proof material.
Music, catalogue and creator content
- Song and album titles, release information, genres, labels, featured artists, contributors, writers, producers and other catalogue metadata.
- Audio files, album or single artwork, artist/profile images, lyrics and other creator content you intentionally upload or submit.
- Requests to create, update or correct songs, albums, lyrics and artist profiles, together with review status, history and related comments.
Device, session and technical information
- Device/platform type, operating environment, app version and installation identifiers used by the app.
- Internet Protocol (IP) address, browser/user-agent information, session identifiers in protected or hashed form, first/last activity times and session revocation state.
- Technical and diagnostic information needed to operate, secure, troubleshoot and improve Rhyto Studio.
Security and administration records
- Security events such as sign-ins, password changes, two-factor authentication activity, passkey-related account state, session revocations and security alerts.
- Administrative audit records for protected Studio actions. The service is designed to redact sensitive request fields such as passwords, secrets, tokens, proof documents, audio and file paths from administrative audit payloads where those fields are classified as sensitive.
3. Where information comes from
We receive information from:
- You, when you create an account, update your profile, submit music or files, make an artist claim, manage a team, contact us or otherwise use Studio.
- Authorised members of an artist team, when they invite you, manage permissions or participate in collaborative Studio workflows.
- Your device and browser, when necessary for sessions, security, app operation and notifications.
- Rhyto catalogue and related Rhyto services, when Studio needs existing artist, song, album or lyrics information to display or process a request.
- Service providers used for security, notification delivery, hosting, email delivery and other infrastructure functions.
4. Why we use information
We process information to:
- Create, authenticate and maintain Rhyto Studio accounts.
- Provide artist claims, team access, artist-profile management, music and album submissions, lyrics tools and catalogue-change workflows.
- Store and process files and creator content that you intentionally submit.
- Route requests to the correct artist, team member, reviewer or Studio account.
- Send transactional emails, security messages, workflow updates and push notifications.
- Protect accounts, enforce permissions, detect abuse, revoke compromised sessions and investigate security incidents.
- Maintain audit trails needed for accountability, security and administration.
- Diagnose faults, maintain performance and improve the reliability of the service.
- Comply with legal obligations and establish, exercise or defend legal rights.
We do not sell personal data. We also do not use Rhyto Studio creator submissions as advertising inventory simply because they were uploaded to a private Studio workflow.
5. Lawful bases for processing
Depending on the activity and applicable law, our lawful basis may include:
- Performance of a contract or steps at your request — for example, creating and operating your Studio account and processing a submission or artist-management request.
- Legitimate interests — for example, securing Studio, preventing abuse, maintaining auditability, supporting users and improving reliability, where those interests are not overridden by your rights.
- Consent — where a particular feature or law requires consent, including permissions you choose to grant on your device.
- Legal obligation — where we must process or retain information to comply with applicable law, regulation or a lawful request.
6. Account security and authentication
Rhyto Studio supports security features including password authentication, email verification where enabled, two-factor authentication, passkeys, session controls and device/session revocation.
We use reasonable administrative, technical and organisational measures designed to protect information against unauthorised access, alteration, loss, misuse or disclosure. These measures include authenticated application programming interfaces, access controls, protected session/token handling and server-side storage of service credentials that should not be embedded in public app packages.
No online service can guarantee absolute security. You should protect your account credentials, recovery information and devices and notify us if you suspect unauthorised access.
7. Push notifications
If notifications are enabled, Rhyto Studio may register your device with a platform notification service. Current supported flows can include Firebase Cloud Messaging for supported mobile platforms and Microsoft Windows Push Notification Services (WNS) for Windows.
To deliver notifications, Studio may process a push token or WNS channel URI, a hashed channel reference, installation identifier, platform, app version, channel expiry time, notification-enabled state and last-seen time. A notification may also contain routing information needed to open the correct Studio activity or account.
You can control notification permission through your operating-system settings. Studio may remove or replace push registrations when your app unregisters a device, a channel changes, a session ends or the registration is otherwise no longer required.
10. How long we keep information
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including providing Studio, maintaining catalogue and request history, protecting users, resolving disputes, satisfying legal obligations and maintaining appropriate business/security records.
Retention periods therefore vary by data type. For example, active account and artist-management records may be needed while the account or relationship remains active; submission and approval history may need to remain with the catalogue workflow; and security/audit records may be kept for a reasonable period to investigate incidents or demonstrate accountability.
When a Studio account deletion is completed, the live account is closed, active artist/team access is revoked, direct authentication and device credentials are removed, and the account name/email are anonymised. The artist catalogue itself is not deleted merely because one team member closes an account. Claim or verification evidence, artist-access history, approved or published submissions, catalogue/request history, and limited fraud, security or audit records may be retained where reasonably necessary to establish previous authority, protect catalogue integrity, investigate impersonation or fraud, resolve rights disputes, demonstrate accountability or comply with law.
When information is no longer required, we may delete it, anonymise it or retain it only where continued retention is permitted or required by law.
11. International processing
Rhyto Studio is operated from Nigeria, but our infrastructure or service providers may process information in other countries. Where applicable law requires safeguards for cross-border transfers, we take appropriate steps designed to protect personal data and use providers or arrangements that support those obligations.
12. Your privacy rights
Subject to the Nigeria Data Protection Act 2023 and any other law that applies to you, you may have rights including the right to:
- Be informed about how your personal data is processed.
- Request access to personal data we hold about you.
- Request correction of inaccurate or incomplete personal data.
- Object to or request restriction of certain processing.
- Request erasure where the legal requirements for erasure are met.
- Request data portability where applicable.
- Withdraw consent where processing is based on consent, without affecting processing that was lawful before withdrawal.
- Raise concerns about qualifying automated decision-making and request appropriate human involvement where applicable.
- Lodge a complaint with the Nigeria Data Protection Commission or another competent supervisory authority.
Some information can be updated directly in Studio. You can initiate deletion of your Studio account from our Account Deletion page or through a supported Studio app. For personal-data access, correction, portability or other privacy requests, contact us using the details below. We may need to verify your identity or authority before providing account information or acting on a request, especially where artist/team information involves other people.
A right may be limited where an applicable law allows or requires us to retain information, protect another person’s rights, preserve catalogue/verification history or security evidence, or refuse a request for another lawful reason.
13. Children’s privacy
Rhyto Studio is designed for artists, creators, representatives and authorised team members rather than as a service directed to children. Where a user is not legally able to consent to the relevant processing in their jurisdiction, any required parent or guardian authorisation must be obtained before using the service.
If you believe a child’s personal data has been provided to Rhyto Studio contrary to applicable law, please contact us so we can review the matter.
14. Changes to this Privacy Policy
We may update this policy when Rhyto Studio features, data practices, service providers or legal requirements change. We will update the “Last updated” date on this page. Where a change is material, we may provide additional notice through Studio or another appropriate communication channel.
15. Contact and privacy requests
Boda Dudu Technologies Limited
Rhyto Studio Privacy & Support
Nigeria
Email: support@bodadudu.com
Rhyto Studio: https://studio.rhyto.com
If your concern is not resolved, you may also contact the Nigeria Data Protection Commission through its official complaint and contact channels.