Privacy Policy

Table of contents

Platform Privacy Policy

We, Piano Software Inc., Philadelphia, USA and affiliated companies belonging to Piano group (collectively, “Piano”, “us”, “our”, or “we”), and incorporating Newzmate, Cxense and AT Internet are committed, as data processor, to partnering with customers and users to help them understand and comply with data protection regulations (GDPR, ePrivacy, CCPA, LGPD …).

Piano provides online products for digital activities, as well as potential additional services on behalf, and based on instructions of the data controller, owners, and publishers of digital platforms – websites, mobile applications, or any other connected platform (“Publishers”).

We collect, process, store and return personal data and other information through our products – Analytics, Subscriptions (Composer, ID, Billing), Audience (DMP, CDP) and Amplifier (ESP, Socialflow) (“Platform”), or when providing our service to Publishers (“Service”). Personal Data Management on the Platform.

To provide the Platform and/or perform the Service, Piano collect, process, store and return data on behalf of the Publisher. The answers to the following questions allow us to explain how we manage personal data on the Platform.


What kind of personal data do we collect?

  • Raw-type of information via the https protocol: for instance, the IP address that can be anonymized and to perform geolocation, and the end-user’s terminal ID (cookie or mobile ID).

  • All standard business information provided by the products of the Platform: for instance, navigation data (browser and device type, type of events or content, …), behavior information (sources, navigation path, time spent on contents, …), information related to registered or subscribed users (first name, last name, email, …)

  • Additional and specific information that the Publisher can collect: based on the technology used to collect data (see following “How do we collect personal data?”), the Publisher can measure, collect, and analyze any business relevant information for him via our Platform

Analytics, Subscriptions (Composer) and Audience (DMP) collect by default pseudonymized information, but directly identifiable information can be added by the Publisher. Composer (ID and Billing) and Amplifier (ESP) services work with directly identifiable information (e.g. an email).

We therefore consider by default all data collected, processed, stored and returned via our Platform as personal data according to GDPR art. 4.1.


What do we do with personal data?

We process the collected data to provide the information requested by the Publisher on the Platform: audience measurement data, content orchestration and personalisation, account management, subscription processes, …


What are we not doing with personal data?

As data processor, and respecting the terms of contracts and the data processing agreement (DPA) signed with the Publisher acting as data controller, we do not:

  • Claim ownership over personal data;

  • Barter personal data for other services or products;

  • Sell personal data to anyone;

  • Monetize personal data by other means.

We do not knowingly process personal data relating to children less than 13 years of age (or 16 if the age of consent is higher in a particular country) or permit Publishers to provide us with such data. If we become aware that a Publisher has provided us with any personal data of children, we delete such data from our databases.

We do not knowingly process sensitive or special categories of personal data as defined in article 9 of the GDPR.


How do we collect personal data?

Personal data is collected via so called tagging libraries (mainly JavaScript on the web and SDK for native applications) implemented by the Publisher on its online platforms. See Cookies and Similar Technologies below for further details on complementary data collection methods.

When a user/data subject visits a Publisher platform, and according to the legal basis chosen by the Publisher (see Purpose of Processing and Legal Basis below), https requests are sent to Piano servers to perform the service requested by the Publisher.


How long do we store personal data?

Depending on the product of the Platform, or regarding specific legal obligation to perform (e.g., for payment within Subscriptions (Billing), the data retention period can be different and always agreed in the contract with the Publisher acting as data controller. Analytics, for instance, has a predefined data retention period of 25 months with the opportunity for the Publisher to customize it.

For all products, all data is deleted at the end of the contract relationship with the Publisher.


Where do we store personal data?

Depending on the product used by the Publisher, the data collected from the end-user can be stored in different places. Please see the Piano Sub-Processors’ table below, to see where the data is stored/hosted.


Do we share personal data?

We, by default, do not share any data to anyone without the Publisher prior approval.

We, however, may share personal data, with all the adequate technical and organizational measures to protect it, in the following cases:

Intragroup: Only if necessary and for specific purposes, we may share personal data within affiliated companies belonging to Piano group (see Piano Affiliates below). Our employees might have access to personal data on a strictly need-to-know basis typically governed and limited by function, role, and department of the particular employee.  Transfers inside Piano affiliates are covered by Binding Corporate Rules approved by the EDP.

Service providers: We use sub-contractors who might process personal data for us and to support us in providing the Platform and Services requested by the Publisher (see Sub-processors and Affiliates below).

Legal disclosures: We may have to release personal data and other information we possess when necessary or appropriate to comply with the law; cooperate with law enforcement or national security requirements; respond to lawful requests; protect the rights of Piano or a Publisher, other Piano customers, and users, and third parties; or to enforce our terms of use. However, in doing so, we may:

  • Dispute demands for release to the extent we believe, in our sole discretion, are unwarranted, illegitimate, or overbroad.

  • Will notify Publishers of any requests unless we have some contradictory orders.

Piano never had to disclose any personal data for legal purposes so far.


Cookies and Similar Technologies

To provide the products of the Platform, Piano is using trackers, especially cookies on standard websites, or mobile IDs on native applications. Local storage, server-to-server request, clear gifs, pixel tags, web beacons or other similar technologies may also be used in some cases.

You can access some information about the trackers used on and across all products  under to the following link:  Piano Cookie Descriptions.

Users can control the use of trackers on their devices via the following means:

  • Use the opt-out mechanism on the dedicated online platform provided by the Publisher

  • Use the device appropriate configuration (browser or cellphone Operating System – Apple or Android mainly – settings)

Some advertising third-party partners may also use tracker, cookies, or similar technologies, to provide users. Users can opt out of interest-based advertising by clicking here.


Publishers can use the Piano Platform and the associated Services for the following main purposes:

  • Understand the audience

  • Optimize an/or personalise content

  • Engage the audience

  • Monetize the online platform

Based on the main purposes observed in the digital marketing world, the following table synthesized for each purpose, what Piano product is by default aimed for, and what is the by default legal basis for seen on our side for this purpose:

Purpose Product Legal Basis
Audience and Analytics Analytics, Audience Consent under GPDR or Exemption under ePrivacy
Content Personalization or Performance Subscriptions, Amplifier Consent under GDPR
Advertising (personalized or not) Audience Consent under GDPR
“One to one relationship” (account management, subscription, newsletter, …) Subscriptions, Amplifier Consent or Contract under GDPR

IMPORTANT: as a data controller, the Publisher can decide to use one or several products of the Platform for other purposes that the one foreseen originally, as well as to choose whatever legal basis he interprets to be the best in his specific case. 

Each Publisher signs a data processing agreement (DPA) with Piano to formalize these purposes and associated responsibilities. 


Data Subject’s Rights

The GDPR, like many privacy laws around the word, empower data subject rights on its personal data. Piano’s Platform enables Publishers to apply these rights to what is applicable regarding the data collected for their purposes (see Purpose of Processing and Legal Basis above).

The following table lists all the main applicable rights regarding online data that and end-user can request to Publishers, and where Piano provide standard solutions to these Publishers.

Data Subject Right Product Mean
Information All Via Publishers’ information (CMP, Privacy Policy, …)
Access All Via a request to the Publisher’s DPO
Rectification Subscriptions, Audience, Amplifier Via a request to the Publisher’s DPO
Erasure All Via a request to the Publisher’s DPO
Portability All Via a request to the Publisher’s DPO
Objection All Via opt-out mechanism provided by the Publisher

Piano’s data protection team is able to support the process of applying a data subject right.

Please contact privacy@piano.io, or any other communication channel listed in Data Protection Officer and Point of Contact below, for any further information.


Data Breaches

Piano maintains an incident response plan which governs the communication and process in the case of data breach. Contractually this is covered between Piano and all Publishers, in the Master Service Agreement (MSA). 


Security Measures

Piano security measures by pseudonymization and encryption of personal data; maintaining a detailed Disaster Recovery Plan (DRP) to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services which in turn allows Piano to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident. Piano maintains a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

For more information visit our Security documentation.


International Data Transfers

Depending on the products of the Platform used by the Publisher, as well as the potential additional services requested by him, data may be transferred outside of original country where the data has been collected.

Please see the hosting option by product within the Piano Sub-Processors’ table below, as well as the ‘Do we share personal data?’ part above.

To meet European requirements under the GDPR in terms of data transfers, Piano uses the following mechanisms:

  • EU Standard Contractual Clauses (SCC) through the data processing agreement (DPA) signed with the Publisher as well as with sub-processors;

  • Binding Corporate Rules (BCRs) approved by the European Data Protection Board (EDPB) for both processors’ and controllers’ transfers;

  • Additional technical measures as encryption, pseudonymization or anonymization of the data.

To meet the guidelines of the PIPEDA in the applicable Canadian provincial legislation, Piano recognizes and has controls in place to ensure that the privacy of personal information about an “identifiable individual” used in the course of “commercial activity” is protected and managed in the appropriate way.

Piano Sub-Processors

To support delivery of our Platform, we may engage and use data processors with access to certain Publisher’s Customer Data (“Sub-processor”).

The following table provides information about the identity, location, and role of core Sub-processors necessary to provide products of our platform:

Product Core Providers Other Providers used for potential complementary services
Name Activity Country
(Hosting options)
Name Activity Country
(Hosting options)
Piano Analytics AWS Cloud computing USA (EU, USA, Japan)
Snowflake Data platform USA (EU, USA)
Piano Subscriptions (Composer, ID, Billing) & Piano Amplifier (ESP, Socialflow) AWS Cloud computing USA (EU, USA, Japan, Australia) Alchemer Strategic service survey USA
Braintree Payment USA Cloudflare Captcha USA
Snowflake Data platform USA (EU, USA) MailChimp Email notification USA
Stripe* Payment & Billing USA Mode Analytics Visualisation USA
Piano Audience Gcore Data center USA (USA, Japan)
Hetzner Data center Germany
All Beamer Product news, notification & satisfaction USA (EU)
Salesforce CRM USA
Userflow Customer on-boarding USA (EU)
Appcues Customer on-boarding USA (EU)
Zendesk Support tickets USA (EU)

Note: AWS is certified for following the CISPE code of conduct endorsed by the EDPB.

* We use Stripe for payments, analytics, and other business services. Stripe may collect personal data including via cookies and similar technologies.  The personal data Stripe collects may include transactional data and identifying information about devices that connect to its services. Stripe uses this information to operate and improve the services it provides to us, including fraud detection, loss prevention, authentication, and analytics related to the performance of its services.  You can learn more about Stripe and read its privacy policy atstripe.com/privacy

For training purposes, the following providers can be used:

  • Classmarker (certification tests management)

  • Digiforma (live training management)

  • Workramp (eLearning and certification management)

Prior engaging any third-party Sub-processor, Piano performs diligence to evaluate their privacy, security, and confidentiality practices, and executes an agreement implementing its applicable obligations.

 

Piano Affiliates

Piano has offices located around the globe who, depending on the Service required by the Publisher, may process its data:

Entity Name Country (GDPR transfer mechanism)
Applied Technologies Internet GmbH Germany (EU - BCR)
Applied Technologies Internet SAS France (EU - BCR)
Newzmate Sp. z o.o. Poland (EU - BCR)
Piano Japan Co. Ltd Japan (Adequacy decision - BCR)
Piano Software B.V. Netherlands (EU - BCR)
Piano Software GmbH Germany (EU - BCR)
Piano Software Inc. United States of America (BCR)
Piano Software LTD United Kingdom (Adequacy decision - BCR)
Piano Software Norway NUF Norway (EEA - BCR)
Piano Software s.r.o Slovakia (EU - BCR)
PSIEZE Data Analytics S.R.L. Argentina (Adequacy decision - BCR)
SocialFlow Inc. United States of America (BCR)

Piano affiliates don’t have automatic access to all Platform data. The access of Platform data is managed and strictly limited to what is necessary.

BCR details are available here.


Data Protection Officer and Point of Contact

For all questions related to our privacy policy and how Piano collects, processes and stores personal data, please feel free to contact the appointed Data Protection Officer (“DPO”):

  • Email: privacy@piano.io

    Mail: Attn: Piano Software Group DPO

    Štefánikova 14

    Bratislava, 811 05

    Slovakia (EU)

For specific requests by legal authorities, courts, government agencies, or parties involved in litigation for customer data, disclosures should include the following information:

  • The requesting party;

  • The relevant criminal or civil matters;

  • A description of the specific Publisher’s data being requested, including the relevant Publisher’s name and relevant authorized user’s name (if applicable).

Requests should be prepared and served in accordance with applicable law. All requests should be narrow and focused on the specific customer data sought. All requests will be construed narrowly by Piano, so please do not submit unnecessarily broad requests.

Piano will notify the Publisher before disclosing any of its data so that the Publisher may seek protection from such disclosure unless Piano is prohibited from doing so or there is a clear indication of illegal conduct or risk of harm to people or property associated with the use of such Publisher’s data.


Privacy Policy Change Log

This Platform Privacy Policy includes information previously incorporated in documents “Piano and GDPR” and “Privacy Policy” of Piano Group.

If you need information about previous wording of both documents, please visit following references:


Archive of Privacy Policies

Privacy Policy – Effective from Oct 27, 2023 - Sept 02, 2025

Privacy Policy - Effective from Sept 03, 2025 - August 31, 2026