İçeriğe geç
Hukuki

Data Processing Addendum

Son güncelleme September 12, 2026

The terms under which StreamRove processes personal data on behalf of its customers, as their processor.

Bu, kolaylık olsun diye sunulmuş bir çeviridir. Bu belgenin bağlayıcı sürümü İngilizce olanıdır; iki metin arasında fark olması hâlinde İngilizce metin geçerlidir.

1. Roles and scope

This Addendum applies whenever StreamRove processes personal data on behalf of a customer in providing the Service, and forms part of the Terms of Service.

For that data the customer is the controller and StreamRove is the processor: the customer decides what is broadcast, who is invited, whether viewers are asked for an email address, and how long material is kept, within the windows their plan provides.

For the customer's own account, billing and support data, StreamRove is the controller. That processing is described in the Privacy Policy, not here.

2. What is processed, and why

Subject matter and purpose: providing the Service — carrying live video to the destinations the customer chooses, running the browser studio, storing recordings and clips, generating analytics, and supporting the account.

Duration: for as long as the customer's account is active, plus the retention windows set out in the Privacy Policy.

  • Categories of data subjects: the customer's team members, the guests they invite into a studio, and the viewers of their broadcasts.
  • Types of personal data: names and email addresses of team members and invited guests; audio and video of anyone appearing in a broadcast or recording; names and email addresses of viewers where the customer turns on an access gate; display names and messages pulled from chat on connected platforms; technical data such as IP address, user agent and timestamps.
  • Special categories: none are requested or required. A customer who broadcasts them does so on its own responsibility.

3. Instructions

StreamRove processes personal data only on the customer's documented instructions, including in relation to transfers. Using the Service's features — adding a destination, starting a recording, enabling an access gate — is an instruction.

If an instruction appears to infringe data protection law, we will say so rather than carry it out silently.

4. Confidentiality

Access to customer data is limited to the people who need it to operate the Service or to answer a support request, and they are bound to confidentiality. Administrative actions on an account are recorded in an audit log.

5. Security measures

We apply, and keep applying, at least the following:

  • Transport encryption for the site, the API and the ingest endpoints we publish.
  • Encryption at rest for the credentials the Service holds on a customer's behalf — stream keys and platform access tokens.
  • Databases and object storage reachable only from the application's own network, never published to the internet.
  • Authenticated, signed webhooks, rate limiting on abusable endpoints, and passwords stored only as hashes.
  • Separate, least-privilege credentials for machine access, with admin capabilities closed to API keys by default.
  • Regular backups of the database, and a restore procedure that is exercised rather than assumed.

6. Subprocessors

The customer gives general authorisation for StreamRove to engage the subprocessors listed in the Privacy Policy, under the section "Service providers we use", which is kept current. Each is bound by a contract imposing obligations equivalent to these.

We will give notice before a new subprocessor starts processing customer personal data. A customer who reasonably objects on data protection grounds may terminate the affected part of the Service.

The studio's media server and our website analytics run on our own servers, so neither involves a third party.

7. Assistance to the customer

Taking into account the nature of the processing, we assist the customer in responding to requests from data subjects, and in meeting its obligations on security, breach notification and impact assessments.

The Service itself provides much of this directly: a customer can export or delete their data from the account, and deleting an account removes the material it holds within the periods described in the Privacy Policy.

8. Personal data breaches

We notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with the information we have at the time, and we keep them updated as we learn more.

9. Deletion and return

On termination, the customer may export their material while the account is still open. After termination we delete it within the retention windows in the Privacy Policy, except where law requires us to keep something — billing records, for example.

10. International transfers

Our servers are in Germany. Some subprocessors operate globally, so personal data may be processed outside the EEA and the UK.

Where that happens, transfers are made under an appropriate safeguard — in practice the European Commission's standard contractual clauses as incorporated in that provider's data processing terms.

11. Audits

On written request, and no more than once a year unless a regulator requires otherwise, we provide the information reasonably necessary to demonstrate compliance with this Addendum.

12. Accepting this Addendum

This Addendum applies automatically to every customer who processes other people's personal data through the Service; no signature is required for it to take effect.

If your organisation needs a countersigned copy, or has its own form, write to [email protected] and tell us which.