Privacy Policy
Last updated: February 27, 2026
1. Introduction and Data Controller
VideoConduit OÜ (“we”, “us”, “VideoConduit”) operates the VideoConduit API and website at videoconduit.com. This Privacy Policy explains what personal data we collect, why we collect it, how we protect it, and what rights you have.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act (isikuandmete kaitse seadus).
Data Controller
VideoConduit OÜ
Registry code: [REGISTRY_CODE]
[BUSINESS_ADDRESS], Tallinn, Estonia
Email: info@videoconduit.com
2. Personal Data We Collect
Data you provide directly
- Account information: email address (required), first name, last name, and company name (optional). Your email serves as your login identifier.
- Payment information: processed entirely by Stripe. We never receive, store, or process your payment card numbers, CVVs, or full card details. We store only your Stripe customer ID, subscription status, and billing interval.
- Support requests: any information you include when contacting us via email or our contact form.
Data collected automatically
- API usage: endpoints called, source URLs submitted, job parameters, job type, job status, timestamps, and credits consumed.
- Technical data: IP address and user agent string, logged in security audit events (retained for 90 days).
- Authentication events: login timestamps and authentication method (email or OAuth provider name). When you sign in via an OAuth provider (GitHub or Google), we store only the provider user ID — we do not store your OAuth tokens.
- Webhook configuration: endpoint URLs you configure for delivery notifications, and associated delivery logs.
Data we do NOT collect
- We do not use analytics cookies or tracking pixels.
- We do not use Google Analytics or any similar service.
- We do not track you across websites.
- We do not collect browsing behaviour, mouse movements, or keystrokes.
- We do not process or inspect the content of files you download or transcribe — we treat your processed content as opaque data.
3. Legal Bases for Processing (GDPR Article 6)
Under the GDPR, we must have a lawful basis for each type of personal data processing. The table below sets out the legal basis we rely on for each purpose.
| Purpose | Legal basis | Data involved |
|---|---|---|
| Providing the Service | Performance of contract (Art. 6(1)(b)) | Account data, API usage, job records |
| Processing payments | Performance of contract (Art. 6(1)(b)) | Billing data (via Stripe) |
| Sending transactional emails | Performance of contract (Art. 6(1)(b)) | Email address |
| Security and abuse prevention | Legitimate interest (Art. 6(1)(f)) | IP addresses, audit logs |
| Sending marketing emails | Consent (Art. 6(1)(a)) | Email address |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c)) | As required by law |
5. How We Use Your Data
We use your personal data for the following purposes:
- To create and manage your account.
- To authenticate your API requests.
- To process and fulfil your API jobs (downloads, transcriptions, translations, format conversions, and other supported operations).
- To track credit usage and manage billing.
- To send transactional emails (welcome, password reset, billing notifications, job notifications).
- To send marketing emails (only with your explicit consent, which you can withdraw at any time).
- To detect, prevent, and respond to security incidents and abuse.
- To maintain audit logs for security purposes (90-day retention).
- To comply with legal obligations.
- To improve the Service (we may analyse aggregated, anonymised usage patterns — never individual behaviour).
We do not use your data for advertising. We do not sell your personal data to anyone. We do not share your data with data brokers. We do not use your processed content for training AI models or any purpose beyond delivering it back to you.
6. Data Sharing and Third-Party Processors
We share your data only with the following processors, and only as necessary to provide the Service:
| Processor | Purpose | Data shared | Location | Safeguards |
|---|---|---|---|---|
| Stripe, Inc. | Payment processing | Email, billing data | US | EU–US Data Privacy Framework |
| Postmark (ActiveCampaign) | Transactional email | Email address, email content | US | EU–US Data Privacy Framework |
| OVH / Hetzner | Server infrastructure | All data (encrypted at rest) | EU (France/Germany) | EU-based, GDPR compliant |
We do not sell your personal data to anyone. We do not share your data with advertisers or data brokers.
We may disclose data if required by law, court order, or government request. We will notify you unless legally prohibited from doing so.
7. International Data Transfers
Our servers are located in the European Union. We do not transfer personal data outside the EU for our own processing purposes.
Some of our processors (Stripe, Postmark) are based in the United States. These transfers are protected by the EU–US Data Privacy Framework and/or Standard Contractual Clauses as approved by the European Commission.
We do not transfer data to countries without adequate data protection unless appropriate safeguards are in place.
8. Data Retention
We retain different categories of data for different periods, based on necessity and legal requirements:
| Data | Retention period | Reason |
|---|---|---|
| Account data (email, name) | Until account deletion | Service provision |
| Processed files (downloads, transcriptions) | 24 hours | Temporary storage only |
| Job records | Duration of account | Billing history, usage tracking |
| Usage logs | Duration of account | Billing, analytics |
| Audit logs | 90 days | Security |
| Stripe billing data | Per Stripe’s retention policy | Legal/tax obligations |
| Email records | Duration of account | Communication preferences |
When you delete your account, we delete your personal data within 30 days. Some data may be retained longer if required by law (e.g., invoicing records for tax purposes — up to 7 years under Estonian law, Accounting Act § 12).
Processed files are automatically and permanently deleted after 24 hours regardless of account status.
9. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15): request a copy of all personal data we hold about you. Use the “Export My Data” feature in your dashboard or email info@videoconduit.com.
- Right to rectification (Art. 16): update inaccurate data via your dashboard settings or by contacting us.
- Right to erasure (Art. 17): delete your account and all associated data via the dashboard or by contacting us. We will process deletion within 30 days.
- Right to restriction (Art. 18): request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format (JSON). Use the “Export My Data” feature.
- Right to object (Art. 21): object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): where processing is based on consent (e.g., marketing emails), you may withdraw consent at any time without affecting the lawfulness of prior processing. Use the unsubscribe link in any email or update your preferences in the dashboard.
- Right to lodge a complaint: you have the right to file a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee, or with the supervisory authority in your EU member state of residence.
To exercise any of these rights, contact us at info@videoconduit.com. We will respond within 30 days as required by the GDPR. There is no fee for exercising your rights.
10. Data Security
We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:
- All data in transit is encrypted via TLS 1.2 or higher.
- API keys are stored as irreversible SHA-256 hashes.
- Webhook secrets are encrypted.
- Database connections use TLS.
- File download URLs use signed tokens that expire after 24 hours.
- We implement rate limiting, brute-force protection, and IP-based security measures.
- Access to production systems is restricted to authorised personnel.
- We maintain security audit logs.
In the event of a personal data breach, we will notify the supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Articles 33 and 34.
11. Children’s Privacy
The Service is not directed to children under 18. We do not knowingly collect personal data from children under 18. If we learn that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal data, contact us at info@videoconduit.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before they take effect.
The “Last updated” date at the top indicates the most recent revision. Continued use of the Service after changes take effect constitutes acceptance.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
VideoConduit OÜ
Data Controller
Registry code: [REGISTRY_CODE]
[BUSINESS_ADDRESS], Tallinn, Estonia
Privacy enquiries: info@videoconduit.com
General support: info@videoconduit.com
Supervisory authority: Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), aki.ee