GDPR Compliance

Last updated: March 31, 2026

Fynstream is committed to protecting the privacy and rights of individuals in accordance with the General Data Protection Regulation (GDPR). This page explains how we comply with GDPR requirements and outlines your rights as a data subject.

1. Our Role

Fynstream acts as both a data controller and a data processordepending on the context:

2. Lawful Basis for Processing

We process personal data under the following lawful bases:

PurposeLawful Basis
Account registration and managementContract performance
Billing and payment processingContract performance
Service delivery (streaming, VOD, player)Contract performance
Security monitoring and fraud preventionLegitimate interest
Platform analytics and improvementLegitimate interest
Service-related notificationsContract performance
Marketing communicationsConsent
Compliance with legal obligationsLegal obligation

3. Your Rights Under GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:

3.1 Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you. We will provide this within 30 days of your request.

3.2 Right to Rectification (Article 16)

You can request correction of inaccurate or incomplete personal data. You can update most information directly through your dashboard settings.

3.3 Right to Erasure (Article 17)

You can request deletion of your personal data. Upon receiving a valid request, we will delete your data within 30 days, except where we are legally required to retain it (e.g., financial records for tax compliance).

3.4 Right to Restrict Processing (Article 18)

You can request that we limit how we process your data while a dispute or request is being resolved.

3.5 Right to Data Portability (Article 20)

You can request your data in a structured, commonly used, machine-readable format (JSON or CSV) so you can transfer it to another service.

3.6 Right to Object (Article 21)

You can object to processing based on legitimate interest. We will cease processing unless we can demonstrate compelling legitimate grounds.

3.7 Right to Withdraw Consent (Article 7)

Where processing is based on consent, you may withdraw it at any time. This does not affect the lawfulness of processing before withdrawal.

4. Data We Collect

We collect the following categories of personal data:

5. Data Processing Agreements

As a data processor for our customers, we offer a Data Processing Agreement (DPA) that covers:

Enterprise customers can request a signed DPA by contacting info@fynstream.com.

6. Sub-Processors

We use the following sub-processors to deliver our services:

Sub-ProcessorPurposeLocation
Backblaze B2Cloud storage for media filesUnited States / EU
CloudflareCDN, DDoS protection, securityGlobal (edge nodes)
StripePayment processingUnited States / EU
PayPalPayment processingUnited States / EU
GoogleOAuth authenticationUnited States / EU

We will notify customers at least 30 days before adding new sub-processors. Enterprise customers with a DPA can object to new sub-processors.

7. International Data Transfers

When personal data is transferred outside the EEA, we ensure adequate protection through:

8. Data Security

We implement appropriate technical and organizational measures including:

9. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

10. Data Retention

11. Data Protection Officer

For any GDPR-related inquiries or to exercise your rights, contact our Data Protection team:

12. Supervisory Authority

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we are not processing your personal data in accordance with GDPR. We encourage you to contact us first so we can address your concerns directly.

13. Related Policies