Privacy Policy
This is a translation provided for convenience. In case of divergence, the Portuguese version prevails.
This policy explains which personal data we process, why, for how long and what your rights are. The service is offered internationally: we apply the same protection standard to every user and honour the rights granted by the data protection law of your country of residence — among them the GDPR (European Union), the UK GDPR and the LGPD (Brazil). It applies to the website, the panels and the platform. See also the Terms of Service.
Last updated: 31 July 2026 · preliminary version, subject to legal review
1. What we collect
- Account: name, email and access credentials (passkey or password).
- Billing: payment data is collected and stored by Stripe, our processor; we do not store card numbers.
- Operation: technical broadcast telemetry (bitrate, connection health, session events) and access logs, to run and protect the service.
- Destination credentials: stream keys and tokens you connect (Twitch, YouTube and so on), stored encrypted — see section 4.
2. Your video
The live broadcast is not recorded by default and video content is not inspected: the media plane only transports and processes the signal. BRB clips are a temporary buffer configured by your organisation and are removed with the account. Abuse response is based on reports and metadata, never on video analysis.
3. What we use it for
- Providing the contracted service (ingest, Cloud OBS, re-transmission, panels).
- Billing, consumption metering and tax obligations.
- Security: authentication, action auditing and abuse prevention.
- Operational communications (incidents, plan changes, maintenance notices).
We do not sell personal data and do not use it for third-party advertising.
4. Destination credentials
Stream keys and tokens from connected platforms are encrypted with envelope encryption in a dedicated vault: the key protecting them is never written to the database and the values never appear in clear text in logs or events. You can revoke and rotate these credentials from the panel at any time.
5. Who we share with
- Stripe, to process payments.
- The destination platforms you connect (they receive the signal you asked us to re-transmit).
- Infrastructure providers that host the platform, under contract and only as needed to run the service.
- Authorities, when required by law.
6. How long we keep it
The periods below are applied automatically by a purge routine:
| Data | Retention | Legal basis |
|---|---|---|
| Account and profile | life of the account + 30 days | performance of contract |
| Billing and tax data | 5 to 10 years after the transaction, depending on applicable tax law | legal obligation |
| Audit trail | 2 years | legitimate interest (security) |
| Broadcast telemetry | 13 months | performance of contract / legitimate interest |
| Access logs | 30 days | legitimate interest |
| Exports you generate | 7 days | performance of contract |
| Backups | 35 days immutable, purged per cycle | legal obligation / continuity |
| BRB clips | while configured by the organisation; removed with the account | performance of contract |
| Live video | not recorded by default | — |
7. International transfer
The platform is distributed across multiple PoPs and our primary infrastructure runs in Europe and the United States, so your data may be processed outside the country where you live. Every international transfer uses the safeguards required by applicable law — EU Standard Contractual Clauses (SCCs) and equivalent clauses with our providers, plus the LGPD guarantees for data subjects in Brazil. Data residency in a specific region is on the roadmap for Enterprise plans.
8. Your rights
Wherever you live, you may confirm processing, access, correct, export (portability) and delete your personal data, object to processing based on legitimate interests and withdraw consent at any time — withdrawal does not affect processing carried out before it. Export and deletion are self-service in the panel: the export is ready within 72 hours and deletion removes data within the periods in the table above. You may also lodge a complaint with your data protection authority (your national authority in the EU, the ICO in the UK, the ANPD in Brazil). For any request or question, contact our data protection officer: privacy@xurvo.cloud.
9. Security incidents
Incidents posing a risk to personal data are reported to the competent data protection authority and to affected data subjects within the legal deadlines of each jurisdiction — 72 hours to the authority under the GDPR, a reasonable period under the LGPD — describing what happened and the measures taken.
10. Cookies
We use no advertising cookies and we do not sell data to advertisers. We use what is essential to operate — an authenticated session in the panels and local preferences such as theme — plus Google Analytics 4 on the marketing site, which sets its own cookies (_ga) to measure audience in aggregate: pages visited, traffic source and device type. Analytics does not run inside the authenticated panels.
11. Changes and contact
Material changes to this policy will be announced by email or in the panel. Data protection officer (DPO): privacy@xurvo.cloud.
