1. Who we are
The controller for the personal data described here is Royalcode Robert Sztygowski, ul. Józefa Wybickiego 2/9, 05-820 Piastów, Poland, VAT PL 8222319203. For any privacy or data-protection matter, contact us at hello@mdreel.com. We are a small business and are not required to appoint a Data Protection Officer; the address above reaches the person responsible for data protection.
2. Controller vs. processor
We act in two different roles, and this Policy is about the first:
- As controller — for your account, billing and analytics data, where we decide the purposes and means of processing. This Policy governs that data.
- As processor — for the recordings and outputs you upload and generate (“Customer Content”), which we process only on your instructions. There, your organisation is the controller and processing is governed by our Data Processing Agreement, not this Policy (see section 4).
3. What we process and why
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|
| Account data — email, password (hashed), your organisation, volume answers you give | Create and operate your account; provide the Service | 6(1)(b) — performance of our contract with you |
| Billing data — plan, VAT/NIP, payment and invoice records | Take payment, issue invoices, meet tax and accounting duties | 6(1)(b) contract; 6(1)(c) legal obligation |
| Usage & product events — actions in the app, job metadata | Operate, secure and understand the Service | 6(1)(f) — our legitimate interest in running and improving the Service |
| Support & communications — messages you send us | Respond to requests, handle complaints | 6(1)(b) contract; 6(1)(f) legitimate interest |
Providing account and billing data is necessary to enter into and perform the contract; without it we cannot provide the Service.
4. Recordings you upload
The video and audio you upload may contain personal data of people who appear or speak in it, and of people mentioned or shown on screen. For that content we act as your processor: we process it only to deliver the Service to you, on your instructions, under the DPA. Your organisation, as controller, is responsible for having a lawful basis and the necessary notices or consents for that content.
Where individuals in a recording are not our own customers, we generally cannot identify or contact them, so providing information to each of them directly would involve disproportionate effort. In line with Article 14(5)(b) GDPR, we make this Policy publicly available as the means of informing them, and we support the controller in honouring their rights.
5. Analytics and cookies
We use Umami, a privacy-friendly analytics tool that we self-host on our own EU infrastructure. It is cookieless and does not track you across sites or build advertising profiles; it produces aggregate usage statistics only. Because it sets no cookies and performs no cross-site tracking, no cookie-consent banner is required.
We do not use Google Analytics or any other US-based analytics, tracking pixels, session-replay or heat-mapping tools. Nothing on our site sends your browsing data to a third party outside the EU.
6. Who receives your data
We share personal data only with the subprocessors needed to run the Service — our cloud infrastructure and AI provider, our payment provider, and our email provider — each bound by a data-processing agreement and each processing in the EU. The current list, with each provider's role and location, is on our Subprocessors page. We do not sell personal data.
7. EU processing — no international transfers
All personal data is processed exclusively within the European Economic Area (EEA). We do not transfer personal data to third countries outside the EEA as part of the Service, so no Chapter V transfer mechanism is required. If this ever changes, we will update this Policy and put an appropriate safeguard in place before any such transfer.
Honest note: our infrastructure runs on Google Cloud in EU regions. This is EU data residency, not full EU sovereignty — Google is a US-headquartered company. We say so plainly and publish our sovereignty roadmap rather than overclaim.
8. How long we keep data
- Uploaded source recordings are deleted after processing by default. You may choose a short configurable retention window per job; a storage lifecycle rule acts as a backstop.
- Generated outputs are retained while your account is active so you can access them, and are deleted when you delete them or close your account.
- Account data is kept for the life of your account.
- Billing and invoice records are kept as long as tax and accounting law requires.
9. Your rights
Under the GDPR you have the right to:
- access your data (Art. 15) and receive a copy;
- rectify inaccurate data (Art. 16);
- erase data (Art. 17) — the app also offers direct deletion of jobs and outputs;
- restrict or object to processing (Arts. 18, 21), including processing based on our legitimate interests;
- data portability (Art. 20) — our outputs are portable Markdown by design;
- withdraw any consent you have given, without affecting prior processing.
To exercise a right, email hello@mdreel.com. We do not carry out automated decision-making that produces legal or similarly significant effects on you.
You also have the right to lodge a complaint with the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl.
10. Security
We apply appropriate technical and organisational measures (Art. 32 GDPR): EU-region processing, encryption in transit and at rest, least-privilege access, secret management, and audit logging of data access and deletion. Our security measures are summarised in the DPA.
11. Changes to this Policy
We may update this Policy; the effective date and version at the top reflect the current text. For material changes affecting you as a customer we will give reasonable notice.
Published by Royalcode Robert Sztygowski, ul. Józefa Wybickiego 2/9, 05-820 Piastów, Poland · VAT PL 8222319203 · hello@mdreel.com. Version 1.0, effective 2026-07-18.