Privacy Policy
This policy explains what personal data remoteroom.io processes, why we process it, where it is stored, and the rights you have under the EU General Data Protection Regulation (GDPR). We have tried to keep it readable — if anything is unclear, write to us at office@remoteroom.io.
Last updated:
Controller
The controller responsible for data processing on remoteroom.io is:
Remoteroom GmbH
Theodorstraße 41P
22761 Hamburg, Germany
Managing Directors: Max Hartmann, Finn Jakob Jaeger
Commercial Register: Amtsgericht Hamburg, HRB 199300
Privacy contact: office@remoteroom.io
General contact: info@remoteroom.io · Phone +49 40 33 44 22 72
Full company details are on our imprint.
Scope
This policy covers the remoteroom.io website and the remoteroom.io platform — Remote Rooms with media review, livestreams, video calls, notes, calendars, and related collaboration features. It applies to visitors of the public website, to customers with accounts, and to the people they invite into their rooms. Invited viewers and reviewers join through signed access links and never need an account.
Website, hosting, and server logs
The application, database, media storage, and streaming and call infrastructure are hosted by netcup GmbH in Nuremberg, Germany (EU). All traffic is TLS-encrypted with automatic certificates. The public website carries no third-party advertising or analytics trackers.
Like almost every web server, ours writes technical logs when you access the site — typically the requested page, the time of the request, your IP address, and basic browser information. We use these logs to operate the service, diagnose problems, and defend against abuse. The legal basis is our legitimate interest in running a secure and reliable service (Art. 6(1)(f) GDPR). Logs are kept only for short operational windows and are then deleted.
Accounts and authentication
When a customer creates an account, we process their email address, name, and password. Passwords are stored bcrypt-hashed — we never store them in plain text. Customers can enable optional two-factor authentication (2FA) using time-based one-time passwords (TOTP); 2FA secrets are encrypted at rest (AES-256-GCM). We process this data to provide the account and the service, based on Art. 6(1)(b) GDPR (performance of a contract).
Customers can optionally use "Sign in with Google" through Google Ireland Limited (Ireland). Google is involved only when a customer actively chooses this sign-in method.
Rooms, media, and collaboration content
Rooms contain the content that customers and their invitees create: media uploads, review comments and annotations, chat messages, notes, and calendars. We process this content to provide the collaboration features the customer signed up for (Art. 6(1)(b) GDPR).
Uploads live on our own EU servers; review media and transcoded assets are additionally stored in Cloudflare R2 object storage configured for EU data residency, and delivered through the Cloudflare and bunny.net (BunnyWay d.o.o., EU) content delivery networks. Stream and media URLs are HMAC-SHA256 signed with an expiry, so files cannot be hotlinked or shared beyond the access the room owner granted.
Viewers and reviewers access rooms through signed access links. They do not need an account, and we do not require them to register to watch, review, or comment.
Livestreams and video calls
Livestreams and video calls run on infrastructure that Remoteroom GmbH operates on its EU servers in Germany: LiveKit for video calls (including the TURN relay) and our own streaming engine for SRT livestream ingest and low-latency playback. No third-party conferencing provider receives your audio or video. Streams and calls are not recorded unless a host starts a recording. The legal basis is Art. 6(1)(b) GDPR (providing the service).
Payments and billing
Checkout, payment processing, invoices, subscription management, and the customer billing portal are handled by Stripe Payments Europe, Ltd. (Ireland). We process billing data to perform the contract (Art. 6(1)(b) GDPR) and keep payment and invoice records for as long as statutory commercial and tax retention duties require.
Transactional email
We send transactional email — onboarding, password reset, and account notifications — through Resend, Inc. (USA). Transfers to Resend are safeguarded by EU Standard Contractual Clauses. The legal basis is Art. 6(1)(b) GDPR, since these messages are part of providing the service.
Optional managed AI features
remoteroom.io offers optional managed AI features. Delivery interpretation and meeting summaries are the first Mistral-powered workflows. Roomy, room and sharing assistance, support and ticketing, transcription, subtitles, and Delivery automation are rolling out on the same managed AI boundary.
For the managed LLM path, only the selected text, transcript, audio, room metadata, or bounded project context needed for the requested feature is sent to Mistral AI (France) through the EU-hosted profile. One account-level switch disables every managed AI feature and stops new content from being sent to Mistral. Business and enterprise customers can instead bring their own LLM and S3-compatible storage.
During the subtitle-provider transition, selected media audio may still be processed by ElevenLabs, Inc. (USA), safeguarded by EU Standard Contractual Clauses, and selected subtitle text may be processed by DeepL SE (Cologne, Germany). These providers remain listed on the compliance page while in use.
These features run only when enabled and requested by an authorized user. The legal basis is Art. 6(1)(b) GDPR as part of the contracted service.
Embedded third-party players in rooms
Inside collaboration features such as the whiteboard and notes, room participants can paste links to external video platforms — YouTube, Vimeo, Dailymotion, or Twitch. When such an embed is shown, your browser loads the player directly from that platform, which may process your IP address and set its own cookies under its own privacy policy. We use privacy-enhanced embed modes where the platform offers them (YouTube’s no-cookie domain, Vimeo’s Do-Not-Track mode). Embeds only appear where a room participant has actively added one; the legal basis is Art. 6(1)(f) GDPR — displaying content that room members chose to share.
Service providers
We use a small, fixed set of service providers: netcup for EU hosting, Cloudflare for media object storage and delivery, bunny.net for CDN delivery of media files, Stripe for billing, Google for optional sign-in, Resend for transactional email, Mistral for optional managed AI, and DeepL and ElevenLabs during the subtitle-provider transition. Each provider processes data only for the purpose described above. The full processor list, with locations and safeguards, is on our compliance page.
International transfers
The application and primary data are hosted in the EU (Germany). Where a provider processes data outside the EU — Cloudflare, Resend, and ElevenLabs are US-headquartered companies, even where the underlying data is stored in the EU — transfers are protected by EU Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework.
Retention and deletion
We keep personal data only as long as it is needed:
- Account data is kept for the life of the account.
- Customer-uploaded media and room content are kept until the customer deletes them or the account closes; after a contract ends, content remains retrievable for at least 30 days before deletion.
- Payment and invoice records are kept for the statutory commercial and tax retention periods.
- Server logs are kept only for short operational windows.
We also run regular database backups as part of operating the service.
Your rights
Under the GDPR, you have the right to:
- access the personal data we hold about you,
- have inaccurate data rectified,
- have your data erased,
- restrict processing,
- receive your data in a portable format,
- object to processing based on legitimate interests, and
- withdraw any consent you have given, at any time — this does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, email office@remoteroom.io.
Right to lodge a complaint
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Hamburg Commissioner for Data Protection and Freedom of Information
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22
20459 Hamburg, Germany
No automated decision-making
We do not use your personal data for automated decision-making or profiling within the meaning of Art. 22 GDPR.
Changes to this policy
We update this policy when our service or our providers change. The date at the top of this page shows the current version. For an overview of our security practices and the full processor list, see our compliance page.