We use cookies and similar technologies for proper service operation, analytics and – if you consent – personalization.

At least essential cookies are required for the app to function. You may decline – that will terminate further use of the service.

Not accepting cookies may result in some features of the site being unavailable!

We use cookies for essential functions, analytics and – with consent – personalization. Privacy Policy.

Privacy Policy

MediaDock logo
2025-12-03
§1. PERSONAL DATA CONTROLLER

The Controller of your personal data is Recin LTD, 7 Bell Yard, London, WC2A 2JR, UK. For matters related to data protection, you may contact us at the e-mail address: r.szykowski@ilcoud.com or by writing to the address of our registered office indicated above.

§2. TO WHOM DOES THIS POLICY APPLY?

The Data Protection Officer has been appointed: Marek Kilichowski (contact: adwokat@kilichowski.eu).

§3. PURPOSES AND GROUNDS FOR PROCESSING

We process your data for the following purposes:

- Service Provision and Account Management: for the purpose of concluding and performing the Agreement, enabling login, using System functionalities, and publishing Profiles (Art. 6(1)(b) of the GDPR)

- Billing: issuing invoices and maintaining accounting records (Art. 6(1)(c) of the GDPR – legal obligation)

- Communication and Support: handling requests, complaints, and technical notifications (Art. 6(1)(f) of the GDPR – legitimate interest)

Security and Claim Assertion: ensuring the security of the System, defense against claims, and fulfilling obligations arising from the Digital Services Act (DSA) (Art. 6(1)(f) of the GDPR).

The provision of data marked as required in the registration form (in particular, the Client's identification data and the contact details of the person setting up the Account) is necessary for the conclusion and performance of the Agreement regarding the Service. Failure to provide them will prevent the creation of an Account and the use of the Media Dock Service.

The provision of data required for billing (e.g., invoicing data) is necessary for us to fulfill our obligations arising from tax and accounting regulations; failure to provide them will prevent the proper documentation of services rendered.

Within the purposes described above, we do not make decisions about you solely by automated means, including profiling, which would produce legal effects concerning you or similarly significantly affect you.

§4. DATA RECIPIENTS

Your data may be transferred to trusted entities that support us in providing services (so-called processors):

1. IT Infrastructure Providers: we use the services of AWS (Amazon Web Services) for hosting and data storage.

2. Payment Operators: we use the Stripe service to process payments. You enter your payment card data directly with the operator – we only receive confirmation of the payment status.

3. Accounting and Legal Services: entities supporting us in running the company.

Due to the use of services from certain providers, such as the payment operator Stripe, personal data may be transferred to countries outside the European Economic Area (EEA), particularly to the United States of America. In such cases, we ensure that the data transfer takes place only based on the mechanisms provided for in Chapter V of the GDPR, in particular:

- adequacy decisions adopted by the European Commission or

- standard contractual clauses adopted by the European Commission, possibly supplemented by additional technical and organizational measures.

Information about the applied safeguards and the possibility of obtaining a copy can be received by contacting us at the e-mail address indicated in the “Contact” section.

§5. DATA RETENTION PERIOD

1. We store data related to the performance of the Agreement for its duration.

2. After the termination of the Agreement, data in your Instance will be stored for 30 days to enable their export, and then permanently deleted.

3. We store billing data (invoices) for 5 years, in accordance with tax regulations.

4. Technical data (logs) and data concerning Regulation violations (in accordance with the DSA) may be stored for the period necessary for evidentiary purposes.

§6. YOUR RIGHTS

In accordance with the GDPR, you have the right to:

- access your data and receive a copy thereof

- rectification (correction) of your data

- erasure of data

- restriction of data processing

- data portability

- object to processing

- lodge a complaint with the President of the Personal Data Protection Office.

§7. THE SYSTEM'S ROLE AS A "PROCESSOR" (DATA ENTERED INTO THE INSTANCE)

A distinction must be made between the data for which we are the Controller (your registration and billing data) and the data that you enter into the System as part of your activity (e.g., data of your contractors, video content). With respect to the data contained in your Instance, you are the Controller, and Media Dock acts as a Processor. The detailed rules for entrusting the processing of data are regulated by the Regulations and the Data Processing Agreement (DPA).

§8. COOKIES

The Media Dock System uses cookies necessary for the proper functioning of the Application (e.g., maintaining a login session) and for analytical purposes. Managing cookies is possible through your web browser settings.

Within our website and the User Panel, we use cookies and similar technologies:

1. essential cookies – enabling the correct operation of the website and the System, User authentication, session maintenance, and the performance of basic Service functions

2. analytical cookies – used to collect information on how our website and System are used (e.g., number of visits, traffic sources, error statistics), which help us improve the Service;

Essential cookies are used based on our legitimate interest (Art. 6(1)(f) of the GDPR), which consists of ensuring the proper functioning of the website and the Service. We use analytical cookies only based on your consent (Art. 6(1)(a) of the GDPR), which you can withdraw at any time using your browser settings or the consent management tool available on the website.

§9. POLICY CHANGES

We reserve the right to change this Privacy Policy, about which we will inform Users in the System or by e-mail.

DATA PROCESSING AGREEMENT (DPA)

(Appendix to the Media Dock Privacy Policy and Regulations).

Effective Date: 3.12.2025.

This Data Processing Agreement (hereinafter: "Agreement" or "DPA") regulates the principles under which RecIn P.S.A. (Service Provider) processes personal data on behalf of the Client in connection with the use of the Media Dock System.

§1. Definitions and Parties to the Agreement

1. Processor: Recin LTD, 7 Bell Yard, London, WC2A 2JR, UK (Service Provider).

2. Data Controller: The Client (Broadcaster or Freelancer) who established an Account in the Media Dock System and accepted the Regulations.

3. GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data.

4. Service: Services provided electronically within the Media Dock System, described in the Regulations.

§2. Subject Matter and Duration of Processing

1. The Controller entrusts the Processor with the processing of personal data under Article 28 of the GDPR, for the purpose and to the extent necessary for the performance of the Service (execution of the Regulations).

2. Data processing takes place in electronic form (in IT systems).

3. The Agreement is concluded for the duration of the Client's use of the Service and expires upon the deletion of data from the System after the termination of cooperation (including the retention period described in § 8).

§3. Scope and Nature of Data

1. Categories of data subjects: Employees and co-workers of the Controller (System Users); Contractors of the Controller whose data are entered into the System (e.g., as part of project management or in video materials); Individuals visible in audio-video materials uploaded and streamed through the System.

2. Types of personal data: Identification data (first name, last name, login); Contact data (e-mail address, phone number); Image and voice (contained in video/audio materials hosted in the System); Technical data and system logs associated with natural persons.

§4. Processor's Obligations

1. Processing data solely on documented instructions from the Controller. Acceptance of the Regulations and actions taken by the Controller in the System (e.g., uploading files, adding users) are considered such instructions.

2. Ensuring that persons authorized to process the data (personnel, co-workers) have committed themselves to confidentiality.

3. Taking all measures required pursuant to Art. 32 of the GDPR (security of processing), including the use of encryption and backup systems.

4. Assisting the Controller – to the extent technically possible – in fulfilling the obligation to respond to requests from data subjects (e.g., the right to be forgotten).

5. Supporting the Controller in notifying the supervisory authority of data breaches.

6. The Processor undertakes to immediately, but no later than within 48 hours of identifying a personal data breach entrusted under the Agreement, inform the Controller of any such breach. The notification should, to the extent available, include at least: a) a description of the nature of the breach, including the category and approximate number of data subjects affected, and the category and approximate number of personal data records concerned; b) a description of the likely consequences of the breach; c) a description of the measures taken or proposed by the Processor to address the breach, including measures to mitigate its possible adverse effects; d) contact information for the person or team on the Processor's side that the Controller may contact to obtain further information. The Processor shall provide the Controller with additional information regarding the breach as soon as it becomes available.

§5. Sub-entrustment of Processing (Sub-processors)

1. The Controller gives general consent to the Processor's use of further processors (sub-processors).

2. The key sub-processors whose services are used by the System are: Amazon Web Services (AWS) – for cloud infrastructure, hosting, and data storage. Server location: European Economic Area (EEA).

3. The Processor ensures that sub-processors are subject to the same data protection obligations as those specified in this Agreement.

4. Information about changes to key sub-processors will be made available on the Service Website or via e-mail notification, giving the Controller the opportunity to object.

§6. Controller's Rights and Audit

1. The Controller has the right to monitor whether the Processor processes data in accordance with the Agreement and the GDPR.

2. Due to the cloud nature of the Service, monitoring can be carried out by: Reviewing security documentation and certificates made available by the Processor; Sending inquiries regarding security processes.

3. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations set out in Art. 28 of the GDPR.

§7. Liability

1. The Processor is liable for damage caused by processing only if it has failed to comply with obligations that the GDPR places directly on processors, or if it has acted outside or contrary to the lawful instructions of the Controller.

2. The financial liability of the Processor is limited in accordance with the rules set out in the Service Regulations.

§8. Deletion of Data After Termination of Cooperation

1. After the termination of the Service Agreement (account closure), the Processor allows the Controller to export the data collected in the System for a period of 30 days.

2. After this period, the personal data entrusted for processing will be permanently deleted from the Processor's production systems and backup copies, unless Union or Member State law requires the storage of personal data.

This Privacy Policy is effective from November 17, 2025, and constitutes the final, binding version of the information required in accordance with Art. 13 and 14 of the GDPR. It contains a description of the categories of data, purposes of processing, legal grounds, retention periods, safeguards during transfers, and the rights of data subjects. We will inform users about material changes; updates will be published as a new version of the document. For matters concerning personal data or to exercise your rights, please contact: r.szykowski@ilcoud.com. Key GDPR articles: Art.6, Art.7, Art.13-14, Art.15-22, Art.32, Art.44-50.