Fluent Church Privacy Policy
Effective Date: September 21, 2026
Version: 2026-09-21
Tingdahl IT Management AB ("Provider", "we", "us", or "our"), based in Uddevalla, Sweden, operates fluent.church (the "Service"). This Privacy Policy explains how we collect, process, store, and protect personal data in connection with the Service in compliance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applicable Swedish data protection legislation.
For inquiries regarding this Privacy Policy or our data protection practices, please contact us at legal@tingdahl.it.
Data Controller
The data controller for personal data processed through fluent.church is:
Tingdahl IT Management AB
Uddevalla, Sweden
Company Registration: Sweden
Email: legal@tingdahl.it
Personal Data We Collect
Depending on how you interact with the Service, we process different categories of personal data:
1. Administrators and Broadcasters
When an Administrator signs up, logs in, or manages an account:
- Identity and Authentication Data: Full name, email address, profile picture (if provided by your identity provider), and unique identity provider account identifiers (such as Microsoft Entra ID Object/Subject ID or Google Account ID).
- Network and Session Data: IP address, browser type and version, operating system, and login session timestamps.
- Account and Billing Records: Organization name, purchase records, package allocations, and transaction receipts. (Note: Payment card details are handled directly by our payment processor, Stripe, and are never stored on our servers).
2. Connected Devices
For hardware or software encoders enrolled by an account:
- Device identifiers, assigned labels, associated channel slugs, authentication tokens, IP addresses, and broadcast start/stop event logs.
3. Audience Members and Listeners
Audience members access live captions without creating accounts or signing in:
- Ephemeral Technical Telemetry: IP address, user-agent string, connection timestamps, and language selection preferences stored locally in your browser.
4. Broadcast Audio Content
- Audio streams submitted by broadcasters for transcription. Audio is processed in real time in volatile memory for speech-to-text conversion and instant translation, and is not stored or retained after processing.
Lawful Bases for Processing (GDPR Article 6)
We process personal data only when an applicable legal basis exists under the GDPR:
| Purpose of Processing | Categories of Data | Lawful Basis (GDPR) |
|---|---|---|
| Authentication & Account Provisioning | Administrator identity, email, OIDC credentials | Contractual Necessity (Art. 6(1)(b)) — necessary to authenticate authorized personnel and provide console access. |
| Delivering Live Captions & Translations | Broadcast audio stream, selected languages | Contractual Necessity (Art. 6(1)(b)) — core functionality of the Service. |
| Billing & Accounting | Customer name, organization, payment receipts, invoice history | Legal Obligation (Art. 6(1)(c)) — statutory compliance with Swedish accounting legislation (Bokföringslagen). |
| Service Security & Abuse Prevention | IP addresses, request logs, device audit trails | Legitimate Interests (Art. 6(1)(f)) — protecting system integrity, preventing unauthorized broadcasting, and troubleshooting network faults. |
| Local Preferences (Themes, Language) | Client-side cookies and browser storage keys | Contractual Necessity / Legitimate Interest — remembering user interface state without tracking across third-party websites. |
Subprocessors and Third-Party Services
To provide an ultra-low latency, globally distributed captioning platform, we engage reputable third-party infrastructure and service providers ("Subprocessors"). Each subprocessor is bound by data processing agreements ensuring equivalent data protection standards:
| Subprocessor | Role & Purpose | Data Handled | Location / Data Transfer Basis |
|---|---|---|---|
| Scaleway | Cloud hosting, application compute, and database storage | User and account records, channel configurations, billing receipts | European Union (France / Netherlands) |
| Microsoft | OpenID Connect (OIDC) identity authentication provider | User email, name, Microsoft Account / Entra ID subject identifier | EU / Standard Contractual Clauses |
| OpenID Connect (OIDC) identity authentication provider | User email, name, Google Account subject identifier | EU / Standard Contractual Clauses | |
| Cloudflare | Global CDN, Web Application Firewall (WAF), edge routing, and WebSockets | Network requests, IP addresses, transient caption WebSocket data | Global Edge / EU-US Data Privacy Framework & SCCs |
| Deepgram | Real-time speech-to-text automated transcription | Ephemeral live audio stream during broadcast | US / Data Processing Agreement with zero-retention commitment |
| Stripe | Payment processing and checkout | Billing name, email, payment card data (tokenized), transaction receipts | Global / PCI-DSS Level 1 & EU-US Data Privacy Framework |
Data Retention
We retain personal data only for as long as strictly necessary to fulfill the purposes for which it was collected:
- Administrator & Account Records: Retained for the duration of the active account relationship, plus up to seven (7) years following account termination in compliance with Swedish accounting requirements (Bokföringslagen).
- Connected Device Audit Trails: Retained for up to one (1) year to maintain accountability and security logs.
- Listener & Network Connection Logs: Ephemeral access logs collected for diagnostics and DDoS mitigation are retained for up to seven (7) days before automated deletion.
- Broadcast Audio: Streamed in real-time; never written to persistent disk storage or retained after transcription.
Data Subject Rights
Under the GDPR, you have the right to:
- Access: Request confirmation of whether we process your personal data and obtain a copy of it.
- Rectification: Request correction of inaccurate or incomplete personal data.
- Erasure ("Right to be Forgotten"): Request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, subject to statutory retention obligations (e.g. tax records).
- Restriction of Processing: Request restriction of processing under certain circumstances specified in Article 18 GDPR.
- Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format.
- Objection: Object to processing based on legitimate interests.
To exercise any of these rights, please email legal@tingdahl.it. We will respond within one calendar month in accordance with statutory guidelines.
You also have the right to lodge a complaint with a supervisory authority. In Sweden, the lead supervisory authority is:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
Website: https://www.imy.se
Email: imy@imy.se
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect operational, legal, or regulatory changes. The updated version will be indicated by an updated "Effective Date" and version number at the top of this document. Continued use of the Service following notice of modifications constitutes acknowledgment of the revised Privacy Policy.