Key Information: Your audio/video files are processed 100% locally on your computer. We never upload their content to the cloud or our servers.
§1. Data Controller
- The Controller of your personal data is: KOMBA Maciej Włodarczak, Tax ID (NIP): PL777-288-21-91, having its registered office in: 62-080 Tarnowo Podgórne.
- For matters related to data protection, you can contact us at: contact@srting.com.
§2. How and why do we process data?
We collect only the data necessary to provide the Service:
- Registration and login: Email address and password (encrypted). Legal basis: Contract performance (Art. 6(1)(b) GDPR).
- Billing: Transaction history, balance status, invoice data (if provided). Legal basis: Legal obligation (Art. 6(1)(c) GDPR).
- Communication: Email address for sending technical notifications and responding to reports. Legal basis: Legitimate interest (Art. 6(1)(f) GDPR).
- Device Identifier (UUID): To prevent promotional abuse (creating multiple accounts), we process an irreversible cryptographic hash of the computer's hardware identifier. We do not store the original UUID – only its hash. The hash is retained for the duration of Account activity plus 12 months after deletion. Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) – protection against abuse.
- Payments (Paddle): Our order process is conducted by our online reseller Paddle.com. Paddle.com is the Merchant of Record for all our orders. Paddle provides all customer service inquiries and handles returns. Personal and financial data necessary for the transaction are transferred to Paddle.com Market Ltd. Paddle's privacy policy is available here: https://paddle.com/privacy. Legal basis: Contract performance (Art. 6(1)(b) GDPR).
§3. Audio and Local Processing (Local AI)
- SRTing operates in a Local AI model. This means that the transcription process (speech-to-text) takes place entirely on your device.
- We do not upload your audio files or generated subtitles to our servers.
- Our servers receive only technical metadata necessary for billing the service (e.g., "user X processed 60 seconds of audio"), but have no access to the audio content.
- This ensures that your projects, even those covered by strict confidentiality (NDA), are safe.
§5. Your Rights (GDPR)
As a User, you have the right to:
- Access data: You can request a copy of your data.
- Rectify data: If it is incorrect or outdated.
- Delete data ("Right to be forgotten"): You can request account and data deletion if there are no other grounds for processing (e.g., tax requirements).
- Restrict processing: In specific cases.
- Data portability: Receive your data in a structured format.
To exercise these rights, write to us at: contact@srting.com.
§6. Security
- We use SSL/TLS encryption for all communication with our servers.
- Passwords are stored in hashed form (we cannot view them).
- We use proven cloud infrastructure compliant with security standards.
- To ensure service security and stability, we use Google Firebase infrastructure. Data is stored on servers located within the European Union (region europe-west), ensuring GDPR compliance.
§7. Contact
If you have questions regarding privacy, we are at your disposal:
Email: contact@srting.com