Privacy
Policy.
How VDO handles personal information when you use VDO Platform. Updated alongside the product. This is the source of truth.
1. Introduction
VDO (“we,” “our,” or “us”) is a beta tool operated by Sebastian K. Nielsen. We operate VDO Platform, a real-time collaboration platform for professional post-production, colour, streaming, and related workflows. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our websites, APIs, and client applications that link to this policy.
VDO Platform is a personal project operated by an individual based in Sydney, NSW, Australia. It is not operated by a registered company, and is currently a limited public testing beta (pre-release software). Access remains invite-only, capped, and directly onboarded. If you use the Service from outside Australia, your information may be processed in Australia and in other countries where we or our service providers operate (see International data transfers below).
Beta access is provided for testing, evaluation, and feedback, without service-level commitments. It is not intended as the sole path for production, client-facing, or mission-critical work. See the Terms of Service for the beta-use limitations.
By using the Service, you acknowledge this Privacy Policy. If you do not agree, do not use the Service.
2. Information we collect
2.1 Personal information
We may collect:
- Account information: name, email address, password (stored using secure hashing), company or organisation name, optional phone number, your stated use case, and profile details you choose to provide.
- Payment information: billing details and payment method information processed by our payment provider (we do not store full card numbers on our own servers).
- Team and organisation data: membership, roles, invitations, and identifiers needed for collaboration features.
- Communications: messages you send to support, feedback forms, and service-related email.
- Beta access requests: details you submit when requesting beta access or invitations, such as your name, email, and the workflow you are interested in.
2.2 Usage and technical data
We automatically collect information such as:
- Device and connection data: IP address, browser type and version, operating system, app version, and device identifiers where applicable.
- Service usage: features used, session and room identifiers, participation metadata, approximate timing and duration of sessions, and similar operational data.
- Performance and diagnostics: connection quality metrics, error reports, and logs needed to operate and secure the Service.
- Security and anti-abuse: when you register, Cloudflare Turnstile processes your IP address and limited browser signals to confirm you are not an automated bot.
2.3 Real-time audio, video, and control data
VDO Platform is built for real-time collaboration (for example streaming, review, editorial sessions, and remote desktop-style control where enabled). To deliver these features, audio, video, and related data may be processed in real time through our systems and through infrastructure operated by our subprocessors (for example real-time media servers and relays).
The Service is not marketed as a long-term cloud storage or file delivery product for uploaded media libraries. Unless a specific feature explicitly records or stores content and we describe that feature to you, we do not intend to retain your real-time media as a personal archive. We may still retain metadata (such as session identifiers, timing, quality metrics, and security logs) as described in this policy.
3. How we use your information
We use personal information to:
- Provide, operate, maintain, and secure the Service
- Create and manage accounts, teams, and billing
- Communicate about the Service, including transactional messages and (where permitted) product updates
- Monitor performance, troubleshoot issues, and improve reliability
- Detect, investigate, and help prevent fraud, abuse, and security incidents
- Comply with law and enforce our terms
4. Sharing and disclosure
We do not sell your personal information. We may disclose information in these situations:
- Service providers: vendors that host infrastructure, process payments, send email, provide analytics, or supply real-time media infrastructure, subject to appropriate contractual protections.
- Collaboration: other participants in a session may see profile or presence information as needed for the feature (for example display name).
- Legal and safety: where required by law, regulation, legal process, or to protect rights, safety, and security.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to safeguards.
5. Data security
We implement technical and organisational measures appropriate to the nature and beta stage of the Service. We take security seriously, including during testing, and these measures may include:
- TLS encryption for data in transit between clients and our web/API surfaces
- Industry-standard protections for real-time media (for example encrypted transport where applicable); media may traverse relays or media routing infrastructure when direct peer connectivity is not possible, which means sessions are not “end-to-end encrypted” in the narrow sense that no intermediary ever handles packets
- Access controls, authentication, monitoring, and secure configuration management
- Encryption at rest for certain stored data where appropriate
No method of transmission or storage is completely secure; we cannot guarantee absolute security.
5.1 Data breach notification
We maintain a process to detect, contain, and respond to data breaches. Where a breach is likely to result in serious harm to affected individuals, we will notify those individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), and take reasonable steps to remediate the incident.
6. Data retention
We retain personal information for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce our agreements. Retention periods depend on the data type (for example account records, billing records, security logs, and backups). Operational logs and security records may be retained for a limited period consistent with incident response and compliance needs.
7. Your rights and organisation accounts
Depending on your location, you may have rights to access, correct, delete, or export personal information, and to object to or restrict certain processing. To exercise rights, contact [email protected]. We may need to verify your request.
If you use VDO Platformthrough an organisation (for example a studio), your organisation may control certain aspects of your account and may process personal information independently. Where that applies, you may also need to contact your organisation’s administrator. Enterprise customers may request a data processing addendum by contacting [email protected].
8. Cookies and analytics
We use a small number of cookies and similar technologies, in these categories:
- Essential authentication: secure session and login cookies (for example HttpOnly cookies) required for the Service to function and to keep you signed in.
- Security and anti-abuse: cookies or tokens set by our security and bot-protection tooling (for example Cloudflare Turnstile) on certain pages such as registration.
- Analytics (cookie-free): for website analytics we use Umami, a privacy-oriented tool that does not set tracking cookies or persistent visitor identifiers.
We do not use Google Analytics or Facebook Pixel on the marketing site. We do not currently present an analytics cookie consent banner because our marketing analytics do not set analytics cookies or persistent visitor identifiers. If that changes, we will update this policy and the site’s consent controls as needed.
9. Subprocessors and infrastructure
We rely on categories of providers that may process personal information in order to operate the Service, including:
- UpCloud: cloud hosting for the platform, database, and VDO-operated real-time media infrastructure. Primary infrastructure is in Sydney, Australia, with media servers in multiple UpCloud locations.
- VDO-operated media and relay infrastructure on UpCloud, TURN services, and Google public STUN: real-time connection setup, media routing, and relay for live sessions.
- Resend (United States): transactional email such as invitations, verification, and password resets.
- Cloudflare (global), including Cloudflare Turnstile: DNS and bot protection on the registration form.
- Umami (VDO-operated on our infrastructure): cookie-free web analytics.
- Polar (European Union / United States): payment processing. Not active during the free beta; enabled only when paid plans launch.
Specific vendors may change over time; we will update this policy as our practices evolve. If you are in the EEA or UK, we process personal information to provide the Service you request and for our legitimate interest in operating and securing it.
10. Third-party services
The Service may link to or integrate with third-party sites and services that have their own privacy policies. We are not responsible for those practices.
11. International data transfers
Our primary infrastructure is located in Sydney, Australia (UpCloud), and our real-time media servers may run in multiple UpCloud locations. Some service providers are located overseas, which means your personal information may be disclosed outside Australia, including:
- Resend (transactional email) in the United States;
- Cloudflare (DNS and bot protection) globally;
- Polar (payments, if and when paid plans are enabled) in the European Union and United States.
Where we disclose personal information overseas, we take steps reasonable in the circumstances to protect it, consistent with Australian Privacy Principle 8.
12. Children
The Service is intended for professional users and is not directed at children. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, contact us and we will take appropriate steps. If you are in the EEA, UK, or other regions with a higher minimum age for certain services, you must meet those requirements.
13. United States state privacy notices
No sale of personal information. We do not sell your personal information for money. Certain US state laws may give residents additional rights (for example access, deletion, correction, and opt-out of certain sharing). If you are a US resident and wish to exercise privacy rights, contact [email protected]. We may verify your request as permitted by law.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the “Last updated” date. Where changes are material, we will provide additional notice as appropriate (for example by email or in-product notice).
15. Contact us
Questions about this Privacy Policy or our privacy practices: [email protected]. General support: [email protected].
Sebastian K. Nielsen
An individual operator based in Sydney, NSW, Australia. VDO is not a registered company, so no ACN applies.
We aim to respond to privacy requests within 30 days, subject to complexity and applicable law.
Related: Terms of Service · Refund Policy
