Skip to content
Streamline Agency logo STREAMLINE

Legal documents

Data Protection (GDPR)

Revision
Articles
Governing law
France · EU

Purpose of this document

RGPD art. 13 et 14

This policy describes how your personal data is collected, used, shared and retained when you use the Streamline website and panel. It constitutes the information required by articles 13 and 14 of Regulation (EU) 2016/679 (GDPR) and by French law no. 78-17 of 6 January 1978 on data protection.

It applies to website visitors, to creators who are members of the agency, and to staff with access to the panel. It does not cover processing carried out by TikTok, Discord or other third-party platforms where you hold your own accounts: those services act as independent controllers and have their own policies.

Data controller

RGPD art. 13.1.a

The controller of your personal data is:

STREAMLINE (Société à responsabilité limitée (SARL))
4 chemin des Églantines, 69580 Sathonay-Village, France
RCS Lyon 937 823 300
contact@streamlineagency.eu

No data protection officer has been appointed: the nature and volume of the processing carried out do not make such an appointment mandatory under article 37 GDPR. Your requests are handled directly by management, at the address above.

Processing activities

RGPD art. 13.1.c et 13.2.a

Each processing activity serves a specific purpose, relies on an identified legal basis and has a defined retention period:

Purpose Data concerned Legal basis Retention
Creating and managing your account Discord ID, username, email address, avatar, language, linked TikTok account ID Performance of a contract (art. 6.1.b) For as long as the account exists, then 30 days after it is closed
Creator performance tracking Live statistics from the TikTok creator programme: diamonds, live duration, valid days, followers, matches, subscription revenue Performance of a contract (art. 6.1.b) For the duration of the contractual relationship
Calculating and paying bonuses Amounts earned, tiers reached, payout history, any debts or adjustments Contract and legal accounting obligation (art. 6.1.b and 6.1.c) 10 years (accounting obligation, art. L123-22 French commercial code)
Handling your reports and support requests Problem description, screenshots you send, technical state of the account at the time of the report, related application errors, exchanges with the team Legitimate interest: keeping the service working (art. 6.1.f) 1 year
Technical logging and security IP address, user agent, pages visited, timestamps, response codes Legitimate interest: information system security (art. 6.1.f) 1 year
Audit trail of sensitive actions Administrative actions: role changes, sanctions, account impersonation, configuration changes Legitimate interest and security obligation (art. 6.1.f and 32) 3 years
API call logging Endpoints called, request and response bodies, IP address, key used Legitimate interest: abuse detection and debugging (art. 6.1.f) 90 days
In-panel notifications Information messages sent within the panel and their read status Performance of a contract (art. 6.1.b) 180 days
Measuring traffic to our services Pages viewed, referring page, country, device and browser type. No identifier, no cookie, no IP address retained Legitimate interest (art. 6.1.f) — understanding how our services are used in order to improve them 25 months

Where processing relies on our legitimate interest, you have a right to object which you may exercise at any time (see "Your rights" below). A balancing test has been carried out for each of these activities to confirm that it does not disproportionately affect your rights.

Where the data comes from

RGPD art. 14.2.f

Not all your data comes directly from you. There are three sources:

  • Data you provide us: when creating your account, linking your TikTok account, or writing to us.
  • Data provided by TikTok under the creator programme: your live and performance statistics, shared with the agency you belong to.
  • Data generated automatically by your use of the service: connection logs, history of actions in the panel, technical errors encountered.

Recipients and processors

RGPD art. 13.1.e et 13.1.f

Your data is accessible to authorised agency staff, limited to what their role requires. It is also processed by the following technical providers, acting on our instructions:

Provider Role Location
NVHCloud SAS Hébergement de l'ensemble de l'infrastructure : site, panel, base de données, serveurs de jeu et serveur dédié France et Union européenne
Discord Netherlands BV / Discord Inc. Authentification (OAuth), notifications et communauté Pays-Bas et États-Unis
Transfer outside the EU
TikTok Technology Limited Programme créateurs : statistiques de live et de performance Irlande, avec accès hors UE
Transfer outside the EU
Google Ireland Limited Agenda : planification des rendez-vous avec les créateurs Irlande et États-Unis
Transfer outside the EU
Functional Software, Inc. (Sentry) Supervision technique et collecte des erreurs applicatives États-Unis
Transfer outside the EU

Some of these providers process data outside the European Union. Those transfers rely on the following safeguards:

  • Discord Netherlands BV / Discord Inc. — Clauses contractuelles types de la Commission européenne
  • TikTok Technology Limited — Clauses contractuelles types et mesures complémentaires du programme Project Clover
  • Google Ireland Limited — EU-US Data Privacy Framework
  • Functional Software, Inc. (Sentry) — Clauses contractuelles types ; les champs sensibles sont expurgés avant envoi

Your data is never sold, rented or shared with third parties for marketing purposes.

Automated bonus calculation

RGPD art. 13.2.f et 22

Your bonus amount is calculated automatically from your performance statistics, the configured tiers and any applicable multipliers. This calculation has direct financial effects for you.

It is not a solely automated decision within the meaning of article 22 GDPR: every payout is reviewed and approved by an authorised member of staff, who can correct it. You may at any time ask for the detail of the calculation applied, contest an amount and obtain a review by a human being.

Your rights

RGPD art. 15 à 22

You have the following rights over your data:

  • Right of access: confirm whether your data is processed and obtain a copy of it.
  • Right to rectification: have inaccurate or incomplete data corrected.
  • Right to erasure: request deletion of your data, except data we must keep under a legal obligation.
  • Right to restriction: request that processing be frozen while a dispute is examined.
  • Right to portability: receive the data you provided in a structured, machine-readable format and have it sent to another organisation.
  • Right to object: object at any time to processing based on our legitimate interest, on grounds relating to your particular situation.
  • Right to withdraw consent where processing depends on it, without affecting the lawfulness of processing carried out beforehand.
  • Right to give instructions on what happens to your data after your death.

To exercise these rights, write to contact@streamlineagency.eu.

We reply within one month of receiving your request. That period may be extended by two months where the request is complex or where there are many of them: you would be informed within the first month, with the reasons.

Where there is reasonable doubt about your identity, we may ask for additional proof, strictly limited to what is needed to confirm the request comes from you.

Complaint to the supervisory authority

RGPD art. 13.2.d et 77

If, after contacting us, you believe your rights are not being respected, you may lodge a complaint with the French supervisory authority:

Commission Nationale de l'Informatique et des Libertés (CNIL)
3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
Phone : +33 1 53 73 22 22
www.cnil.fr/fr/plaintes

Security

RGPD art. 32 et 34

Technical and organisational measures appropriate to the risk are in place to protect your data against destruction, loss, alteration, unauthorised disclosure or access:

  • Encryption of traffic between your browser and our servers (HTTPS).
  • Authentication through an external identity provider, with no password stored by us.
  • Mandatory email two-factor authentication for all administrative access.
  • Segregated permissions: each staff member only accesses the functions matching their role.
  • Logging and traceability of sensitive actions, with automatic expiry of administrative sessions.
  • Sensitive fields are stripped before anything is sent to our technical monitoring tool.

In the event of a data breach likely to result in a high risk to your rights and freedoms, you would be informed as soon as possible in accordance with article 34 GDPR, and the supervisory authority would be notified within 72 hours.

Changes to this policy

This policy may be amended to reflect changes in law or in our processing activities. Where a change is substantial, you will be informed by a notification in the panel before it takes effect. The date of the latest update appears at the top of this page.

A question about this document?