Privacy Policy
Last updated: April 23, 2026
1. Controller
The controller of your personal data within the meaning of Regulation (EU) 2016/679 ("GDPR") and Act No. 110/2019 Coll., on the processing of personal data, is:
- Panda Studio s.r.o., Czech Republic
- Registered office: [COMPANY_ADDRESS_PLACEHOLDER], Czech Republic
- IČO: [COMPANY_IC_O_PLACEHOLDER]
- DIČ: [COMPANY_DIC_PLACEHOLDER]
- Data Protection Officer (Telegram): @Pandastudiolive
2. Categories of personal data processed
We process the following categories of data about you:
- Identification and contact data: name, email, phone, Telegram handle.
- Account data: password hash, role, status, language preference, notification settings.
- Identity verification data: government-issued ID, selfie with ID — only where required by applicable law (AML/KYC) or by the third-party platforms to which you choose to connect.
- Financial data: earnings aggregated from integrated platforms, withdrawal requests, payout method details, processing fees.
- Technical data: IP address, device and browser information, session cookies, audit log entries.
- Support communications: messages you send to us and attachments.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service (account, dashboard, payouts) | (b) performance of a contract |
| Identity verification and AML/KYC compliance | (c) legal obligation |
| Fraud prevention, security, audit logging | (f) legitimate interest |
| Transactional emails (earnings, withdrawals, verification, support) | (b) performance of a contract |
| Marketing communications | (a) consent — opt-in only |
| Accounting records | (c) legal obligation (Czech Accounting Act) |
4. Recipients and transfers
We share personal data only with processors acting on our behalf under a data-processing agreement, including:
- Cloud infrastructure provider (hosting the Service)
- Object storage provider (identity documents and profile photos)
- Transactional email provider
- Payment providers used for your chosen payout method
- Integrated cam platforms — only the credentials you enter for each platform, for the sole purpose of fetching your earnings
Where a processor is located outside the European Economic Area we rely on the European Commission's Standard Contractual Clauses (SCCs) to ensure an adequate level of protection.
We do not sell your personal data.
5. Retention
- Account and profile data: until account deletion.
- Identity verification documents: up to 5 years after the end of the contractual relationship (AML obligations).
- Accounting and tax records: 10 years (Czech Accounting Act, Income Tax Act).
- Audit log entries: up to 3 years.
After the retention period expires we delete or anonymize the data.
6. Your rights under the GDPR
You have the right to:
- request access to your personal data (Art. 15);
- request rectification of inaccurate data (Art. 16);
- request erasure — "right to be forgotten" (Art. 17);
- request restriction of processing (Art. 18);
- receive your data in a portable format and have it transmitted to another controller (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent at any time for processing based on consent, without affecting lawfulness of prior processing.
To exercise any of these rights, message us on Telegram @Pandastudiolive. We will respond within 30 days (extendable by two months for complex requests).
You also have the right to lodge a complaint with the supervisory authority: Úřad pro ochranu osobních údajů (Czech Data Protection Authority), Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz.
7. Security
We use industry-standard technical and organisational measures including TLS in transit, AES-256-GCM encryption of third-party platform credentials at rest, bcrypt password hashing, role-based access controls, audit logging, and regular security reviews.
We will notify you and the supervisory authority of any personal data breach within 72 hours where legally required.
8. Cookies
For details on the cookies we use, see our Cookie Policy.
9. Changes to this Policy
We may update this Privacy Policy. Material changes take effect no earlier than 14 days after we notify you. The "Last updated" date above reflects the current version.