GDPR Policy
Last Updated: May 2026 Website: downloadcloudstream.com
GDPR is one of those things most websites treat as a box to tick. A paragraph buried at the bottom of a privacy policy, some cookie banner nobody reads, and done.
That’s not what this page is. If you’re in the European Union or European Economic Area, GDPR gives you real, specific rights over your data, and this page tells you exactly what those rights are, what data we process, why we’re legally allowed to, and how to exercise those rights if you want to.
Plain language. No legal padding. Let’s go.

Who This Applies To
The General Data Protection Regulation, GDPR, is European law. It applies to people located in the European Union (EU) and European Economic Area (EEA) when their personal data is being processed.
If you’re visiting cloudstreamdownload.com from the EU or EEA, this applies to you. If you’re visiting from elsewhere, our Privacy Policy covers your data handling, but GDPR-specific rights don’t legally apply to you.
Who We Are — The Data Controller
Under GDPR Policy, the “data controller” is the entity that decides how and why personal data is processed.
Data Controller: cloudstreamdownload.com Contact: Available through the contact page on this website
We are an independent informational website. We are not the developers of CloudStream, not affiliated with the reCloudStream GitHub organization, and not a registered company in any EU member state. We are a website that provides guides and download information about the CloudStream appp.
What Data We Collect and Why
Here’s the honest version, separated clearly so you know exactly what’s happening.
1. Website Analytics Data
What: IP address, browser type, pages visited, time on site, referring URL, device type
Why we collect it: To understand how people use the site so we can improve it
Lawful basis under GDPR Article 6: Legitimate interests (Article 6(1)(f)) — we have a genuine interest in understanding our audience to make the site more useful, and this interest doesn’t override your rights
Who processes it: We use standard web analytics tools. These act as data processors on our behalf.
How long we keep it: Anonymized aggregated data is retained indefinitely. Raw IP-level data is retained for no longer than 14 months.
2. Contact Form Submissions
What: Your name (if provided), email address, and the content of your message
Why we collect it: To respond to your query
Lawful basis under GDPR Article 6: Legitimate interests (Article 6(1)(f)), you contacted us, so responding is a reasonable expectation on both sides
How long we keep it: Messages are retained for as long as reasonably needed to resolve your query, then deleted. We don’t build contact databases.
3. Cookies
What: Small text files stored on your browser
Types we use:
| Cookie Type | Purpose | Can You Block It? |
|---|---|---|
| Essential | Keeps the Site Functioning Correctly | No — Site Breaks Without These |
| Analytics | Helps Us Understand Traffic Patterns | Yes — Block in Browser Settings |
| Preference | Remembers Your Settings Between Visits | Yes — Blocking Resets Preferences |
What we don’t use: Advertising cookies, tracking pixels, retargeting cookies, third-party profiling tools.
Under GDPR, non-essential cookies require your consent before being placed. Our cookie banner handles this when you first visit. You can change your preferences anytime through your browser settings.
4. What We Don’t Collect
This is worth saying clearly:
- We don’t collect names unless you give them to us voluntarily
- We don’t build user profiles
- We don’t track you across other websites
- We don’t sell data to anyone
- We don’t share data with advertisers
The CloudStream app itself collects nothing, no account, no login, no analytics. What you do in the app stays on your device. That’s a separate matter from this website, but worth stating since it’s often the first thing people want to know.
Your Eight Rights Under GDPR Policy
GDPR Policy gives you eight rights. Here’s what each one actually means for you on this site:
1. Right to be Informed You’re reading it. This page is how we fulfil this right.
2. Right of Access You can ask us what data we hold about you. Given that we collect minimal data and nothing personally identifiable beyond what you voluntarily send us, most requests result in “we have very little.” But you’re entitled to ask.
3. Right to Rectification If the data we hold about you is wrong, you can ask us to correct it.
4. Right to Erasure (“Right to be Forgotten”) You can ask us to delete your data. If you’ve contacted us and want that conversation deleted, ask, and we’ll handle it.
5. Right to Restrict Processing You can ask us to stop using your data in certain ways, even if you don’t want it deleted entirely.
6. Right to Data Portability You can ask for a copy of your data in a structured, commonly used format. Given the limited nature of what we collect, this is usually just a copy of any messages you’ve sent us.
7. Right to Object You can object to us processing your data under legitimate interests. If you do, we stop, unless we can demonstrate compelling, legitimate grounds that override your interests.
8. Rights Related to Automated Decision-Making We don’t use automated decision-making or profiling. This right doesn’t apply here, but you have it.
To exercise any of these rights, use the contact page. We respond within 30 days, which is the GDPR Policy requirement. We won’t make you jump through hoops.
Third-Party Data Processors
Under GDPR Policy, any third-party service that processes data on our behalf is a “data processor” and needs to be disclosed.
| Service | Purpose | Their GDPR Info |
|---|---|---|
| Web Hosting Provider | Serves the Website | Refer to Their Privacy Policy |
| Analytics Tool | Anonymised Traffic Data | Refer to Their Privacy Policy |
| Cloudflare (If Applicable) | Security and Performance | cloudflare.com/privacypolicy |
These processors handle data according to their own GDPR-compliant policies. We don’t permit them to use your data for anything outside of what’s described here
International Data Transfers
Web infrastructure is global. Data about your visit may pass through servers outside the EU, for example, if our hosting provider or analytics tool has servers in the US or elsewhere.
Where this happens, we rely on:
- Standard Contractual Clauses approved by the European Commission
- Processors that maintain EU-US Data Privacy Framework compliance
This is standard practice for websites operating globally. If you want specifics about where your data goes, ask through the contact page.
How Long We Keep Data
| Data Type | Retention Period |
|---|---|
| Analytics Data (Anonymized) | Indefinitely |
| Raw IP-Level Data | Maximum 14 Months |
| Contact Form Messages | Until the Query Is Resolved, Then Deleted |
| Cookie Preferences | Until You Clear Browser Data |
We don’t hold onto data longer than we need it. No archives, no databases of visitor records.
Complaints
If you think we’ve handled your data wrong, you have the right to complain to your national data protection authority.
In the EU and EEA, your local supervisory authority is the right place, for example, the ICO in the UK, CNIL in France, or the relevant authority in your country. A full list is available at edpb.europa.eu.
We’d genuinely rather you come to us first; most issues can be sorted out quickly through direct contact. But if you’re not satisfied with our response, the supervisory authority route is your legal right.
Changes to This Policy
If this GDPR policy changes, the date at the top changes with it. Major changes get noted clearly. Staying on the site after a change means you accept the updated policy
Contact
GDPR requests, questions about your data, or anything else related to this policy — contact page on this site. We respond within 30 days. Always.
