GDPR / Data Protection Notice
directvideocall.com · Effective August 26, 2026 · Last updated September 4, 2026
This notice is provided under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), the UK GDPR, and, where applicable, the Swiss Federal Act on Data Protection. It supplements the Privacy Policy. It applies to Users in the EEA, United Kingdom, and Switzerland.
1. Identity of the controller
Controller: Direct Video Call, the operator of directvideocall.com. Privacy contact: privacy@directvideocall.com. Provider has not appointed a data protection officer.
Provider has not appointed an EU or UK representative under Article 27. If a representative is appointed, this notice will be updated.
2. Categories of personal data
- Technical data generated when the website is requested (Internet Protocol address, user-agent, requested URL, timestamps), typically processed by the hosting platform.
- Session-setup data when User starts or joins a call (Room Identifier, signaling messages, ICE candidates, and related network data), processed by the browser, the other participant, and signaling / STUN providers.
- Audiovisual signals captured on User’s device after permission, transmitted toward the other participant, and not retained by Provider as a recording.
- Interface position for the local video overlay, held in memory during a Session.
Provider does not require identity data (name, email, account). Provider may be unable to identify a data subject from the limited technical data within its control.
3. Sources
Data are obtained from User’s device and browser, from the other Session participant (connection data), and from processors that operate hosting, signaling, and network-discovery functions. Provider does not purchase lists of personal data for the Service.
4. Purposes and legal bases (Article 6)
- Article 6(1)(b): providing a Session User has requested, including exchanging the technical data required to connect two devices.
- Article 6(1)(f): operating, securing, and protecting the Service and preventing abuse. Provider’s legitimate interests are the delivery of a functioning website and mitigation of fraud or attack. Those interests are balanced against User’s rights; User may object as described below.
- Article 6(1)(c): compliance with applicable law, including responding to lawful requests.
Provider does not engage in automated decision-making producing legal or similarly significant effects (Article 22).
5. Recipients
Recipients include: the other Session participant; hosting and content-delivery operators; signaling operators; STUN or network-discovery operators (presently including services associated with Google and Cloudflare); and competent authorities where required by law. Categories are described further in the Privacy Policy.
6. Transfers outside the EEA / UK / Switzerland
Processing may occur in the United States and in the country of the other participant. Transfer tools, where required, may include adequacy decisions, a processor’s participation in a recognized framework, or Standard Contractual Clauses (and the UK international data transfer addendum). Provider has not represented that it is certified under the EU-U.S. Data Privacy Framework. Appropriate safeguards in Provider’s possession may be requested, subject to redaction of confidential terms.
7. Retention
Provider does not retain Session audiovisual content. Technical logs held by processors follow those processors’ retention practices. Provider has not published a separate numeric retention period for data it does not itself store.
8. Rights of the data subject
Subject to the conditions of the GDPR / UK GDPR, User may:
- access personal data (Art. 15);
- rectify inaccurate data (Art. 16);
- obtain erasure (Art. 17);
- restrict processing (Art. 18);
- receive data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw consent without affecting lawfulness of processing before withdrawal (Art. 7(3)).
Requests: privacy@directvideocall.com. Provider may ask for information reasonably necessary to verify the request. Because Provider stores little or no identifiable Session data, Provider may be unable to locate information relating to User.
User has the right to lodge a complaint with a supervisory authority, in particular in the Member State of habitual residence, place of work, or place of the alleged infringement (Art. 77), or with the UK Information Commissioner’s Office.
9. Requirement to provide data
User is not required by statute to provide personal data to Provider. If User withholds camera or microphone permission, a Session may have no audio or video. If User’s network or browser blocks signaling or network discovery, a Session may fail.
Questions: privacy@directvideocall.com