Skip to content
Request a $750 pilot

Privacy

Effective from 12 October 2026

Current

Permanent link

recordius.studio/privacy/2026-10-12

Version history

  • 12 October 2026Current

    First published version.

Transparent version history. Every version of this Privacy policy stays online permanently at its own link, exactly as it was published. We never edit a published version: any change is published as a new dated version with a one-line summary of what changed.

About

We have written this page in plain English on purpose, so that you can see exactly what personal data Recordius handles, why, how long we keep it, and what you can ask us to do with it. It is the privacy policy of Durasius s.r.o. for Recordius, and it applies to recordius.studio, to our emails and to the services we provide.

In short

This summary helps you find the key points. It does not replace the policy below; if anything differs, the full policy applies.

  • We collect only what we need to answer you, do the work and keep our accounts. What we collect and why
  • No tracking or advertising cookies. Visit statistics are anonymous and cookie-free. Cookies
  • With your recordings, we work for you: only on your instructions, never sold, never used to train our own AI models, and raw files are deleted 60 days after release. Recordings and client files
  • We email businesses only about our service, and only at work addresses. Reply "stop" and we stop. Business outreach
  • You can ask what we hold about you, and ask us to correct or delete it. Your rights

Who we are

The controller of the personal data described in this policy is:

Durasius s.r.o.Bajkalská 18831/45G, 821 05 Bratislava, SlovakiaCompany ID (IČO): 56575335 · VAT ID (IČ DPH): SK2122349889Registered in the Commercial Register of Mestský súd Bratislava III, section Sro, file 182228/BEmail: hello@recordius.studio or legal@durasius.com

We are a small company and have not appointed a data protection officer, as we are not required to. Write to either email address above with any privacy question and a person will answer.

Two roles

We handle personal data in two different roles.

  • As controller. For data about people who visit our website, contact us, book a call, buy from us, or receive our business emails. This policy covers that data in full.
  • As processor, on behalf of our clients. For the recordings, files and materials a client sends us so we can produce their episodes. Those recordings contain the voices, faces, names and statements of the client's hosts and guests. For that data, the client decides what happens to it and is the controller. We process it only on the client's instructions, under the data processing terms in our Terms. If you appeared in a client's show and have a question about your data, contact that client first. We will help them answer.

What we collect and why

Website visits

  • Data: anonymous visit statistics collected by Vercel Web Analytics without cookies: the page visited, the referring website, approximate location (country, region and city), device type, browser and operating system. These statistics are not linked to you, and the temporary identifier used to count visits is discarded after 24 hours. We remove query strings from page addresses, except campaign tags (utm_source, utm_medium, utm_campaign). If your browser sends a Global Privacy Control or Do Not Track signal, we do not record your visit. Our hosting provider also processes your IP address and basic request details briefly, to deliver the website and keep it secure.
  • Why: to see which pages work and to keep the site running and secure.
  • Legal basis: our legitimate interest in running, securing and improving the website (Art. 6(1)(f) GDPR).

Enquiries and calls

  • Data: your name, email, company, and whatever you write to us. If you book a call: the time slot and any notes you add.
  • Why: to answer you and hold the call you asked for.
  • Legal basis: steps taken at your request before a contract (Art. 6(1)(b) GDPR), or our legitimate interest in replying to business enquiries (Art. 6(1)(f) GDPR).

Clients

  • Data: names, work email addresses and phone numbers of the people we work with, billing details, the content of our communication, intake form answers, and review comments.
  • Why: to deliver the service, communicate about it, and invoice it.
  • Legal basis: performance of our contract with the client (Art. 6(1)(b) GDPR); for contact persons who are not themselves the contracting party, our legitimate interest in working with the client's team (Art. 6(1)(f) GDPR).

Payments and accounting

  • Data: billing name and address, company and VAT details, amounts, dates, and invoices. Card details are entered on Stripe's pages and are never seen or stored by us.
  • Why: to take payment, issue invoices, and keep the accounting records the law requires.
  • Legal basis: legal obligation (Art. 6(1)(c) GDPR), mainly under the Slovak Accounting Act (No. 431/2002 Coll.) and VAT Act (No. 222/2004 Coll.).

Legal claims

  • Data: the records listed above, where needed.
  • Why: to establish, exercise or defend legal claims.
  • Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).

Business outreach

  • See the next section.

We do not sell personal data or use it for advertising.

Business outreach

We sometimes email founders and partners of firms whose public work suggests our service could be useful to them, usually because the firm already publishes a podcast.

  • Data: your name, job title, company, work email address, the public podcast or website we refer to, and whether and how you replied.
  • Source: public sources, such as your company's website, podcast directories and platforms, and professional profiles you have made public.
  • Why: to offer our service to businesses for which it is relevant.
  • Legal basis: our legitimate interest in offering a relevant business service to businesses (Art. 6(1)(f) GDPR). We contact only work addresses, only about our service, and keep the number of messages low.
  • Every outreach email says who we are, gives our postal address, explains where we found you, and tells you how to opt out.
  • Your right to object: you can tell us to stop at any time by replying "stop" or using the opt-out line in the email. We then stop immediately and keep only the minimum record needed to make sure we never contact you again.
  • Retention: if you do not reply, we delete your data 12 months after our last email. If you ask us to stop, we keep only your email address on a do-not-contact list.

Recordings and client files

When a client sends us recordings, logos, past episodes or other materials, we process them only to produce, review and deliver that client's releases. We act as the client's processor under Art. 28 GDPR and the data processing terms in our Terms.

  • Recordings are stored in a private folder for that client and opened only by the people who cut and check the episode.
  • We never sell recordings or use them for anything else.
  • We never publish anything a client has not approved.
  • We do not use client recordings to train our own AI models.
  • Raw recordings are deleted 60 days after the release they were used for. Final files are kept for 12 months so the client can download them again, then deleted. A client can ask us to delete them sooner.

Who else sees it

We use a small number of trusted providers to run the service. They process data only to provide their service to us, under data processing agreements.

  • Microsoft Ireland Operations Ltd: OneDrive (file storage and upload links), Microsoft Forms (intake), Microsoft Bookings (call booking), email.
  • Adobe Inc. (Frame.io): review and approval of drafts.
  • Stripe Payments Europe Ltd: payments and subscriptions. Stripe also acts as an independent controller for fraud prevention and legal compliance, under its own privacy policy.
  • Vercel Inc.: website hosting and cookie-free visit statistics.
  • Google Ireland Ltd: Google Workspace email accounts used for business outreach.
  • Our accountant: invoices and accounting records, as the law requires.
  • Freelance editors, if we engage them: only for the episodes they work on, under written confidentiality and data processing terms. We will name them in a new version of this page before they receive any client files.

Their privacy policies: Microsoft privacy statement (opens in a new tab) · Adobe privacy policy (opens in a new tab) · Stripe privacy policy (opens in a new tab) · Vercel privacy policy (opens in a new tab) · Google privacy policy (opens in a new tab)

If we add an email-sending tool, a lead database, or any other tool that handles personal data, we will list it in a new version of this page before we use it for that purpose.

We may also disclose data where the law requires it, for example to tax authorities or a court.

Transfers outside the EU

Some providers above are based in the United States or may access data from outside the European Economic Area. Where that happens, the transfer is protected by the provider's certification under the EU–US Data Privacy Framework or by the European Commission's Standard Contractual Clauses. You can ask us for a copy of the relevant safeguards.

How long we keep it

  • Website visit statistics: anonymous and aggregated; the temporary visit identifier is discarded after 24 hours.
  • Enquiries and call bookings that do not lead to work: 12 months after our last contact.
  • Business outreach: 12 months after our last email if you do not reply; a do-not-contact entry for as long as needed to keep honouring it, if you ask us to stop.
  • Client communication and contract records: for the duration of the contract and 4 years after it ends, the general limitation period for commercial claims.
  • Invoices and accounting records: 10 years, as required by the Slovak Accounting Act.
  • Raw recordings: 60 days after release. Final files: 12 months after delivery.

Cookies

Our website does not use cookies for tracking or advertising, and our visit statistics work without cookies or similar storage on your device. When you pay, you leave our site for Stripe's checkout page, and when you book a call, you use Microsoft's booking page. Those pages may set their own cookies under their own policies.

Security

We use two-factor authentication on every account that holds client data, keep each client's files in a separate private folder, give access only to the people who need it, and delete files on the schedule above. Our providers encrypt data in transit and at rest.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased;
  • restrict how we use it;
  • receive your data in a portable format;
  • object to processing based on our legitimate interest, and object at any time to direct marketing, after which we stop;
  • withdraw any consent you gave, without affecting what happened before.

Because we are based in the EU, these rights apply wherever you live. To use any of them, email hello@recordius.studio or legal@durasius.com. We answer within one month. We may ask you to confirm your identity first.

You can also complain to the Slovak data protection authority: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava 27, Slovakia (dataprotection.gov.sk). If you are in the United Kingdom, you can also contact the Information Commissioner's Office (ico.org.uk).

Automated decisions

We make no decisions about you based solely on automated processing.

Children

Our service is for businesses. We do not knowingly collect data from anyone under 16.

Changes

We publish a new dated version of this page when the way we handle personal data changes. Every version shows its date at the top and stays available at its own permanent address, for example recordius.studio/privacy/2026-10-12. We never edit a published version: any change is published as a new dated version with a one-line summary of what changed. If a change materially affects clients, we tell them by email before it applies.