Privacy Policy
Last Updated: April 11, 2026
This privacy policy describes how Nordic Stream Agency ("we", "us", or "our")
collects, uses, and protects your personal data when you use the NordicStream mobile application.
The app is available in Google Play and Apple App Store.
Data Controller
Nordic Stream Agency
Email: info@nordicstream.fi
Website: nordicstream.fi
Data We Collect
When you use the NordicStream app, we collect and process the following personal data:
- TikTok Account Information: Your TikTok username, display name, and profile picture, obtained through TikTok's OAuth API with your explicit consent
- Authentication Data: OAuth tokens to maintain your authenticated session (stored securely, not shared)
- Application Data: Content you create and interactions you make within the app, including chat messages, media attachments, reactions, battle scheduling, and course progress
- Device Tokens: Push notification tokens for delivering notifications to your devices
- Diagnostic Data: Performance and error information generated during your use of the app, such as request timing and error details. This data may be linked to your account for troubleshooting purposes but is not used for profiling or behavioral analysis
We do not collect any other personal information. We do not use cookies, tracking pixels, or analytics services.
Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process your data based on:
- Contractual Necessity (Art. 6(1)(b) GDPR): Processing is necessary to provide the services you requested through the app
- Consent (Art. 6(1)(a) GDPR): You provide explicit consent when authorizing the app to access your TikTok account
How We Use Your Data
Your personal data is used exclusively for:
- Authenticating your identity and managing your access to the app
- Enabling communication between you and Nordic Stream Agency staff and other creators
- Scheduling and coordinating battles between creators
- Tracking your progress in educational courses
- Delivering push notifications about app activity
We do not use your data for marketing, profiling, or automated decision-making.
Data Sharing and Disclosure
We do not sell, rent, or share your personal data with third parties, except:
- When required by law or legal process
- To protect our rights or the safety of our users
- With TikTok, solely for authentication purposes through their official API
- With Expo, solely for delivering push notifications to your devices
- With our S3-compatible storage provider, for storing media attachments you upload
Data Storage and Security
Your data is stored on secure servers located in the European Union.
We implement industry-standard security measures including encryption,
access controls, and regular security assessments to protect your data
against unauthorized access, alteration, disclosure, or destruction.
Data Retention
We retain your personal data for the following periods:
- Account data: For the duration of your active use of the app and up to 90 days after your last login
- Chat messages and attachments: 7 days, after which they are permanently deleted
- Diagnostic data: 2 weeks
- Other application data: For the duration of your creator relationship with Nordic Stream Agency
You may request immediate deletion of your data at any time (see Your Rights below).
Your Rights Under GDPR
As a data subject in the European Union, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restriction: Request limitation of processing in certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing of your personal data
- Right to Withdraw Consent: Withdraw your consent at any time
To exercise any of these rights, contact us at info@nordicstream.fi.
We will respond to your request within 30 days.
You can also revoke the app's access to your TikTok account at any time
through TikTok's account settings.
Supervisory Authority
If you believe we have not adequately addressed your concerns,
you have the right to lodge a complaint with your local data protection supervisory authority.
International Data Transfers
Your data is stored and processed within the European Union.
We do not transfer your personal data outside the EU/EEA.
Children's Privacy
The NordicStream app is intended for use by TikTok creators
who are at least 13 years old. We do not knowingly collect data from children under 13.
If you believe we have collected data from a child under 13,
please contact us immediately.
Changes to This Policy
We may update this privacy policy from time to time.
Significant changes will be communicated through the app.
Continued use of the app after changes constitutes acceptance of the updated policy.
Contact Us
For questions about this privacy policy or to exercise your data rights, contact us at:
Email: info@nordicstream.fi
Related: Terms of Service