Privacy Policy for the SirokoTV television apps
Document version: v1.0 Effective date: 8 September 2026 Last updated: 8 September 2026
This policy applies only to the SirokoTV apps for television sets (Android TV, LG webOS and Samsung Tizen). It does not apply to the SirokoTV website or to the iOS and Android mobile apps, which are covered by the general SirokoTV Privacy Policy.
1. Who processes your data
- Controller: SIROKO SOLUTIONS, S.L.
- Tax ID (NIF): B-33950338
- Address: Plaza 6 de Agosto, nº 6, 2º — 33203 Gijón (Asturias), Spain
- Data Protection Officer: Mr Martín López Escartín, member of the Madrid Bar Association, no. 103516, on behalf of HONOS ABOGADOS, SLP. External DPO under Art. 37 GDPR
- Privacy and data rights: gdpr@siroko.com
- App support: support-tv@siroko.com
The DPO is the single point of contact for any question about the processing of your data and for exercising the rights in Articles 15 to 22 GDPR. Write to gdpr@siroko.com.
2. Which apps this covers
The SirokoTV app for connected TVs, in its three versions:
- Android TV (Google Play) — package name
com.siroko.tv - LG webOS (LG Content Store)
- Samsung Tizen (in preparation)
All three are the same app: a free catalogue of sports and adventure video (cycling, snow, fitness) with 24 h channels, vertical clips ("jumps"), search and subtitles, with the interface available in 12 languages.
This policy does not cover:
- The SirokoTV website or the iOS and Android mobile apps → see the general policy.
- Purchases on the siroko.com store (see section 9).
- Any processing Google, LG or Samsung carry out on their own account when you install or rate the app in their stores (see section 10).
3. The short version
- No account and no sign-in. Everything works without identifying yourself.
- No advertising, no analytics, no advertising identifiers (we do not use AAID or IDFA), and no third-party SDKs that collect data.
- The app stores two settings on your own TV (language and "likes") and never sends them to any server.
- The app sends no identifier of you or your TV to our servers. As with any internet connection, your IP address does reach our servers and the video CDN: that is the only information that can be considered personal data. Section 4 explains exactly what we do with it.
- We do not store your IP address to count views: it is immediately turned into an irreversible code that cannot be turned back into your IP.
- All communications are encrypted with HTTPS/TLS.
4. Processing table
Each row is one purpose. There are four today; if we add new features we will add rows and raise the version of this document (see sections 17 and 18).
T1 · Responding to the app's requests
What data: Your IP address (needed at network level so the response can reach your TV), the language code you selected, and an application key that is identical across all installations (it does not identify you)
What for: Responding to the app's requests: catalogue, images, video and live streams, from the servers listed in section 7
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR): without using your IP address it is technically impossible to deliver the content you requested
Who receives it: The processors listed in section 10: hosting, API protection, CDN and live streaming
How long we keep it: For the duration of the request. Anything written to logs is covered by T2
T2 · Keeping the service running
What data: The technical logs our server writes when serving each request: the address you connect from, the date and time, the address requested, the response code, and the browser or device your TV reports
What for: Keeping the service running: detecting and diagnosing faults, and detecting abuse and attacks
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) in the security and proper operation of the service
Who receives it: Written and stored by our own server. The CDN and the API protection service also keep their own logs, each under its own terms
How long we keep it: On our server, 14 days: rotated daily and deleted automatically after two weeks. On the CDN and the API protection service, no longer than needed for those same security and diagnostic purposes
T3 · Counting views of each video without duplicates and knowing
What data: Your IP address, which we do not store: it is immediately turned into an irreversible code (that code cannot be turned back into your IP). Using that code we (a) avoid counting the same view twice and (b) store the country, region and approximate city reported by a geolocation database installed on our own servers, without querying any external service
What for: Counting views of each video without duplicates and knowing in which countries the catalogue is watched. The resulting counter is aggregated per video, country and region: it does not record who watched what
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR): aggregated audience measurement. We do no profiling, no advertising and no automated decision-making about you
Who receives it: Nobody outside Siroko, beyond the infrastructure processors in T1
How long we keep it: The de-duplication code: 10 minutes. The approximate location linked to that code: 24 hours. Both are then deleted automatically. The aggregated counters are kept indefinitely, as they contain no personal data
T4 · Handling your query or your rights request
What data: Your email address and the content of your message, if you write to support-tv@siroko.com or gdpr@siroko.com. If you exercise your rights, the minimum data needed to verify your identity
What for: Handling your query or your rights request, and keeping a record of our response
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) for handling queries; legal obligation (Art. 6(1)(c) GDPR) for handling data subject rights
Who receives it: Our email provider (section 10)
How long we keep it: For as long as needed to handle your query and, if you have exercised your rights, for as long as we may be held accountable for our response
We do not process special categories of data (health, beliefs, biometrics) and we do not knowingly process children's data (section 12).
5. What is stored on your TV
The app stores two values in the local storage of the TV itself. Neither of them is sent to any server.
sirokotv_language
What it stores: The language you chose in Settings
What for: So the app opens in your language next time
Does it leave the TV?: No
How to delete it: By clearing the app's data or uninstalling it from your TV's menu
sirokotv_likes
What it stores: The identifiers of the vertical clips ("jumps") you have liked with the heart button
What for: To remember your likes on that TV. The like is purely local: the server never learns about it
Does it leave the TV?: No
How to delete it: Same as above
The app uses no sessionStorage, no IndexedDB and no other storage or tracking
technique.
About cookies. Our catalogue server returns a technical session cookie
(sirokotv_session) with its responses — the same one the SirokoTV website uses,
because they share a server. The television app does not need it, does not store it
and does not send it back: there is no sign-in and no state to keep. We do not use
cookies to identify you, for advertising or for analytics.
6. What the app does not do
To leave no room for doubt, the TV app does not:
- Ask you to create an account, register or sign in. There are no user accounts.
- Show advertising or integrate advertising networks.
- Use advertising identifiers (no Android AAID, no Apple IDFA) or any device identifier.
- Include analytics tools or advertising SDKs. There are three dependencies running on the TV: Capacitor (used solely to make the remote's "back" button work), an HTTP client, and our live streaming provider's player, which only comes into play when you watch a live broadcast (section 7).
- Access the microphone, camera, contacts, device location or your files.
- Process payments or purchase data.
- Offer comments, chat or any form of interaction between users.
- Sell, rent or transfer your data to third parties for commercial purposes.
7. How the app connects to our servers
The app is a packaged web application. To work, it makes HTTPS requests to Siroko servers:
api-tv.siroko.com: Catalogue: videos, channels, series, search and subtitlesimgtv.siroko.com: Images and thumbnailscdnst.siroko.com: On-demand video delivery- A server belonging to our live streaming provider, on its own domain: Playback of live broadcasts. That server is only contacted if you open a live stream
With each request the app sends an application key — identical for every installation, it identifies the application, not the viewer — and the interface language code. It sends no device or user identifiers, and it sets no custom header that identifies you.
8. Security
All communications between the app and our servers are encrypted using HTTPS/TLS. We apply reasonable technical and organisational measures to protect the information we process, in line with Art. 32 GDPR.
9. Products and QR codes
Some videos show Siroko products with a QR code. If you scan it with your phone you leave the app: the purchase happens on the siroko.com store, on your phone, and is governed by that store's privacy policy.
The TV app does not process payments, card data or order data, and does not receive any information back about whether you bought anything.
10. Recipients and processors
For the app to work, these providers process data on our behalf, as processors:
Hosting provider
What for: The servers running the API
What it receives: The requests reaching the server, including the source IP address
Where it processes data: European Union
API protection and acceleration service
What for: Filtering malicious traffic and accelerating api-tv.siroko.com
What it receives: API requests pass through its network before reaching our server
Where it processes data: Global network of servers; parent company outside the EEA
Content delivery network (CDN)
What for: Delivering images (imgtv.siroko.com) and on-demand video (cdnst.siroko.com)
What it receives: Image and video requests, including the source IP address
Where it processes data: Global network of servers
Live streaming provider
What for: Broadcasting live streams
What it receives: Live playback requests, including the source IP address
Where it processes data: European Union
Email provider
What for: The support-tv@ and gdpr@ mailboxes
What it receives: Only what you write to us
Where it processes data: Parent company outside the EEA
You can ask us for the current list of providers, with their names, by writing to gdpr@siroko.com. We keep that list up to date separately so we do not have to change this policy every time we change provider.
Apart from these providers, we share information with nobody else. There are no advertising networks, no analytics providers and no data brokers. The app requests nothing from any server that does not belong to Siroko or to one of these providers.
Note as well that Google, LG and Samsung process data on their own account, as independent controllers, when you download, update or rate the app in their stores. We do not control that processing; it is governed by each platform's own privacy policy.
11. International transfers
The app connects to servers located in the European Union: both ours and the one that broadcasts live streams.
Even so, two of the providers in section 10 — the API protection and acceleration service and the email provider — are companies headquartered outside the EEA and may process data in other countries. Those transfers are covered by the standard contractual clauses approved by the European Commission, which both providers incorporate into their data processing terms.
The content delivery network is provided by a company established in the United Kingdom, a country covered by an adequacy decision from the European Commission: that means the Commission considers it protects data to the same standard as the European Union. By its very nature, that network serves from servers around the world; those servers are covered by the data processing agreement we hold with the provider.
You can ask us for a copy of the applicable safeguards by writing to gdpr@siroko.com.
12. Children
The app is not directed to children and we do not knowingly collect children's data. There is no registration, so we ask for neither age nor any other personal data in order to use it. Its content is general-audience sports video.
If you believe a child has provided us with personal data by another route (for example, by writing to support), please write to gdpr@siroko.com and we will delete it.
13. Your rights
You have the right to:
- Access: know what personal data of yours we process.
- Rectification: correct it if it is inaccurate.
- Erasure: ask us to delete it.
- Objection: object to the processing we base on our legitimate interest (T1, T2 and T3 in section 4).
- Restriction of processing.
- Portability: receive your data in a reusable format, where applicable.
To exercise them, write to gdpr@siroko.com stating which right you wish to exercise. We may ask you for information to confirm it is you. We will reply within one month, extendable to two if the request is complex (Art. 12(3) GDPR).
An honest note about what we can do: because the app has no accounts and no identifiers, in practice we cannot tell which information in our logs belongs to a specific person unless you give us additional details, such as the IP address you connected from and the approximate date. If we cannot identify you, Art. 11(2) GDPR allows us to tell you that we are not in a position to act on the request, and we will explain it to you in those terms.
14. Complaints
If you believe we have not handled your request properly, you can lodge a complaint with the Spanish Data Protection Agency (AEPD):
- C/ Jorge Juan, 6 — 28001 Madrid, Spain
- www.aepd.es
If you prefer, write to gdpr@siroko.com first and we will try to resolve it.
15. Applicable law
- Regulation (EU) 2016/679, General Data Protection Regulation (GDPR).
- Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).
16. Where to find this policy
This policy is permanently published and accessible without signing in at:
https://www.siroko.com/tv/apps/privacy-policy
The app links to that address from its Settings screen.
17. Changes to this policy
When we add a feature that processes new data, we will update the table in section 4, raise the document version and record it in the changelog in section 18, with its date.
If the change is substantial — for example, when we introduce user accounts — we will also announce it inside the app itself, before or at the moment the feature is switched on, and never earlier than the effective date of the new version.
18. Version and changelog
Current version: v1.0 (effective 8 September 2026).
v1.0
Date: 2026-09-08
Summary of change: First version. Policy specific to the television apps (Android TV, LG webOS, Samsung Tizen), separated from the general SirokoTV policy. Four processing activities: content delivery, technical logs, aggregated view counting and handling of queries.