Privacy Policy
Effective 6 September 2026. Data controller: Utgard LLC, registration number HE 439217, Arch. Makariou III, 155, Office 301, 3027 Limassol, Cyprus (“the Operator”, “we”). This policy explains what data we collect on tv.utgard.tv and in your account area, why, on what legal basis, and how long we keep it.
We process personal data in line with the EU General Data Protection Regulation (GDPR) and the data protection law of the Republic of Cyprus.
1. What we collect
- Account data: login, email address, password stored as an irreversible hash, interface language, registration date.
- Payment data: amounts, dates, payment method, the transaction identifier at the payment provider, balance history. We never receive or store card numbers — they are handled by the payment provider on its own side.
- Subscription data: active packages, expiry dates, number of screens, your playlist access code.
- Technical data: IP address, device and application type (user agent), stream connection times and the number of simultaneous sessions — needed to enforce the screen limit and to prevent access being shared with third parties.
- Support requests: the text of the conversation and any attachments you send, plus your Telegram identifier if you write through the bot.
We do not collect health data, political opinions, religious beliefs or other special categories of data, and we ask you not to send them in support requests.
2. Why we process it, and on what basis
- Performance of a contract (Art. 6(1)(b) GDPR): creating your account, providing channel access, taking payments, support, and emails about the state of your subscription.
- Legitimate interests (Art. 6(1)(f)): protection against password guessing, abuse of the free trial and sharing of access, enforcing the screen limit, diagnosing faults, and basic traffic statistics.
- Consent (Art. 6(1)(a)): marketing emails and optional cookies. You can withdraw consent at any time via the unsubscribe link in any email or the notification settings in your account.
- Legal obligation (Art. 6(1)(c)): keeping payment records for accounting and tax purposes.
3. How long we keep it
- Account data — while the account exists and for 12 months after deletion (to resolve payment disputes).
- Payment records — 7 years, as required by accounting law.
- Technical connection logs — 90 days, then deleted or anonymised.
- Support conversations — 24 months from the last message.
4. Who we share it with
We do not sell personal data and do not pass it on for anyone else’s advertising. Data reaches only the processors without which the service cannot work, and only to the extent needed:
- payment providers — to take payments and issue refunds;
- our email delivery provider — for subscription and support emails;
- hosting and anti-DDoS providers — to run the Service;
- Telegram — if you contact support through the bot.
Some processors are located outside the European Economic Area. Such transfers rely on the European Commission’s standard contractual clauses or on an adequacy decision.
We disclose data to public authorities only on a lawful and properly issued request.
5. Your rights
You have the right to obtain a copy of your data, correct inaccurate data, have it erased, restrict processing, object to processing based on legitimate interests, port your data to another provider, and withdraw consent to marketing.
To exercise a right, write to us at [email protected]. We answer within 30 days. Some actions are available immediately in your account: changing the password and email, turning notifications off, and signing out on other devices.
If you believe we are infringing your rights, you may complain to a data protection authority — in Cyprus that is the Commissioner for Personal Data Protection — or to the authority in your country of residence.
6. Deleting your account
We delete an account on request to support. After deletion, channel access stops and any unused paid period is neither transferred nor compensated, except as set out in the refund policy. Payment records are retained for the period required by law — these cannot be deleted, and we will say so in our reply.
7. Cookies
Essential cookies are needed to sign in, remember your language and protect forms against request forgery — without them the Service does not work, and they are set without separate consent. Analytics cookies (a traffic counter) are set only with your consent and help us see which pages are useful. There are no third-party advertising cookies on the Service.
You can manage cookies in your browser settings. If you block them, signing in may stop working.
8. Security
Connections to the Service are protected by TLS. Passwords are stored as irreversible hashes — the original password cannot be recovered, not by us and not by anyone who obtains the database. Staff access to data is limited and granted on a need-to-know basis; access to internal systems requires keys and two-factor authentication. Backups are encrypted.
We never ask for your password or one-time codes by email, chat or phone. If someone asks for them in our name, it is fraud.
If a breach is likely to affect your rights, we will notify the supervisory authority within 72 hours and inform you where the risk is high.
9. Children
The Service is not intended for people under 18 and we do not knowingly collect their data. If such data has reached us, tell us and we will delete it.
10. Changes to this policy
We may update this policy. Material changes are published here at least 14 days before they take effect, and we notify you by email. The date at the top always shows the version in force.
11. Contact
For data protection matters: Utgard LLC, Arch. Makariou III, 155, Office 301, 3027 Limassol, Cyprus, [email protected]. We have not appointed a Data Protection Officer: the scale and nature of our processing does not require one.
Related documents: terms of service, guarantee and refunds, DMCA.