Screencord — Privacy Policy
Effective date: 29 June 2026 Last updated: 29 June 2026
1. Introduction and controller
This Privacy Policy explains how T Minus One GmbH (trading as "Screencord"), a limited liability company organised under the laws of Switzerland, with registered office at Aubrigstrasse 22, 8833 Samstagern and statutory seat in Richterswil (ZH), UID CHE-306.571.225 ("Screencord", "we", "us"), collects and processes personal data in connection with the Screencord digital-signage platform (the "Service").
Screencord is the controller of the personal data we process to provide the Service to account holders, as described in this Policy. For personal data contained within the content you upload or display through the Service, you are the controller and we act as a processor (see Section 11).
This Policy forms part of our Terms and Conditions.
2. What personal data we collect
We collect only what we need to provide and secure the Service:
a) Account and identity data
- email address and username (derived from your email);
- password — stored only as a cryptographic hash, never in plain text.
b) Authentication and security data
- two-factor authentication (TOTP) secret, encrypted at rest;
- registered passkeys / security keys — we store only the public key; the secret never leaves your device;
- two-factor recovery codes, stored as hashes;
- session identifiers and a short-lived "2FA pending" handle;
- the IP address recorded at the moment a device is paired (the pairing code is valid for about 5 minutes, after which the record expires).
c) Billing and payment data
- billing profile: first and last name, address, city, postcode, country;
- invoices, payment history and usage data (Screen-Days);
- a token referencing your card, plus the card brand, last 4 digits and expiry date. We do not store your full card number — it is held by our payment processor in accordance with card-scheme security standards (PCI-DSS).
d) Content you provide
- media you upload (images, video), designs, playlists, schedules and device names. This content may contain personal data you choose to include; for that data you are the controller (see Section 11).
e) Usage and technical data
- connected screens, device "last seen" timestamps, usage events (screen added/removed);
- application logs and error reports.
f) Communications
- the content of messages you send us (e.g. support requests by email).
We do not collect special categories of personal data, and we do not use the Service for advertising or cross-site tracking.
3. Purposes and legal bases
| Purpose | Data categories | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and operating your account; providing the Service | account, content, usage | Performance of a contract (Art. 6(1)(b)) |
| Authentication, 2FA, fraud and abuse prevention | security data, pairing IP | Legitimate interests (Art. 6(1)(f)); contract |
| Metering, billing and issuing invoices | billing, payment, usage | Performance of a contract; legal obligation (Art. 6(1)(c)) |
| Keeping accounting and tax records | invoices | Legal obligation (Art. 6(1)(c)) |
| Error monitoring and improving service reliability | technical data, logs | Legitimate interests (Art. 6(1)(f)) |
| Service-related communications | account, contact | Performance of a contract; legitimate interests |
| Optional communications (where offered) | contact | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests, those interests are the security, reliability and improvement of the Service and the protection of our rights; we always balance them against your rights and freedoms.
Under the revised Swiss FADP the same processing is justified on equivalent grounds (contract performance, legal obligation and overriding legitimate interest).
4. Cookies
We use strictly necessary (functional) cookies only:
- a session cookie (httpOnly) — to sign you in and maintain your session;
- a "2FA pending" cookie — temporary, during login;
- a language/locale cookie — to remember your chosen interface language.
We do not use third-party advertising or analytics cookies. Because all of our cookies are strictly necessary to operate the Service, no prior consent is required for them.
5. Who we share data with (sub-processors)
We do not sell personal data. We share it only with carefully selected service providers that process it on our behalf under data-processing agreements, solely to provide the Service:
- Hosting and database: Hetzner (Hetzner Online GmbH), servers located in the European Union;
- Object storage (S3-compatible): Cloudflare R2 (Cloudflare, Inc.), EU region, for media, invoice PDFs and logos;
- Payment processor: Payrexx AG (Switzerland) and the connected payment service providers;
- Email delivery (SMTP): Resend (Resend, Inc.) — for transactional emails (verification, password reset, invoices);
- Error monitoring: Sentry — for application error diagnostics.
We may also disclose data to authorities where required by law, and in connection with a corporate transaction (e.g. a merger or sale of the business), subject to appropriate safeguards.
6. International data transfers
We host our application and database in the European Union (Hetzner) and store uploaded media in the European Union (Cloudflare R2, EU region). Some of our providers are headquartered in the United States — Cloudflare (storage), Resend (email) and Sentry (error monitoring) — so personal data may be accessed from or transferred to the United States. We protect such transfers with an appropriate mechanism — an adequacy decision (including the Swiss–U.S. / EU–U.S. Data Privacy Framework where the provider is certified), or the European Commission's Standard Contractual Clauses (SCCs) together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner (FDPIC) — with additional measures where needed. You can request a copy of the relevant safeguards at [email protected].
7. Retention
- Account data and content: kept while your account is active and for a short period after closure (so you can reactivate or export), after which we delete or anonymise it.
- Invoices and accounting records: kept for as long as required by applicable accounting and tax law (under the Swiss Code of Obligations, generally 10 years).
- Security data: pairing codes and the IP addresses recorded in them expire after about 5 minutes; sessions are kept until they expire.
- Backups: rolling, with a limited retention window.
When we no longer need data for the purposes above or to meet a legal obligation, we delete or irreversibly anonymise it.
8. Data security
We apply appropriate technical and organisational measures, including:
- password hashing with Argon2;
- encryption of 2FA (TOTP) secrets with AES-256-GCM at rest;
- a passkey model in which secrets never leave the user's device;
- encryption of data in transit (TLS/HTTPS);
- processing of card data at a PCI-DSS-compliant payment processor;
- access controls and data-minimisation by design.
No system is perfectly secure, but we work to protect your data and, where the law requires, to notify you and the competent authority of a data breach.
9. Your rights
Under the GDPR and the Swiss FADP, you have the right to:
- access your personal data;
- rectify inaccurate or incomplete data;
- erasure ("right to be forgotten"), where the legal conditions are met;
- restrict processing;
- data portability (in a structured, machine-readable format);
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent (without affecting prior lawful processing).
You can carry out many of these actions yourself in your account settings (e.g. change your email, export or delete content, close your account). For other requests, contact us at [email protected]; we will respond within the time limits set by law.
Right to complain: if you are in Switzerland, you may contact the Federal Data Protection and Information Commissioner (FDPIC) (www.edoeb.admin.ch). If you are in the EU/EEA, you may lodge a complaint with your local supervisory authority.
10. Automated decision-making
Billing for the Service is automated (Screen-Day metering and automatic card charging), but we do not make decisions based solely on automated processing that produce legal or similarly significant effects within the meaning of Art. 22 GDPR, and we do not carry out profiling.
11. Our role as processor for your content
When you display content through the Service that contains personal data (for example, photographs of individuals), you are the controller of that data and Screencord acts as a processor, processing it only on your instructions to provide the Service. You confirm that you have a lawful basis and any necessary consents for that processing. The terms of that processing are governed by our Terms and Conditions and, where applicable, a separate Data Processing Agreement (DPA).
12. Children
The Service is intended for business users and is not directed at anyone under 18. We do not knowingly collect children's data.
13. Changes to this Policy
We may update this Policy from time to time. We will notify you of material changes by email and/or in-app notice before they take effect. The "last updated" date at the top reflects the latest revision.
14. Contact
For any privacy question or to exercise your rights:
T Minus One GmbH (trading as Screencord) Aubrigstrasse 22, 8833 Samstagern, Switzerland UID: CHE-306.571.225 Email: [email protected]