AdCast Privacy Notice (GDPR)
GDPR & Data Protection
TIMONIX DOO · Carkovacka 30v, 34206 Donja Sabanta, Serbia · privacy@adcast.app
Last updated:
1) Scope & Roles
Controller: For our website, user accounts, billing, customer support, marketing, security, product analytics/telemetry, and similar first-party processing, TIMONIX DOO, the operator of AdCast Digital Signage, acts as the data controller.
Processor: When personal data is processed through AdCast Digital Signage on behalf of a business customer, TIMONIX DOO acts as a data processor and the applicable business customer acts as the data controller. That processing is governed by our Data Processing Addendum (DPA).
EU/EEA Representative (Art. 27 GDPR)
In accordance with Article 27 of the EU General Data Protection Regulation (“GDPR”), TIMONIX DOO has appointed the following representative in the European Union:
Aleksandar Milenkovic
Piazza Giuditta Tavani Arquati 119
00153 Rome, Italy
gdpr@timonix.com
Submit a GDPR request
EU data subjects and EU Data Protection Authorities may contact our EU Representative regarding matters related to the processing of personal data and the exercise of rights under the GDPR through ourGDPR request form.
We have not appointed a Data Protection Officer as we do not meet the statutory criteria. You may contact us at privacy@adcast.app.
2) What Personal Data We Process (Controller)
- Account & Identity: name, email, password hash, organization, country.
- Billing: payment token/ID, last-4, VAT/tax info, invoices (via payment provider).
- Device & Display: device/display IDs, OS/version, app version, screen size/orientation, IP address, coarse location (from IP).
- Service Telemetry: playlist/ad playback events, timestamps, error/crash logs, performance metrics.
- Support & Communications: tickets, chat/email content, attachments, feedback.
- Marketing Preferences: newsletter opt-in/out, campaign/UTM data (only if non-essential cookies/SDKs are consented).
- Cookies & Online IDs: strictly necessary cookies; non-essential analytics/ads only after consent.
- Push Notification Token: FCM device token generated by Firebase Cloud Messaging when you grant notification permission; used solely to deliver push notifications to your device.
3) Purposes & Lawful Bases
| Purpose | Examples of Data | Lawful Basis |
|---|---|---|
| Provide & maintain the service | account, device, telemetry | Contract (Art. 6(1)(b)) |
| Billing, fraud prevention, tax | payment token/ID, invoices | Legal obligation (Art. 6(1)(c)); Legitimate interests (Art. 6(1)(f)) |
| Security & reliability | IP, device info, logs, crash data | Legitimate interests (service security, Art. 6(1)(f)) |
| Customer support | contact details, ticket content | Contract; Legitimate interests |
| Product analytics/A-B tests (non-essential) | cookies/online IDs | Consent (Art. 6(1)(a)) |
| Marketing communications | email, preferences | Consent (withdraw anytime) |
| Push notifications (screen alerts, content updates, account notices) | FCM device token | Consent (withdraw anytime via device notification settings) |
When we act as a processor, the customer is the controller and determines the lawful basis; we process only on documented instructions (see DPA).
5) Recipients & Sub-Processors
We use vetted vendors under data-processing agreements and appropriate safeguards. We disclose the minimum necessary data for the stated purposes. Customers will be notified of material sub-processor changes as required by the DPA.
| Vendor | Purpose | Typical Data | Region | Safeguard |
|---|---|---|---|---|
| Amazon Web Services (AWS) – S3, CloudFront, Lambda, MediaConvert | Hosting, storage, media processing, CDN | media files, telemetry, logs | EU/US (per service config) | SCCs; encryption at rest/in transit |
| Firebase Cloud Messaging (Google) | Push notifications | device token, app ID | Global (incl. US) | SCCs; limited use of tokens |
| Stripe / RevenueCat | Payments/subscriptions | payment token/ID, receipts | US/EU | SCCs; PCI-DSS |
| Sentry | Error & crash reporting | crash logs, stack traces, device/app metadata | EU/US (per plan) | SCCs; PII scrubbing |
| Email (e.g., Amazon SES) | Transactional emails | email address, metadata | US/EU (per region) | SCCs |
| Analytics (if enabled) – [e.g., GA4 or Plausible] | Product analytics | pseudonymous IDs, events | [EU/self-hosted/US] | Consent-based; SCCs if outside EEA/UK |
| Support (if used) – [e.g., Help Scout/Intercom] | Ticketing/chat | contact details, ticket content | [EU/US] | SCCs |
6) International Transfers & TIAs
When personal data is transferred outside the EEA/UK (e.g., to the United States), we rely on the European Commission’s Standard Contractual Clauses (and UK Addendum where applicable), apply supplementary measures (encryption, access controls, data minimization), and document transfer impact assessments for significant transfers. Where a vendor participates in an adequacy framework (e.g., EU–US Data Privacy Framework), we may rely on it in addition to SCCs where appropriate.
7) Security (Art. 32)
- Encryption in transit (TLS) and at rest (e.g., S3 SSE); key management.
- Least-privilege access, RBAC/MFA, audit logging, and monitoring.
- Network segmentation, WAF/CDN protections, throttling/rate limiting.
- Secure SDLC: code review, dependency scanning, secret hygiene.
- Incident response playbooks, on-call procedures, evidence collection.
- Backups and disaster recovery with periodic restore testing.
- Vendor due diligence and contractual security obligations.
8) Data Retention
We keep personal data only as long as necessary for the purposes described above or to meet legal obligations, then delete or irreversibly anonymize it.
TIMONIX DOO retains personal data only for as long as necessary for the purposes for which it was collected or processed, including providing and securing the AdCast Digital Signage services, fulfilling contractual obligations, resolving disputes, and complying with applicable legal obligations.
9) Your Rights (EEA/UK)
You can request access, rectification, erasure, restriction, portability, and objection, and you may withdraw consent at any time (withdrawal does not affect prior lawful processing). We respond within one month (extendable by two months for complex requests) and may verify your identity.
How to exercise: use our GDPR request form or email privacy@adcast.app.
You may lodge a complaint with your local supervisory authority (EU list via the EDPB; UK: ICO).
10) Children
AdCast is not directed to children and should not be used by individuals under the age of 16 without parental consent where required by law.
11) Automated Decision-Making
We do not make decisions producing legal or similarly significant effects solely by automated means. If this changes, we will provide meaningful information and a right to human review.
12) Data Breach Notification
We assess suspected personal-data incidents without undue delay. Where required, we notify the competent supervisory authority within 72 hours and affected individuals without undue delay.
13) Changes
We may update this page to reflect legal, technical, or business developments. We will indicate the “Last updated” date and, where appropriate, notify you.
14) Contact
TIMONIX DOO
Carkovacka 30v
34206 Donja Sabanta, Serbia
Email: privacy@adcast.app
Phone: +381 63 302 531
Appendix A - Processor Activities (Summary for Customers)
Subject matter & duration: operation of AdCast Player and related services for the term of the customer agreement.
Nature & purpose: storage, transmission, processing of media/playlists, device telemetry, and related support.
Types of data: device/display IDs, playback timestamps/events, IP address, user/admin account details in the customer workspace, support content.
Categories of data subjects: customer admins and users, and display operators, to the extent their personal data is processed through the Services.
Customer responsibilities: provide a lawful basis and transparent notices to end users, configure retention, and honor data-subject rights requests directed to them as controller.
AdCast obligations: process only on documented instructions; confidentiality; security measures; sub-processor controls; assist with data rights, DPIAs, and incidents; delete/return data at end of services; audits per the DPA. See /dpa.