01 Overview
Signaro is a platform for digital signage. Using the mobile app, you create content and playlists and transfer them to Signaro Player devices or e-paper displays.
The transfer of content from the app to a device happens exclusively locally: over your Wi-Fi or via Bluetooth, directly between the app and the device. A user account and an internet connection to our servers are not required for this.
This privacy policy applies to all components of the current platform: the mobile app (iOS & Android, brands "Signaro" and "Wolk") as well as the firmware of the Signaro Player and Seeed E1002 devices.
02 Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
AZ Buchstaben GmbH
Kassler Landstraße 13
37213 Witzenhausen, Germany
Email: datenschutz@signaro.eu
Represented by: Nicolas Döring · Commercial register: Eschwege Local Court, HRB 2053
03 What data we process
We follow the principle of data minimization: only what is actually needed for the respective function is collected. The table below shows all data categories that may occur within the platform.
| Category | Examples | Purpose | Legal basis |
|---|---|---|---|
| Device & pairing data | Device ID, device name, IP address on the local network, firmware/app version, storage utilization, playback status | Pairing of app and device, status display, remote maintenance/updates | Art. 6(1)(b), (f) GDPR |
| Camera (QR code scan) | Camera image is processed exclusively for local QR code recognition | Device pairing via QR code | Art. 6(1)(b) GDPR |
| Bluetooth & local network | Device addresses in the vicinity, transmitted content packages | Direct device-to-device communication for content push and pairing | Art. 6(1)(b) GDPR |
| Crash & diagnostic data mobile app only |
Technical error reports (stack trace, app version, operating system) via Sentry | Error analysis, stability, further development | Art. 6(1)(f) GDPR (legitimate interest) |
App permissions (operating system)
For the functions listed above, the mobile app requests the following permissions from your operating system:
- Camera: exclusively for scanning QR codes for device pairing; no photos or videos are taken or stored.
- Bluetooth: for direct pairing and content transfer between the app and the Signaro device in close proximity.
- Local network: to find and communicate with Signaro devices on your Wi-Fi.
These permissions are used exclusively for the purposes stated and are not used for location determination or advertising purposes. The device addresses visible in the vicinity, as well as the content transmitted via Bluetooth or the local network, are exchanged exclusively between the app and the device; this information is not transmitted to our servers.
To the extent we rely on our legitimate interest (Art. 6(1)(f) GDPR), the following brief balancing of interests applies: for device and pairing data, our interest lies in reliably operating the pairing between app and device and enabling remote maintenance and updates. For the crash and diagnostic data collected via Sentry, our legitimate interest lies in detecting errors, increasing app security, and ensuring software stability. Since in both cases only technical data is processed, without any conclusions about users' private behavior, users' interests do not outweigh our interest in processing.
04 How it works & local data processing
Signaro is deliberately designed to be "local-first": the app and the Signaro Player devices communicate directly with each other, without content or control commands passing through our servers.
- Device pairing takes place either via QR code scan or by selecting the device on the shared Wi-Fi network. A session token is negotiated locally between the app and the device, valid exclusively for that connection.
- Content transfer (playlists, images, banner designs) takes place directly over your local network or via Bluetooth.
- Status queries (storage space, active package, playback status) are retrieved live over the local connection as needed and are not stored by us.
Operation requires neither a user account nor a permanent internet connection. Possible future extensions of the platform are described in item 12.
05 Recipients & service providers used
We currently use a single external service provider that comes into contact with personal data:
| Service provider | Function | Data processed | Location |
|---|---|---|---|
| Functional Software, Inc. (Sentry) | Crash reports for the mobile app | Stack trace, device model, app/OS version, no plain-text account data | EU region (EU data residency) |
We do not transfer data to any other third parties, in particular not for advertising purposes. We do not sell data. Should additional service providers be added in the future, we will include them in this overview before their use and update this privacy policy accordingly.
06 International data transfer
Our service provider Sentry processes the crash and diagnostic data collected via the mobile app in the EU region (EU data residency). No transfer of personal data to countries outside the EU/EEA therefore currently takes place in connection with error analysis.
Beyond this, no transfer of personal data to countries outside the EU/EEA currently takes place. Should this change as a result of future feature extensions or a change of service providers used, we will base such transfers on an adequacy decision of the EU Commission or on EU standard contractual clauses (Art. 46 GDPR) and inform you in advance as part of the updated privacy policy (see item 12).
07 Retention period
- Device & pairing data: remains exclusively local on the app and device for as long as the pairing exists, and is removed upon unpairing or deleting the device in the app.
- Live status queries (storage space, active package, playback status): not stored, retrieved exclusively live over the local connection as needed.
- Crash reports (Sentry): according to Sentry's standard retention, generally 90 days.
- Local app data (playlists, images, settings): remain on your device until you delete them or uninstall the app.
08 Data security
We employ technical and organizational measures to protect your data:
- Device-side authentication via a session token that is renegotiated between the app and the device with every pairing process and applies exclusively to that connection.
- Local content is signed before playback and verified on the device to detect tampering.
- Pairing and session tokens are stored encrypted on the mobile device in the system's secure storage (iOS Keychain / Android Keystore), not in plain text.
- Communication between the app and the device is limited to the local network or Bluetooth; there is no permanently open connection to external servers.
- Access to diagnostic data at our service provider Sentry is restricted to authorized staff and used exclusively for error analysis purposes.
Despite all due care, complete protection against any kind of third-party access cannot be guaranteed.
09 Local storage on the device
The mobile app does not use cookies. Pairing and session tokens for the connection to your Signaro devices are stored encrypted in your mobile device's secure system storage (iOS Keychain / Android Keystore, Art. 6(1)(b) GDPR). Analytics, marketing, or third-party tracking are not used.
10 Your rights under the GDPR
You have the following rights regarding your personal data:
- Access (Art. 15 GDPR) to the data we process
- Rectification (Art. 16 GDPR) of inaccurate data
- Erasure (Art. 17 GDPR), e.g. by deleting paired devices or content directly in the app
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) in a common, machine-readable format
- Objection to processing based on legitimate interest (Art. 21 GDPR)
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
- Complaint to a data protection supervisory authority (Art. 77 GDPR)
To exercise these rights, an informal message to the contact address given in item 13 is sufficient.
11 Minors
Signaro is aimed at business customers and their employees and is not designed for use by children. Persons under the age of 16 should not create an account without the consent of a parent or legal guardian.
12 Future development & changes to this policy
Signaro is continuously being developed further. Future updates may introduce additional, optional features — for example account-based management of multiple devices or locations for organizations. Should such an extension involve processing of personal data beyond the scope described in this policy, we will publish an updated version of this privacy policy before its introduction and notify you in the app before the feature in question can be actively used.
We also adapt this privacy policy as existing features or the legal situation change. The current version can always be found at this address; the date of the last update is shown at the top of this page.
13 Contact & supervisory authority
Please direct questions about data protection to datenschutz@signaro.eu.
If you believe that the processing of your personal data violates the GDPR, you have the right — without prejudice to any other administrative or judicial remedy — to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for our company's registered office in Witzenhausen (Hesse) is:
Hessian Commissioner for Data Protection and Freedom of Information (HBDI)
Postfach 3163, 65021 Wiesbaden, Germany
Visitor address: Wilhelmstraße 7, 65185 Wiesbaden
Phone: +49 611 1408-0