This English translation is provided for convenience. In case of any discrepancy, the original at cordsignage.com/pravila-privatnosti prevails.

Cord Signage — Privacy Policy

Effective date: June 29, 2026 Last updated: June 29, 2026


1. Introduction and Data Controller

This Privacy Policy explains how CORD, registered as a sole proprietorship (obrt) in Bosnia and Herzegovina, JIB 4329083140000, email [email protected] ("CORD", "we", "us"), collects and processes personal data in connection with the Cord Signage digital signage platform (the "Service").

CORD is the data controller of the personal data we process in order to provide the Service to account holders, as described in this Policy. For personal data contained in the content you upload or display through the Service, you are the controller and we act as a processor (see Section 11).

This Policy forms an integral part of our Terms of Use.


2. What Personal Data We Collect

We collect only the data necessary to provide and secure the Service:

a) Account and identity data

  • email address and username (derived from the email address);
  • password — stored solely as a cryptographic hash, never in plain form.

b) Authentication and security data

  • the two-factor authentication (TOTP) secret key, encrypted at rest;
  • registered passkeys / security keys — only the public key is stored; the private part never leaves your device;
  • 2FA backup codes — stored as hashes;
  • session identifiers and a short-lived "awaiting 2FA" identifier;
  • the IP address recorded at the time of device pairing (the pairing code is valid for about 5 minutes, after which the record expires).

c) Billing and payment data

  • billing profile: first and last name, address, city, postal code, country;
  • invoices, payment history, and usage data (Screen-Days);
  • a reference token for your card, together with the card brand, last 4 digits, and expiration date. We do not store your full card number — it is held by the payment processor in accordance with card scheme standards (PCI-DSS).

d) Content you provide to us

  • media you upload (images, video), designs, playlists, schedules, and device names. This content may contain personal data that you choose to include; for that data, you are the controller (see Section 11).

e) Usage and technical data

  • connected screens, the device's last activity time ("last seen"), usage events (adding/removing screens);
  • application logs and error reports.

f) Communications

  • the content of messages you send us (e.g., support requests by email).

We do not collect special categories of personal data, and we do not use the Service for advertising or for tracking you on other sites.


3. Purposes of Processing and Legal Basis

Purpose Data categories Legal basis (Art. 6 GDPR)
Creating and maintaining your account, providing the Service account, content, usage Performance of a contract (Art. 6(1)(b))
Authentication, 2FA, protection against abuse and fraud security data, pairing IP Legitimate interest (Art. 6(1)(f)); performance of a contract
Metering, billing, and invoicing billing, payment, usage Performance of a contract; legal obligation (Art. 6(1)(c))
Keeping accounting and tax records invoices Legal obligation (Art. 6(1)(c))
Error monitoring and improving Service stability technical data, logs Legitimate interest (Art. 6(1)(f))
Service-related communication (service notices) account, contact Performance of a contract; legitimate interest
Optional communication (where applicable) contact Consent (Art. 6(1)(a))

Where processing is based on legitimate interest, that interest is the security, reliability, and improvement of the Service and the protection of our rights; we always balance it against your rights and freedoms.


4. Cookies

We use only essential (functional) cookies:

  • a session cookie (httpOnly) — for signing in and maintaining your session;
  • an "awaiting 2FA" cookie — temporary, used during sign-in;
  • a language/localization cookie — remembers your chosen interface language.

We do not use third-party advertising or analytics cookies. Because all cookies are strictly necessary for the operation of the Service, no prior consent is required for them.


5. With Whom We Share Data (Sub-Processors)

We do not sell personal data. We share it only with carefully selected service providers who process it on our behalf, under data processing agreements, solely for the purpose of providing the Service:

  • Hosting and database: Hetzner (Hetzner Online GmbH), servers located in the European Union;
  • File storage (S3-compatible object storage): Cloudflare R2 (Cloudflare, Inc.), region: European Union — for media, PDF invoices, and logos;
  • Payment processor: Bankart (payment gateway) and its associated banks/acquiring partners;
  • Email delivery (SMTP): Resend (Resend, Inc.) — for transactional emails (verification, password reset, invoices);
  • Error monitoring: Sentry — for diagnosing application errors.

We may also disclose data to competent authorities where required by law, and in connection with corporate changes (e.g., a merger or sale of the business), subject to appropriate safeguards.


6. International Data Transfers

We host the application and database in the European Union (Hetzner) and store uploaded media in the European Union (Cloudflare R2, EU region). Some of our service providers are headquartered in the United States — Cloudflare (storage), Resend (email), and Sentry (error monitoring) — so data may be transferred to, or accessed from, the US. We protect such transfers with appropriate mechanisms — an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs), with supplementary measures where needed. You may request a copy of the relevant safeguards at [email protected].


7. Retention Period

  • Account data and content: retained while the account is active and for a short period after closure (so that you can reactivate the account or export your data), after which we delete or anonymize them.
  • Invoices and accounting records: retained for as long as required by the applicable accounting and tax regulations of Bosnia and Herzegovina (10 years).
  • Security data: pairing codes and the IP addresses recorded with them expire after about 5 minutes; sessions are retained until their validity expires.
  • Backups: rotating, with a limited retention period.

When we no longer need to retain data for the purposes described above or for legal obligations, we delete it or irreversibly anonymize it.


8. Data Security

We apply appropriate technical and organizational measures, including:

  • password hashing using the Argon2 algorithm;
  • encryption of 2FA (TOTP) secrets at rest using the AES-256-GCM algorithm;
  • a passkey model in which secrets never leave the user's device;
  • encrypted data transmission (TLS/HTTPS);
  • card data processing by a payment processor compliant with the PCI-DSS standard;
  • access controls and the principle of data minimization.

No system is absolutely secure, but we strive to protect your data and, where required by law, to notify you and the competent authority in the event of a data breach.


9. Your Rights

In accordance with the GDPR and the Law on Personal Data Protection of Bosnia and Herzegovina, you have the right to:

  • access your personal data;
  • rectification of inaccurate or incomplete data;
  • erasure (the "right to be forgotten"), in the cases provided for by law;
  • restriction of processing;
  • data portability (in a structured, machine-readable format);
  • object to processing based on legitimate interest;
  • withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of prior processing).

You can carry out many of these actions yourself in your account settings (e.g., changing your email, exporting/deleting content, closing your account). For other requests, contact us at [email protected]; we will respond within the time limits prescribed by law.

Right to lodge a complaint: if you believe that we are processing your data in violation of the regulations, you may lodge a complaint with the Personal Data Protection Agency of Bosnia and Herzegovina (AZLP) (www.azlp.ba). Users residing in the EU may also contact their competent data protection supervisory authority.


10. Automated Decision-Making

Billing for the Service is automated (Screen-Day metering and automatic card charging), but we do not make decisions based solely on automated processing that would produce legal or similarly significant effects concerning you within the meaning of Article 22 GDPR, nor do we carry out profiling.


11. Our Role as Processor for Your Content

When you display content containing personal data through the Service (e.g., photographs of individuals), you are the controller of that data, and CORD acts as a processor that processes it solely on your instructions, for the purpose of providing the Service. You represent that you have a lawful basis for such processing and the necessary consents. The terms of that processing are governed by our Terms of Use and, where applicable, a separate data processing agreement (DPA).


12. Children

The Service is intended for business users and is not directed at persons under 18 years of age. We do not knowingly collect children's data.


13. Changes to This Policy

We may update this Policy from time to time. We will notify you of material changes by email and/or in-app notification before they take effect. The date of the last update is stated at the top of this document.


14. Contact

For any privacy questions or to exercise your rights:

CORD (sole proprietorship — obrt) JIB: 4329083140000 Email: [email protected]

Digital signage – managing content on screens. Simple enough for one café, ready for a whole chain.

Made in Bosnia and Herzegovina

Product
  • Features
  • How it works
  • Hardware
  • Pricing
  • FAQ
Account
  • Sign in
  • Create an account
Contact
  • [email protected]
© 2026 Cord · All rights reserved.
Terms of Use Privacy Policy
app.cordsignage.com