Privacy Policy
Effective 18 July 2026
This policy covers people who use the Marketing Team platform — workspace members signing in at marketing.onscreen.io. Data our customers (tenants) process about their end customers is governed by our Data Processing Agreement, under which we act as processor; each tenant’s own privacy policy covers their customers.
Controller
Onscreen ApS, CVR 30363698, Folkvarsvej 2A, 4th, 2000 Frederiksberg, Denmark. Contact: hello@onscreen.io. No Data Protection Officer is appointed; none is required at our current scale.
What we process, why, and on what basis
| Data | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Name, work email | Account, sign-in (magic links), invitations | Contract (Art. 6(1)(b)) | Life of the account + 30 days |
| Session data (database-backed sessions, IP address, user agent) | Authentication and session security | Contract; legitimate interest (security) | Life of the session; security logs 90 days |
| Activity and audit records (who approved or edited what) | The product’s core review-accountability feature | Contract (Art. 6(1)(b)) | Life of the workspace (part of tenant audit history) |
| Support communications | Providing support | Contract; legitimate interest | 24 months |
We do not sell personal data, run third-party advertising or tracking, or profile users.
Cookies
Strictly necessary cookies (the session cookie for sign-in and CSRF/security cookies) plus one functional preference cookie that remembers how you last chose to display the asset gallery (view and tile shape) — set only when you click those toggles, kept in your browser for a year, never sent anywhere else. No marketing cookies and no third-party analytics cookies. Should we introduce first-party product analytics or cookie-based analytics, this policy will be updated first (with consent where required).
Recipients (subprocessors)
We use the following subprocessors under GDPR Art. 28 terms. We announce additions with advance notice in-app.
| Provider | Role | Location |
|---|---|---|
| Railway | Application and database hosting | EU (Amsterdam) |
| Resend | Transactional email (sign-in links, invitations) | EU sending region |
| Anthropic | AI processing (content generation). Member personal data is not included in AI prompts. | US, under EU Standard Contractual Clauses |
Data from connected platforms (Meta, Google)
When a workspace administrator connects an advertising or analytics account (for example a Meta ad account), we store the connection tokens encrypted and ingest advertising performance data (campaign metrics, spend, impressions) for that account. We request read-only permissions until the workspace explicitly enables publishing features. We do not receive or store end-consumer personal data from these platforms. Disconnecting the integration stops ingestion and revokes our access; data deletion instructions describe how to have stored platform data deleted.
International transfers
Hosting, storage and backups are EU-resident by default. Transfers to the US occur only as listed under subprocessors, safeguarded by EU Standard Contractual Clauses.
Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection. Contact hello@onscreen.io to exercise them — see also data deletion instructions. You may lodge a complaint with Datatilsynet (the Danish Data Protection Authority), datatilsynet.dk.
Security
Row-level tenant isolation enforced in the database, role-based access control, encrypted transport and storage, audited access, and EU-resident backups with tested restore procedures.
Changes
We announce material changes in-app 30 days ahead.