Privacy Policy
Last updated: 17 September 2026
This Privacy Policy explains how Poweron s.r.o. ("we", "us", "Bohemica Signage") collects, uses, stores and shares personal data when you visit our website, create an account, use the Bohemica Signage digital signage service (the "Service"), run our player software on your screens, or connect a third-party account such as Google or Microsoft to the Service.
It applies to the website www.bohemicasignage.com, the web application at app.bsgn.cc and other bsgn.cc subdomains, our APIs, the player operating system and any related support channels. This policy supplements our Terms of Use. Capitalised terms not defined here have the meaning given in the Terms of Use.
Contents:
- Who we are
- What data we collect
- Your content and your own users
- Sign in with Google or Microsoft
- Google user data (Google Slides integration)
- Microsoft user data (Power BI integration)
- Why we process data and on what legal basis
- Cookies and similar technologies
- Who we share data with
- Where data is stored and international transfers
- How long we keep data
- How we protect data
- Your rights
- Children
- Changes to this policy
- Contact
1. Who we are
The data controller for the personal data described in this policy is:
Poweron s.r.o.
Czech registration number (IČ): 062 05 712
Palachova 504/7, 460 01 Liberec, Czech Republic
Registered in the commercial register kept by the Regional Court in Ústí nad Labem, file C 39873/KSUL
E-mail: [email protected]
Bohemica Signage is a product of Poweron s.r.o. We have not appointed a data protection officer; privacy questions can be sent to the e-mail address above.
2. What data we collect
We only collect data that we need to provide, secure, bill and improve the Service. Depending on how you use it, this includes:
- Account and registration data. Your name, e-mail address, password (stored only as a salted hash), phone number (optional; required if you enable SMS two-factor authentication or ask for a welcome call), preferred language, preferred hosting region, registration code, the consents you gave at sign-up (Terms of Use, this policy, marketing e-mails, welcome call) and, if you sign in with Google or Microsoft, the identifier of that account (see section 4). If you enable two-factor authentication we also store your encrypted authenticator secret and recovery codes.
- Organisation and billing data. Company name, billing address, country, EU VAT ID, business registration number, billing e-mail, invoice notes, currency, chosen price plan, billing periods, invoices and payment history. When you save a payment card, the card details are entered directly on the page of our payment provider; we receive and store only the masked card number, expiry date and card brand together with a payment token.
- Workspace and content data. Media you upload (images, videos, audio, documents), web page addresses you add as content, playlists, schedules, folders, display and location names, team members you invite (name, e-mail, role), and configuration of integrations. Technical metadata about uploaded files (format, duration, resolution) and preview thumbnails are generated automatically.
- Device and screen data. Player devices paired to your account report the technical information needed to manage and monitor them, such as network identifiers (IP and MAC addresses), hardware and software details, connected screens and online status. If you share remote-support access details with us so that we can help you with a device, we store them for that purpose only.
- Location data. Names, time zones and map coordinates of the physical locations you create for your screens, and any network configuration details you choose to enter for them. We do not collect the location of your devices automatically.
- Security and usage logs. IP address, browser and operating system of each sign-in (shown to you in your account's login history), session data, the approximate location derived from the IP address of a new sign-in, records of e-mails we sent you, server logs and application error reports.
- Website and marketing data. When you use the contact or download forms on our website we collect your name, e-mail address, phone number (optional), whether you are an existing customer, your message and, if you arrived from an advertising campaign, the campaign parameters (utm_*) of that visit. We also collect usage data about the website through the analytics and advertising tools described in section 8.
- Support communication. The content of e-mails, calls and messages you exchange with our team.
3. Your content and your own users
Content you upload or schedule (your Media Library) and the personal data of people you invite to your workspace or otherwise include in that content belong to you. For this data you are the data controller and we act as your data processor: we process it only to provide the Service, according to your instructions and the data processing agreement that forms Annex No. 1 of the Terms of Use. You are responsible for having a lawful basis to upload such content and for informing the people concerned.
Web pages you add as content are periodically rendered by a headless browser to produce preview images. Only the public address you entered is used for this; no data about your account is attached to it.
4. Sign in with Google or Microsoft
You can create an account or sign in with a Google or Microsoft account instead of a password. When you do, we ask the identity provider only for basic profile information (the openid, email and profile scopes for Google; openid, profile and User.Read for Microsoft).
- We store the unique account identifier, your name and your e-mail address, and mark the account as a single sign-on account.
- We do not store the access or refresh tokens issued for signing in, your profile picture, your contacts or any other data from the provider.
- Signing in this way gives us no access to your files, e-mails, calendar or other content at Google or Microsoft.
You can review or remove Bohemica Signage's access at any time in your Google account permissions or your Microsoft account.
5. Google user data (Google Slides integration)
The Service lets you show Google Slides presentations on your screens. To do this you can connect a Google account to your workspace in the "Apps" section. This section describes exactly how we handle the data we receive from Google APIs through that connection, in line with the Google API Services User Data Policy.
What we ask for. When you connect a Google account we request the following OAuth scopes:
https://www.googleapis.com/auth/presentations.readonly– read-only access to Google Slides presentations, so that we can read the presentations you choose and render their slides on your screens.openid,email,profile– to identify the connected account by its e-mail address and name in your workspace settings.
We do not request access to Google Drive, Gmail, Calendar, Contacts, Photos, YouTube or any other Google service. We cannot see, list or search your files: we can only read the specific presentations whose link you paste into the Service.
What we access and how we use it. We use Google user data only to provide the feature you asked for, namely displaying the selected presentation on your screens and showing a preview of it in the dashboard:
- The e-mail address and name of the connected Google account, to label the connection in your workspace and to notify the person who created it if the connection stops working and needs to be re-authorised.
- For each presentation you add: its identifier, title, revision identifier and the list of its slides, and a rendered image of each slide. Slide images are downloaded to our servers and served from there to your screens; the temporary Google image links themselves are never passed on to devices or anyone else.
What we store.
- The OAuth access token and refresh token for the connection, encrypted at rest on our servers, so that your screens keep working without you having to sign in again. We ask Google for offline access for this reason. Tokens are refreshed automatically when they are about to expire and at least once a week.
- The list of scopes you granted, the connection status, the last error message (if any), and which member of your workspace created the connection.
- The identifier of each presentation you added and its display settings.
- Rendered slide images, cached for up to one hour so that many screens can show the same deck without exceeding Google's quotas, and one preview image per presentation that is kept as the item's thumbnail and regenerated daily.
What we do not do with Google user data. We do not use it for advertising, we do not sell it, we do not use it to build profiles, we do not use it to train artificial intelligence or machine learning models, and we do not transfer it to third parties except as strictly necessary to run the Service (our hosting provider, see section 9) or where required by law. Our staff do not read your Google data except with your permission (for example when you ask for support), for security purposes, or when the law requires it. Once downloaded, slide images are shared only with the screens and users of your own workspace.
Limited Use disclosure. Bohemica Signage's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How to disconnect and delete Google data. You can remove a Google connection at any time in the "Apps" section of the dashboard. When you do, we stop using the tokens immediately, delete the stored tokens, and content items that relied on the connection stop playing. You can also revoke our access directly at myaccount.google.com/permissions; the connection will then fail and we will no longer be able to access your presentations. Cached slide images expire within one hour; stored preview images are deleted together with the content item. Deleting your workspace or account deletes all remaining Google data associated with it. You may also ask us to delete this data at any time by e-mail (section 16).
6. Microsoft user data (Power BI integration)
In the same way, you can connect a Microsoft work account to show Power BI reports on your screens. We request the identity scopes (openid, profile, email, offline_access) and the Power BI permission needed to embed reports you have access to. We store the encrypted access and refresh tokens, the account e-mail and name, the granted scopes and the identifiers of the reports you added, and we use them only to render those reports on your screens. Everything said in section 5 about our use, sharing, retention and deletion of Google data applies equally to Microsoft data. If your organisation requires administrator consent, the Service shows you a link that your IT administrator can use to approve the connection.
7. Why we process data and on what legal basis
- To provide the Service (performance of a contract, GDPR Art. 6(1)(b)). Creating and managing your account and workspace, pairing and monitoring devices, storing and delivering your content to screens, running integrations you connect, sending transactional e-mails (verification, password reset, invitations, device alerts, billing notices) and providing support.
- To bill you and keep accounts (contract and legal obligation, Art. 6(1)(b) and (c)). Processing payments, issuing invoices and keeping tax and accounting records as required by Czech law.
- To keep the Service secure (legitimate interest, Art. 6(1)(f)). Authenticating users, two-factor authentication, alerting you to sign-ins from new devices, rate limiting, logging, error reporting, backups, preventing abuse and enforcing the Terms of Use.
- To improve the Service and our website (legitimate interest, Art. 6(1)(f), or consent where required by law). Analysing how the website and dashboard are used, recording sessions to find usability problems, and measuring the results of our advertising.
- To communicate with you (legitimate interest or consent). Answering your enquiries, and sending product news and marketing e-mails only if you opted in at sign-up. You can withdraw that consent at any time using the link in each e-mail or by contacting us.
- To comply with the law (legal obligation, Art. 6(1)(c)). Responding to lawful requests from authorities and meeting our regulatory obligations.
Where we rely on legitimate interests we have assessed that they are not overridden by your rights. You may object to such processing as described in section 13.
10. Where data is stored and international transfers
Your workspace, content and device data are stored on servers in the data centre region you select when registering: Nuremberg (Germany, EU), Ashburn (Virginia, USA) or Hillsboro (Oregon, USA). If you express no preference, we choose a region for you, normally within the European Union. Account, billing and sign-in data are stored in the European Union. Backups are stored in the same region as the data they protect.
Some of the providers listed in section 9 are located in, or may access data from, countries outside the European Economic Area, in particular the United States. Where that happens we rely on the European Commission's adequacy decisions (including the EU-US Data Privacy Framework for certified providers) or on the Commission's Standard Contractual Clauses together with additional safeguards. You can ask us for a copy of the relevant safeguards.
11. How long we keep data
We keep personal data only for as long as necessary for the purposes described in this policy:
- Account, workspace and content data – for as long as your account exists. Under the Terms of Use an account is considered terminated two years after its last sign-in, after which it and its content may be deleted. You can delete users, devices, locations, content and integrations yourself at any time, and you can ask us to delete your whole account.
- Google and Microsoft integration tokens – until you disconnect the account, revoke access, delete the workspace or ask us to delete them (section 5).
- Security logs, sign-in history and device status history – for a limited period, typically no longer than one year.
- Backups – on a rolling basis for a limited period, after which they are overwritten.
- Invoices and payment records – for the period required by Czech tax and accounting law.
- Error reports and session recordings – according to the retention settings of the respective tool, typically a few months at most.
- Website form submissions and support communication – for as long as needed to handle your request and thereafter to establish or defend legal claims.
Data may remain in backups for a short time after deletion. After the retention period we delete or anonymise the data.
12. How we protect data
We use technical and organisational measures appropriate to the risk, including: encryption of data in transit (TLS) on all our domains; hashing of passwords; encryption at rest of integration tokens, two-factor authentication secrets and recovery codes; optional two-factor authentication by authenticator app or SMS; e-mail alerts for sign-ins from new devices; rate limiting of sign-in attempts; a separate database for each customer workspace; an encrypted private network (VPN) between player devices and our servers; role-based access control within workspaces; restricted staff access on a need-to-know basis; regular backups; and monitoring and error tracking. No system is completely secure, so please choose a strong, unique password, enable two-factor authentication and tell us immediately if you suspect misuse of your account.
13. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data (most account data can be edited directly in the dashboard);
- erase your data where there is no longer a legal reason to keep it;
- restrict processing in certain circumstances;
- data portability – receive data you provided to us in a structured, machine-readable format;
- object to processing based on legitimate interests, and to direct marketing at any time;
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal;
- not be subject to automated decisions with legal or similarly significant effects (we do not make such decisions).
To exercise these rights, e-mail [email protected]. We may need to verify your identity first. We will respond within one month; this period may be extended by two further months for complex requests, in which case we will tell you.
If you believe we have processed your data unlawfully, you have the right to lodge a complaint with a supervisory authority, in particular the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.cz) or the authority of the EU member state where you live or work.
14. Children
The Service is intended for businesses and is not directed at persons under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to this policy
We may update this policy from time to time, for example when we add new features or integrations or when the law changes. The date at the top shows when it was last revised. For material changes we will notify you in the dashboard or by e-mail before they take effect. Continued use of the Service after that date means the updated policy applies.
16. Contact
Questions, requests and complaints about privacy can be sent to:
Poweron s.r.o. (Bohemica Signage)
Palachova 504/7, 460 01 Liberec, Czech Republic
E-mail: [email protected]