Legally binding · GDPR compliant

Privacy Policy

This policy describes what data the Signaro mobile app and the Signaro Player process. Signaro is deliberately local-first and does not collect data beyond what is described here.

Last updated: August 1, 2026 No tracking, no advertising cookies
🔒
Local-first
Playlist delivery runs over your local network or via Bluetooth — directly between your devices, without any detour through external servers.
🚫
No analytics
We do not analyze your usage behavior — no tracking or advertising SDKs are used.
🛠️
Full control
Devices and content can be reviewed and deleted at any time — no account required.
Show table of contents
Courtesy translation This English version is provided for your convenience. In the event of any discrepancy or ambiguity, the German original is legally binding.

01 Overview

Signaro is a platform for digital signage. Using the mobile app, you create content and playlists and transfer them to Signaro Player devices or e-paper displays.

The transfer of content from the app to a device happens exclusively locally: over your Wi-Fi or via Bluetooth, directly between the app and the device. A user account and an internet connection to our servers are not required for this.

Scope of the current version The currently released version operates entirely locally and without any account or registration requirement. We continuously develop Signaro further; future updates may introduce additional, optional features. Should such an extension require additional processing of personal data, we will update this privacy policy before its introduction and notify you in the app before you use the feature in question (see item 12).

This privacy policy applies to all components of the current platform: the mobile app (iOS & Android, brands "Signaro" and "Wolk") as well as the firmware of the Signaro Player and Seeed E1002 devices.

02 Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

AZ Buchstaben GmbH

Kassler Landstraße 13

37213 Witzenhausen, Germany

Email: datenschutz@signaro.eu

Represented by: Nicolas Döring · Commercial register: Eschwege Local Court, HRB 2053

03 What data we process

We follow the principle of data minimization: only what is actually needed for the respective function is collected. The table below shows all data categories that may occur within the platform.

CategoryExamplesPurposeLegal basis
Device & pairing data Device ID, device name, IP address on the local network, firmware/app version, storage utilization, playback status Pairing of app and device, status display, remote maintenance/updates Art. 6(1)(b), (f) GDPR
Camera (QR code scan) Camera image is processed exclusively for local QR code recognition Device pairing via QR code Art. 6(1)(b) GDPR
Bluetooth & local network Device addresses in the vicinity, transmitted content packages Direct device-to-device communication for content push and pairing Art. 6(1)(b) GDPR
Crash & diagnostic data
mobile app only
Technical error reports (stack trace, app version, operating system) via Sentry Error analysis, stability, further development Art. 6(1)(f) GDPR (legitimate interest)

App permissions (operating system)

For the functions listed above, the mobile app requests the following permissions from your operating system:

  • Camera: exclusively for scanning QR codes for device pairing; no photos or videos are taken or stored.
  • Bluetooth: for direct pairing and content transfer between the app and the Signaro device in close proximity.
  • Local network: to find and communicate with Signaro devices on your Wi-Fi.

These permissions are used exclusively for the purposes stated and are not used for location determination or advertising purposes. The device addresses visible in the vicinity, as well as the content transmitted via Bluetooth or the local network, are exchanged exclusively between the app and the device; this information is not transmitted to our servers.

To the extent we rely on our legitimate interest (Art. 6(1)(f) GDPR), the following brief balancing of interests applies: for device and pairing data, our interest lies in reliably operating the pairing between app and device and enabling remote maintenance and updates. For the crash and diagnostic data collected via Sentry, our legitimate interest lies in detecting errors, increasing app security, and ensuring software stability. Since in both cases only technical data is processed, without any conclusions about users' private behavior, users' interests do not outweigh our interest in processing.

What does not happen Your playlists, images, banner designs, and playlist content do not leave your device or your Wi-Fi. We do not evaluate the substance of your content. Device status (storage space, active package, playback status) is queried exclusively locally via LAN or Bluetooth between the app and the device and is not transmitted to us or stored by us.

04 How it works & local data processing

Signaro is deliberately designed to be "local-first": the app and the Signaro Player devices communicate directly with each other, without content or control commands passing through our servers.

  • Device pairing takes place either via QR code scan or by selecting the device on the shared Wi-Fi network. A session token is negotiated locally between the app and the device, valid exclusively for that connection.
  • Content transfer (playlists, images, banner designs) takes place directly over your local network or via Bluetooth.
  • Status queries (storage space, active package, playback status) are retrieved live over the local connection as needed and are not stored by us.

Operation requires neither a user account nor a permanent internet connection. Possible future extensions of the platform are described in item 12.

05 Recipients & service providers used

We currently use a single external service provider that comes into contact with personal data:

Service providerFunctionData processedLocation
Functional Software, Inc. (Sentry) Crash reports for the mobile app Stack trace, device model, app/OS version, no plain-text account data EU region (EU data residency)

We do not transfer data to any other third parties, in particular not for advertising purposes. We do not sell data. Should additional service providers be added in the future, we will include them in this overview before their use and update this privacy policy accordingly.

06 International data transfer

Our service provider Sentry processes the crash and diagnostic data collected via the mobile app in the EU region (EU data residency). No transfer of personal data to countries outside the EU/EEA therefore currently takes place in connection with error analysis.

Beyond this, no transfer of personal data to countries outside the EU/EEA currently takes place. Should this change as a result of future feature extensions or a change of service providers used, we will base such transfers on an adequacy decision of the EU Commission or on EU standard contractual clauses (Art. 46 GDPR) and inform you in advance as part of the updated privacy policy (see item 12).

07 Retention period

  • Device & pairing data: remains exclusively local on the app and device for as long as the pairing exists, and is removed upon unpairing or deleting the device in the app.
  • Live status queries (storage space, active package, playback status): not stored, retrieved exclusively live over the local connection as needed.
  • Crash reports (Sentry): according to Sentry's standard retention, generally 90 days.
  • Local app data (playlists, images, settings): remain on your device until you delete them or uninstall the app.

08 Data security

We employ technical and organizational measures to protect your data:

  • Device-side authentication via a session token that is renegotiated between the app and the device with every pairing process and applies exclusively to that connection.
  • Local content is signed before playback and verified on the device to detect tampering.
  • Pairing and session tokens are stored encrypted on the mobile device in the system's secure storage (iOS Keychain / Android Keystore), not in plain text.
  • Communication between the app and the device is limited to the local network or Bluetooth; there is no permanently open connection to external servers.
  • Access to diagnostic data at our service provider Sentry is restricted to authorized staff and used exclusively for error analysis purposes.

Despite all due care, complete protection against any kind of third-party access cannot be guaranteed.

09 Local storage on the device

The mobile app does not use cookies. Pairing and session tokens for the connection to your Signaro devices are stored encrypted in your mobile device's secure system storage (iOS Keychain / Android Keystore, Art. 6(1)(b) GDPR). Analytics, marketing, or third-party tracking are not used.

10 Your rights under the GDPR

You have the following rights regarding your personal data:

  • Access (Art. 15 GDPR) to the data we process
  • Rectification (Art. 16 GDPR) of inaccurate data
  • Erasure (Art. 17 GDPR), e.g. by deleting paired devices or content directly in the app
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR) in a common, machine-readable format
  • Objection to processing based on legitimate interest (Art. 21 GDPR)
  • Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR)
  • Complaint to a data protection supervisory authority (Art. 77 GDPR)

To exercise these rights, an informal message to the contact address given in item 13 is sufficient.

11 Minors

Signaro is aimed at business customers and their employees and is not designed for use by children. Persons under the age of 16 should not create an account without the consent of a parent or legal guardian.

12 Future development & changes to this policy

Signaro is continuously being developed further. Future updates may introduce additional, optional features — for example account-based management of multiple devices or locations for organizations. Should such an extension involve processing of personal data beyond the scope described in this policy, we will publish an updated version of this privacy policy before its introduction and notify you in the app before the feature in question can be actively used.

We also adapt this privacy policy as existing features or the legal situation change. The current version can always be found at this address; the date of the last update is shown at the top of this page.

13 Contact & supervisory authority

Please direct questions about data protection to datenschutz@signaro.eu.

If you believe that the processing of your personal data violates the GDPR, you have the right — without prejudice to any other administrative or judicial remedy — to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for our company's registered office in Witzenhausen (Hesse) is:

Hessian Commissioner for Data Protection and Freedom of Information (HBDI)

Postfach 3163, 65021 Wiesbaden, Germany

Visitor address: Wilhelmstraße 7, 65185 Wiesbaden

Phone: +49 611 1408-0

Email: poststelle@datenschutz.hessen.de

Web: datenschutz.hessen.de