Política de privacidade
Esta política de privacidade explica como a CASTOVIA recolhe, utiliza, armazena e protege os seus dados pessoais.
1. Data Controller
CASTOVIA is operated from Switzerland. For all data protection inquiries, contact us at [email protected].
2. Data We Collect
Account Data:
- Name, email address, company name (provided at signup)
- Password (stored as a secure hash, never in plain text)
- IP address and user agent at login
Platform Usage Data:
- Admin actions (activity logs for audit purposes)
- Stream configurations, VOD metadata, subscriber line data
- Server registration data (hostname, IP, agent metrics)
Subscriber Data (managed by operators):
- Subscriber usernames, connection data, and IP addresses
- This data is managed by the operator (our customer), not by end subscribers directly
- Operators are responsible for their own subscriber privacy compliance
Contact Data:
- Name, email, company, and message content from the contact form
3. How We Use Your Data
- Account management: To create and maintain your operator account
- Service delivery: To provide the IPTV management platform
- Security: To protect against unauthorised access and abuse
- Communication: To respond to inquiries and send service notifications (server offline alerts, welcome emails)
- Audit: To maintain activity logs for operational transparency
We do not sell, rent, or share your personal data with third parties for marketing purposes.
4. Data Storage & Security
- Data is stored in secure, managed databases with encryption at rest
- Passwords are hashed using industry-standard algorithms
- All communications use HTTPS encryption
- Multi-tenant data isolation ensures your data is separated from other operators
- Access to production systems is restricted and logged
5. Data Retention
We retain your data for as long as your account is active. Upon account deletion:
- Account data is deleted within 30 days
- Activity logs may be retained for up to 90 days for security purposes
- Anonymised usage statistics may be retained indefinitely
6. Your Rights
Under applicable data protection laws (including GDPR and Swiss FADP), you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate personal data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to certain processing of your data
To exercise any of these rights, contact [email protected].
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on the platform. Continued use after changes constitutes acceptance.