Parties and agreement
The company identified in its account and agreement is the controller, or a processor acting with its controller’s authorization. The Connecterman operator below is its processor or subprocessor for company delivery data. Separate account administration and service security processing are described in the privacy policy.
Operator details pendingContact email pendingThese terms must be incorporated into a binding agreement with an authorized company representative before processing company personal data on its behalf. Contact the operator to record the company’s legal identity, authorized representative, instructions and acceptance. Creating an employee account or reading this page does not by itself establish authority to bind the company.
These terms address Article 28 of the GDPR and Article 9 of the Swiss Federal Act on Data Protection where applicable. Mandatory law prevails over conflicting contractual terms.
Processing details
Subject and purpose: coordinating footage deliveries between a company’s authorized people and devices, applying project permissions and reporting results. Processing lasts for the service relationship and the return or deletion period below.
Operations: collection, organization, storage, retrieval, access control, transmission of delivery metadata, coordination of provider access, status recording and deletion. Original media moves directly between the connected storage provider and the receiving device; Connecterman’s application server stores coordination data rather than a library of the media.
Data: member names and email addresses, company and project identifiers, roles, invitations, file identifiers and names, paths, sizes, checksums, delivery and device identifiers, status, errors and activity records. Authorization tokens are processed as needed to connect the user’s storage account.
People concerned: company owners, employees, contractors, collaborators, clients and other people identified in file or project metadata. Particularly sensitive categories of data are not intended for this development service and require a separate suitability assessment and written agreement.
Instructions and confidentiality
The company decides the purposes, lawful basis, recipients, access permissions and retention requirements for its data and gives documented instructions through the service and agreed support channels. It must provide necessary notices and hold the rights needed to direct the processing.
The operator processes company data only on those instructions, including for transfers abroad, unless law requires otherwise. In that case it informs the company beforehand unless prohibited. If an instruction appears unlawful, the operator informs the company promptly and may pause the affected operation while it is clarified.
People authorized to access company data must be bound by confidentiality and have access limited to their duties. The operator does not use company data for its own advertising or to train general purpose AI models.
Security measures
- HTTPS for the public application and protected authentication for browser and native access.
- Password hashes and encrypted provider tokens, with device credentials kept in macOS Keychain.
- Company membership and project permission checks, device revocation and administrative activity records.
- Database and application services restricted from direct public access, administrative access using SSH keys, and a firewall limiting exposed services.
- Service isolation, security updates, rate limiting and restricted operational logs.
- Daily server backups with limited retention and a documented recovery procedure.
These measures are maintained and reviewed according to the processing risk. They do not represent certification, a guarantee of uninterrupted service, or a claim that all records and backups are encrypted at rest. The company remains responsible for its storage provider, recipient devices and downloaded copies.
Assistance and incidents
Taking account of the processing and information available, the operator assists with rights requests, security obligations, breach handling, impact assessments and supervisory consultation. Requests concerning company data are forwarded to the company unless a response is required by law or authorized by its instructions.
On becoming aware of a personal data breach affecting company data, the operator informs the company without undue delay, provides available information about the event, affected records, likely consequences and response, and supplements it as the investigation proceeds. The company remains responsible for its own notifications to authorities and affected people.
Subprocessors and locations
The initial hosting subprocessor is Hostinger, providing the VPS, database infrastructure and routine server backups. The selected hosting country is United Kingdom (Manchester). Operator administration and restricted recovery copies are handled from Switzerland. The applicable Hostinger contracting entity and any transfer safeguards must be recorded with the company agreement.
The company’s written agreement authorizes the identified hosting subprocessor. The operator gives at least 30 days’ advance notice of an intended addition or replacement, so the company can object on reasonable data protection grounds before the change. If the concern cannot be resolved, the affected processing can be ended without an exit penalty. Equivalent data protection obligations must bind each subprocessor, and the operator remains responsible for its performance.
Google Drive and Adobe Frame.io accounts are chosen and held by the users or their companies. Their separate provider agreements continue to govern their own processing. A connected account alone does not authorize an unrelated subprocessor or a new use of its data.
Processing in another country requires documented instructions and an applicable lawful transfer mechanism. Where required, this includes appropriate contractual safeguards and Swiss adaptations. These terms alone do not constitute the international standard contractual clauses or create an adequacy decision.
Return and deletion
At the end of the processing service, the company can request return of the company data held by Connecterman in a commonly readable format or its deletion. The operator then deletes remaining copies unless a legal retention duty applies, and confirms completion on request. Routine backup copies are isolated from normal use and removed through their approximately 15 day rotation; exceptional recovery copies are addressed separately. If a backup is restored, previously required deletions must be reapplied.
The operator informs the company about any legally required retention and restricts that data to the required purpose. Cloud originals and copies already downloaded to recipient devices remain under the company’s or provider’s control and must be dealt with there.
Evidence and audits
The operator provides information reasonably needed to demonstrate compliance and permits audits or inspections by the company or an independent auditor it appoints. Practical arrangements protect other customers’ data and service security and must not prevent the exercise of statutory audit rights. The parties cooperate with competent supervisory authorities.
Any updates to these terms must maintain the protections required by applicable law and be agreed through the company’s contractual process. Contact the operator to arrange the agreement or obtain its current processing details.