Who is responsible
This notice covers connectorman.de and the Connecterman macOS application. The operator below is responsible for account administration, service security and support.
Operator details pendingContact email pendingYour company determines which colleagues receive footage and which projects they may access. Where we process company data on its instructions, the company is the controller and we act as its processor. See our data processing terms. Contact your company administrator about its use of your information, or contact us for help identifying the responsible company.
Information we process
- Account information: your name, email address, password hash, account identifiers, invitation redemption and sign in sessions. Session records can include IP address and browser information.
- Company information: company and project names, descriptions, membership, roles, invitations, permissions and administrative activity.
- Storage and delivery information: provider account identifiers, encrypted authorization tokens, selected folders, file names and paths, file identifiers, sizes, checksums, versions, senders, recipients, delivery progress, timestamps and errors.
- Device information: device name and identifier, platform, app version, receiving readiness, destination label, last connection and download status. Each enrolled device on an account can receive an assigned delivery.
- Technical and support information: network connection data, security events, rate limiting identifiers, diagnostic messages and information you choose to send when requesting help.
We receive data from you, your company’s authorized members, your enrolled devices and the storage accounts you connect. File names and project descriptions may contain information about clients, contributors or people appearing in footage. The company selecting those files is responsible for providing appropriate information to those people.
The server coordinates deliveries and stores metadata. Original video files are downloaded directly from the storage provider to the selected device, rather than stored as footage on our application server. The app keeps download state and preferences locally, and stores its sign in credentials in macOS Keychain.
Purposes and legal grounds
We use account and delivery data to provide the requested service, authenticate people and devices, enforce company permissions, connect storage accounts, resume downloads and answer support requests. When the GDPR applies, processing necessary for our contract with you is based on Article 6(1)(b). Administration of company user accounts and protection against abuse rely on Article 6(1)(f), with the legitimate interests of operating a reliable service and protecting users and their files.
Processing required by law relies on Article 6(1)(c). Where a separate, optional purpose requires consent, we ask for it and permit withdrawal under Article 6(1)(a). Authorizing a storage connection gives the app permission to access that provider; it does not constitute consent to unrelated uses. Company processing follows the company’s documented instructions and lawful basis.
We apply the Swiss Federal Act on Data Protection where applicable. Required account fields and technical identifiers are needed to provide the service. You can choose not to connect storage, but browsing and downloading from that provider will then be unavailable. We do not use service data for advertising, sell personal data, or make automated decisions producing legal or similarly significant effects about individuals.
Google Drive data
Connecting Google Drive requests read access to files available to your Google account, plus OpenID and email identity scopes. The Drive permission is broader than a single selected folder. Connecterman uses it to display folders, read metadata, enumerate the footage you select and download originals for authorized deliveries. It does not request permission to edit, upload or delete Drive files.
We store encrypted access and refresh tokens so that an authorized transfer can continue when the website is closed. File metadata is recorded with its delivery. For direct downloads, the receiving app obtains a temporary access token for the recipient’s own connected Google account. We do not give recipients the sender’s Google credentials. Connecterman membership does not grant Google Drive access; the file owner must separately share the footage with each recipient’s Google account.
Connecterman’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google data is used only to provide the visible storage and delivery features. It is not used for advertising, sold to data brokers, used for credit decisions or used to train general purpose AI models. Operator access is restricted to consented support, necessary security work, legal requirements or other uses permitted by Google’s policy. Sharing is limited to your instructed delivery, necessary service providers, security and legal obligations within those restrictions.
Disconnect Google Drive in Storage connections to delete the saved connection credentials from the live database. You can also revoke Connecterman in your Google account connections. Disconnecting stops future access through that connection, but does not erase completed delivery history or copies already downloaded to a device.
Processing locations
The application server, database and routine server backups are hosted by Hostinger in United Kingdom (Manchester). Administration and any restricted recovery copies are handled from Switzerland.
Google and Adobe operate internationally, including in the United States. The countries used for your cloud files also depend on your provider account and its settings. A delivery to a colleague abroad makes the selected files and their metadata available in that recipient’s country, including the United States when you select a recipient there.
Transfers requiring an international transfer safeguard must be covered by an applicable adequacy decision or appropriate contractual safeguards, with Swiss adaptations where required. The EU and Switzerland recognize certain countries and participating US organizations under their respective frameworks; a US location alone is not proof of protection. Contact us for the safeguards applicable to our processing and a copy where available. Your company must assess the countries and recipients it selects for its own deliveries.
How long we keep data
Account, company and device records are kept for the active relationship and for as long as needed to operate the service, resolve delivery issues or document permissions. On account or company closure, we review associated records and delete or anonymize information no longer needed, subject to legal obligations, justified security needs and legal claims. Contact us to request deletion; removing a member or revoking a device disables access but does not automatically erase all history.
Transfer access normally expires after 30 days. This is an access deadline, not an automatic deletion deadline for transfer history. Invitation codes expire after the chosen 1, 7 or 30 days, while their redemption and administrative history may remain. Storage credentials remain until the connection is removed or the account is closed.
Routine server backups rotate after approximately 15 days. Operational system logs are configured for a maximum of 14 days, subject to earlier size based rotation. Exceptional recovery copies or records needed for an incident or claim are restricted and retained only while that purpose remains. Deleted data in backups is isolated from normal use and ages out on the backup cycle; a restore must preserve prior deletion requests.
Original cloud footage remains subject to the storage provider’s and your company’s retention choices. Files already downloaded remain on the recipient’s device until removed there. Disconnecting a device or deleting a Connecterman account cannot remotely erase those copies.
Security and your controls
We use HTTPS, password hashing, encryption of stored provider credentials, company permission checks, restricted server administration and database backups. These measures reduce risk but cannot guarantee that every incident is prevented. Provider tokens are encrypted at the application layer; this does not mean every database field or backup is separately encrypted.
You can disconnect a storage account, revoke a device, stop receiving in the Mac app and ask your company administrator to change project permissions. Revocation prevents new authorized requests; a download already in progress may continue until its current provider authorization or request ends.
Your rights
Depending on the applicable law and circumstances, you may request access, correction, deletion, restriction and a portable copy of your data. You may object to processing based on legitimate interests and withdraw consent for processing that relies on it, without affecting prior lawful processing. Contact the operator above; we may ask for proportionate information to verify your identity.
We respond within the applicable statutory period, generally one month under the GDPR or 30 days for Swiss access requests, and explain any permitted extension. For company controlled data, we help the responsible company handle your request.
You may complain directly to the competent data protection authority without contacting us first. In the EU, this can be the authority where you live or work or where an alleged infringement occurred. See the European data protection authorities. In Switzerland, contact the Federal Data Protection and Information Commissioner.
Changes to this policy
We update this notice when the service or its processing changes and show the current version above. Material changes will be communicated through an appropriate service notice. New optional uses requiring consent will not begin without that consent. This privacy notice explains processing; reading it does not waive your rights.