Privacy Policy

Last updated: 1 January 2026

1. Who We Are

This Privacy Policy explains how Bosphorus Group Ltd ("we", "us", or "our") collects, uses, and protects your personal data when you use the SignageWorks platform at swtv.uk.

Bosphorus Group Ltd is the data controller for your personal data. Our registered address is 96A Ethel St, Brighton and Hove, Hove BN3 3LL. You can contact us about privacy matters at info@signageworks.co.uk.

We are committed to protecting your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

2. What Data We Collect

We collect the following categories of personal data:

Account Data

  • Email address (required to create and manage your account)
  • Password (stored as a secure hash — we never store your plain-text password)
  • Company name (optional, provided during registration)
  • Account role (customer or administrator)

Usage Data

  • Screen names and configuration you create within the platform
  • Content files (videos and images) you upload to the Service
  • Timestamps of logins and content updates
  • IP address and browser/device type (collected automatically by our hosting infrastructure)

Payment Data

  • Billing information is collected and processed by our third-party payment provider
  • We do not store full payment card details on our systems
  • We retain records of subscription status and billing history

Communications Data

  • Any messages you send to us via email or contact forms

3. How We Use Your Data

We use your personal data for the following purposes:

  • Service delivery: To create and manage your account, authenticate your identity, and operate the SignageWorks platform
  • Billing: To process subscription payments and manage your billing relationship
  • Communications: To send service notifications, billing alerts, and responses to your enquiries
  • Security: To detect and prevent fraud, abuse, and unauthorised access
  • Legal compliance: To comply with our legal obligations under UK law
  • Service improvement: To understand how the Service is used and improve its functionality

Our legal basis for processing your data is primarily contract performance (to provide the Service you have subscribed to) and legitimate interests (security and service improvement). For marketing communications, we rely on your consent.

4. Data Storage and Third-Party Services

Your data is stored and processed using the following trusted third-party infrastructure providers:

Supabase

We use Supabase for database storage and user authentication. Your account data, screen configurations, and uploaded content are stored on Supabase infrastructure. Supabase stores data in the EU (AWS eu-west-1 region). Supabase is compliant with GDPR and SOC 2 Type II.

Vercel

Our web application is hosted on Vercel. Vercel may process request logs and IP addresses as part of serving the application. Vercel is GDPR compliant and operates under a Data Processing Agreement.

We do not sell your personal data to any third party. We will only share your data with third parties where necessary to provide the Service, comply with legal obligations, or protect our legitimate interests.

5. Cookies

SignageWorks uses cookies and similar technologies to operate the Service. Specifically, we use:

  • Authentication cookies: Essential session cookies set by Supabase to keep you logged in. These are strictly necessary and cannot be disabled.
  • Preference cookies: To remember your settings and preferences within the dashboard.

We do not use advertising, tracking, or analytics cookies. We do not use Google Analytics or any third-party tracking scripts on the SignageWorks platform.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from logging in to the Service.

6. Data Retention

We retain your personal data for as long as your account is active. Specifically:

  • Active account data is retained for the duration of your subscription
  • After cancellation, account data is retained for 30 days before permanent deletion
  • After a trial expires without subscription, data is retained for 30 days
  • Billing records are retained for 7 years to comply with UK financial regulations
  • Communications (emails) are retained for up to 2 years

7. Your Rights Under UK GDPR

Under the UK General Data Protection Regulation, you have the following rights:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to restriction: Request that we limit how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Rights related to automated decisions: Not be subject to solely automated decisions that significantly affect you

To exercise any of these rights, please contact us at info@signageworks.co.uk. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) — the UK's data protection authority — at ico.org.uk.

8. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:

  • All data transmitted over HTTPS (TLS encryption)
  • Passwords stored as bcrypt hashes — never in plain text
  • Row-level security policies on all database tables
  • Access to production systems restricted to authorised personnel only
  • Regular security reviews of our infrastructure

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours and affected users without undue delay.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on the Service. The "Last updated" date at the top of this page will always reflect the most recent revision.

Continued use of the Service after changes have been posted constitutes your acceptance of the revised Policy.

10. Contact Us

For any privacy-related questions or to exercise your data rights, please contact: