Privacy Policy
Digital Online Support (“DOS”) is designed so that the provider has no access to the content of your session. This policy explains which personal data is processed, on what legal basis, for how long, with whom it is shared and what your rights are under the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
1. Data controller
The controller of the processing is:
DIGITALCENTAR.KOM Bitola LLC (registered Macedonian name: Друштво за
производство, трговија и услуги ДИГИТАЛЦЕНТАР.КОМ увоз-извоз ДООЕЛ Битола)
Address: Partizanska St. 28-9, 7000 Bitola, Republic of North Macedonia
Company reg. no. (ЕМБС): 6706754 · Tax no. (ЕДБ): 4002011523975 · VAT no.: MK4002011523975
Email: info@digitalcentar.com · Tel: 070 339 129
2. Representative in the European Union
Because the controller is established outside the EU/EEA and offers the service to individuals in the Union, a representative in the EU has been designated in accordance with Article 27 GDPR. Data subjects and supervisory authorities may contact this representative on all matters relating to the processing:
Digitalvario AB
Luthersgatan 19, 214 34 Malmö, Sweden · Company registration number (org.nr): 559593-5775
Email for privacy enquiries: info@digitalcentar.com
3. Session content — not processed by us
We do not record, inspect or store the screen stream, audio, chat messages, clipboard content, keyboard input or transferred files. This data is transmitted only between the participants and is end-to-end encrypted. When the connection is direct (peer-to-peer), session traffic does not pass through our infrastructure at all, and it stays within your local network when the devices are on the same network.
4. What personal data we process, for what purpose and on what legal basis
We process only the minimum data necessary for the service to function:
- DOS Viewer sign-in and account access — your email address and password are sent over HTTPS to authenticate your account. We store an account-linked access-key hash, device name, creation and last-use timestamps, associated IP addresses and revocation status. Failed sign-in protection records the IP address, a hash of the supplied email address and the attempt time. The app keeps its access key on your device; it does not save the password entered in the sign-in form. We also process account-to-host associations and service usage totals to apply access permissions and service limits. Purpose: authentication, providing the requested service and preventing abuse. Legal basis: Article 6(1)(b) and Article 6(1)(f) GDPR.
- Operational connection data — device identifier (DOS ID), network address (IP), online status, connection type and the aggregate volume of relay traffic. Purpose: establishing and maintaining the connection, service status and reasonable use (fair use). Legal basis: Article 6(1)(b) GDPR (performance of the service you request) and Article 6(1)(f) GDPR (legitimate interest in stable and secure infrastructure). This data contains no session content and is not used for profiling.
- Update checks — when checking for a new version, only what is needed to determine whether a newer version exists is transmitted. Legal basis: Article 6(1)(f) (legitimate interest in security — every update is digitally signed and the signature is verified before it is applied).
- Communication — if you write to us, we process your email address and the content of your message in order to reply. Legal basis: Article 6(1)(f) (legitimate interest in responding to a request).
We carry out no automated decision-making and no profiling that produces legal or similarly significant effects for you (Article 22 GDPR).
5. How long we keep it
Retention depends on the purpose for which the data is needed. For account and device records, we consider whether they are needed to provide the requested service and manage access permissions. For connection and security records, we consider what is needed to operate the service, investigate incidents and prevent abuse. Correspondence is retained to handle your request and meet any applicable accounting or legal obligations. Data needed to establish, exercise or defend legal claims may be retained for that purpose. Ending a session or signing out does not automatically erase all of these records.
Account and access-key records are separate from short-lived operational logs. Signing out removes the app's local access key and revokes the server key; it does not delete your account, access records or device associations. To request access to or deletion of these records, contact info@digitalcentar.com. We may need to verify that the request concerns your account. Records required for an ongoing service, a legal obligation or a legal claim may need to be retained; we explain any applicable restriction when responding to your request.
6. Who we share it with
We do not sell your data. We share it only with processors that enable the service for us and act on our instructions:
- Hosting/relay provider — the server infrastructure through which, where necessary, encrypted bytes are forwarded. The provider has no access to the keys or to the session content.
We may also disclose data where required by law or by a competent authority.
7. International transfers
The controller is in North Macedonia, and the infrastructure may be located in the EU/EEA or in third countries. When data is transferred outside the EU/EEA, this is done with appropriate safeguards in accordance with Chapter V of the GDPR (for example, standard contractual clauses), and the session content itself is in any case end-to-end encrypted.
8. Your rights
Under the GDPR you have the right to: access your data (Art. 15), rectification (Art. 16), erasure (“right to be forgotten”, Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection to processing based on legitimate interest (Art. 21) and withdrawal of consent at any time where the processing is based on consent (without affecting the lawfulness of processing carried out beforehand). To exercise these rights, contact us at info@digitalcentar.com.
You also have the right to lodge a complaint with a supervisory authority. In North Macedonia this is the Agency for Personal Data Protection (АЗЛП, azlp.mk). If you are in the EU/EEA, you may also contact the supervisory authority in your member state of residence.
9. Local diagnostics
No diagnostic log file is created by default. A user may deliberately enable local logging to troubleshoot a technical problem; the file remains on their device and is not sent automatically to the controller.
10. Website
The DOS website and apps do not use advertising tracking or third-party analytics. The public website stores language and theme preferences locally. The account portal also uses functional session cookies for sign-in and a language preference cookie. These are used to operate the portal, not for advertising. Signing in to the portal sends account and security information to our server as described above.
11. Consent and session control
An interactive session requires clear consent on the remote device. Authorised unattended access is optional and is configured locally by the owner of the device.
12. Changes to this policy
This policy may be updated. The date of the last update appears above; material changes will be published on this page.
See also: Terms of Use