SCR-LEGAL/02
Legal / Privacy
Privacy Policy
What we collect, why we collect it, and the choices you have. The short version: your recordings belong to you, and we only process what the product needs.
01Who is responsible
The controller for data processing described in this policy is PLANFRED GmbH, Billrothstraße 29 / Top 6, 1190 Vienna, Austria (“ScreenLast”, “we”). ScreenLast is a product of PLANFRED GmbH. You can reach our privacy team at info@screenlast.com.
02The desktop app is local-first
The open-source desktop app records, edits, and renders on your machine. Flows, DOM stills, narration drafts, and rendered videos stay on your device unless you explicitly connect a ScreenLast Cloud organization or a third-party AI provider with your own keys.
03Data we process in ScreenLast Cloud
When you create a Cloud account we process the following categories:
- Account data — name, email address, password hash, organization and workspace roles.
- Content data — flows (.scrl), stills, voice-over scripts, rendered videos you upload or render with hosted workers.
- Usage data — feature interactions, render minutes, storage consumption, log and diagnostic data.
- Billing data — plan, invoices, and payment status. Card details are processed by our payment provider and never touch our servers.
04Purposes and legal bases
- Providing the service and rendering infrastructure — Art. 6(1)(b) GDPR (contract).
- Security, abuse prevention, and service diagnostics — Art. 6(1)(f) GDPR (legitimate interest).
- Billing and tax retention duties — Art. 6(1)(c) GDPR (legal obligation).
- Product news, only if you opt in — Art. 6(1)(a) GDPR (consent, revocable at any time).
05Cookies and analytics
This website uses only technically necessary cookies (session, language, theme preference). We use a self-hosted, cookie-free analytics tool that stores aggregated statistics without persistent identifiers or cross-site tracking. No advertising networks are involved.
06Processors and transfers
We use a small set of subprocessors for hosting (EU data centers), video delivery, e-mail, and payments. A current list is published on our GDPR page. Where a provider processes data outside the EU/EEA, we rely on adequacy decisions or EU Standard Contractual Clauses.
07Retention
Content data is retained as long as your organization exists and is deleted within 30 days after organization deletion. Backups roll off within a further 35 days. Invoices are retained for the statutory period of 7 years.
08Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15).
- Rectification (Art. 16) and erasure (Art. 17).
- Restriction of processing (Art. 18) and data portability (Art. 20).
- Object to processing based on legitimate interest (Art. 21).
- Lodge a complaint with a supervisory authority — in Austria the Datenschutzbehörde, dsb.gv.at.
09Contact
For any privacy request, write to info@screenlast.com. We answer within one month at the latest. This policy may be updated when the product changes; the date above always reflects the current version.