1. Who is responsible?
CasBizz Holding B.V., trading as Screentext, is the controller for account, contract, security and billing data. Our full contact details are available on the contactpagina.
For text processed by a customer through ScreenText, the customer is generally the controller and Screentext acts as processor. A Data Processing Agreement beschikbaar.
2. What data do we process?
- organisation details, names, business email addresses, roles and account status;
- billing details and payment references, including Mollie customer, payment, subscription and mandate identifiers;
- sign-in, session and security data, such as IP addresses, device information and audit events;
- support communications and information supplied by a user in a support request;
- encrypted screen content, initialisation vectors and encrypted session keys.
Screen text is end-to-end encrypted in the browser using AES-256-GCM. The server stores and transmits encrypted content only and does not normally hold the key required to read it. A designated employee can gain access only through explicitly approved, temporary support access.
3. Purposes and legal bases
- performance of the agreement: providing accounts, the ScreenText service, subscriptions and support;
- legitimate interests: security, abuse prevention, troubleshooting and service improvements;
- legal obligations: record-keeping, tax retention requirements and requests from competent authorities;
- consent, where this is legally required for a specific processing activity.
4. Service providers and recipients
We engage carefully selected providers for hosting, email delivery, storage and backups, and payment processing. Mollie processes payment data as an independent controller under its own privacy notice. Providers receive only the information required to perform their role.
We do not sell personal data. We disclose it only where necessary to provide the service or where legally required.
5. Retention periods
Active screen sessions have a preset end time. When a session expires or is closed, encrypted text and wrapped keys are irreversibly deleted. Account and contract data is retained for the duration of the agreement and afterwards for as long as necessary for disputes or legal obligations. Financial records are generally retained for seven years. Security and audit data is not kept longer than necessary for security and accountability.
6. Security and international transfers
Our measures include encrypted transport, end-to-end encryption of screen content, role-based access, strong authentication, temporary support access and audit logging. Where a provider processes data outside the European Economic Area, we use a legally recognised transfer mechanism where required.
7. Cookies and local storage
ScreenText uses only functional cookies and browser storage required for sign-in, security, session management, preferences and the encrypted connection. We do not use advertising cookies on the public website.
8. Rights and complaints
Where applicable, you may request access, rectification, erasure, restriction or portability, or object to processing. Send your request to info@casbizz.nl. We may ask you to verify your identity. For content processed on behalf of a customer organisation, contact that organisation first.
You may also lodge a complaint with the Dutch Data Protection Authority.
9. Changes
We may update this notice when the service or applicable law changes. The date above identifies the current version.