WeDisplay · Legal
Privacy Policy
This Privacy Policy explains how EN6IA, operating as "WeDisplay" ("WeDisplay", "we", "us", or "our"), collects, uses, discloses, and protects personal information in connection with our cloud-based digital signage platform, including our marketing websites, dashboard, applications, player software, APIs, and related services (collectively, the "Service"). It applies to visitors to our websites, customers and their team members who use the Service ("Customers" or "you"), and job applicants and other individuals who interact with us.
We are based in Québec, Canada, and this Policy is written primarily to comply with Québec's Act respecting the protection of personal information in the private sector("Law 25") and the federal Personal Information Protection and Electronic Documents Act ("PIPEDA"). Where the Service is used by individuals in the European Economic Area, the United Kingdom, or Switzerland, we also honor applicable rights under the General Data Protection Regulation and UK GDPR. Where the Service is used by residents of California, we also honor applicable rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). Section 7 explains how these different frameworks' rights apply to you.
1. Who We Are; Controller and Processor Roles
EN6IA (Québec enterprise number (NEQ) 2266497173), operating as WeDisplay, is a Québec-based company that provides the Service described above. For most of the personal information described in this Policy, WeDisplay acts as the controller(or "organization responsible for personal information" under Law 25) — meaning we decide why and how that information is collected and used. This includes account, billing, marketing, and website-visitor information described in Section 2.
For content that our Customers upload, schedule, or display through the Service, and for information about the end viewers of that content that a Customer chooses to collect or process using the Service (for example, through embedded forms, QR codes, or analytics a Customer configures), WeDisplay acts as a processor(or "service provider") acting on the Customer's instructions. In that role, the Customer is the controller responsible for that data, and questions about it should be directed to the Customer organization in question. Business customers can request a Data Processing Addendum governing our processor role — see the Legal Center.
This Policy describes our practices as controller unless stated otherwise. It does not apply to third-party websites, applications, or services that we do not control, even if you access them through the Service (see Section 5).
2. Personal Information We Collect
We collect the following categories of personal information, directly from you, automatically through your use of the Service, and from the third parties described below:
- Account information. When you or your organization create an account, we collect your name, email address, organization name, and a hashed (never plaintext) password.
- Single sign-on information. If you choose to sign in with Google, Microsoft, or GitHub, we receive the profile information and email address those providers share with us under their own consent flows, so that we can create or match your account.
- Billing information. Payments are processed by our payment processor, Stripe. When you subscribe to a paid plan, Stripe collects your payment details directly; WeDisplay never receives or stores your full card number or other sensitive card details. We retain billing-related records such as your billing name, address, invoices, and subscription history.
- Content and media you upload. Images, video, documents, and other media, layouts, playlists, and schedules that you or your organization upload to or create within the Service.
- Connected-service credentials. If you connect a calendar (such as Google Calendar or Microsoft Outlook/Exchange) or an AI-provider API key to power the optional AI Assistant, we store the resulting access tokens or keys in encrypted form.
- Crash reports and telemetry. Technical diagnostic information generated when the Service or a player encounters an error, used to identify and fix defects.
- Device and screen identifiers. Identifiers associated with the screens, players, and sources you register to your account, used to authenticate and address them.
- IP address and request logs. Standard server logs generated by use of our websites and Service, including IP address, browser and device information, and pages or endpoints accessed.
- Lead and contact-form information.Name, email, company, and any message you submit through a "get started", contact, or lead-capture form on our marketing site.
- Cookies and similar technologies. Information collected through cookies and comparable technologies — see Section 4 and our Cookie Policy.
We do not knowingly collect special categories of personal information (such as health, biometric, or precise-location data) about you through account creation or billing, and ask that Customers do not upload such data as Customer Content unless they have an independent lawful basis and appropriate safeguards for doing so.
3. How We Use Personal Information; Legal Bases
We use personal information for the following purposes:
- to create and administer your account and provide the Service you have requested;
- to process payments, issue invoices, and manage subscriptions and billing;
- to authenticate you, your screens, players, and sources, and to secure the Service;
- to provide customer support and respond to your requests;
- to send transactional communications, such as invite, receipt, and security notifications;
- to send product updates and, where you have opted in, marketing communications;
- to monitor, maintain, debug, and improve the Service, including through crash telemetry;
- to detect, investigate, and prevent fraud, abuse, and security incidents; and
- to comply with our legal obligations and enforce our agreements.
Under Law 25 and PIPEDA, we collect and use personal information only for purposes that a reasonable person would consider appropriate in the circumstances, and we identify those purposes to you at or before the time of collection. Where we rely on your consent (for example, for marketing communications or non-essential cookies), you may withdraw that consent at any time, as described in Section 7. Where consent is not the applicable basis, we rely on the necessity of the processing to perform our contract with you, our legitimate interests in operating and securing the Service (balanced against your rights), or compliance with a legal obligation. For individuals in the European Economic Area or the United Kingdom, these same purposes map to the legal bases of contractual necessity, legitimate interests, legal obligation, and consent under the GDPR/UK GDPR.
4. Cookies and Similar Technologies
We and our service providers use cookies, local storage, and similar technologies on our websites and in the Service to keep you signed in, remember your preferences, understand how our websites are used, and, where you consent, support marketing. You can review the specific cookies we use, their purposes, and how to manage or withdraw your consent to non-essential cookies, in our Cookie Policy, including through the cookie-preference control available on our websites.
5. How We Disclose Personal Information; Sub-Processors and International Transfers
We do not sell personal information, and we do not disclose personal information to third parties for their own independent marketing purposes. We disclose personal information only as described below:
- Sub-processors and service providers who process personal information on our behalf, under contractual confidentiality and security obligations, to help us operate the Service. These currently include: Stripe (billing and payment processing); Google, Microsoft, and GitHub(authentication/OAuth sign-in, plus calendar integrations you choose to connect with Google or Microsoft); Resend (transactional email delivery); Anthropic (the optional AI Assistant feature, when enabled by a Customer); Cloudflare (content delivery, web-application firewall, and encrypted off-site backup storage); and OVH (infrastructure hosting). Our WebRTC relay (coturn/TURN) infrastructure is self-hosted on our own servers, so live-streaming relay traffic is not shared with a third-party TURN provider.
- Other members of your organization, to the extent your account role and permissions allow visibility into shared account, team, and content information.
- Professional advisors, and successors in a corporate transaction such as a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations.
- Regulators, courts, and law enforcement, where required by law, legal process, or to protect the rights, property, or safety of WeDisplay, our users, or others.
Some of our sub-processors, including Stripe, Google, Microsoft, Resend, Anthropic, and Cloudflare, may process personal information on servers located outside Québec, including in the United States and the European Union. Before relying on such a transfer, we assess whether the recipient provides a level of protection for personal information that is equivalent to that required under Law 25, consistent with the transfer-assessment obligation under that Act. Where personal information of individuals in the European Economic Area or United Kingdom is transferred outside those regions, we rely, where applicable, on the European Commission's Standard Contractual Clauses or an equivalent recognized transfer mechanism.
6. Retention and Security
We retain personal information for as long as needed to provide the Service and fulfil the purposes described in this Policy, plus any additional period required to comply with our legal, tax, accounting, dispute-resolution, or security obligations. Account and Customer Content are generally retained for the duration of your subscription and for a limited period after termination, as described in our Terms of Service, to allow you to export your data before deletion. Billing records are retained for as long as required by applicable tax and accounting law. Crash telemetry and request logs are retained for a limited operational window sufficient for debugging and security investigation, after which they are deleted or aggregated. When personal information is no longer needed for these purposes, we delete, destroy, or anonymize it, subject to legal retention requirements.
We maintain administrative, technical, and organizational security measures designed to protect personal information appropriate to its sensitivity, including: organization-scoped data isolation, so one Customer's data is not visible to another; encryption of sensitive secrets (such as connected-calendar tokens and AI-provider keys) at rest; encryption in transit via TLS; magic-byte validation of uploaded media to prevent disguised or malicious file uploads; a guarded outbound proxy that blocks server-side request forgery (SSRF) when the Service fetches external content on your behalf; role-based access control built on granular, individually assignable permissions; rate limiting on sensitive endpoints such as account registration and password reset; audit logging of sensitive account and administrative actions; a boot-time safeguard that prevents our production systems from starting with a default or insufficiently strong secret; and regular database backups stored with a provider that encrypts data at rest. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we work to continuously review and improve these measures.
7. Your Rights
Subject to applicable law and any exceptions it provides, you have the following rights with respect to your personal information:
- Access. You may request confirmation of whether we hold personal information about you and a copy of that information.
- Rectification. You may request that we correct inaccurate or incomplete personal information.
- Deletion. You may request that we delete personal information about you, subject to our legal, contractual, and legitimate operational retention needs.
- Portability. You may request a copy of certain personal information you have provided to us, in a structured, commonly used, machine-readable format, so it can be transmitted to another organization.
- Withdraw consent. Where we rely on your consent (for example, for marketing communications or non-essential cookies), you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
- De-indexing and cessation of dissemination (Law 25). In certain circumstances — for example, where the dissemination of your personal information causes serious injury to your reputation or privacy — you may request that we cease disseminating it or de-index it from associated search results.
- Object to or restrict processing (GDPR/UK GDPR). If the GDPR or UK GDPR applies to you, you may object to processing based on legitimate interests and request that we restrict processing in certain circumstances.
- Do-not-sell / do-not-share and non-discrimination (CCPA/CPRA). WeDisplay does not sell or share personal information as those terms are defined under the CCPA/CPRA, so no opt-out request is necessary to stop a sale or share that does not occur. California residents also have the right not to receive discriminatory treatment for exercising any privacy right, and we do not discriminate against you for doing so — for example, by denying goods or services, charging different prices, or providing a different level of service.
To exercise any of these rights, contact our Privacy Officer using the details in Section 8. We may need to verify your identity before acting on a request, and we will respond within the time limits required by applicable law (generally 30 days under Law 25 and PIPEDA). If we cannot fulfil a request in whole or in part, we will explain why. If your personal information forms part of Customer Content controlled by one of our Customers, we will direct your request to that Customer, or, where appropriate, assist the Customer in responding to it, since the Customer — not WeDisplay — controls that data as described in Section 1.
8. Privacy Officer
In accordance with Law 25, we have designated a Privacy Officer responsible for ensuring compliance with this Policy and applicable privacy law, and for handling inquiries, complaints, and requests regarding personal information:
Privacy Officer, EN6IA (operator of the WeDisplay Service)
Email: [email protected]
If you are not satisfied with our response to a privacy request or complaint, you have the right to lodge a complaint with the applicable data protection authority, including, for residents of Québec, the Commission d'accès à l'information du Québec, or, for individuals in the European Economic Area or United Kingdom, your local supervisory authority.
9. Children
The Service is designed and intended for use by businesses, organizations, and professionals, and is not directed to children or other individuals under the age of majority in their jurisdiction of residence. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, please contact our Privacy Officer at [email protected] so that we can investigate and, if appropriate, delete that information.
10. Automated Decision-Making
We do not currently use automated processing of personal information, including profiling, to make decisions about you that produce legal effects or similarly significantly affect you. If this changes in the future, we will update this Policy to describe the logic involved, the significance of the processing, and the rights available to you in relation to it, as required by Law 25 and other applicable law.
11. Breach Notification
If we become aware of a confidentiality incident (a breach of security measures leading to the loss, unauthorized access to, or unauthorized use or disclosure of personal information) that poses a risk of serious injury to an affected individual, we will notify the affected individuals and the applicable regulator, including the Commission d'accès à l'information du Québec where required, without undue delay, and will take reasonable steps to mitigate the risk of harm, consistent with our obligations under Law 25, PIPEDA, and other applicable breach-notification law. We also maintain an internal incident register of confidentiality incidents as required by Law 25.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Service, our data practices, or applicable law. If we make a material change, we will provide reasonable advance notice by email, an in-app notice, or by posting the updated Policy on this page with a revised effective date. Changes take effect on the stated effective date, and your continued use of the Service after that date constitutes acknowledgement of the updated Policy. We encourage you to review this Policy periodically.
Questions about this document? Contact [email protected]. See all policies in the Legal Center.