Privacy Policy
This Privacy Policy explains how we collect, use, disclose, protect, and process your personal information when you use our products and services.
Effective Date: 5/1/2026
Last Updated: 7/11/2026
At FGPR, Inc. ("we," "us," or "our"), accessible from https://www.fgr.cx, protecting the privacy of our visitors and platform users is one of our main priorities. This Privacy Policy explains what information we collect, how we use and share it, how we safeguard it, and the rights available to you when you use our digital signage and marketing Software-as-a-Service (SaaS) platform, software applications, media players, and website (collectively, the "Services").
1. Our Role: Controller vs. Processor
Because we provide business-to-business services, our role under data protection law depends on the data involved:
-
We act as a data controller for information relating to our direct customers and their authorized users — such as account registration details, billing records, support communications, and website analytics. For this data, we decide how and why it is processed, and this Privacy Policy applies in full.
-
We act as a data processor (or "service provider" under the CCPA) for any personal data contained in Customer Content or otherwise processed on behalf of our customers through the platform. For this data, our customer is the controller, and we process it only on their documented instructions in accordance with our Data Processing Agreement (DPA), available at https://www.fgr.cx/dpa.
If you are an employee, visitor, or member of the public whose personal data may have been processed through a customer's use of our Services (for example, in content displayed on a customer's screens), please direct privacy inquiries to that organization first, as they control that data. We will support our customers in responding to such requests as required by law and our DPA.
2. Information We Collect
We collect information directly from you, automatically through your interaction with our Services, and from hardware/media players running our software.
A. Account & User Data (Direct Information)
When you register for, manage, or interact with our Services, we may collect:
-
Contact Information: Name, email address, phone number, company name, and job title.
-
Account Credentials: Username, hashed passwords, and authentication tokens.
-
Billing Information: Payment details, billing address, and transaction histories. (We do not directly store full credit card numbers; payment processing is handled securely by our third-party payment processor.)
-
Support Data: Communications, feedback, or support requests submitted to our help team.
B. Device & Display Data (Hardware & Player Telemetry)
To operate, monitor, and deliver content through your digital signage media players, smart displays, or edge devices, we collect technical operational data. Some of this data (such as IP addresses, MAC addresses, and device serial numbers) may constitute personal data under applicable law, and we treat it accordingly:
-
Hardware Identifiers: MAC address, IP address, device serial numbers, and device names/IDs.
-
System Metrics: Screen resolution, operating system version, app version, network connectivity status, storage space, memory usage, and internal device diagnostics (e.g., thermal statistics, uptime).
-
Proof-of-Play & Logs: Playback timestamps, content logs, display schedules, error reports, and media asset deployment metrics.
C. Audience Analytics & Sensors
Our Services do not include cameras, facial detection, audience measurement, demographic analysis, or other sensor-based technologies that collect information about individuals viewing our customers' displays. Our media players collect only the device telemetry described in Section 2(B).
D. Automatically Collected Web Data (Website & Admin Console)
-
Log Files: Browser type, Internet Service Provider (ISP), date/time stamps, referring/exit pages, and click counts.
-
Cookies & Tracking Technologies: Cookies, local storage, and tracking pixels used to preserve session state, authentication, and platform preferences. For details on the cookies we use and how to manage them, see our Cookie Policy at [link]. You can control cookies through your browser settings, and we honor opt-out preference signals such as the Global Privacy Control (GPC) where required by law.
3. Legal Bases for Processing (EEA/UK Users)
Where the GDPR or UK GDPR applies and we act as a controller, we process your personal data on the following legal bases:
-
Performance of a contract: To provide the Services, manage your account, deliver content to your displays, and provide support (Sections 2A, 2B).
-
Legitimate interests: To secure and improve our Services, prevent fraud, monitor device health, and conduct business analytics — where these interests are not overridden by your rights.
-
Legal obligation: To retain billing and tax records, respond to lawful requests, and comply with applicable law.
-
Consent: For non-essential cookies and marketing communications, where required. You may withdraw consent at any time.
4. How We Use Your Information
We use collected information for the following purposes:
-
Service Provision & Operations: To manage your account, deliver digital signage content to configured displays, render dynamic feeds, and maintain display connectivity.
-
Maintenance & Optimization: To monitor device uptime, troubleshoot playback errors, issue remote device commands, and optimize infrastructure performance.
-
Billing & Account Management: To process subscription fees, manage invoices, and send administrative notices.
-
Customer Support: To diagnose network/hardware issues and respond to technical inquiries.
-
Analytics & Platform Improvement: To analyze usage trends, evaluate feature utilization, and enhance platform security and user experience.
-
Security & Fraud Prevention: To protect against unauthorized access, malicious activity, and display tampering.
Remote Device Management
To maintain the Services, we may issue remote commands to media players running our software — for example, restarts, configuration changes, log retrieval, and software/firmware updates. Remote access is limited to management of our software and the functions described in this Policy; it is authenticated, encrypted, and logged. Customers can view device management activity in the admin console [and may configure update windows or disable specific remote functions in account settings — adjust to match your actual capabilities].
5. How Information Is Shared
We do not sell or rent your personal data, and we do not share it for cross-context behavioral advertising. We share information only in the following circumstances:
-
Third-Party Service Providers (Subprocessors): We work with vendors who provide cloud hosting and storage, payment processing, email delivery, analytics, and support tooling. These vendors are bound by contractual confidentiality and data protection obligations and may access only the data necessary to perform their services. A current list of our subprocessors is available at [link to subprocessor list], and customers may subscribe to notifications of changes.
-
Publicly Displayed Content: Content you explicitly schedule or publish to your public-facing physical displays is intended for public view.
-
Legal Requirements: We may disclose information if required by law, court order, subpoena, or government regulation, or where necessary to protect the rights, property, or safety of [Company Name], our users, or others. Where legally permitted, we will notify affected customers of such requests.
-
Business Transfers: In the event of a merger, acquisition, restructuring, or sale of assets, user data may be transferred as part of the business assets. We will notify you of any such transfer and of any resulting changes to this Policy.
6. Content & Data Ownership (Customer Media)
You retain all intellectual property rights to the media, images, video assets, live feeds, and text content uploaded to our platform ("Customer Content"). We access Customer Content strictly to host, encode, render, and deliver media assets to your designated screens as directed by your account configuration, and as otherwise permitted by our DPA and Terms of Service.
7. International Data Transfers
Our Services are hosted in [the United States, using data centers operated by Amazon Web Services and Google Cloud Platform]. If you access the Services from outside that region, your information will be transferred to, stored, and processed there.
For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including: the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum. You may request a copy of the relevant safeguards by contacting us as described in Section 12.
8. Security of Your Data
We employ industry-standard administrative, technical, and physical safeguards to protect your personal data and media infrastructure against loss, theft, misuse, and unauthorized access, including:
-
Encryption in transit (TLS/HTTPS) and encryption at rest for sensitive account data.
-
Token-based authentication between cloud controllers and media player devices.
-
Access controls, logging, regular security audits, and vulnerability patching.
No method of transmission or electronic storage is 100% secure. While we use commercially reasonable measures to protect your information, we cannot guarantee absolute security. In the event of a personal data breach, we will notify affected customers and regulators as required by applicable law.
9. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy, to comply with legal obligations, resolve disputes, and enforce our agreements. Our current retention practices include:
-
Account data: Retained for the life of the account and deleted or anonymized within 90 days of account termination, except as needed for the categories below.
-
Device telemetry and player logs: Retained for 90 days on a rolling basis.
-
Proof-of-play records: Retained for 90 days to support customer reporting and audit needs.
-
Billing and transaction records: Retained for 5 years as required by tax and accounting law.
-
Support communications: Retained for 2 years after the ticket is closed.
-
Customer Content: Deleted or returned in accordance with our DPA following account termination.
Where exact periods are not fixed, we determine retention based on the amount and sensitivity of the data, the purpose of processing, and applicable legal requirements.
10. Your Data Protection Rights
Depending on your location, you may have the following rights. Note that where we act as a processor for a customer (see Section 1), we may redirect your request to that customer and assist them in responding.
European Economic Area / United Kingdom (GDPR / UK GDPR)
-
Right of Access: Request copies of your personal data.
-
Right to Rectification: Request correction of inaccurate or incomplete information.
-
Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data under certain conditions.
-
Right to Restrict or Object to Processing: Request limits on how we process your data, including processing based on legitimate interests.
-
Right to Data Portability: Request transfer of your data in a structured, commonly used, machine-readable format.
-
Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
-
Right to Lodge a Complaint: Contact your local supervisory authority (or the UK Information Commissioner's Office) if you believe our processing violates the law.
California (CCPA / CPRA)
We do not sell personal information and do not share it for cross-context behavioral advertising. California residents have the right to:
-
Know/Access: Request disclosure of the categories and specific pieces of personal information we collect, use, and disclose.
-
Delete: Request deletion of personal information we collected from you, subject to legal exceptions.
-
Correct: Request correction of inaccurate personal information.
-
Limit Use of Sensitive Personal Information: To the extent we process sensitive personal information, request that its use be limited to permitted purposes.
-
Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
You may exercise these rights via the contact details in Section 12 or through [webform/portal link]. We will verify your identity before fulfilling a request and respond within the timeframes required by law. Authorized agents may submit requests on your behalf with appropriate proof of authorization.
11. Additional Disclosures
-
Children's Privacy: Our Services are business tools and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
-
Third-Party Links & Integrations: Our platform may allow integration with third-party feeds, dynamic web widgets, RSS streams, or social media platforms. We do not control and are not responsible for the privacy practices of these external services, and we encourage you to review their privacy policies before enabling an integration.
-
Changes to This Policy: We may update this Privacy Policy from time to time. We will post the revised version with an updated "Last Updated" date and, for material changes, notify account holders by email or in-console notice at least 30 days before the changes take effect. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.
12. Contact Us
If you have questions, concerns, or data requests regarding this Privacy Policy, contact us at:
-
Company: FGPR, Inc.
-
Email: legal@fgr.cx
-
Mailing Address: 333 Sylvan Ave, Suite 305, Englewood Cliffs, NJ 07632