Most signage vendors answer a security question with a badge. We cannot, because we hold none. What we can do is tell you who we are, where the data sits, how the screens connect, and what we do not have, so you can decide in ten minutes rather than in a three-week procurement loop. If the honest answer on this page rules us out, it is better that you find that out now.
Who we are, and which law we answer to
easyCMS is a product of DynamicDigital sp. z o.o., a limited company registered in Warsaw, Poland. Our EU VAT number is PL5213678094. We have traded in digital signage since 2014 and launched easyCMS in 2016.
That matters for three practical reasons.
- Jurisdiction. We are established in the European Union, so the GDPR applies to us directly. There is no US parent in the ownership chain, and the CMS that holds your content and your screen list runs on a server in the EU. The two places data touches a US-headquartered provider are website hosting and payments, and both are named in the table below.
- Invoicing. We invoice in euro and issue a VAT invoice carrying our Polish VAT number, handled under normal EU VAT rules. Your finance team gets a document it already knows how to process.
- Time of day. Support is answered by people in Central European Time, Monday to Friday, 09:00 to 17:00 CET. If your IT team, your finance office and your data protection officer all work European hours, so do we.
You can reach us at info@myeasycms.com or +48 509 937 137. Company details are on the about page.
Where your data lives
Three components hold anything, and here is all three.
| Component | What it holds | Where it runs |
|---|---|---|
| The easyCMS CMS | Your media, layouts, schedules, display records, account login | A server in the European Union, at Hetzner in Falkenstein, Germany |
| This website | The pages you are reading, plus contact and support form traffic | Firebase Hosting |
| Payments | Card and billing data for your order | Stripe |
The signage system itself, the part that holds your content and your screen list, runs on one server inside the EU. Nothing about your layouts, your media library or your display estate needs to leave the bloc for the product to work.
This site uses analytics cookies with your consent, and publishes a cookie policy that says what they are.
Good to know We do not publish a backup schedule, a retention period, an encryption algorithm or a sub-processor list on this page, because writing a number here that we have not committed to contractually would be worse than saying nothing. If you need any of those in writing, email info@myeasycms.com and ask. You will get an answer from a person, not a portal.
How the players connect, and why that design is the safe one
This is the part most IT departments actually care about, and it is the part where signage gets a bad name. Some systems want an inbound port opened to every screen. easyCMS does not.
- Players pull, they never listen. Each screen connects outward to the CMS on a schedule, asks what it should be showing, and downloads it. Nothing listens on the screen and nothing connects inward to it, so there is no inbound port to open on your firewall and no service on the display for someone on your network to knock on.
- The traffic is encrypted. Player to CMS communication runs over an encrypted connection.
- Every display is authorised first. A newly installed player registers itself and then sits there showing nothing. Until someone signs in to the CMS and authorises that display, it receives no content, no schedule and no media. An unauthorised device on your network cannot help itself to your content.
- Content is cached locally. Because the player holds what it needs, a network outage does not blank the screens. It stops updates, which is a very different failure.
The practical effect is that a screen on your network behaves like a workstation browsing the web, not like a server. Your firewall rules stay outbound only. The specific hosts and ports are on network requirements, which is the page to send to whoever runs your network before installation rather than after it.
Tip Put signage players on the guest or IoT VLAN if you have one. Outbound-only players work perfectly there, and it removes the screens from any conversation about lateral movement inside your main network.
What personal data signage does and does not touch
Signage is often waved through a data protection review because “it is just a notice board”. Sometimes that is right. Often it is not, and it depends entirely on what you put on the screen. What follows is general guidance from a signage vendor, not legal advice, and your own data protection officer or lawyer has the final word.
| What is on the screen | ¿Datos personales? | What that means for you |
|---|---|---|
| Corridor notices, menus, opening hours, weather, KPIs from a spreadsheet | Normally none | Low effort. Keep a note of why you concluded that |
| Visitor welcome screen naming today’s guests | Yes: names, often employer and host | Short display window, no logging of the list, and tell visitors at sign-in |
| Staff photo board, new starters, employee of the month | Yes: images of identifiable people | Get consent, and honour a withdrawal quickly, which means someone must own removals |
| Queue, ticket or appointment displays | Yes if it shows names or anything reidentifiable | Prefer initials or a ticket number over a full name |
| Camera-based audience measurement bolted on alongside signage | Yes, and this is the highest-risk category | Expect a full assessment, a lawful basis and clear signage about the camera |
Two things internal to the system are worth a moment of thought as well.
Display monitoring screenshots. The CMS can take an on-demand screenshot of what a given screen is playing. That is useful when a screen looks wrong and you are three floors away, but if the screen is showing a visitor list or a staff photo board, the screenshot contains that too. Decide who is allowed to take one.
Proof-of-play logs, on PRO and Enterprise, record which content played on which screen and when. They are about screens and content, not about viewers, and they contain no audience data. They are still records, so decide how long you keep them.
Nuestro Lista de verificación del RGPD para señalización digital Explica todo el proceso paso a paso, incluyendo las preguntas que te hará el evaluador.
Control de acceso, explicado sin rodeos
Esta es la parte menos halagadora, y preferimos que la lean aquí en lugar de descubrirla en la segunda semana.
En la cuenta easyCMS estándar y en PRO, Hay un único inicio de sesión, y todos los que publican lo comparten. No existen cuentas de usuario independientes, ni roles por usuario, ni límites de permisos. Si tres personas de su organización actualizan pantallas, las tres utilizan las mismas credenciales y el sistema no permite distinguirlas.
Las cuentas por usuario, los grupos de usuarios, los roles y los permisos son una Empresa característica. También es de marca blanca en su propio dominio, y Enterprise es el único plan recurrente que vendemos, a 1290€ por año.
| Si lo necesita | El plan correcto |
|---|---|
| Una o dos personas de confianza publicando en un puñado de pantallas | Cuenta por 49€ o PRO por 299€, un inicio de sesión compartido. |
| Separación de funciones, alcance por sitio o por departamento, inicios de sesión individuales con nombre en lugar de una contraseña compartida. | Empresa a 1290 euros al año |
Si su política de seguridad requiere cuentas individuales con nombre, y muchas lo requieren, la verdad es que los planes de pago único no la cumplen y Enterprise es la única versión de easyCMS que sí lo hace. No compre la cuenta de 49 € esperando agregarle usuarios más adelante. Encontrará más detalles en usuarios y permisos .
Tampoco ofrecemos inicio de sesión único ni autenticación multifactor en ningún plan. Las cuentas están protegidas con contraseña, y eso es todo. Elija una contraseña segura y única, y guárdela en su gestor de contraseñas, no en una hoja de cálculo compartida.
Tus datos son tuyos.
En toda evaluación seria surgen dos preguntas: ¿Qué sucede con nuestro contenido si nos vamos y qué sucede si ustedes desaparecen?
Puedes exportar tus archivos multimedia, diseños y horarios. Son archivos y registros estructurados, no una caja negra propietaria a la que solo puedes acceder a través de nuestra interfaz.
Una plataforma de suscripción no puede ofrecerle esa respuesta. Si un proveedor de SaaS, que antes era una empresa cerrada, es adquirido, cambia de rumbo o cierra, el software desaparece con él y sus pantallas se convierten en paneles. Con easyCMS usted conserva el contenido multimedia que ha subido, así como los diseños y las programaciones que ha creado, en formato exportable y alojados por nosotros en la Unión Europea. Esta promesa es menos sólida que un contrato de depósito en garantía, pero más sólida que una página de estado, y representa la esencia del argumento de la continuidad.
Lo que no tenemos
La sección más importante de esta página. Todo lo siguiente son cosas de easyCMS no tiene y no daremos a entender lo contrario en una conversación de ventas:
- Ningún informe SOC 2, de ningún tipo.
- Sin certificación ISO 27001
- Sin autorización TX-RAMP y sin certificación HIPAA.
- Ninguna certificación de ningún tipo, de nadie
- No hay un acuerdo de nivel de servicio (SLA) de tiempo de actividad publicado ni créditos de servicio.
- No hay página de estado público
- Sin SSO ni SAML, y sin autenticación multifactor
- No hay programa de recompensas por errores.
- No se ha publicado ningún informe de prueba de penetración.
- Ningún producto de registro de auditoría está incluido en ningún plan, ni tampoco hay un registro de actividad que indique quién cambió qué.
Si su oferta, su aseguradora o su cuestionario de seguridad requiere alguno de esos, No somos el proveedor adecuado para usted. Y publicarlo en una página pública nos ahorra un mes a ambos. Existen proveedores que publican un acuerdo de nivel de servicio (SLA) formal y un programa de certificación; cobran una suscripción por pantalla al año para financiar ese trabajo, y para algunas organizaciones, ese es el trato justo. El nuestro es otro trato: jurisdicción de la UE, alojamiento en la UE, un precio único para todos los planes excepto el Enterprise, y sin papeleo que no hayamos realizado nosotros mismos.
Lo que publicamos y lo que no.
| Pregunta | Nuestra respuesta |
|---|---|
| ¿Dónde está alojado el CMS? | Publicado en: UE, Hetzner , Falkenstein, Alemania |
| ¿Quién es la entidad contratante? | Publicado por: DynamicDigital sp. z oo, Varsovia, Polonia, NIF PL5213678094 |
| ¿Cómo se conectan los jugadores? | Publicado: cifrado, solo saliente, autorizado por pantalla |
| Privacidad, cookies y términos | Publicado en este sitio |
| Acuerdo de procesamiento de datos | No publicado. Correo electrónico myeasycms.com |
| Períodos de retención y lista de subprocesadores | No publicado. Correo electrónico myeasycms.com |
| Detalles del cronograma de copias de seguridad y del cifrado | No publicado. Correo electrónico myeasycms.com |
| Acuerdo de nivel de servicio (SLA) de tiempo de actividad, página de estado, prueba de penetración | No existen |
| SOC 2, ISO 27001, HIPAA, TX-RAMP | No existen |
Solicitar un DPA o una respuesta de seguridad específica
Correo electrónico myeasycms.com con la pregunta o el cuestionario, e indíquenos su fecha límite. Un Acuerdo de Procesamiento de Datos y las preguntas sobre obligaciones específicas del RGPD se gestionan de esa manera, por personas en lugar de por una biblioteca de documentos. Si le resulta más fácil, utilice el formulario de solicitud de soporte o llame +48 509 937 137 durante el horario de oficina CET. Cómo funciona el soporte y qué es gratuito frente a qué es de pago, se detalla en Opciones para obtener ayuda y apoyo .
Nuestras políticas publicadas son las política de privacidad , el política de cookies y el Términos y condiciones . Los precios de cada plan mencionado anteriormente, incluyendo lo que Enterprise agrega, se encuentran en el página de precios .