Controller
[TODO: company name and address (see imprint)]
Contact for privacy questions: [TODO: privacy contact e-mail; data protection officer if required]
This website
- The public pages (home, features, pricing, docs, legal) use no analytics, no tracking and no third-party content. Fonts, images and scripts are served from this site.
- The theme you pick (light, dark, automatic) is kept in your browser’s local storage and never sent to us.
- Our web server processes your IP address and the request to deliver the page and to limit abuse (rate limits on registration and login). [TODO: server/ingress log retention, hosting provider]
License portal (account)
- Account: e-mail address, optional company or name, password (stored only as a salted hash), when the address was confirmed, roles (reseller, admin) and, for reseller customers, the reseller account.
- Session cookie: after you log in, a strictly necessary, HTTP-only cookie keeps you logged in. No other cookies.
- E-mails: we send the address confirmation, password reset links and license expiry reminders (14, 7 and 1 days before expiry). [TODO: e-mail provider]
- Trial: to grant one trial per company e-mail domain (free-mail addresses: per address), we keep the domain or address that received a trial.
- Licenses: the licenses issued to your account, their seats and the servers that use them.
Media server: license heartbeat
Every Alteox Media Server installation — with or without a license — sends a heartbeat to the license portal
(https://license.alteox.app/api/v1 by default) once per hour over HTTPS. Accepting the EULA includes this heartbeat; there is
no separate opt-out. It contains:
| Field | Content |
|---|---|
install_id | Random installation id, created on the server’s first start |
fingerprint | Hash (SHA-256, truncated) of the machine id, the DMI product UUID and the MAC addresses of physical network cards — identifies the machine, not a person |
version, commit, build_date | Media server version |
license_id, status | The license in use (if any) and its state: unlicensed, trial, active, grace, expired or invalid |
channels, nodes | Number of channels and cluster nodes |
os, arch, cpu_cores, gpus | Operating system, CPU architecture, number of CPU cores, GPU models |
hostname, public_url | The server’s host name and its configured public URL |
eula_version, eula_accepted_at | Which EULA version was accepted, and when |
The portal stores the latest values per installation together with the time of the first and the last heartbeat, the number of heartbeats and the IP address the last request came from. It answers with the server time and messages shown in the server’s UI (for example “license expires in 7 days”).
- Heartbeats of servers without a license appear in the portal as unclaimed servers; entering a license key assigns the server to the license holder’s account.
- When a license is activated and while it is in use, the server also sends the license, its
install_idandfingerprintto obtain a lease (hourly renewal). - The heartbeat contains no stream content, no source URLs, no viewer data and no configuration beyond the counts above.
- A failed heartbeat never changes what the server does. A lease stays valid for 72 hours without contact; offline licenses need no connection at all.
[TODO: legal basis for the heartbeat and lease data, retention period, recipients]
Your rights
[TODO: data-subject rights (access, rectification, erasure, restriction, portability, objection), right to lodge a complaint with a supervisory authority]