Security & data handling

Transparent about how we handle your data.

This page is maintained by JKL Screens to answer common security, privacy and hosting questions from customers and their IT teams. It reflects the controls that are live in the product today — not any certification or independent audit.

Where data lives

Customer databases, media uploads and backups are hosted in the European Union (Ireland / Frankfurt regions) via our managed infrastructure provider. Static assets and edge routing are served from Cloudflare's global network, with EU points-of-presence preferred for European visitors.

Encryption

All traffic to jklscreens.com and to the API is served over HTTPS with modern TLS. Databases and object storage encrypt data at rest. Payment card data never touches our servers — Stripe collects it directly.

Authentication

Email + password (PBKDF2/argon2 handled by the auth provider) and Google OAuth. Sessions use signed tokens with automatic refresh. Multi-factor authentication is on our roadmap for Q1 2027.

Role model & tenant isolation

Every table in the database is protected by row-level security scoped to your organisation. Server-side checks derive the organisation ID from the authenticated session — never from client input. Roles available today: Owner, Admin, Member.

Sub-processors

We use the following service providers to run JKL Screens. If any of this changes we will update this page before or as the change goes live.

ProviderPurposeRegion
Supabase (Lovable Cloud)Database, authentication, media storageEU (Ireland / Frankfurt)
CloudflareCDN, DNS, DDoS protection, edge runtimeGlobal, EU point-of-presence
StripePayment processing & subscription billingEU / UK
Lovable EmailsTransactional email deliveryEU
Google Cloud (OAuth)Optional Google sign-inEU / Global

UK GDPR position

JKL Screens is the data processor for content and playback data you upload. You (the venue operator) are the data controller. We only process personal data on your documented instructions and do not use customer data to train AI models or for advertising.

Data Processing Addendum

A DPA is available on request. Email security@jklelectrix.com with the legal entity name and we'll send our current template.

Security contact

Suspected vulnerability or incident? Email security@jklelectrix.com. We aim to acknowledge within one working day. Please do not exploit or publicly disclose issues before we've had a chance to respond.