Legal · Privacy

Privacy policy.

How Mediasoft Development protects personal data when you visit eMedia Cards or use the software.

Last updated: 2 October 2026 · Controller: Mediasoft Development S.A.S.

This page explains how Mediasoft Development S.A.S. processes personal data when you visit www.emedia.cards and when you use the eMedia Cards software (including partner beta builds). It refers to Articles 13 and 14 of the GDPR (EU 2016/679).

We do not sell personal data. Cardholder records, photos and print jobs stay on your computer unless you use Mobile Print Center or Web Print Center. Those cases are described below.

1. Who we are

Mediasoft Development S.A.S. (“we”, “us”) is the data controller for licensee, workstation and support data.

We have not appointed a DPO. Privacy requests go to the address above.

2. What this policy covers

  • This public website.
  • eMedia Cards partner-beta licensing (Activate and the silent launch check).
  • Optional crash logs and diagnostic reports you send to us.
  • Software-update downloads.
  • Optional cloud feature: Mobile Print Center (Wifimage).
  • Optional cloud feature: Web Print Center (a browser link that prints on this PC).
  • Optional connection to Google Sheets / Google Drive from the PC.

It does not cover how you process cardholder data in your own files, databases or printers. For that processing you are the controller; we may act as your processor only for Mobile Print Center in section 4.5 and for Web Print Center in section 4.7.

3. Controller and processor

ActivityOur role
License key, registrant name and e-mail, Device ID, hostname, crash/diagnostic files sent to usController
This websiteController
Mobile Print Center (Wifimage) jobs and photos on our cloudProcessor (you remain controller of the photos and fields)
Web Print Center jobs on www.emedia.cards (encrypted form, photo and printed-card picture)Processor (you remain controller of the cardholder data). The content key is not sent to us.
Google account, Sheets and Drive filesGoogle is an independent controller of the Google account. OAuth tokens remain on the PC. eMedia Cards uses the Google connection only to access, at the user's request, files that the user selects or authorises for use with the software.

4. What we process

4.1 Help → Activate (partner beta)

When you activate an eMedia Cards license, we receive:

  • Required: license key, name, e-mail, Device ID (derived from workstation hardware).
  • Optional on the same form: title/civility, company, country, phone/fax, postal address, ZIP/city.
  • Technical: hostname, application version, compile date. On activation we also store the hardware values used to compute that Device ID, with the license seat.

These fields identify a person at a company (ordinary personal data). They are not “special categories” under Article 9 (health, biometrics used to uniquely identify someone, etc.).

4.2 Later launches (silent check)

Each launch of a partner-beta build asks our license server whether this PC may still run. The software sends only:

  • license key, Device ID, hostname, application version, compile date.

It does not re-send your name, e-mail, address, civility or those hardware values.

Our server also sees the public IP address of the connection (standard for HTTPS).

4.3 Crash logs and diagnostic reports

  • Automatic crash report (partner beta, on by default): after an unexpected close, the next successful launch may send a crash report only (process identifiers, exception traces). Paths in that file can include a Windows user name. It does not include card records or photos. You can turn this off in Options → Logs.
  • Manual diagnostic report: Help → Send diagnostic report (or Options → Logs). You choose which log files to include and confirm twice. Those files can contain file paths and, if you turned those logs on, text related to records. We do not receive that report unless you send it.

4.4 Software updates

When the software downloads an update, the request may include a Device ID so we can tell which workstations applied a given build. It is not used for advertising.

4.5 What stays on your PC

  • Card templates, internal databases (.eccdb), Excel/CSV links, print-activity names, local diagnostic logs.
  • Face framing for photos runs on the device to compose the picture. We do not send a biometric template to our servers and we do not use it to uniquely identify a person.

If you enable Mobile Print Center, photos and field values are captured on the phone, stored on wifimage.mediasoft.dev, then downloaded to this computer for printing. For this processing, you remain the controller and Mediasoft acts as your processor on your documented instructions. The processing is subject to the applicable data-processing terms required by Article 28 GDPR.

4.6 Visits to this website

When you visit these pages, the hosting server may log a technical request (IP address, date, browser, URL) for security and operation. We do not run advertising or audience-measurement cookies on this privacy page.

4.7 Web Print Center

If you turn Web Print on, a browser that opens the link can fill in the card that is open on this PC and ask this PC to save and print it. The link carries a content key after #. Browsers do not send that part of the address, so our server does not receive the key and cannot read the fields, the photo or the picture of the printed card.

Before anything is sent, the phone and this PC encrypt it. We store only that ciphertext on the server that hosts www.emedia.cards, in France. A job is deleted when this PC fetches it. The picture sent back to the browser is deleted when the browser fetches it. The description of the open card (field names, choice lists and the template preview) is deleted when you turn Web Print off or choose a new link. If this PC goes offline with Web Print still on, or if a delete does not finish, what remains is deleted within 24 hours.

We also keep the link identifier, which license and workstation it belongs to, a language code, a short-lived note of which browsers have the page open, and daily counts of jobs fetched or dropped. Those records do not contain card fields or photos. The counts are operational totals. The link identifier stays while that PC keeps the link.

For this processing you remain the controller of the cardholder data. Mediasoft acts as your processor on your documented instructions. The processing is subject to the applicable data-processing terms required by Article 28 GDPR. The phone may keep the last printed picture in its own browser storage until you clear the form or this PC opens another card. That copy is on the phone, not on our server.

5. Why, and on which legal basis

PurposeBasis (GDPR Art. 6)
Bind a license key to a workstation; support the licensee (name, e-mail, Device ID)(b) contract (beta / software license)
Hostname, launch check log, IP, crash telemetry (closed partner beta, EULA, opt-out), update Device ID(f) legitimate interest — operate the beta, fix defects, attribute applied updates. You may object (see rights).
Optional Activate fields (address, phone, civility) and manual diagnostic report(a) consent — you choose to fill them or to send the report
Mobile Print Center photos and fields (Wifimage)We act as processor on your documented instructions (Art. 28)
Web Print Center card data (encrypted on the way through www.emedia.cards)We act as processor on your documented instructions (Art. 28)
Website security logs(f) legitimate interest — keep the site available and secure

6. Who receives data

  • Mediasoft staff who operate licensing and support (France).
  • The self-hosted server that hosts the license API and crash store (not a public SaaS).
  • The Mobile Print Center (Wifimage) cloud, only if you enable that feature (phone jobs until this PC downloads them).
  • The Web Print Center mailbox on www.emedia.cards, only if you turn that feature on. It holds ciphertext until this PC or the browser fetches it, and it does not receive the content key.
  • Hosting of www.emedia.cards (the web server that receives HTTPS requests).
  • Google, only if you sign in to Sheets/Drive from the app (your Google account).

We do not sell data and we do not use it for third-party advertising. Data is stored in France. We do not intend to transfer licensee files to a country outside the EEA. If a transfer were required, we would use an adequacy decision or Standard Contractual Clauses.

7. How long we keep it

DatasetPeriod
Licensee / workstation on the bound seat (name, e-mail, Device ID, hardware values stored at Activate)Life of the license, then up to 5 years after the end of the contractual relationship where necessary for support, the establishment, exercise or defence of legal claims, and proof of the contractual relationship. The data is then deleted or anonymised, unless a longer period is required by law.
Launch check log (Device ID, hostname, IP, version)90 days, then deleted automatically. Support can delete a workstation on request where applicable (that removes the bound seat; the launch log is already time-limited).
Crash and diagnostic files90 days, then deleted
Mobile Print Center (Wifimage) card data and photos awaiting retrievalNormally only for the time required to transfer and process the job. Pending card data may be retained for up to approximately 7 days and is deleted after retrieval/printing. Unretrieved card previews may be retained for up to 24 hours. Pairing and service metadata may be removed after 6 months of inactivity.
Web Print Center ciphertext (the job, the printed-card picture, and the open-card description)The job is deleted when this PC fetches it. The picture is deleted when the browser fetches it. The open-card description is deleted when you turn Web Print off or choose a new link. Anything still waiting, including after this PC goes offline, is deleted within 24 hours. The link identifier, license, workstation, language and daily counts (without card contents) stay while that PC keeps the link.
Local logs on your PCCapped on disk (about 1 MB per file, 16 MB folder). You can clear them in Options → Logs
Website server logsShort technical retention by the host, for security

8. Security

License and crash connections use HTTPS. Access to the administration site is password-protected and restricted by IP address. Web Print jobs also travel over HTTPS and are encrypted with a key that stays in the link and on the PC. That key is not sent to our server. No security measure is perfect; we limit what we collect on ordinary launches for that reason as well.

9. Your rights

If the GDPR applies to you, you may request access, rectification, erasure, restriction, objection (including to legitimate-interest processing such as crash auto-submit), and data portability where the basis is contract or consent. You may withdraw consent for optional fields or a diagnostic send without affecting Activate itself.

Write to support@emedia-cs.com from an address we can match to the license, and identify the Device ID or hostname if you can. We will answer within one month (extendable by two months for complex requests, with notice).

You may also lodge a complaint with the CNIL (see contact) or with your local supervisory authority in the EU/EEA.

10. This website

The product site is https://www.emedia.cards (apex emedia.cards redirects here). These privacy pages do not set advertising cookies and do not load third-party analytics. If we later add audience measurement, we will update this page and, where required, ask for consent.

11. Google Sheets and Google Drive

Connecting Google Sheets and Google Drive is an optional feature of eMedia Cards. It is enabled only when you explicitly choose to connect a Google account from within the software.

eMedia Cards uses Google APIs to let you select, read and, when you request it, modify Google Sheets files or other Google Drive files used as data sources or resources for card creation and personalisation.

The access requested is limited to the files you explicitly select or authorise for use with eMedia Cards. eMedia Cards is not intended to browse or use your entire Google Drive without an action from you.

The OAuth tokens required for the connection are stored locally in the Windows user profile on the relevant workstation. Mediasoft Development does not receive or store your Google password. Access tokens are not used for any purpose other than operating the Google connection requested by the user.

Data obtained from Google Sheets or Google Drive — for example spreadsheet cells, file names, images or other selected resources — is processed only to perform the features requested in eMedia Cards, including using a Google Sheet as a data source for creating, personalising and printing cards.

This data is not sold, rented, used for advertising, used to build marketing profiles, or used by Mediasoft Development to train artificial-intelligence models. It is not copied to Mediasoft servers solely because the Google connection is used, unless another feature explicitly enabled by the user requires this and is described in this policy.

You can disconnect your Google account from eMedia Cards. Doing so removes the OAuth authorisation information stored locally by the software. You can also revoke eMedia Cards’ access directly from the security and permissions settings of your Google Account.

Revoking access prevents any further access through that authorisation. It does not delete files or data that you have already chosen to store locally on your computer, or data already printed or exported at your request.

eMedia Cards’ use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

12. Changes

We will update this page when our processing changes in a material way. The date at the top is the last revision.

13. Contact and CNIL

Mediasoft Development S.A.S.
228, rue de la Convention
75015 Paris, France
support@emedia-cs.com

Commission Nationale de l’Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
www.cnil.fr