Trust Center
How Mediasphere protects your creative work, your data, and your team's privacy. Everything procurement and legal teams need, in one place.
Security Practices
- Encryption: All data is encrypted in transit (TLS 1.2+) and at rest.
- Tenant isolation: Every record is scoped to your organization with row-level security enforced at the database layer — verified by automated cross-tenant isolation tests.
- Access control: Role-based permissions (Owner, Admin, Member, Viewer, Guest) with server-side enforcement. Approval and audit fields are server-controlled and cannot be modified by end users.
- Authentication: Google single sign-on (OAuth), email verification (OTP), and secure password reset flows.
- Share links: Optional password protection, expiry dates, download limits, watermarking, and full access logging.
Audit & Compliance Records
Mediasphere maintains server-stamped, append-only records designed to stand up to legal and regulatory review:
- Complete approval chains: who approved which exact file, when, with what feedback
- Downloadable Approval Certificates (PDF) for any approved creative
- Workflow audit trails with every stage transition, delegation, and escalation
- Usage rights tracking with automated expiry enforcement and takedown checklists
- Organization-level activity logs retained per your configured retention policy
GDPR & Your Data Rights
We support data subject rights for all users, in line with GDPR and similar frameworks (CCPA):
- Right to access / portability: Self-serve export of your personal data and full organization data (ZIP) from Settings → Privacy.
- Right to erasure: Self-serve deletion of personal data and full account deletion with cascade removal of organization data.
- Consent records: Cookie and processing consent is recorded with timestamps, per category.
- Withdraw consent anytime: Update your cookie choices below — changes are logged to your consent history.
- Talent consent: Usage rights for talent/models are tracked with expiry dates; expired consent automatically flags and archives affected creatives.
Subprocessors
We use a small number of vetted subprocessors to deliver the service:
| Provider | Purpose | Location |
|---|---|---|
| Base44 (Wix) | Application hosting, database & authentication | United States / EU |
| Cloudflare R2 | Creative file & asset storage | Global (distributed) |
| Stripe | Payment processing & billing | United States |
| Resend | Transactional email delivery | United States |
| Google Cloud | Single sign-on (OAuth) & AI services | United States / EU |
Data Retention & Deletion
- Deleted creatives and projects are recoverable from Trash for 30 days, then permanently purged.
- Configurable organization-level data retention policy (default 365 days for activity logs).
- On account cancellation, organization data is retained briefly for recovery, then permanently deleted on schedule.
- Backups follow the same deletion lifecycle.
Data Residency
Application data is hosted on Base44 infrastructure (US/EU). Creative files are stored on Cloudflare R2's distributed network with private buckets — files are only accessible through short-lived signed URLs issued after permission checks.
Data Processing Agreement (DPA)
We offer a Data Processing Agreement to all customers on request. Enterprise plans include custom DPA review, security questionnaires, and vendor assessment support.
Security questions? DPA request?
Our team responds to security questionnaires and DPA requests within 2 business days.
Contact Us