Legal · updated 14 September 2026

Privacy Policy

Draft pending legal review. This document describes how TKDS intends to operate and may change before it is finalised. Questions: info@tkdsmedia.com.

This policy covers two things: the personal data TKDS Media collects through this website, and how we handle data as the company behind MediaCore2. On every platform, the organisation running it decides what happens to its audience’s data — we process that data on their behalf.

01Who we are

MediaCore2 — Unified Media Ecosystem is built and operated by TKDS Media. In this policy, “TKDS”, “we” and “us” mean TKDS Media.

We work from two offices: Cairo, Egypt (Zahraa Maadi · Katameya · Kenda Compound, +1 202 555 0147) and Ohio, United States (2792 Indian Ripple Rd, +1 231 360 0088). Privacy questions and requests go to info@tkdsmedia.com.

02Two roles, depending on whose data it is

We carry different responsibilities for different people. Which one applies depends on how your data reached us.

Whose dataOur roleWhose notice applies
Visitors to this website, and anyone who sends us a demo request, a message or a partner applicationController — we decide why and how it’s usedThis policy
People at our customers and partners: buyers, administrators, billing and technical contactsControllerThis policy
Viewers, subscribers, buyers, commenters and staff on a platform an operator runs on MediaCore2Processor — we act on the operator’s instructionsThe operator’s own privacy notice

03What we collect through this website

  • Demo requests — your name, work email, organisation, what you broadcast and roughly how large your audience is.
  • Messages and partner applications — the contact details you give us and whatever you choose to write.
  • Correspondence — emails, call notes and meeting details when we talk with you about MediaCore2.
  • Documentation feedback — whether an article helped, and any comment you add.
  • Request data — like every website, the servers that deliver this one receive standard technical details with each request: IP address, browser and device type, the page asked for, the referring page and the time. We use them to deliver pages, keep the site secure and find faults.
  • A preference on your device — whether you’re viewing the site in the light or dark theme. It stays in your browser and isn’t sent to us. See the cookie notice.

We don’t ask for sensitive information through this website, and we’d ask you not to send any.

04How we use it

PurposeWhat we useLegal basis
Answer your enquiry and arrange a demoDemo requests, messages, correspondenceSteps you asked us to take before a contract, and our legitimate interest in replying
Scope, price and set up a platform for your organisationBusiness contact details, correspondencePerforming, or preparing to perform, a contract
Review and manage partner applicationsPartner applications, correspondenceLegitimate interests
Deliver the site, keep it secure and fix faultsRequest dataLegitimate interests
Improve our documentationDocumentation feedbackLegitimate interests
Keep the business records the law requiresContracts, invoices, correspondenceLegal obligation

We send product news only to business contacts who asked for it, or where the law otherwise allows it. Tell us to stop at any time and we will.

We don’t sell personal data, and we don’t use enquiry details to build advertising profiles.

05Data inside the platforms operators run

Each MediaCore2 platform belongs to the organisation that runs it — the operator. Their content, their audience and their customer list are theirs. In running a platform for an operator, we process its audience’s data on the operator’s behalf, under our agreement with them and the Data Processing Addendum.

What a platform holds depends on the modules and add-ons the operator switches on. It can include:

  • Viewer accounts: a name and email address, or a mobile number where phone-number sign-in is installed
  • Subscriptions, event tickets and store orders, with their payment status and receipts
  • Signed-in devices, and when each one was last active
  • What a viewer saved, how they rated it, and where they stopped watching
  • Comments, reels, clips, contact messages and form submissions — including any uploads and signatures a form asks for
  • Notification preferences, and the announcements a person received
  • Staff accounts, their roles, and the activity log of what each person changed

We use this data only to provide, secure and support the operator’s platform. We don’t sell it, we don’t use it to market our own services to an operator’s audience, and we don’t contact their viewers on our own account.

06Built to hold less

Several privacy decisions are made in the product itself, so an operator doesn’t have to remember to make them:

  • No readable IP addresses in analytics. The built-in audience analytics keep an irreversible scrambled value for each visitor — never a readable IP address.
  • Repeat views are de-duplicated. The same visitor on the same page within 30 minutes, or on the same title within 6 hours, isn’t counted twice.
  • Collection can be switched off. An operator can turn built-in analytics off entirely, or use their own external analytics account instead — in which case that provider’s terms and the operator’s notice apply.
  • Card details never touch the platform. Buyers pay on Stripe, PayPal or Square’s own hosted page, or type their card into the provider’s own secure field, where it becomes a token. Only the token is sent on, and every payment is re-verified with the provider before access is granted.
  • Payment keys are stored encrypted and shown back to staff only as their last four characters.
  • Form uploads stay private, released only to a reviewer or to the applicant’s own link.
  • Viewers control their own devices. Every signed-in browser, phone and TV is listed on the viewer’s account, and they can sign any of them out in one tap.
  • People choose their notifications. Each recipient sets their own switches by category; only a small set of billing-critical messages stays on.

07Who we share it with

A short list, deliberately:

  • Service providers who work for us — hosting, streaming and delivery infrastructure, email and business tools — bound by contract to use the data only to provide their service to us. The categories that handle platform data are described in the DPA.
  • Services an operator connects themselves — their Stripe, PayPal or Square merchant account, their own mail account, an external analytics account, a chat widget. Those are the operator’s choices and relationships, covered by the operator’s notice.
  • Professional advisers, such as lawyers and accountants, under a duty of confidentiality.
  • Authorities, where the law requires it. When a request concerns an operator’s platform, we refer it to the operator unless the law prevents us.
  • A successor business, if TKDS or MediaCore2 is reorganised, merged or sold — with the same protections described here.

08International transfers

TKDS works from Egypt and the United States, and some of our service providers operate in other countries. Personal data may therefore be processed outside the country where it was collected. Where the law requires a safeguard for that transfer, we put one in place.

09How long we keep it

  • Enquiries that don’t lead anywhere are kept as long as we need to reply and follow up, then deleted or anonymised.
  • Customer and partner records are kept for the life of the relationship, and afterwards for as long as contract, tax and accounting law requires.
  • Request data is kept for a limited period for security and fault-finding, then deleted.
  • Platform data is kept on the operator’s instructions, and returned or deleted when their agreement ends, as the DPA sets out.

10Security

We protect personal data with measures suited to the risk: access limited to the people who need it, passwords stored only as one-way hashes, payment credentials stored encrypted, and an activity log on every platform that records who changed what across 54 record types.

No system is perfectly secure. If a breach affects personal data, we notify those we must — the operator, for data on their platform, and you or the relevant authority where the law requires. Our trust page describes the platform’s protections in more detail. Report a vulnerability to security@tkdsmedia.com.

11Your rights

Depending on where you live, you may have the right to:

  • Find out whether we hold personal data about you, and get a copy
  • Correct data that’s wrong or incomplete
  • Ask us to delete it
  • Object to, or ask us to restrict, how we use it
  • Receive the data you gave us in a portable format
  • Withdraw consent, where consent is what we rely on
  • Complain to the data protection authority where you live or work
  1. 1
    Write to us

    Email info@tkdsmedia.com and tell us what you’d like us to do.

  2. 2
    Confirm it’s you

    We may ask for information to verify your identity before we act, so nobody else can obtain your data.

  3. 3
    Get our answer

    We reply within the time the law that applies to your request allows, and explain if we can’t do everything you asked.

12Children

This website is for organisations evaluating and buying MediaCore2. It isn’t directed at children, and we don’t knowingly collect their data through it.

Operators whose platforms serve young people — a youth league, a club’s junior teams — are responsible for the consents their law requires, including a parent or guardian’s where one is needed.

13Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects how we use personal data we already hold, we tell the people affected before it takes effect.

14Contact

  • Privacy questions and requests: info@tkdsmedia.com
  • Security reports: security@tkdsmedia.com
  • Cairo, Egypt: Zahraa Maadi · Katameya · Kenda Compound · +1 202 555 0147
  • Ohio, United States: 2792 Indian Ripple Rd · +1 231 360 0088