Data Protection Contacts
Version 3.0 · Effective 5 October 2026
This page explains who to contact at Cyberinfra Limited ("ScreenJournal", "we", "us") about data protection, privacy rights and grievances, how we handle your request, and where you can complain if you are not satisfied.
How to contact us
Email support@screenjournal.ai with the subject line "Data protection request". Dedicated officer mailboxes will replace this address once they exist; we will update this page when they do.
Post: Cyberinfra Limited, 50 Athol Street, Douglas, Isle of Man IM1 1JB.
Our contacts are roles, not named individuals:
- Data Protection Officer (role): our point of contact for data protection questions and rights requests, including under the Philippine Data Privacy Act of 2012, UK and EU data protection law, and the Isle of Man's data protection law.
- Grievance Officer, India (role): our point of contact for grievances under India's Digital Personal Data Protection Act, 2023.
Which officer handles your request
You do not need to work this out yourself: write to the address above and we route the request. For reference, we decide which officer and which law applies from the jurisdiction setting of the organisation that uses ScreenJournal and, for individuals, the region recorded when you sign in to the desktop app (derived from the network address you sign in from).
If you are a monitored employee
If your employer uses ScreenJournal to monitor work activity, your employer is the first point of contact. Your employer decides what is collected and why; we process that data on its behalf, as its processor. Please raise access, correction or deletion requests with your employer first. If you write to us directly, we will pass the request to your employer and help it respond, but we may not be able to act on monitoring data without its instruction.
Where your employer has enabled it, you can also redact a time range yourself from your own timeline. A redaction removes the activity data for that range. Alert evidence clips are not removed by a member's redaction request. See our Retention & Deletion Protocol for how long each kind of data is kept and how it is deleted.
How we handle a request
What you can ask for. You can ask to access, correct or delete your personal data, to withdraw a consent you have given, or to object to or restrict processing where the law that applies to you gives you that right.
Verifying who you are. Before we act, we verify that the request comes from you or from someone entitled to act for you. We do this through the sign-in email on your account: we send a sign-in (magic) link to that address, or ask you to write from it. For monitored employees we may instead verify the request through your employer's administrator. We will not disclose personal data to anyone we cannot reasonably verify, and we use verification details only for verification.
Agents and nominees. If someone acts for you (an authorised agent, a nominee under India's law, or an heir or personal representative under Philippine law), we ask for proof of their authority and verify their identity before we act.
Acknowledgement. We acknowledge every request.
Timing and extensions. We respond within the period the law that applies to you sets. Where a request is complex, or you send several at once, and the law allows an extension, we tell you before the original period ends, explain why, and say when you can expect a reply.
Refusals. If we cannot do what you ask, in whole or in part, we explain why and the legal ground we rely on, and tell you how to complain (see below). We may decline requests that are manifestly unfounded or repetitive, and where we do, we tell you so and why.
Complaints
If you are not satisfied with how a request has been handled:
- Your employer. If you are a monitored employee, raise it with your employer first; it is responsible for the monitoring.
- Us. Write to us at the address above and ask for the response to be reviewed.
- A regulator. You can complain to a data protection authority at any time:
- Isle of Man: the Isle of Man Information Commissioner, our home regulator (inforights.im).
- EEA and UK: your local data protection authority (in the UK, the Information Commissioner's Office).
- India: the Data Protection Board of India, once its complaint provisions commence. Until then, raise the grievance with our Grievance Officer through the address above.
- Philippines: the National Privacy Commission (privacy.gov.ph).
Security reports
To report a security vulnerability, follow our Vulnerability Disclosure Policy.
Language
We handle requests in English. Ask us if you need another language.
Related documents
Our Privacy Policy explains what we collect and why. Our Subprocessors page lists the third parties that process data for us, and our Security page describes how we protect it. All our legal documents are listed on the Legal page.
Changes and previous versions
- 5 October 2026v3.0: role-based contacts routed to support@ until the officer mailboxes exist; Isle of Man Information Commissioner and EEA/UK routes; acknowledgement rules.
Questions about this document: support@screenjournal.ai. Canonical URL: /legal/dpo-grievance-contacts.