Mobile App Privacy Policy

Meteoros Mobile App / Meteoros Operations System (MOS) — Global

Effective date: 1 September 2026Last updated: 1 September 2026

This Privacy Policy explains how Meteoros Sensing Private Limited ("Meteoros," "MOS," "we," "us," or "our") handles personal data when you download, access, or use the Meteoros Mobile App, contact support, or interact with related services.

For App account, product, support, and service-operation data, Meteoros may act as a controller/data fiduciary. For Customer Data processed in a customer's MOS environment, the customer is generally the controller/data fiduciary and Meteoros acts as a processor/data processor under the customer's documented instructions. The applicable customer agreement and data-processing agreement control those roles.

1. Scope and controller

Meteoros Sensing Private Limited

Registered office: No. 9 (Plot 16), Kennedy Street, Tambaram West, Chennai, Tamil Nadu, India, Pin - 600045

CIN: U62011TN2025PTC180776

GST: 33AATCM4130F1ZL

Privacy, support and security-incident contact: desk@meteoros.io

2. Personal data we may process

The App may process the following categories, depending on your role, permissions, customer configuration, and use of features:

CategoryExamplesWhy it is used
Account and professional dataName, work email, phone number, employer, job title, username, user ID, role, organizationAuthentication, access management, support, auditability
Authentication and security dataPassword hash or identity-provider token, MFA status, login history, device/session identifiers, IP address, security eventsSecure access, fraud prevention, investigation
Operational and audit dataLock/device identifiers, asset and site labels, lock status, tamper events, battery/connectivity telemetry, actions, approvals, timestamps, notes, work recordsDevice monitoring, operational workflows, alerts, traceability, audit reports
NFC dataNFC tag/device identifier and scan time; associated user, device, asset, or actionIdentify authorized devices/assets and create traceable operational records
Camera and uploaded mediaQR/barcode scan value; photos or attachments you choose to capture/upload; metadata included in the fileIdentify an asset/device; provide evidence, support, or audit records
Location dataApproximate or precise device location, timestamp, and accuracy where permission is granted and feature/customer configuration requires itField-action verification, site association, nearby assets, audit records, safety/operational workflow support
Notification dataDevice push token, platform, alert preferences, delivery and interaction statusDeliver authorised push notifications and manage preferences
Technical and diagnostic dataApp version, operating system, device model, crash reports, logs, network state, language, performance eventsMaintenance, support, security, quality improvement
Support communicationsMessages, ticket details, attachments, call/meeting notes, contact detailsRespond to requests and improve support

Location: the Meteoros Mobile App does not use location data for advertising. Unless clearly stated in the App and enabled by the applicable build and customer configuration, MOS does not collect location in the background.

Camera: the camera is activated only after you choose a camera-based feature and grant permission. Camera images are not used for facial recognition, advertising, or biometric identification unless a future feature is separately disclosed, legally reviewed, and enabled with an appropriate lawful basis.

NFC: NFC data is used to read compatible tags or identifiers for MOS functionality. It is not used for contactless payment processing.

3. Sources of data

We receive personal data from you, your device, your employer or customer administrator, the connected MOS environment, compatible locks/devices/gateways, identity providers, support interactions, and service providers that assist with the App.

4. Purposes and legal bases

Where GDPR or equivalent law applies, we process data on one or more of these legal bases:

PurposeTypical legal basis
Provide accounts, access control, requested App features, support, and contractual servicesPerformance of a contract or steps requested before a contract
Process device, audit, NFC, camera, and location records configured by a customerContract; legitimate interests; or processing on the customer's documented instructions, as applicable
Secure the App, prevent misuse, maintain logs, investigate incidents, and improve reliabilityLegitimate interests and, where applicable, legal obligations
Comply with law, regulatory requests, tax/accounting rules, or legal claimsLegal obligation and legitimate interests
Optional location, camera, notifications, analytics, or other permission-based processing where consent is requiredConsent, which you may withdraw through device settings or the App where available
Send direct marketing unrelated to essential service communicationsConsent or legitimate interests where permitted; always subject to opt-out

Where the Digital Personal Data Protection Act, 2023 and applicable Indian rules apply, Meteoros will provide the required notice and seek consent when consent is the appropriate basis. You may withdraw consent using device settings, in-app controls where available, or by contacting desk@meteoros.io. Withdrawal does not affect processing already carried out lawfully before withdrawal, and some functions may no longer operate.

5. Permissions and your choices

You control mobile permissions through iOS or Android settings. Refusing a permission does not prevent you from using unrelated features, but it may prevent the corresponding feature from working.

  • NFC permission/availability: you can choose not to use NFC-based workflows. NFC scans may be unavailable on devices without compatible hardware.
  • Camera permission: you can scan or capture only after granting camera access. You may revoke access at any time; QR/barcode scanning and photo capture will then be unavailable.
  • Location permission: you can choose not to grant location access or later revoke it. Location-dependent features may then be unavailable or less accurate. Where a feature allows it, you may choose approximate rather than precise location.
  • Notifications: you can enable or disable notifications in device settings. Critical safety decisions must not rely solely on push-notification delivery.
  • Account and data requests: contact desk@meteoros.io or your customer administrator as described below.

6. Sharing and recipients

We may disclose personal data to:

  • the customer organisation, its administrators, authorised users, auditors, and contractors, according to its MOS configuration and access controls;
  • cloud hosting, database, identity, notification, mapping/location, email, support, security, analytics, crash-reporting, and IT providers acting under contract;
  • Meteoros affiliates, staff, contractors, professional advisers, insurers, and auditors who need the data for legitimate business purposes;
  • competent authorities, courts, regulators, or law-enforcement bodies where legally required or necessary to protect rights, safety, or security; and
  • a buyer, investor, lender, or adviser in connection with a corporate transaction, subject to applicable confidentiality and data-protection law.

We do not sell personal data. We do not use App data for third-party behavioural advertising. We do not share NFC, camera, or location data with third parties for their independent marketing purposes.

7. International transfers

Meteoros and its providers may process data in India, the European Economic Area, and other countries where Meteoros, customers, or service providers operate. For transfers subject to GDPR, we will use an approved safeguard, such as an adequacy decision, standard contractual clauses, or another lawful mechanism, and apply supplementary measures where appropriate.

8. Retention

We retain personal data only as long as reasonably necessary for the purpose, customer agreement, legal obligation, security need, dispute, or retention setting that applies. The customer agreement controls Customer Data retention where Meteoros processes it on the customer's instructions.

CategoryRetention approach
Account/profile dataCustomer relationship term plus 6 months, unless deletion or law requires otherwise
Operational and audit recordsPer customer configuration/contract; current MOS commercial materials refer to 1–3 years of included history/audit retention, but the signed agreement and deployment settings control
NFC/QR/barcode action recordsIncluded in the relevant audit record; retain per customer configuration/contract
Location recordsCustomer contract term plus 6 months or linked audit-record retention; minimise collection and retention
Photos and uploaded attachmentsCustomer contract term plus 6 months or linked customer record retention
Security and access logsCustomer contract term plus 6 months
Diagnostics/crash logsCustomer contract term plus 6 months
BackupsDeleted or overwritten on a rolling schedule

9. Security

We implement technical and organisational measures designed to protect App data, appropriate to the nature of the processing and associated risk. These may include encrypted communications, encryption at rest where appropriate, role-based access controls, least-privilege permissions, authentication safeguards, logging, secure development practices, vulnerability management, backups, and incident-response procedures.

No App, device, network, wireless connection, cloud service, or storage environment is completely secure. You must protect your device with a passcode/biometric lock where available, keep the operating system and App updated, avoid jailbroken/rooted devices, and report suspected compromise promptly.

10. Your rights

Depending on the law that applies, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, and information about how data is processed. You may also have the right to complain to a competent data-protection authority.

To submit a request, email desk@meteoros.io with the subject line "Meteoros Mobile App Privacy Request." Include your name, account email, customer organisation, country of residence, the request type, and enough information for us to locate the relevant data. We may request identity verification to protect your data.

If the request concerns Customer Data controlled by your employer or customer organisation, we may refer the request to that organisation, which is best placed to decide and respond. For India, you may submit a grievance to desk@meteoros.io. For EEA users, requests may also be directed to the relevant supervisory authority.

11. Children

MOS is intended for professional and authorised business users and is not directed to children (below the age of 18). We do not knowingly collect personal data from children (below the age of 18) through the App. Contact us at desk@meteoros.io if you believe a child has provided data.

12. Changes and contact

We may update this Privacy Policy to reflect legal, technical, operational, or service changes. We will publish the revised version in the App, on meteoros.io/mobile-app-privacy, or through another appropriate channel and update the date above. Where required, we will provide additional notice or obtain consent.

Privacy contact: desk@meteoros.io

Support: desk@meteoros.io

Security incidents: desk@meteoros.io

Postal address: No. 9 (Plot 16), Kennedy Street, Tambaram West, Chennai, Tamil Nadu, India, Pin Code - 600045