Mobile App Privacy Policy
Meteoros Mobile App / Meteoros Operations System (MOS) — Global
This Privacy Policy explains how Meteoros Sensing Private Limited ("Meteoros," "MOS," "we," "us," or "our") handles personal data when you download, access, or use the Meteoros Mobile App, contact support, or interact with related services.
For App account, product, support, and service-operation data, Meteoros may act as a controller/data fiduciary. For Customer Data processed in a customer's MOS environment, the customer is generally the controller/data fiduciary and Meteoros acts as a processor/data processor under the customer's documented instructions. The applicable customer agreement and data-processing agreement control those roles.
1. Scope and controller
Meteoros Sensing Private Limited
Registered office: No. 9 (Plot 16), Kennedy Street, Tambaram West, Chennai, Tamil Nadu, India, Pin - 600045
CIN: U62011TN2025PTC180776
GST: 33AATCM4130F1ZL
Privacy, support and security-incident contact: desk@meteoros.io
2. Personal data we may process
The App may process the following categories, depending on your role, permissions, customer configuration, and use of features:
| Category | Examples | Why it is used |
|---|---|---|
| Account and professional data | Name, work email, phone number, employer, job title, username, user ID, role, organization | Authentication, access management, support, auditability |
| Authentication and security data | Password hash or identity-provider token, MFA status, login history, device/session identifiers, IP address, security events | Secure access, fraud prevention, investigation |
| Operational and audit data | Lock/device identifiers, asset and site labels, lock status, tamper events, battery/connectivity telemetry, actions, approvals, timestamps, notes, work records | Device monitoring, operational workflows, alerts, traceability, audit reports |
| NFC data | NFC tag/device identifier and scan time; associated user, device, asset, or action | Identify authorized devices/assets and create traceable operational records |
| Camera and uploaded media | QR/barcode scan value; photos or attachments you choose to capture/upload; metadata included in the file | Identify an asset/device; provide evidence, support, or audit records |
| Location data | Approximate or precise device location, timestamp, and accuracy where permission is granted and feature/customer configuration requires it | Field-action verification, site association, nearby assets, audit records, safety/operational workflow support |
| Notification data | Device push token, platform, alert preferences, delivery and interaction status | Deliver authorised push notifications and manage preferences |
| Technical and diagnostic data | App version, operating system, device model, crash reports, logs, network state, language, performance events | Maintenance, support, security, quality improvement |
| Support communications | Messages, ticket details, attachments, call/meeting notes, contact details | Respond to requests and improve support |
Location: the Meteoros Mobile App does not use location data for advertising. Unless clearly stated in the App and enabled by the applicable build and customer configuration, MOS does not collect location in the background.
Camera: the camera is activated only after you choose a camera-based feature and grant permission. Camera images are not used for facial recognition, advertising, or biometric identification unless a future feature is separately disclosed, legally reviewed, and enabled with an appropriate lawful basis.
NFC: NFC data is used to read compatible tags or identifiers for MOS functionality. It is not used for contactless payment processing.
3. Sources of data
We receive personal data from you, your device, your employer or customer administrator, the connected MOS environment, compatible locks/devices/gateways, identity providers, support interactions, and service providers that assist with the App.
4. Purposes and legal bases
Where GDPR or equivalent law applies, we process data on one or more of these legal bases:
| Purpose | Typical legal basis |
|---|---|
| Provide accounts, access control, requested App features, support, and contractual services | Performance of a contract or steps requested before a contract |
| Process device, audit, NFC, camera, and location records configured by a customer | Contract; legitimate interests; or processing on the customer's documented instructions, as applicable |
| Secure the App, prevent misuse, maintain logs, investigate incidents, and improve reliability | Legitimate interests and, where applicable, legal obligations |
| Comply with law, regulatory requests, tax/accounting rules, or legal claims | Legal obligation and legitimate interests |
| Optional location, camera, notifications, analytics, or other permission-based processing where consent is required | Consent, which you may withdraw through device settings or the App where available |
| Send direct marketing unrelated to essential service communications | Consent or legitimate interests where permitted; always subject to opt-out |
Where the Digital Personal Data Protection Act, 2023 and applicable Indian rules apply, Meteoros will provide the required notice and seek consent when consent is the appropriate basis. You may withdraw consent using device settings, in-app controls where available, or by contacting desk@meteoros.io. Withdrawal does not affect processing already carried out lawfully before withdrawal, and some functions may no longer operate.
5. Permissions and your choices
You control mobile permissions through iOS or Android settings. Refusing a permission does not prevent you from using unrelated features, but it may prevent the corresponding feature from working.
- NFC permission/availability: you can choose not to use NFC-based workflows. NFC scans may be unavailable on devices without compatible hardware.
- Camera permission: you can scan or capture only after granting camera access. You may revoke access at any time; QR/barcode scanning and photo capture will then be unavailable.
- Location permission: you can choose not to grant location access or later revoke it. Location-dependent features may then be unavailable or less accurate. Where a feature allows it, you may choose approximate rather than precise location.
- Notifications: you can enable or disable notifications in device settings. Critical safety decisions must not rely solely on push-notification delivery.
- Account and data requests: contact desk@meteoros.io or your customer administrator as described below.
6. Sharing and recipients
We may disclose personal data to:
- the customer organisation, its administrators, authorised users, auditors, and contractors, according to its MOS configuration and access controls;
- cloud hosting, database, identity, notification, mapping/location, email, support, security, analytics, crash-reporting, and IT providers acting under contract;
- Meteoros affiliates, staff, contractors, professional advisers, insurers, and auditors who need the data for legitimate business purposes;
- competent authorities, courts, regulators, or law-enforcement bodies where legally required or necessary to protect rights, safety, or security; and
- a buyer, investor, lender, or adviser in connection with a corporate transaction, subject to applicable confidentiality and data-protection law.
We do not sell personal data. We do not use App data for third-party behavioural advertising. We do not share NFC, camera, or location data with third parties for their independent marketing purposes.
7. International transfers
Meteoros and its providers may process data in India, the European Economic Area, and other countries where Meteoros, customers, or service providers operate. For transfers subject to GDPR, we will use an approved safeguard, such as an adequacy decision, standard contractual clauses, or another lawful mechanism, and apply supplementary measures where appropriate.
8. Retention
We retain personal data only as long as reasonably necessary for the purpose, customer agreement, legal obligation, security need, dispute, or retention setting that applies. The customer agreement controls Customer Data retention where Meteoros processes it on the customer's instructions.
| Category | Retention approach |
|---|---|
| Account/profile data | Customer relationship term plus 6 months, unless deletion or law requires otherwise |
| Operational and audit records | Per customer configuration/contract; current MOS commercial materials refer to 1–3 years of included history/audit retention, but the signed agreement and deployment settings control |
| NFC/QR/barcode action records | Included in the relevant audit record; retain per customer configuration/contract |
| Location records | Customer contract term plus 6 months or linked audit-record retention; minimise collection and retention |
| Photos and uploaded attachments | Customer contract term plus 6 months or linked customer record retention |
| Security and access logs | Customer contract term plus 6 months |
| Diagnostics/crash logs | Customer contract term plus 6 months |
| Backups | Deleted or overwritten on a rolling schedule |
9. Security
We implement technical and organisational measures designed to protect App data, appropriate to the nature of the processing and associated risk. These may include encrypted communications, encryption at rest where appropriate, role-based access controls, least-privilege permissions, authentication safeguards, logging, secure development practices, vulnerability management, backups, and incident-response procedures.
No App, device, network, wireless connection, cloud service, or storage environment is completely secure. You must protect your device with a passcode/biometric lock where available, keep the operating system and App updated, avoid jailbroken/rooted devices, and report suspected compromise promptly.
10. Your rights
Depending on the law that applies, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, and information about how data is processed. You may also have the right to complain to a competent data-protection authority.
To submit a request, email desk@meteoros.io with the subject line "Meteoros Mobile App Privacy Request." Include your name, account email, customer organisation, country of residence, the request type, and enough information for us to locate the relevant data. We may request identity verification to protect your data.
If the request concerns Customer Data controlled by your employer or customer organisation, we may refer the request to that organisation, which is best placed to decide and respond. For India, you may submit a grievance to desk@meteoros.io. For EEA users, requests may also be directed to the relevant supervisory authority.
11. Children
MOS is intended for professional and authorised business users and is not directed to children (below the age of 18). We do not knowingly collect personal data from children (below the age of 18) through the App. Contact us at desk@meteoros.io if you believe a child has provided data.
12. Changes and contact
We may update this Privacy Policy to reflect legal, technical, operational, or service changes. We will publish the revised version in the App, on meteoros.io/mobile-app-privacy, or through another appropriate channel and update the date above. Where required, we will provide additional notice or obtain consent.
Privacy contact: desk@meteoros.io
Support: desk@meteoros.io
Security incidents: desk@meteoros.io
Postal address: No. 9 (Plot 16), Kennedy Street, Tambaram West, Chennai, Tamil Nadu, India, Pin Code - 600045
