Privacy Policy
This policy explains how Patrolix LLC ("we", "us") handles data in the PatrolIX mobile app and the service behind it. PatrolIX is used by security organizations (our "customer organizations") and their staff.
Who Is Responsible for Your Data
Patrolix LLC is the controller for its own account data about customer organizations, such as contact details for the people who manage a subscription.
For data that a customer organization and its staff enter into PatrolIX, such as user accounts and reports, the customer organization is the controller and Patrolix LLC processes that data on its behalf and under its instructions. If you use PatrolIX through your employer or another organization, that organization decides what is collected and how long it is kept.
Data We Collect
- Account Data: your email address, name, role, and the organization you belong to. Accounts are created by an administrator of your organization through an invitation; there is no public sign-up.
- Sign-In Data: you sign in with your email address and a password. Administrators can also protect sign-in with an authenticator-app second factor; we store the enrollment needed to check it.
- Report Data: the fields you fill in on a report (for example building, location, description, severity, and suspected cause), the time of the report, and your device's GPS location when your device allows it. If location is denied or unavailable, the report is still accepted and the missing location is recorded.
- Photos: photos you attach to a report. Each original photo is kept unchanged as evidence, including its embedded metadata (EXIF), which can include the time, device details, and location where the photo was taken.
- Audit Records: when a report, user, or setting is created or changed, we record who did it, what changed, when, the network address recorded for the request, and a request identifier.
How We Use Data
- To provide the service: sign-in, recording and editing reports, storing photos, and sending notifications and work orders your organization has set up.
- To keep records that can serve as evidence: original submissions are kept alongside every later edit, and audit records show who did what and when.
- To secure the service, investigate misuse, and fix problems.
Where Data Is Stored
Data is stored on Google Cloud and Firebase in the United States.
Who We Share Data With
- Google Cloud and Firebase: our hosting, database, file storage, and sign-in provider.
- Google Chat: only when your organization configures it, report notifications are sent to the Google Chat spaces it chooses.
- MaintainX: only when your organization configures it, work orders with report details are created in its MaintainX account.
- Email Provider: once email notifications are enabled, an email delivery provider will send report notifications to the recipients your organization sets.
- Expo: the app checks Expo's update service for app updates, which receives your device's IP address and basic app and device details.
Notifications and work orders state how many photos a report has; photos themselves are viewed in the PatrolIX app.
We may also disclose data when required by law or valid legal process.
How Long Data Is Kept
Reports, photos, and audit records are currently kept indefinitely so they remain available as evidence. Deletion requests are handled through your organization, case by case (see Your Rights and Requests).
Security
Data is encrypted in transit and at rest by Google Cloud. Access requires sign-in and is limited by each user's role, and changes are recorded in audit records.
Your Rights and Requests
Requests to access, correct, or delete data held in PatrolIX for an organization are handled through that organization, because it controls that data. Contact your organization's administrator first; we will help your organization respond. Some records may need to be kept as evidence even after a deletion request, where the law allows it.
For data Patrolix LLC controls itself, contact us at the address below.
Contact
Patrolix LLC
Email: privacy@patrolix.us