1. Who we are
This Privacy Policy explains how Sapphco (“we”, “us”, “our”) processes personal data in connection with The Technician App mobile application (iOS and Android) and the related web application (the “Service”).
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), Sapphco acts as the data controller for the personal data described below. Where we operate the Service on behalf of a client organisation (for example, a facility operator or maintenance vendor), that client may also act as a data controller for data relating to its own staff and operations; in those cases, we process such data on the client's instructions as a processor under Article 28 GDPR.
You can contact us about this policy at developer@sapphco.ae.
2. Scope of this policy
This policy applies to two groups of users:
- Technicians and receptionists using the mobile app to scan QR codes issued by their organisation, view assigned work orders, submit feedback, and upload photos.
- Administrators using the web application to issue QR codes, manage sessions, and configure their organisation's account.
The Service is a business-to-business tool. It is not intended for, marketed to, or designed for consumer use.
3. Personal data we collect
3.1 Account information (administrators only)
- Email address
- Display name
- Role within your organisation (e.g. site administrator, receptionist)
- A hashed copy of your password (we never store passwords in cleartext)
- Organisation identifier (the “space key”)
3.2 Session and authentication data
- An ephemeral session token (JSON Web Token) that authenticates your device while you are signed in
- Vendor identifier and plant identifier associated with the QR code you scanned
- Login method (QR code or password) and timestamps
- For audit purposes, a record of session creation, expiry, and administrator-initiated termination events
3.3 Work-order content you submit
- Free-text feedback that you enter against a job
- Photographs that you take or upload as evidence of work performed
3.4 Technical data
- IP address and basic request metadata observed by our backend while serving your requests
- Aggregated and anonymised performance metrics collected via Vercel Analytics (see section 13)
We do not collect contacts, calendar data, health data, financial data, or precise location data.
4. How we use your data & legal bases
We process the personal data above for the following purposes, each with its lawful basis under Article 6(1) GDPR:
- To provide the Service — authenticating you, showing your assigned jobs, accepting feedback and photos, and relaying the result to your organisation's work-order system. Legal basis: performance of a contract (Art. 6(1)(b)) between us and your organisation, of which you are a beneficiary.
- To secure the Service and detect abuse — maintaining session integrity, enforcing licence limits, logging administrator actions for audit. Legal basis: our legitimate interests (Art. 6(1)(f)) in keeping the Service secure and accountable.
- To comply with legal obligations — responding to lawful requests from competent authorities and exercising legal claims. Legal basis: legal obligation (Art. 6(1)(c)).
We do not use your data for advertising. We do not sell your data. We do not use automated decision-making that produces legal or similarly significant effects on you.
5. Device permissions (mobile app)
The mobile app asks for the following device permissions. Each one is requested only when you first use the feature that needs it, and you can revoke any of them at any time in your device settings.
- Camera — used to scan QR codes issued by your organisation, and to take new photos that you attach to a job report. The camera feed is processed on-device for the QR scan; we do not record video.
- Photos / photo library — used so you can select an existing photo from your device to attach to a job report. We access only the photos you explicitly pick; we do not browse your library.
The app does not request location, contacts, microphone, calendar, health, or push notification permissions.
7. International data transfers
The primary database holding your personal data is hosted in the European Economic Area (EEA). Some processors listed above operate global infrastructure that may transfer data outside the EEA. Where that occurs, we rely on appropriate safeguards under Article 46 GDPR, in particular the European Commission's Standard Contractual Clauses, and, where applicable, the EU-US Data Privacy Framework. You may request a copy of the relevant transfer safeguards by contacting us at developer@sapphco.ae.
8. Data retention
- Active sessions — expire automatically (30 minutes for QR-based technician sessions; up to 24 hours for administrator sessions) and are deleted from the database when they expire.
- Session audit logs — retained for 12 months from the date of the logged event, then deleted, unless a longer period is required to comply with a legal obligation or to defend a legal claim.
- Administrator accounts — retained while the account is active. We will delete or anonymise an account on the instruction of your organisation, or following a verified request from you, except where retention is required by law.
- Work-order content (feedback & photos) — retained for as long as your organisation requires for its work-order records, and copied into your organisation's Ultimo system. Deletion in our systems is performed on your organisation's instruction.
9. Security
We take reasonable technical and organisational measures to protect personal data, including:
- TLS encryption for all data in transit
- Industry-standard password hashing (bcrypt) for stored administrator credentials
- Short-lived, signed session tokens that are revocable by administrators
- Role-based access control: technicians can access only their own session and the jobs assigned to them; administrators can access only data scoped to their organisation
- Tamper-evident audit logging of administrator actions and session events
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where required, notify affected individuals in accordance with Articles 33 and 34 GDPR.
10. Your rights under the GDPR
Subject to the conditions in the GDPR, you have the following rights with respect to your personal data:
- Access (Art. 15) — a copy of the personal data we hold about you
- Rectification (Art. 16) — correction of inaccurate or incomplete data
- Erasure (Art. 17) — deletion of your data, subject to lawful exceptions
- Restriction (Art. 18) — limit how we use your data while a dispute is resolved
- Portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format
- Object (Art. 21) — object to processing based on our legitimate interests
- Withdraw consent (Art. 7(3)) — where processing is based on your consent, you may withdraw it at any time without affecting prior lawful processing
- Lodge a complaint with your local supervisory authority — for users in the EU, this is the data protection authority of your country of residence or workplace
11. How to exercise your rights
To exercise any of the rights listed in section 10, email developer@sapphco.ae. We will respond within one month of receiving your request, in line with Article 12(3) GDPR. We may extend that period by a further two months for complex requests; if we do, we will tell you within one month and explain why.
We may need to verify your identity before acting on your request. We will not charge a fee unless your request is manifestly unfounded or excessive.
12. Children
The Service is intended for adult professionals (16 years of age or older). We do not knowingly collect personal data from children under 16. If you believe we have, please contact us at developer@sapphco.ae and we will delete it.
14. Changes to this policy
We may update this policy from time to time to reflect changes in the Service, our processors, or applicable law. When we make material changes, we will update the “Effective date” at the top of this page and, where appropriate, notify your organisation's administrator. Continued use of the Service after an update means you accept the revised policy.
15. Contact
For any question, request, or complaint relating to this policy or our processing of your personal data, contact us at: