1. Scope and our roles
This notice applies to the native AssetControl mobile applications for iOS and Android, any AssetControl desktop application, and the application programming interfaces those apps use. It supplements our separate Website Privacy Notice, which applies to the public website, website analytics, enquiries and hosted web checkout.
“AssetControl”, “we”, “us” and “our” mean Keytracker Ltd, Station Road, Rowley Regis, West Midlands B65 0JY, United Kingdom.
For trial registration, billing, account administration, security and support, Keytracker Ltd is normally the data controller. When your employer, school or other organisation puts people or operational records into its AssetControl workspace, that organisation normally decides why the data is used and is the controller; Keytracker Ltd processes it on that organisation’s instructions.
2. Data the apps process
- Account identity: name, work email address, work telephone number, user ID, role, department, permissions, authentication status and tenant or workspace details.
- Business and asset records: organisation details, sites, locations, asset tags, barcodes, descriptions, serial numbers, maintenance information, assigned users and other fields entered by authorised users.
- Activity and audit records: check-ins, check-outs, handovers, returns, dates, due dates, responsible users, changes, notes and security events.
- Optional photos and signatures: images attached to users, assets or maintenance records, and signatures captured for configured transactions.
- Optional precise location: foreground latitude and longitude submitted with a check-in, check-out or handover when you allow location access. We do not use this feature for continuous or background tracking.
- Scan and tag information: barcode or QR values read with the camera and compatible asset-tag identifiers read using NFC. Camera video and NFC radio data are not retained as recordings.
- Device and notification data: device identifier, app version, operating system information and a Firebase or platform push token used to deliver reminders and service messages.
- Subscription and invoice data: billing provider, product, order, invoice or transaction identifiers, purchase token or signed transaction, plan and licence limits, subscription status, renewal state, entitlement dates, invoice status, dates, currency and amounts. Authorised users may ask the app to retrieve an available invoice PDF or email it to their AssetControl account address. We do not receive full payment-card details from Apple or Google, and invoice access does not expose full card details to the app.
- Diagnostics: error message, stack trace, affected screen or URL, file and line information, time, tenant and user identifiers, and limited device context when the app reports an error.
Do not add special-category, highly sensitive or unnecessary personal data to free-text fields, photos or attachments unless your organisation has authorised that use and put appropriate safeguards in place.
3. Device permissions and app features
- Location: requested in the foreground when a configured check-in, check-out or handover needs a location. If submitted, the coordinates become part of the relevant activity record.
- Camera and photos: used to scan QR codes or barcodes and, when you choose, capture or select an image to upload. A scan sends the decoded identifier, not a recording of the camera feed.
- NFC: used to read a compatible asset-tag identifier so the app can find the matching record.
- Notifications: used for reminders, due-back information and operational service messages. You can control notification permission in device settings.
- Biometrics: Face ID, Touch ID, fingerprint or equivalent checks are performed by your device to unlock locally stored credentials or access. We do not receive or store your biometric template.
You can deny or withdraw an operating-system permission. The related feature may then be unavailable, but unrelated parts of the app will continue to work where technically possible. An operating-system permission is a device control and is not, by itself, the legal basis for every use of personal data.
4. How we use data and our legal bases
- To create and authenticate accounts, provide the subscribed service, verify entitlement and deliver requested app features — performance of a contract or steps requested before entering one.
- To maintain asset custody, transaction and audit records for the customer organisation — the organisation’s documented instructions and its applicable legal basis; Keytracker Ltd normally acts as processor.
- To secure accounts, prevent fraud, troubleshoot faults, maintain availability and improve reliability — our legitimate interests in operating a safe and effective business service.
- To verify Apple App Store and Google Play purchases, administer renewals, cancellations, refunds, billing failures and grace periods — performance of a contract, legitimate interests and legal obligations.
- To show authorised users the organisation’s plan, licence, renewal and invoice history, and to fulfil a request to download an invoice or send it to the requesting user’s account email — performance of a contract, legitimate interests and legal obligations relating to billing records.
- To deliver notifications selected or expected as part of the service — performance of a contract or legitimate interests, subject to your device-level notification choice.
- To retain billing, complaint and compliance records — applicable legal obligations and legitimate interests in establishing and defending legal claims.
Where consent is the appropriate legal basis, it can be withdrawn without affecting processing that was lawful beforehand. Your organisation is responsible for identifying its legal basis and providing any workplace, student or other notices required for the data it controls.
6. International transfers
Production application data is hosted in Germany within the European Economic Area. Apple, Google, Cloudflare, Postmark and Stripe may process limited data in other countries. Where UK or EEA personal data is transferred internationally, we use an applicable adequacy regulation or decision, approved contractual safeguards and supplementary measures where required. You may contact us for more information about the safeguard relevant to a transfer.
7. How long we retain data
- Accounts and tenant data: kept while the account or customer workspace is active, then handled under the customer agreement, verified closure request and normal backup-expiry cycle. Billing and contractual records may be retained for statutory tax, accounting and claims periods.
- Asset and audit history: kept for the life of the customer workspace and any additional period configured or required by the customer, contract or law. Removing an individual login does not automatically erase shared transaction history needed to show who handled an asset; identifiers may be restricted or anonymised where appropriate.
- Photos and signatures: kept with the user, asset, maintenance or activity record they support and deleted when the underlying record or workspace is deleted, unless the customer or law requires the evidential record to remain.
- Location: kept as part of the specific activity or audit record to which it was submitted; the app does not build a separate continuous location history.
- Purchase and subscription records: kept while needed to provide entitlement, reconcile payments, handle disputes and satisfy financial or legal record-keeping duties. An invoice PDF requested in the app is transmitted for that request; a copy saved or shared by the user is then controlled through the user’s device, email provider or chosen sharing destination.
- Push tokens: kept while the registered device and notifications remain active, and replaced or removed when no longer valid or needed.
- Diagnostics: kept only for the period reasonably needed to investigate reliability or security issues and maintain an appropriate security record. A relevant security incident record may be kept longer where needed to meet legal duties or establish and defend claims.
- Deletion requests: kept as needed to verify and demonstrate how the request was handled.
Deletion from protected backups occurs through the normal backup rotation. Until expiry, backups are isolated and used only for security and disaster recovery.
8. Security
We use encrypted transport, tenant separation, access controls, authentication tokens, permission checks, backups, monitoring and supplier controls appropriate to the risk. Subscription and invoice information is limited to roles with the relevant permission, and an emailed invoice can be sent only to the requesting user’s account address. Store purchase proofs and Stripe invoice ownership are verified server-side before access is granted. You should protect your device, install updates, use device security, remove locally saved invoices when no longer needed and report a lost or shared device promptly. More information is available in our Security & Trust Centre.
9. Account and data deletion
You can request deletion from the app through Settings → Account → Request Account Deletion. You can also use our public AssetControl account-deletion request page without installing or signing in to the app.
We verify identity and, where relevant, your authority to act for the customer workspace. If your organisation controls shared asset or audit records, we may refer the request to its administrator or restrict/anonymise your profile while retaining records the organisation or law still requires. We will explain any data we cannot delete.
Deleting an AssetControl account does not itself cancel an Apple App Store or Google Play subscription. The purchasing administrator must cancel that subscription using the relevant store’s subscription-management controls. Uninstalling the app also does not cancel a subscription.
10. Your UK and EEA data-protection rights
Depending on the circumstances, you may ask for access to your personal data, correction, deletion, restriction, portability, or object to processing. You may withdraw consent where processing relies on it and complain about how your data is handled. These rights can be limited by exemptions and the rights of others.
If your employer, school or another customer organisation controls the data, contact that organisation first. We assist customers with valid requests. Where Keytracker Ltd is the controller, email [email protected]. We may need information to verify your identity and normally respond within one month, subject to lawful extensions.
11. Children and educational users
AssetControl is a business and organisational service, not a consumer service directed at children. A school or other educational customer may create authorised accounts for students. In that situation the educational organisation is responsible for deciding whether and how student data is used, providing appropriate information, managing permissions and identifying the applicable legal basis. Children should not independently purchase a subscription or create an organisation account unless legally permitted and authorised.
12. Google Play Data Safety alignment
For the Android app’s current described behaviour, the Play Console Data Safety form should reflect the following. The release owner must re-check every SDK, permission and build before submission because the declaration must match the shipped app, not only this website.
- Collected and linked to the user or organisation: name, work email and telephone; user and tenant identifiers; user-generated asset and audit records; optional photos and signatures; optional precise foreground location; purchase history, subscription identifiers and invoice metadata; device identifiers and push tokens; and diagnostics.
- Purposes: app functionality, account management, security and fraud prevention, customer support, developer communications and diagnostics.
- Optional collection: photos, signatures and precise location are collected only when the user or customer enables and uses the related feature. Account identity, workspace data and purchase verification are required for the applicable service.
- Not collected by Keytracker through the Android app: biometric templates, address-book contacts, continuous background location, camera recordings, NFC radio data or full payment-card details.
- Handling: data is encrypted in transit; billing and invoice access is permission-controlled; deletion can be requested in the app and on the public web page; data is not sold, used for advertising or used for cross-app tracking.
- Service-provider transfers: hosting, Postmark, Cloudflare, Google/Firebase and other transfers listed above must be classified in Play Console according to Google’s current definitions of “collected” and “shared”.
13. Contact, complaints and changes
For app support, privacy questions, rights requests or data-protection complaints, email [email protected] or write to Keytracker Ltd, Station Road, Rowley Regis, West Midlands B65 0JY, United Kingdom.
If you are in the UK, you can complain to the Information Commissioner’s Office through ico.org.uk/make-a-complaint. If you are in the EEA, you may complain to the supervisory authority where you live, work or believe an infringement occurred. We would appreciate the opportunity to address your concern first.
We may update this notice when app features, suppliers or legal requirements change. We will publish the revised date here and provide additional notice where a change materially affects users.