Privacy Policy
Effective date:June 1, 2025 · Last updated: June 1, 2025
1. Introduction
IOTcontrol (“Company,” “we,” or “us”) operates a telemetry and remote-control platform for industrial compressor equipment. This Privacy Policy explains what data we collect, how we use it, how long we retain it, and your rights with respect to that data.
This policy applies to all users of the IOTcontrol web application and API, including customer managers, mechanics, and end customers (collectively “you”).
2. Data We Collect
2.1 Account Information
- Full name and email address
- Phone number (optional, used for SMS alarm notifications)
- Role assignment and tenant affiliation (which organization you belong to and what access level you hold)
- AWS Cognito subject identifier (“sub”) — a UUID that links your IOTcontrol account to your authentication session
- Account creation date and last-updated timestamp
2.2 Telemetry Data
We collect real-time sensor readings transmitted by field units equipped with Sierra Wireless RV50/RV55 cellular modems. This includes:
- Engine speed (RPM), engine temperature, oil pressure
- Battery voltage, suction and discharge pressure
- Runtime hour counters and system operating state registers
- Active fault and event codes, alarm bitmaps
- Raw Modbus register payloads retained for debugging and replay purposes
Telemetry data is associated with a specific unit identifier and timestamp. It does not directly identify individual people but is linked to equipment your organization operates.
2.3 Command and Audit Logs
Every remote command issued through the platform (e.g., engine start, stop, fault clear) is recorded with the issuing user’s identity, the target unit, timestamps for each lifecycle stage (dispatched, acknowledged, failed), and any error details. These records form an immutable audit trail.
2.4 Usage Logs
We log API requests for security, debugging, and capacity planning. Log entries may include your IP address, request path, HTTP method, response status, and timestamp. We do not sell or share usage logs with third parties for advertising purposes.
3. How We Use Your Data
- Service delivery: Authenticating your identity, enforcing role-based access controls, and displaying telemetry on your dashboard.
- Alarm notifications: Delivering email and SMS alerts when unit conditions exceed configured thresholds or faults are detected, using AWS SES (email) and AWS SNS (SMS).
- Audit logging: Maintaining a tamper-evident record of all sensitive actions — commands issued, invitations sent, role changes — for accountability and compliance purposes.
- Security and fraud prevention: Detecting unauthorized access attempts and protecting the integrity of remote control operations.
- Service improvements: Analyzing aggregated usage patterns to improve reliability and features. We do not use individual behavioral data for advertising.
4. Data Storage and Security
All data is stored on Amazon Web Services (AWS) infrastructure located in United States regions. Specific services used include:
- Amazon RDS (PostgreSQL): Hot telemetry, account data, commands, and audit logs.
- Amazon S3: Archived telemetry older than 90 days.
- AWS Cognito: Authentication and identity management. Cognito stores your email and manages password hashing; we do not store raw passwords.
Data is encrypted at rest and in transit using industry-standard protocols (AES-256 at rest, TLS 1.2+ in transit). Access to production databases is restricted to authorized personnel and application service roles only.
5. Data Retention
- Hot telemetry: Retained in the active database for 90 days from the time of collection.
- Archived telemetry: Moved to Amazon S3 cold storage after 90 days. Archived data is retained for an additional period consistent with your subscription plan and applicable legal requirements.
- Account data and audit logs: Retained for the lifetime of your account plus a minimum of 12 months after closure. Audit records may be retained longer if required for legal, regulatory, or dispute-resolution purposes.
- Usage logs: Retained for up to 90 days in operational log systems.
6. Third-Party Services
We use the following third-party services to operate the platform. We do not use advertising networks, analytics trackers, or social media pixels.
- AWS Cognito — user authentication and identity management.
- AWS SES (Simple Email Service) — transactional email delivery (invitations, alarm notifications).
- AWS SNS (Simple Notification Service) — SMS alarm notifications.
- Amazon RDS and S3 — data storage and archival.
Each of these services is governed by AWS’s own privacy and data processing terms. AWS is certified under SOC 1/2/3, ISO 27001, and participates in the EU-US Data Privacy Framework.
7. Data Sharing and Disclosure
We do not sell your personal data. We may share data only:
- With other users within your tenant organization, to the extent required to deliver the Service (e.g., your name appearing in an audit log visible to your tenant’s manager).
- With third-party service providers listed in Section 6, solely to operate the platform.
- When required by law, court order, or government authority, or to protect the rights, property, or safety of the Company, our users, or the public.
- In connection with a merger, acquisition, or asset sale, provided the acquiring party agrees to honor this Privacy Policy.
8. Your Rights
Depending on applicable law, you may have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate personal data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements. Note that audit logs and command histories may not be deletable where they constitute operational records.
- Portability: Request your account data in a machine-readable format.
To exercise any of these rights, contact us at support@iotcontrol.app. We will respond within 30 days. We may need to verify your identity before processing your request.
9. Cookies and Tracking
The Service uses session cookies and secure HTTP-only cookies to maintain authentication state. We do not use advertising cookies, third-party tracking pixels, or behavioral analytics tools. No data is shared with data brokers.
10. Children's Privacy
The Service is intended for use by business professionals in industrial settings. We do not knowingly collect personal data from anyone under the age of 18. If you believe a minor has provided us data, contact us at support@iotcontrol.app and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email to the address on file or via a notice within the Service at least 14 days before the change takes effect. Continued use of the Service after that date constitutes acceptance of the revised policy.
12. Contact Us
Questions, access requests, or deletion requests should be sent to:
IOTcontrol
Email: support@iotcontrol.app