App privacy policy

App Privacy Policy

Phoenix Smartlocks — Access control mobile application

Last updated: August 27, 2026

1. Introduction and data controller

This Privacy Policy describes how Phoenix Smartlocks, S.L. (Spanish Tax ID / CIF B24890832), with registered address at Calle Pedro de Asúa, 69, Vitoria-Gasteiz, Spain (hereinafter, "Phoenix Smartlocks", "we", "us"), collects, uses, stores and protects the personal data of users of the Phoenix Access App mobile application (hereinafter, the "App"), available for Android and iOS.

The App is used to access Phoenix Smartlocks NFC smart locks installed by the organization or entity that contracts our services (hereinafter, the "Client"). Users of the App may be either customers or end users of the Client (for example, guests, members, or users of its facilities) or the Client itself. As a general rule, the Client acts as the data controller with respect to the data of the individuals to whom it grants access, and Phoenix Smartlocks acts as data processor on behalf of the Client and following its instructions, under the corresponding data processing agreement (Art. 28 GDPR).

Phoenix Smartlocks only processes each Client's data within that Client's own environment: we do not share, combine, or compare personal data of users across different Clients. The sole exception is aggregated, anonymized service performance statistics, which Phoenix Smartlocks generates in a way that does not allow any user to be identified, directly or indirectly, for the purpose of maintaining and improving the platform; with respect to these anonymized statistics, Phoenix Smartlocks acts as controller on the basis of its own legitimate interest, although, being anonymized, they fall outside the scope of the GDPR.

For any privacy-related query, you can contact us at: info@phoenixsmartlocks.com.

2. Data we collect

We collect only the data necessary for the App to function and to provide the access control service:

2.1 Identification and account data

  • Full name.
  • Mobile phone number, used exclusively to send a one-time verification code (OTP) via SMS when creating or linking your account.
  • User identifier: an internal code or identifier defined and assigned by the Client for your account. This identifier does not need to match a national ID number or any other official identity document — its format and content are defined by each Client according to its own criteria.
  • Email address (if required by the Client to create the account).

2.2 Location data (GPS)

The App uses the device's location services for two distinct purposes, which we describe separately as they involve different levels of sensitivity:

  • Geofencing: while you have an active job/visit open, the App monitors whether the device leaves the authorized geographic area associated with that lock. This check also runs while the App is in the background or closed, since its purpose is to alert you (via notification and a voice alert) if you move away from the location without confirming that the job/visit has been closed, helping to avoid jobs being left open by mistake.
  • Location associated with user actions: when a user successfully performs an action on a lock (e.g. opening or closing it), the App records the most recent known GPS position of the device (no more than a few minutes old) at the time of that action, together with the timestamp (date and time) and the identifier of the lock involved. If no recent position is available, the event is recorded without coordinates. Action attempts that do not complete successfully do not generate any location record.

This location record tied to actions serves a security and audit purpose: it allows us to verify that the action was physically carried out at the corresponding location, to detect anomalous or fraudulent access, and to meet the traceability requirements that some of our Clients require (e.g. in regulated or physical-security environments).

Periodic background data synchronization (while the App is closed) never accesses your location; the only background location processing is the geofence check described above.

2.3 Photos and media content

  • When you choose to attach an image to an incident report, the App lets you take a photo with the camera or select an existing image from your gallery. This image is sent together with the incident report. The App does not access the camera or gallery unless you initiate this action yourself.

2.4 Device and technical data

  • Device model, operating system, and App version.
  • App installation identifier: a randomly generated identifier created on your device (not derived from the IMEI, serial number, or any other hardware identifier), used to associate your session and push notifications with your installation of the App.
  • Usage and error logs (technical logs), for diagnostics and service improvement.

2.5 Diagnostic and error-prevention data

We use Google/Firebase tools for technical diagnostics of the service:

  • Crash reporting (Crashlytics) and usage analysis (Analytics and Performance): these help us detect technical errors and performance issues. As part of the technical error context ("breadcrumbs"), these tools may receive data such as the device's time zone, local file paths of incident images, or the last few digits of your phone number (the rest is masked). No GPS coordinates or full phone numbers are sent to these tools.
  • App integrity verification (App Check): protects our servers against requests that do not come from a legitimate installation of the App.
  • Push notifications (Firebase Cloud Messaging): used to send service-related notifications to your device.

2.6 Data we do NOT collect

  • We do not access your contacts, messages, audio/video files, or any other device data not listed in this policy.
  • We do not use Bluetooth or hardware device identifiers (IMEI, serial number, etc.).
  • We do not use location or usage data for advertising purposes, nor do we sell it to third parties.

3. Purpose and legal basis for processing

In accordance with the General Data Protection Regulation (GDPR), we process your data for the following purposes and on the following legal bases:

 

Where the legal basis is legitimate interest, we have assessed that this interest does not override the rights and freedoms of users, given the limited scope of the processing and the security measures applied. In any case, you may exercise your right to object as described in Section 8.

4. Who we share data with

Phoenix Smartlocks acts as a technical intermediary between the user and the relevant Client's system. Accordingly:

  • The data collected by the App is transmitted to the system of the Client that registered you, which manages access permissions and, where applicable, audit reports (e.g. access records with location).
  • We do not store or make your data available outside the relevant Client's environment: there is no shared database across different Clients that Phoenix Smartlocks freely accesses or compares.
  • The only information Phoenix Smartlocks retains and uses beyond each Client's environment is aggregated, anonymized service performance statistics (e.g. response times, error rates), which do not allow any user to be identified.
  • With our technology providers (data processors/sub-processors), who process data solely on our instructions and under the corresponding data processing agreement (Art. 28 GDPR):

  – Twilio Inc., for sending SMS verification codes.

  – Amazon Web Services (AWS), for hosting infrastructure and databases, within each Client's segregated environment.

  – Google Ireland Limited (Firebase), for crash reporting, performance analysis, App integrity verification, and push notifications, as described in Section 2.5.

  • We do not transfer or sell your personal data to third parties for advertising purposes.
  • We may disclose data to law enforcement or competent authorities where there is a legal obligation to do so.

5. International data transfers

The App is also offered outside the European Union. Where the contracting Client is located outside the European Economic Area (EEA), its users' data may be processed within the infrastructure environment corresponding to that Client, which may be located outside the EEA.

In such cases, Phoenix Smartlocks will apply the safeguards required by applicable data protection law, including, where relevant, the Standard Contractual Clauses approved by the European Commission or another recognized international transfer mechanism under Chapter V of the GDPR. Where the processing is not subject to the GDPR because neither the user nor the Client falls within its territorial scope, applicable local data protection law will apply instead.

6. Data retention

  • Account and identification data: for as long as the user maintains an active relationship with the Client, and for up to 1 year after termination, to manage any potential incidents or claims, without prejudice to any longer statutory retention periods that may apply.
  • Location records associated with actions and incident report photos (access audit trail): 12 months from the date of the record, unless the Client contractually requires a different period.
  • Technical logs and diagnostic data: 90 days.
  • Data stored locally on your device (active session and events pending synchronization): retained on the device itself, protected through the operating system's secure storage mechanisms, until you log out or uninstall the App.

Once these periods have elapsed, the data will be securely deleted or anonymized.

7. Data security

Phoenix Smartlocks applies appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or alteration, including encryption in transit and at rest, role-based access control, and continuous infrastructure monitoring.

8. Your rights

Under the GDPR, you may exercise the following rights at any time by contacting info@phoenixsmartlocks.com:

  • Access: find out what data we process about you.
  • Rectification: correct inaccurate data.
  • Erasure: request deletion of your data once it is no longer needed.
  • Objection: object to processing based on legitimate interest.
  • Restriction: request that processing be temporarily limited.
  • Portability: receive your data in a structured format.

Since, in most cases, the Client managing your access acts as the data controller and Phoenix Smartlocks as processor, if you send us a request concerning your data we may forward it to that Client for resolution, or resolve it ourselves following the Client's instructions, informing you in either case of how it was handled. You also have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es), or with the data protection authority corresponding to your country of residence, if you believe that the processing does not comply with applicable regulations.

9. Device permissions

The App requests the following permissions, each linked to a specific feature:

  • Location, including in the background: required to record location for unlock/lock actions and for the geofence alert when you move away from an open job/visit without confirming it has been closed, as described in Section 2.2.
  • SMS / automatic verification (SMS Retriever API on Android): used exclusively to auto-fill the OTP code received via SMS; we do not read or store any other SMS messages on the device.
  • Camera and gallery: only activated if you choose to attach a photo to an incident report.
  • NFC: for local communication between your device and the physical lock when performing an unlock.
  • Push notifications: for service-related alerts.

You can revoke these permissions at any time from your operating system settings, although some App features may then become unavailable.

10. Minors

The App is intended for adults authorized by the Client that manages access. It is not directed at minors under 18, and we do not knowingly collect data from minors.

11. Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or organizational changes. We will notify material changes through the App or the Client, and we will indicate the date of the last update at the top of this document.

12. Contact

Phoenix Smartlocks, S.L. — CIF B24890832 — Calle Pedro de Asúa, 69, Vitoria-Gasteiz, Spain — info@phoenixsmartlocks.com

©Phoenix Smartlocks // All rights reserved // 2026

Information icon

Necesitamos su consentimiento para cargar las traducciones

Utilizamos un servicio de terceros para traducir el contenido del sitio web que puede recopilar datos sobre su actividad. Por favor revise los detalles en la política de privacidad y acepte el servicio para ver las traducciones.