Privacy Policy
This Privacy Policy describes how Khalid Aboubakr and Sigmantic Digital Technology (collectively, "we", "us", or "our") collect, process, secure, retain, and disclose information in connection with our websites, mobile applications, SaaS platforms, customer portals, dashboards, APIs, operational tools, and any other current or future digital services we operate. We have designed this policy to be transparent, audit-ready, and aligned with global privacy regulations including the EU GDPR, UK GDPR, and equivalent national data protection laws.
Scope of this policy
This policy applies broadly to every product, service, application, platform, and digital interface we operate now or may operate in the future under the legal entities Khalid Aboubakr and Sigmantic Digital Technology.
It covers, without limitation: marketing and corporate websites, mobile applications distributed through Google Play and the Apple App Store, web-based SaaS products, customer and partner portals, internal operations consoles, administrative dashboards, public and private APIs, integration endpoints, and any companion digital tools.
Where a specific product publishes a supplementary notice (for example, an in-app disclosure or a service-level addendum), that notice operates alongside — and not in place of — this Policy.
Categories of information we collect
We collect only the information necessary to operate our services, secure user accounts, satisfy contractual obligations, and meet legal requirements. The categories below describe the typical data we may process.
Account information
- Identifiers you provide on sign-up — such as full name, work email, phone number, organization, role, or job title.
- Authentication credentials (passwords are stored as salted cryptographic hashes; we never store plaintext passwords).
- Profile preferences, language, timezone, and notification preferences.
Operational data
- Records you create or process within a platform — such as tickets, work orders, assets, inventory items, documents, configurations, or workflow events.
- Files and attachments you upload (e.g. PDF documents, photographs of equipment, scanned forms, exports, or operational artifacts).
- Service interactions including comments, status changes, approvals, and audit-relevant actions taken within a workspace.
Device and connection information
- Device model, operating system version, application version, locale, and unique installation identifiers required for service delivery and abuse prevention.
- IP address, approximate geo-region derived from IP, and connection metadata used to secure sessions and prevent fraud.
- Crash diagnostics, performance traces, and error logs limited to information needed to debug and improve reliability.
Authentication, session, and API data
- Session tokens, refresh tokens, and short-lived API keys issued to your client to maintain authenticated state.
- API call metadata — endpoint, status, timestamp, source identifier — captured for security monitoring and rate-limit enforcement.
- Two-factor authentication state, recovery codes (stored as hashes), and trusted-device fingerprints where you have enabled them.
Analytics and product telemetry
- Aggregated, privacy-respecting product analytics that help us understand feature adoption and stability — for example, the number of times a page renders successfully.
- We do not sell analytics data, and we do not combine it with personal identifiers for advertising purposes.
Communications you send us
- Email, support tickets, in-app messages, and any attachments you submit when contacting us.
- Feedback, survey responses, and product improvement suggestions.
How we use information
We process information only for clearly defined purposes that support service delivery, security, legal compliance, and continuous product improvement.
- Service delivery — to authenticate you, render dashboards, persist your work, sync data between devices, and route requests through our APIs.
- Account security — to detect anomalous logins, enforce rate limits, prevent automated abuse, and protect against credential stuffing or account takeover.
- Customer support — to investigate and resolve issues you report, and to respond to compliance, billing, or feature requests.
- Reliability engineering — to detect crashes, regressions, latency spikes, and to roll back or hotfix when needed.
- Product improvement — to measure feature adoption in aggregate and prioritize roadmap investment.
- Legal and regulatory — to comply with applicable law, court orders, lawful requests, and to enforce our Terms of Service.
Secure transmission and storage
- All network traffic between our applications and servers is encrypted in transit using TLS 1.2 or higher with modern cipher suites and certificate pinning where appropriate.
- Sensitive data at rest is encrypted on the underlying storage layer (database, object storage) using AES-256 or equivalent industry-standard encryption.
- Backups and replicas inherit the same encryption guarantees and are stored in regionally appropriate availability zones.
- Keys are managed through hardened key-management infrastructure with strict access controls, periodic rotation, and audit logging of every key operation.
Mobile application permissions
Our mobile applications request only the permissions strictly necessary to deliver the features you choose to use. Each permission request is accompanied by an in-context rationale, and you can review or revoke any permission at any time through your device settings.
For the full per-permission disclosure — including Android/iOS scope, optional vs. required status, and storage/sharing behavior — refer to our Mobile App Permissions Disclosure page.
Camera access
When our mobile applications request access to the device camera, that access is used strictly for operational features such as barcode scanning, QR code recognition, document capture, and asset photography.
- Camera access only occurs during direct user interaction — for example, when you explicitly open the scanner or attach a photograph to a record.
- There is no background capture, no continuous recording, and no silent activation of the camera.
- Raw camera frames used for live scanning are processed transiently in device memory and are not persisted to storage unless you explicitly upload an image.
- We do not perform facial recognition, biometric profiling, or any form of identity inference using the camera.
- Images that you do choose to upload are transmitted over encrypted channels and stored under the same protections as other operational data.
- Camera data is never sold, rented, or shared with external advertisers or unrelated third parties.
Files, attachments, and work uploads
- You may upload files into our services — documents, photographs, spreadsheets, exports, configuration backups, or operational evidence.
- Uploaded content is stored in encrypted object storage and is associated with the workspace or account that submitted it.
- Access to uploaded content is restricted to authenticated members of that workspace and to authorized administrative personnel acting under documented internal procedures.
- You retain ownership of all content you upload. We process it solely to provide the service you have engaged us for.
Notifications and messaging
- We send transactional and operational notifications (e.g. ticket assignments, password changes, security alerts) via push, email, in-app, and — where you have opted in — SMS or messaging integrations.
- Push tokens issued by Apple Push Notification service or Firebase Cloud Messaging are stored only to deliver notifications to your device.
- You can disable notification categories from within the application or your device settings without affecting your account in any other way.
Optional location access
Some operational features — such as geo-tagged work orders, asset location tracking enabled by an organization administrator, or service area routing — may use device location when explicitly enabled.
- Location access is always optional. The application functions fully without it.
- Foreground location is requested only when needed by a specific workflow and is disclosed through native OS prompts.
- Background location is requested only when an organization administrator has enabled a feature that requires it, and only after a separate in-app consent.
- Location coordinates are transmitted over encrypted channels and stored only when associated with a deliberate user action (e.g. checking in to a site).
Security practices and internal access
- Production systems enforce role-based access control with the principle of least privilege — engineers receive only the access required to perform their role.
- Administrative access is gated by multi-factor authentication and is granted on a just-in-time basis where feasible.
- Every administrative action against production data is captured in an immutable audit log, retained according to our Data Retention Policy.
- Source code, infrastructure, and secrets are managed through reviewed change-control processes; secrets are never embedded in source repositories.
- We perform periodic security reviews of dependencies, infrastructure configuration, and access grants.
Detailed engineering safeguards are described in our Security & Data Protection page.
Data retention
We retain information only as long as necessary to deliver the service, satisfy legal obligations, resolve disputes, and enforce our agreements. Specific retention periods for each data category are documented in our Data Retention Policy.
Your rights
Subject to applicable law, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of your information (see our Data Deletion Request page).
- Object to or restrict certain processing activities.
- Receive your information in a portable, machine-readable format.
- Withdraw any consent you have previously granted, without affecting the lawfulness of prior processing.
- Lodge a complaint with the supervisory authority in your jurisdiction.
To exercise any of these rights, contact us through the channels listed below. We respond to verified requests within the timeframes required by applicable law (and in any case within 30 days where reasonably possible).
International data transfers
Our services may process information in jurisdictions different from your country of residence. When personal data originating in the European Economic Area or the United Kingdom is transferred outside those regions, we rely on appropriate safeguards — including the European Commission Standard Contractual Clauses and any supplementary measures required by case law.
Children's privacy
Our services are designed for professional and operational use and are not directed at children under 16. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently received such information, we will delete it promptly.
Changes to this policy
We may update this Policy from time to time to reflect changes in our services, the legal landscape, or operational practices. The "Last updated" date at the top reflects the most recent revision. Material changes will be communicated through a prominent in-product notice or via email to active account administrators.
Contact us
For any question about this Policy, to exercise a privacy right, or to escalate a concern, contact:
- Sigmantic Digital Technology — Privacy Office
- Email: contact@khalidaboubakr.com
- Operating principal
- Khalid Aboubakr · contact@khalidaboubakr.com
Have a privacy or compliance question?
Reach out for a formal response within a few business days.