Introduction

Pro-Alert ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our IoT device monitoring and security service ("Service").

Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Service.

1. Information We Collect

1.1 Personal Information

We collect personal information that you voluntarily provide to us when you:

  • Register for an account: Name, email address, organization name
  • Subscribe to paid plans: Billing information (processed securely by Stripe)
  • Contact support: Name, email, and any information you provide in your message
  • Configure notifications: Phone number (for SMS/WhatsApp/Voice alerts)

1.2 Device Information

When you add IoT devices to monitor, we collect:

  • Device ID, name, and type
  • IP address and network information
  • Device status and heartbeat data
  • Signal strength and connectivity metrics
  • Device metadata (manufacturer, model, firmware version - if provided)

1.3 Alert and Event Data

  • Security alerts and timestamps
  • Alert severity and type
  • Alert resolution status and notes
  • Device events and state changes

1.4 Usage Information

We automatically collect certain information when you use our Service:

  • Log data (IP address, browser type, operating system)
  • API usage and request logs
  • Feature usage statistics
  • Session duration and frequency

1.5 Cookies and Tracking

  • Authentication tokens (JWT stored in localStorage)
  • Session cookies for maintaining login state
  • Preference cookies (notification settings, display preferences)

2. How We Use Your Information

We use the information we collect to:

  • Provide the Service: Monitor your IoT devices, detect security issues, and send alerts
  • Process payments: Manage subscriptions and billing (via Stripe)
  • Send notifications: Deliver security alerts via your preferred channels
  • Improve the Service: Analyze usage patterns and optimize performance
  • Provide support: Respond to your inquiries and troubleshoot issues
  • Ensure security: Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations: Meet regulatory requirements and enforce our Terms
  • Communicate with you: Send service updates, security notices, and marketing (with consent)

3. How We Share Your Information

We do not sell your personal information. We may share your information in the following circumstances:

3.1 Service Providers

  • Stripe: Payment processing (they have their own privacy policy)
  • Twilio: SMS, WhatsApp, and voice call notifications
  • MongoDB Atlas: Database hosting and management
  • Email service: Gmail SMTP for email notifications

3.2 Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.

3.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court orders, subpoenas).

3.4 Team Members (Business Plan)

If you use our Business plan with team features, authorized team members can access shared devices, alerts, and organizational data based on their role permissions.

4. Data Retention

We retain your information for as long as necessary to provide the Service and as follows:

  • Account data: Until you delete your account
  • Alert history: Based on your subscription plan (30 days for Free, 90 days for Pro, 1 year for Business)
  • Billing records: 7 years (UK tax law requirement)
  • Audit logs: 1 year (Business plan only)

After your account is deleted, we may retain certain information for legal, security, or legitimate business purposes, but we will anonymize it where possible.

5. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption: Data in transit (TLS/SSL) and at rest (AES-256)
  • Authentication: Bcrypt password hashing, JWT tokens with expiration
  • Access controls: Role-based permissions, least privilege principle
  • Security headers: HSTS, CSP, XSS protection, frame options
  • Regular security audits: Vulnerability scanning and penetration testing
  • Monitoring: Intrusion detection and security event logging

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Your Privacy Rights

Depending on your location, you may have the following rights:

6.1 GDPR Rights (UK/EU Users)

  • Right to access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure: Request deletion of your data ("right to be forgotten")
  • Right to restriction: Limit how we use your data
  • Right to portability: Receive your data in a machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw consent for marketing or optional processing

6.2 How to Exercise Your Rights

To exercise any of these rights, please contact us at: privacy@iotsecurityplatform.com

We will respond to your request within 30 days.

7. Children's Privacy

Our Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn we have collected information from a child under 18, we will delete it immediately.

8. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

9. Third-Party Links

Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

10. Marketing Communications

With your consent, we may send you marketing emails about new features, promotions, and updates. You can opt out at any time by:

  • Clicking the "unsubscribe" link in any marketing email
  • Updating your preferences in your account settings
  • Contacting us at support@iotsecurityplatform.com

Note: You cannot opt out of transactional emails (account notifications, security alerts, billing statements) as these are necessary for the Service.

11. Do Not Track

Our Service does not respond to Do Not Track (DNT) signals. We do not track users across third-party websites for advertising purposes.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date at the top
  • Sending you an email notification (for material changes)

Your continued use of the Service after such modifications constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions or concerns about this Privacy Policy, please contact us:

Email: privacy@iotsecurityplatform.com
Data Protection Officer: dpo@iotsecurityplatform.com
Address: [Your Business Address]
Phone: [Your Support Phone Number]

14. Data Protection Authority

If you are in the UK or EU and believe we have not addressed your concerns, you have the right to lodge a complaint with your local data protection authority:

UK: Information Commissioner's Office (ICO) - https://ico.org.uk
EU: Your local Data Protection Authority