Version: 01.09.2024
This declaration was written in German (DE). If there are discrepancies between the translated versions of this declaration and the German version, the German version will always prevail.
This privacy policy applies to the mobile application (the "App") used to detect, configure and manage WavePointer beacons.
The App is not a public product. It is intended exclusively for a closed, trained group of users – employees and appointed partners of companies that operate WavePointer beacons. Use requires a user account issued and managed by the respective company; public sign-up is not possible. The App is not offered for private use or to consumers.
Your company (the device owner or client) creates the user accounts, manages them and is responsible for them. It decides who is granted access, which permissions apply and how long an account remains in place. It is therefore the controller for its staff's personal data.
TecBakery GmbH provides the App and the associated service and processes the data exclusively on behalf of, and on the instructions of, that company (as processor):
TecBakery GmbH Gotthardstrasse 62 CH-6415 Arth Switzerland E-mail: datenschutz@wavepointer.com
TecBakery is neither permitted nor technically able to create, change or delete employee accounts, or to disclose account data.
Your point of contact is therefore always the eAdmin contact person (SPOC) at your company. Address all questions about your account and your data, and all data subject requests, to them. We cannot answer requests sent directly to TecBakery on the merits; we forward them to the responsible company.
The App processes only the data required for its operational purpose:
The App processes no sensitive personal data and does not create movement or performance profiles of staff.
Processing is carried out for the following purposes:
The legal bases are the Swiss Federal Act on Data Protection (FADP) and, where applicable, Art. 6(1)(b) GDPR (performance of the contract or employment relationship) and Art. 6(1)(f) GDPR (legitimate interest in secure, properly documented operation). Location capture is based on your consent, which you may withdraw at any time in your device's system settings.
The App requests only the permissions it needs for its task – in particular Bluetooth (detecting and configuring beacons), optionally location (documenting where a reading was taken), optionally camera and photos (capturing codes and documentation images), notifications (status display while a reading is running) and – if you enable it – device authentication (biometrics or device passcode) for simplified sign-in. Any permission may be refused or withdrawn in the system settings; the App then remains usable with the corresponding limitations.
Credentials and session data are stored exclusively in the secure storage provided by the operating system (Android Keystore or iOS Keychain). The App's local database is encrypted. On sign-out, the locally stored data and the associated key material are deleted from the device.
Data is transmitted over an encrypted connection (TLS/HTTPS) to the service operated by TecBakery and processed there. Processing and storage take place exclusively in data centres in Switzerland and the European Union. Any processors engaged (e.g. hosting) are contractually bound to confidentiality and to compliance with data protection requirements. No transfer takes place to countries without an adequate level of data protection.
Account data is retained for the duration of the access authorisation and is deleted or anonymised once it ends; the responsible company decides whether an account exists and when it is deleted. Beacon operating and documentation data is retained for as long as it is required as evidence of system operation or as long as statutory retention obligations apply; the retention period is determined by the responsible company. Technical logs are deleted at regular intervals.
Subject to applicable law, you have the right to information/access, rectification, erasure, restriction of processing, release or portability of your data, and the right to object to processing.
Please direct such requests to the eAdmin contact person (SPOC) at your company, not to TecBakery: only your company manages the accounts and can provide information about them or make changes (see section 2). TecBakery supports the company on its instructions.
You also have the right to lodge a complaint with the competent supervisory authority (in Switzerland: the FDPIC; in the EU: the data protection authority of your country of residence).
We take appropriate technical and organisational measures to protect the data, in particular transport encryption, encryption of local data storage, storage of secrets in secure system storage, and role-based access rights. Access to the App is restricted to authorised, trained personnel.
The App is intended exclusively for professional users. It is not intended for persons under 16 years of age.
This privacy policy may be adapted if the scope of functions or the legal framework changes. The current version published with the App applies.
For account and data matters: the eAdmin contact person (SPOC) at your company.
Operator of the App and the service: TecBakery GmbH · Gotthardstrasse 62 · CH-6415 Arth · Switzerland · E-mail: datenschutz@wavepointer.com · www.wavepointer.com