Privacy Policy of the Defendex app
Defendex is a mobile application for owners of security systems built on CORTEX equipment. It shows the status of your sites, delivers alarm notifications and lets you arm and disarm your system. This policy explains which data is processed when you use the app, for what purpose, and what choices you have.
1. Who we are
The Defendex app and the monitoring platform behind it are developed and operated by SIA CORTEX, Liksnas iela 7, Rīga, Latvia (hereinafter "CORTEX", "we").
Your account and access to specific sites are created by the security company that services your site. For account data and site events, that company is the data controller; CORTEX operates the platform on its behalf as a processor and is the controller for the technical data described below (e.g. push tokens).
2. What data we process
| Data | Source | Purpose |
|---|---|---|
| Username and password (password is stored only as a hash) | Entered by you / issued by the security company | Sign-in and access to your sites |
| Push notification token (an identifier of the app installation on your device) and platform (Android/iOS) | Generated by Google Firebase on your device | Delivering alarm and status notifications to your phone |
| Site events and statuses (armed/disarmed, alarms, zones, mains and battery, communication tests) | Your security equipment via the monitoring platform | Showing status and event history; sending notifications |
| Commands you send (arm/disarm) with time and user ID | Your actions in the app | Executing the command and keeping an audit log of who armed/disarmed the site |
| Notification preferences and interface language | Your settings in the app | Showing the app the way you configured it |
| Technical request data (IP address, time, app version) | Automatically, when the app connects to the server | Security, troubleshooting, protection against abuse |
We do not collect your location, contacts, photos, files, browsing history, health or financial data. The camera is used only to scan a QR code on your device; the image is not sent anywhere. Video from site cameras is streamed for viewing only and is not stored on our servers by the app.
3. Why and on what basis
- Performance of the service (GDPR Art. 6(1)(b)): sign-in, status display, arming/disarming, notifications — this is what the app is for.
- Legitimate interest (Art. 6(1)(f)): security of the platform, technical logs, audit log of commands — so that both you and the security company can see who did what with the system.
- Your choice: push notifications require your permission on the device; you can switch categories on the "Notifications" screen or revoke the permission in the system settings at any time.
4. Third parties
- Google Firebase Cloud Messaging (Google Ireland Ltd.) — delivers push notifications. Google receives the push token and the notification content (site name and event text) solely to deliver it to your device. Google acts as our processor. Firebase privacy.
- Your security company — sees the events and statuses of the sites it services and the commands sent to them (this is the essence of the monitoring service).
- We do not sell personal data and do not share it with anyone for advertising.
5. Storage and security
- The data is stored on servers located in the European Union.
- Connection between the app and the server is encrypted (HTTPS/TLS). Passwords are stored as hashes; sign-in credentials on the device are kept in the secure storage (Android Keystore).
- Retention: account data — while the account exists; push token — until you sign out or uninstall the app (invalid tokens are removed automatically); site events — for the retention period set by your security company's contract, after which they are deleted or anonymised.
6. Your rights
Under the GDPR you may request access to your data, its rectification or erasure, restriction of processing, data portability, and object to processing based on legitimate interest. You also have the right to lodge a complaint with the supervisory authority — in Latvia, Datu valsts inspekcija (dvi.gov.lv).
To exercise these rights contact your security company or CORTEX using the details below. We respond within 30 days.
7. App permissions
| Permission | Why |
|---|---|
| INTERNET | Connection to the monitoring server |
| POST_NOTIFICATIONS | Showing push notifications (Android 13+) |
| CAMERA | Scanning a QR code when adding a site — locally only |
| USE_BIOMETRIC | Optional sign-in by fingerprint/face — processed by the OS, biometric data never leaves the device |
| VIBRATE | Vibration on alarm |
8. Changes
We may update this policy when the app changes. The current version is always available at this address; the effective date is shown at the top of the page. Material changes will be announced in the app.
Deleting your account and data
You can request deletion of your Defendex account and the personal data associated with it at any time.
- Sign out of the app ("Sign out" in the menu). This immediately removes the push token from the server — notifications to this phone stop.
- Send a deletion request to your security company or to CORTEX (contacts below) with the subject "Defendex — delete account" and your username. No other data is needed.
- Within 30 days we delete the account, its site assignments, notification settings and push tokens. Site event history stays with the security company for the contractual retention period (it is data about the site, not about you) and is anonymised from your account.
- Uninstall the app to remove all locally stored data (settings, cached events, saved credentials).
Contact
Liksnas iela 7, Rīga, LV-1003, Latvia