Mobile app · Defendex

Privacy Policy

How the Defendex app and the CORTEX monitoring platform handle your data — and how to delete it.

Effective date: 16.09.2026 · Version 1.0

Privacy Policy of the Defendex app

Defendex is a mobile application for owners of security systems built on CORTEX equipment. It shows the status of your sites, delivers alarm notifications and lets you arm and disarm your system. This policy explains which data is processed when you use the app, for what purpose, and what choices you have.

1. Who we are

The Defendex app and the monitoring platform behind it are developed and operated by SIA CORTEX, Liksnas iela 7, Rīga, Latvia (hereinafter "CORTEX", "we").

Your account and access to specific sites are created by the security company that services your site. For account data and site events, that company is the data controller; CORTEX operates the platform on its behalf as a processor and is the controller for the technical data described below (e.g. push tokens).

2. What data we process

DataSourcePurpose
Username and password (password is stored only as a hash)Entered by you / issued by the security companySign-in and access to your sites
Push notification token (an identifier of the app installation on your device) and platform (Android/iOS)Generated by Google Firebase on your deviceDelivering alarm and status notifications to your phone
Site events and statuses (armed/disarmed, alarms, zones, mains and battery, communication tests)Your security equipment via the monitoring platformShowing status and event history; sending notifications
Commands you send (arm/disarm) with time and user IDYour actions in the appExecuting the command and keeping an audit log of who armed/disarmed the site
Notification preferences and interface languageYour settings in the appShowing the app the way you configured it
Technical request data (IP address, time, app version)Automatically, when the app connects to the serverSecurity, troubleshooting, protection against abuse

We do not collect your location, contacts, photos, files, browsing history, health or financial data. The camera is used only to scan a QR code on your device; the image is not sent anywhere. Video from site cameras is streamed for viewing only and is not stored on our servers by the app.

3. Why and on what basis

  • Performance of the service (GDPR Art. 6(1)(b)): sign-in, status display, arming/disarming, notifications — this is what the app is for.
  • Legitimate interest (Art. 6(1)(f)): security of the platform, technical logs, audit log of commands — so that both you and the security company can see who did what with the system.
  • Your choice: push notifications require your permission on the device; you can switch categories on the "Notifications" screen or revoke the permission in the system settings at any time.

4. Third parties

  • Google Firebase Cloud Messaging (Google Ireland Ltd.) — delivers push notifications. Google receives the push token and the notification content (site name and event text) solely to deliver it to your device. Google acts as our processor. Firebase privacy.
  • Your security company — sees the events and statuses of the sites it services and the commands sent to them (this is the essence of the monitoring service).
  • We do not sell personal data and do not share it with anyone for advertising.

5. Storage and security

  • The data is stored on servers located in the European Union.
  • Connection between the app and the server is encrypted (HTTPS/TLS). Passwords are stored as hashes; sign-in credentials on the device are kept in the secure storage (Android Keystore).
  • Retention: account data — while the account exists; push token — until you sign out or uninstall the app (invalid tokens are removed automatically); site events — for the retention period set by your security company's contract, after which they are deleted or anonymised.

6. Your rights

Under the GDPR you may request access to your data, its rectification or erasure, restriction of processing, data portability, and object to processing based on legitimate interest. You also have the right to lodge a complaint with the supervisory authority — in Latvia, Datu valsts inspekcija (dvi.gov.lv).

To exercise these rights contact your security company or CORTEX using the details below. We respond within 30 days.

7. App permissions

PermissionWhy
INTERNETConnection to the monitoring server
POST_NOTIFICATIONSShowing push notifications (Android 13+)
CAMERAScanning a QR code when adding a site — locally only
USE_BIOMETRICOptional sign-in by fingerprint/face — processed by the OS, biometric data never leaves the device
VIBRATEVibration on alarm

8. Changes

We may update this policy when the app changes. The current version is always available at this address; the effective date is shown at the top of the page. Material changes will be announced in the app.

Deleting your account and data

You can request deletion of your Defendex account and the personal data associated with it at any time.

  1. Sign out of the app ("Sign out" in the menu). This immediately removes the push token from the server — notifications to this phone stop.
  2. Send a deletion request to your security company or to CORTEX (contacts below) with the subject "Defendex — delete account" and your username. No other data is needed.
  3. Within 30 days we delete the account, its site assignments, notification settings and push tokens. Site event history stays with the security company for the contractual retention period (it is data about the site, not about you) and is anonymised from your account.
  4. Uninstall the app to remove all locally stored data (settings, cached events, saved credentials).
If the account was created for you by a security company, it may need to confirm the request — deletion means losing access to monitoring of your site.

Send deletion request

Contact

Operator of the platformSIA CORTEX
Liksnas iela 7, Rīga, LV-1003, Latvia
Phone+371 67 505 603
Privacy requestsinfo@cortex.lv
Websitecortex.eu