Legal
Privacy Policy
Last updated [PUBLICATION DATE]
Draft for review. This document contains unresolved placeholders and has not been reviewed by a lawyer. Do not publish it as-is.
This policy explains what [LEGAL ENTITY NAME] collects when you use the iSmart Module and the NexPool Connect application, why, and what you can do about it.
It is written against what the product actually does. If you change what the app or firmware transmits, this document has to change with it.
1. Who is responsible
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller of the personal data described here. Contact: [SUPPORT EMAIL].
[If you have or need a Data Protection Officer or an EU/UK representative, name them here.]
2. What we collect
Drawn from what the product visibly collects today. Verify against the current build before publishing.
- Account details: first name, last name, email, and the address entered during setup.
- Pool and device records: pool name, device code, module serial, firmware version, and device PIN state.
- Pool location: used to compute sunrise and sunset locally each day for schedule offsets.
- Equipment and sensor data: pump speeds and run windows, heater targets and temperatures, relay states, water temperature, water-balance and chemistry readings, lighting scenes and zones.
- Schedules and settings you configure, including scenes and automation rules.
- Membership and access: who you have invited, join-code use, and role assignments.
- Technical and diagnostic data: connection events, errors, crash reports, app version, device model and operating system.
- Support correspondence you send us.
3. Why we use it
- To operate the service: pairing your module, showing live state, and running your schedules.
- To provide remote access and notifications.
- To support you, diagnose faults, and honour warranty claims.
- To keep the service secure, and to detect misuse.
- To improve reliability and product quality using aggregated or de-identified data.
- To meet legal obligations.
4. Legal bases
Where GDPR or equivalent law applies, we rely on performance of a contract for operating the service; legitimate interests for security, diagnostics and product improvement; consent where required, for example marketing or optional analytics; and legal obligation where a law requires retention.
[Map each purpose above to a basis, and record it. Regulators ask for this mapping.]
6. International transfers
[State where data is stored and processed, and the mechanism used for any transfer out of the EEA/UK — adequacy decision, standard contractual clauses, or another lawful basis.]
7. How long we keep it
[Set a period per category. For example: account data for the life of the account plus [X]; telemetry for [X]; diagnostic logs for [X]; support correspondence for [X].]
Aggregated or de-identified data that can no longer be linked to you may be kept indefinitely.
8. Your rights
Subject to your jurisdiction, you may have the right to access your data, correct it, delete it, restrict or object to processing, take it elsewhere in a portable form, and withdraw consent.
To exercise any of these, contact [SUPPORT EMAIL]. You may also complain to your local supervisory authority.
[CCPA/CPRA additionally requires specific disclosures and a stated non-discrimination commitment. Add them if you sell into California.]
9. Security
We use technical and organisational measures appropriate to the risk, including encryption in transit and access controls on our systems.
You are responsible for your account credentials and your device PIN. No system is perfectly secure, and we do not claim otherwise.
[Describe your breach-notification process and timescale.]
10. Children
The product is not directed at children, and we do not knowingly collect data from anyone under [AGE]. If you believe a child has provided us data, contact us and we will delete it.
12. Changes
We will post changes here and update the date above. Material changes will be notified [HOW] before taking effect.
