Legal

Privacy Policy

Last updated [PUBLICATION DATE]

Draft for review. This document contains unresolved placeholders and has not been reviewed by a lawyer. Do not publish it as-is.

This policy explains what [LEGAL ENTITY NAME] collects when you use the iSmart Module and the NexPool Connect application, why, and what you can do about it.

It is written against what the product actually does. If you change what the app or firmware transmits, this document has to change with it.

1. Who is responsible

[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller of the personal data described here. Contact: [SUPPORT EMAIL].

[If you have or need a Data Protection Officer or an EU/UK representative, name them here.]

2. What we collect

Drawn from what the product visibly collects today. Verify against the current build before publishing.

  • Account details: first name, last name, email, and the address entered during setup.
  • Pool and device records: pool name, device code, module serial, firmware version, and device PIN state.
  • Pool location: used to compute sunrise and sunset locally each day for schedule offsets.
  • Equipment and sensor data: pump speeds and run windows, heater targets and temperatures, relay states, water temperature, water-balance and chemistry readings, lighting scenes and zones.
  • Schedules and settings you configure, including scenes and automation rules.
  • Membership and access: who you have invited, join-code use, and role assignments.
  • Technical and diagnostic data: connection events, errors, crash reports, app version, device model and operating system.
  • Support correspondence you send us.

3. Why we use it

  • To operate the service: pairing your module, showing live state, and running your schedules.
  • To provide remote access and notifications.
  • To support you, diagnose faults, and honour warranty claims.
  • To keep the service secure, and to detect misuse.
  • To improve reliability and product quality using aggregated or de-identified data.
  • To meet legal obligations.

4. Legal bases

Where GDPR or equivalent law applies, we rely on performance of a contract for operating the service; legitimate interests for security, diagnostics and product improvement; consent where required, for example marketing or optional analytics; and legal obligation where a law requires retention.

[Map each purpose above to a basis, and record it. Regulators ask for this mapping.]

5. Who we share it with

We do not sell personal data.

[List every sub-processor: cloud hosting, push notifications, crash reporting, analytics, email delivery, support desk — with the country each operates in. This list must be complete and current.]

  • Service providers acting on our instructions, under contract.
  • People you have granted access to, such as family members or your service company.
  • Authorities, where we are legally required to disclose.
  • A successor entity, if the business is transferred.

6. International transfers

[State where data is stored and processed, and the mechanism used for any transfer out of the EEA/UK — adequacy decision, standard contractual clauses, or another lawful basis.]

7. How long we keep it

[Set a period per category. For example: account data for the life of the account plus [X]; telemetry for [X]; diagnostic logs for [X]; support correspondence for [X].]

Aggregated or de-identified data that can no longer be linked to you may be kept indefinitely.

8. Your rights

Subject to your jurisdiction, you may have the right to access your data, correct it, delete it, restrict or object to processing, take it elsewhere in a portable form, and withdraw consent.

To exercise any of these, contact [SUPPORT EMAIL]. You may also complain to your local supervisory authority.

[CCPA/CPRA additionally requires specific disclosures and a stated non-discrimination commitment. Add them if you sell into California.]

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit and access controls on our systems.

You are responsible for your account credentials and your device PIN. No system is perfectly secure, and we do not claim otherwise.

[Describe your breach-notification process and timescale.]

10. Children

The product is not directed at children, and we do not knowingly collect data from anyone under [AGE]. If you believe a child has provided us data, contact us and we will delete it.

11. This website

[State what this site sets: strictly necessary cookies, analytics, embedded media. If you use anything beyond strictly necessary cookies in the EU/UK you need consent before it loads, not a banner that merely announces it.]

12. Changes

We will post changes here and update the date above. Material changes will be notified [HOW] before taking effect.