Privacy Policy
Version 1.1 · Last updated 14 August 2026
Who this policy covers
This policy describes how Smart IoT ("we", "us", the platform operator based in Chennai, India) handles personal data collected through the Smart IoT platform (web application, mobile-installable PWA, and connected AI assistant).
Smart IoT is offered in several deployment models — cloud, on-premises, edge, and VPN-secured hybrid. If your organization has deployed Smart IoT on-premises or on infrastructure it controls, your organization is the data controller for data processed on that deployment, not Smart IoT; this policy then describes how the software itself handles data, and you should also refer to your own organization's privacy notice. For the hosted Smart IoT Cloud platform, Smart IoT is the data controller.
What we collect
- Account data — username, email address, password (stored as a salted hash, never in plain text), display name, location, timezone, language, and profile photo, all provided by you at registration or via your Profile page.
- Consent record — the Privacy Policy version you agreed to, the date, and the IP address the acceptance was made from.
- Operational data you connect — device and sensor configuration, feed and dashboard definitions, automation rules, and the telemetry readings your devices send once connected. This data belongs to your organization/site and is isolated from other organizations on the same platform.
- AI assistant interactions — if you use the SmartIoT AI voice/chat assistant, the text of your requests and the assistant's responses are processed to answer you; input length is capped and outbound responses are screened to redact API keys/secrets before being shown to you. The assistant only ever acts on data belonging to your own site.
- Technical/session data — a session cookie used to keep you signed in, and standard web server logs (IP address, timestamp, requested page) used for security and troubleshooting.
We do not collect payment card data directly, and we do not sell personal data to third parties.
How we use it
To operate your account and the Smart IoT platform you've registered for: authenticating you, enforcing your organization's role-based access control, running the monitoring/automation/AI features you configure, and maintaining platform security (audit logging, rate limiting, TLS encryption in transit).
Who we share it with
We do not sell or rent personal data. Data may be shared with:
- Sub-processors that keep the platform running (e.g. infrastructure/hosting providers for the cloud deployment model) — bound by confidentiality and security obligations.
- Other members of your own organization/site, according to the role they hold (viewer, operator, engineer, site admin, org admin) — this is the platform's core access-control model, not third-party sharing.
- Law enforcement or regulators, only when we are legally required to.
How long we keep it
Account and operational data is retained for as long as your account is active. There is currently no automatic time-based deletion of historical telemetry — if you need data purged on a schedule, contact us. Deleting your account (see "Your rights" below) removes your account and every record tied to it immediately.
Your rights
- Access & portability — download a copy of your account, site memberships, and platform configuration (feeds, inputs, devices, dashboards, automation rules) at any time from your Profile page ("Download my data").
- Erasure — permanently delete your account and every associated record, password-confirmed, from your Profile page ("Delete account").
- Correction — update your account details (name, email, timezone, etc.) directly from your Profile page at any time.
To exercise any right not covered by the self-service tools above, or if your account was created by an administrator rather than self-registered, contact us using the details below.
Security
The platform enforces TLS 1.3 for connections, role-based access control with per-site data isolation, password hashing, and audit logging of security-relevant actions. Security assessments are performed regularly; see our published VAPT (Vulnerability Assessment & Penetration Testing) reports for details.
Changes to this policy
If we make a material change to this policy, we will update the version number and date above. Your account's Profile page always shows which version you most recently agreed to.
Contact
Smart IoT, Chennai, India
Email: info@smartiot.in
Phone / WhatsApp: +91 73055 00451