Privacy Policy
Last Updated: January 26, 2026
1. Introduction
DIMRP Technologies is committed to protecting your personal data in compliance with GDPR (EU) and LGPD (Brazil). This policy applies to all users of our Occupational Health and Safety (OHS) Monitoring Platform and establishes our Data Processing Agreement (DPA) and Telemetry Privacy terms.
2. Nature, Purpose and Limits of Processing
DIMRP processes data exclusively to provide telemetry services, occupational risk monitoring, and health alerts as provided in the contract. The processing will last for the duration of the main contract. DIMRP commits to processing personal data only according to the documented instructions of the Data Controller.
3. Confidentiality and Industrial Secret Protection
The Controller acknowledges that the processing methodologies, database architecture, Machine Learning models, and inference algorithms used by DIMRP constitute industrial secrets and exclusive Intellectual Property. The Controller has no right to access the source code, AI heuristics, or logical infrastructure.
4. Categories of Sensitive Data and Mobile Permissions
Access to raw health data is restricted by Role-Based Access Control (RBAC). Processing includes:
4.1. Background Location
Continuous background GPS and indoor positioning is strictly justified by life safety needs, allowing AlentoCare to locate workers in case of a collapse.
4.2. Foreground Services
VitalMesh uses continuous foreground processes to prevent smartphone suspension, ensuring zero latency for impact sensors.
4.3. Device Identifiers
Processed only for critical alerts. Sharing with data brokers or use for advertising is strictly prohibited.
4.4. Physiological and Kinematic Data
- Heart Rate (BPM) & SpO2
- Body Temperature
- G-Forces & Fall detection
- Exposure to harmful gases (CO, H2S)
5. Non-negotiable Pseudonymization Protocol
Upon signal ingestion by the gateway, civil identifiers are separated from the telemetry through an isolated cryptographic key. It is impossible to associate a vital sign with an identity without controlled access to this key.
6. Subcontractors and Data Retention
DIMRP uses cloud infrastructure subcontractors bound by rigid DPAs or Standard Contractual Clauses (SCCs) in the case of international transfers. Data lifecycles follow this matrix:
| Data Asset Category | Retention Period | Post-Period Destination |
|---|---|---|
| Raw Sensor Data | 30 Days | Irreversible Automatic Purge |
| Aggregated Metrics | Perpetual | De-identified Statistics |
| Incident Reports | 5 to 10 Years | Encrypted Archive |
7. Incident Response (Data Breach)
In the event of a breach that compromises confidentiality, DIMRP will trigger the emergency protocol and notify the competent supervisory authority within a maximum of 72 hours.
8. Web Tracking and Cookie Policy
Administrative Privacy and Session Management
- Typology and Tracking: On the web administration panels, DIMRP uses only Strictly Necessary Cookies (for authentication via JWT Tokens and CSRF protection) and Performance Cookies for aggregated internal telemetry.
- Restrictions and Management: DIMRP does not use behavioral advertising cookies nor does it share data with data brokers. The blocking of essential cookies by the administrator will result in a technical inability to access the monitoring platforms.
9. Your Rights & Data Controller
DIMRP Technologies, Lda. (Instituto Pedro Nunes - IPN, Coimbra, Portugal)
DPO Contact: [email protected]
You have the right to Access, Rectification, Erasure ("Right to be Forgotten"), and Portability. Contact our DPO to exercise these rights.