Privacy Policy

Last Updated: January 26, 2026

1. Introduction

DIMRP Technologies is committed to protecting your personal data in compliance with GDPR (EU) and LGPD (Brazil). This policy applies to all users of our Occupational Health and Safety (OHS) Monitoring Platform and establishes our Data Processing Agreement (DPA) and Telemetry Privacy terms.

2. Nature, Purpose and Limits of Processing

DIMRP processes data exclusively to provide telemetry services, occupational risk monitoring, and health alerts as provided in the contract. The processing will last for the duration of the main contract. DIMRP commits to processing personal data only according to the documented instructions of the Data Controller.

3. Confidentiality and Industrial Secret Protection

The Controller acknowledges that the processing methodologies, database architecture, Machine Learning models, and inference algorithms used by DIMRP constitute industrial secrets and exclusive Intellectual Property. The Controller has no right to access the source code, AI heuristics, or logical infrastructure.

4. Categories of Sensitive Data and Mobile Permissions

Access to raw health data is restricted by Role-Based Access Control (RBAC). Processing includes:

4.1. Background Location

Continuous background GPS and indoor positioning is strictly justified by life safety needs, allowing AlentoCare to locate workers in case of a collapse.

4.2. Foreground Services

VitalMesh uses continuous foreground processes to prevent smartphone suspension, ensuring zero latency for impact sensors.

4.3. Device Identifiers

Processed only for critical alerts. Sharing with data brokers or use for advertising is strictly prohibited.

4.4. Physiological and Kinematic Data

  • Heart Rate (BPM) & SpO2
  • Body Temperature
  • G-Forces & Fall detection
  • Exposure to harmful gases (CO, H2S)

5. Non-negotiable Pseudonymization Protocol

Upon signal ingestion by the gateway, civil identifiers are separated from the telemetry through an isolated cryptographic key. It is impossible to associate a vital sign with an identity without controlled access to this key.

6. Subcontractors and Data Retention

DIMRP uses cloud infrastructure subcontractors bound by rigid DPAs or Standard Contractual Clauses (SCCs) in the case of international transfers. Data lifecycles follow this matrix:

Data Asset CategoryRetention PeriodPost-Period Destination
Raw Sensor Data30 DaysIrreversible Automatic Purge
Aggregated MetricsPerpetualDe-identified Statistics
Incident Reports5 to 10 YearsEncrypted Archive

7. Incident Response (Data Breach)

In the event of a breach that compromises confidentiality, DIMRP will trigger the emergency protocol and notify the competent supervisory authority within a maximum of 72 hours.

8. Web Tracking and Cookie Policy

Administrative Privacy and Session Management

  • Typology and Tracking: On the web administration panels, DIMRP uses only Strictly Necessary Cookies (for authentication via JWT Tokens and CSRF protection) and Performance Cookies for aggregated internal telemetry.
  • Restrictions and Management: DIMRP does not use behavioral advertising cookies nor does it share data with data brokers. The blocking of essential cookies by the administrator will result in a technical inability to access the monitoring platforms.

9. Your Rights & Data Controller

DIMRP Technologies, Lda. (Instituto Pedro Nunes - IPN, Coimbra, Portugal)

DPO Contact: [email protected]

You have the right to Access, Rectification, Erasure ("Right to be Forgotten"), and Portability. Contact our DPO to exercise these rights.

Effective January 2026. Changes will be notified via platform alert.