Argus / SSIT
Privacy Policy
Effective from: 16 May 2025
The Argus app provides remote monitoring of unattended retail stores — viewing security cameras, controlling system devices, and receiving push notifications about motion and customer entries. This page describes what personal data the app processes and why.
Data controller
The data controller is the operator of the BOP Dashboard system who manages the relevant store or group of stores. Contact e-mail: radek@radeksalomon.com.
What data the app processes
- Login session — when the app is paired with the server, a session cookie and the server URL are stored. This data is kept in the device Keychain and is used solely to authenticate against the BOP Dashboard API.
- Push notifications — to deliver alerts about motion, customer entries, and incoming intercom calls, the app sends the device token (APNs token) to the BOP Dashboard server. The token is stored on the server and used only to send notifications to this device.
- Device location — the app may request location access for geofencing (automatically switching to the nearest store). Location is not recorded on the server — it is processed solely on the device.
- Device camera — the app does not use the phone camera. Camera access is requested solely for the QR code when pairing with the server.
- Diagnostic data — if the app crashes, a crash report may be generated containing an anonymized event log (breadcrumbs) with no personal data. The report is sent to the operational Grafana instance (metrics.ssit.cz) and is used solely to improve app stability.
Purpose of processing and legal basis
All processing is carried out on the basis of the legitimate interest of the system operator (ensuring the security of the premises, remote access for authorized persons) and the consent of the user expressed by installing and pairing the app.
Sharing data with third parties
The app does not share personal data with any third parties for commercial purposes. The technical infrastructure uses:
- Apple Push Notification service (APNs) — to deliver push notifications; Apple processes only the device token, not the notification content.
- BOP Dashboard — the customer's own server, operated by SSIT.
- Grafana / Loki — app crash telemetry; no personal data.
Retention period
Push tokens are retained on the server for as long as the device is actively paired. Uninstalling the app or unpairing it in settings removes the token at the next synchronization. Crash reports are retained for 90 days.
Your rights
In accordance with the GDPR, you have the right to access your data and to its rectification, erasure, restriction of processing, and portability. Send requests to the controller's contact e-mail listed above.
Changes to this policy
Any changes to this policy will be published on this page with an updated effective date.