AlvoTriX
Modules Core & Gateway Apps For Institutions Blog 🧩 Special Needs
My AlvoTriX 🛒 Get AlvoTriX
🛡️ The 10 Modules ⚙️ Core & Gateway 📱 Apps 🏫 For Institutions 📖 Blog 🧩 Special Needs Program 👤 My AlvoTriX 🛒 Get AlvoTriX

Privacy Policy

Last updated: August 24, 2026

1. Data Controller

Your personal data is controlled by: Rolaxit Innovation SRL (CUI 42351163, J40/3171/2020, registered at Str. Știubei 38, Sector 3, București, România), the sole data controller under GDPR. Rolaxit Innovation SRL is the contact for data-protection matters.

Privacy contact: For data access, deletion, correction, consent or other privacy requests, contact [email protected].

Rolaxit Innovation SRL handles all operations including technology, AI processing, data security, regulatory compliance, payment coordination, customer support, data breach notification, and DPIA compliance. You may exercise your data protection rights by contacting [email protected].

2. Data We Collect

We collect the following categories of personal data:

CategoryData TypesPurpose
Account DataName, email, phone, password (hashed), payment details (via Stripe)Account management, billing, communication
Wearer ProfileName, age, gender, health conditions (optional), relationship to GuardianService personalization, AI baseline configuration
Biometric DataHeart rate (HR), HRV, SpO2, skin temperature, steps, calories, sleep stages, accelerometer, gyroscopeAI safety analysis, anomaly detection, informational sensor and activity reports
Location DataGPS coordinates, geofence zones, location historyGeofence Guardian module, location alerts
Ambient DataAmbient noise level (dB — no audio recording)Anti-Bullying module environmental analysis
Usage DataDashboard activity, AI chat logs, report history, alert historyService delivery, product improvement
Technical DataIP address, browser type, device type, operating system, cookiesSecurity, analytics, website optimization

Sensitive data notice: Biometric data constitutes special category data under GDPR Article 9 and sensitive personal information under CCPA. We process this data exclusively based on your explicit consent (GDPR Art. 9(2)(a)).

3. How Data Flows Through AlvoTriX

AlvoTriX uses a hybrid architecture combining on-device and server-side processing.

1. Device configuration
The AlvoTriX service sends Core or Gateway the configuration associated with the Wearer's active Protection Modules. This configuration determines which supported sensors and functions are required.

2. Sensor collection
Core or Gateway collects only the data supported by the connected device and required for the enabled Protection Modules. The data available varies by device model, operating system, permissions, sensor availability and connection method.

3. Local processing
Certain time-critical safety checks are performed locally in Core or Gateway. The application may also temporarily buffer data when a network connection is unavailable.

4. Transmission to AlvoTriX services
Depending on the enabled Protection Modules, Core or Gateway may securely transmit selected sensor readings, derived metrics, device-status information, location data, configuration data and alert events to AlvoTriX services.

Not every supported data category is collected for every Wearer, and data is not necessarily transmitted continuously. The frequency and content depend on the active module, device capabilities and service configuration.

5. Server-side processing
AlvoTriX services process data where necessary to manage accounts and devices, perform server-side module analysis, establish personal baselines, generate alerts and reports, maintain the Guardian dashboard and provide service support.

6. Notifications
Where an alert is generated, limited alert information may be provided to the Wearer's designated Guardian and to contracted notification providers used to deliver SMS, email or push notifications.

Alert information may include the alert type, timestamp, severity, location, device status, selected sensor context and delivery status.

7. Data not accessed
AlvoTriX does not access the content of personal messages, calls, photos or browsing history. Where ambient sound level is supported, the service is designed to use decibel-level measurements and not audio content, subject to the capabilities and implementation of the connected device.

4. Legal Basis for Processing

Under GDPR Article 6, we process personal data based on:

  • Consent (Art. 6(1)(a)): For biometric data processing, marketing communications, cookies, and AI profiling. You may withdraw consent at any time.
  • Contract performance (Art. 6(1)(b)): To provide the AlvoTriX monitoring service you subscribed to.
  • Legitimate interest (Art. 6(1)(f)): For fraud prevention, platform security, product improvement, and anonymous analytics.
  • Legal obligation (Art. 6(1)(c)): To comply with tax, accounting, and regulatory requirements.

For biometric (special category) data, the additional legal basis under GDPR Article 9(2)(a) is your explicit consent, obtained during account setup with a separate, clear affirmative action.

5. AI Processing & Automated Profiling

AlvoTriX uses AI and machine learning to analyze biometric data patterns. This constitutes automated profiling under GDPR Article 22. Our AI processes include: biometric baseline establishment per Wearer, anomaly detection across 10 Safety Modules (Special Needs Detector, Urgent Anomaly Monitor, Metabolic Guardian, Anti-Bullying, Sleep Monitor, Heart Rate Guardian, Activity Anomaly, Geofence Guardian, Fall Detector, Panic & SOS), risk severity classification (low/medium/high/critical), automated alert triggering, and personal-baseline analysis and historical sensor-trend summaries for reports.

Your rights regarding AI decisions: You may request human review of any automated decision, obtain an explanation of the AI logic, object to specific profiling activities, and disable individual Safety Modules via your dashboard. No automated decision by AlvoTriX constitutes a legally binding or similarly significant decision — all alerts are informational and require human judgment.

6. Data Sharing & Third Parties

We do NOT sell, rent, trade, or share your personal or biometric data with any third party for their own purposes. This is an absolute commitment. Your data is used exclusively for delivering the AlvoTriX service.

We use the following sub-processors, strictly limited to their operational purpose:

  • Stripe — Payment processing only. Stripe does not access biometric data.
  • Cloud infrastructure provider — Data hosting within EU/EEA. Encrypted at rest and in transit.
  • SMS gateway provider — Alert delivery only. No data storage beyond delivery.
  • FormSubmit.co — Contact form submissions only.
  • Google Analytics — Website analytics with anonymized IP (cookie consent required).
  • Facebook/Meta Pixel — Marketing analytics only (cookie consent required). No biometric data shared.
  • Cookiebot — Cookie consent management.
  • ipapi.co (Kloudend, Inc.) — IP-based geolocation for automatic language detection. IP address only, no storage beyond the request. Privacy policy: ipapi.co/privacy.
  • Google Fonts (Google LLC) — Font delivery service. IP address transmitted on page load. Privacy policy: policies.google.com/privacy. We are transitioning to self-hosted fonts to eliminate this transfer.

We may disclose data if required by law, court order, or regulatory authority. We will notify you unless legally prohibited.

7. Data Retention & Deletion

During an active subscription

We retain personal data only for as long as necessary to provide the enabled AlvoTriX functions, maintain account security and comply with documented legal obligations. Different data categories have different retention periods. Raw sensor data, location history, reports, alert records, technical logs and account records are not necessarily retained for the same period. The current category-specific retention periods are described in our Data Retention Schedule.

Subscription cancellation

Cancelling a subscription stops future renewal. Service access continues until the end of the paid billing period. When the paid service ends, monitoring and new sensor collection stop. Service data is retained for 30 days to allow reactivation, unless the Account Holder requests earlier deletion. After the 30-day reactivation period, data is deleted from active production systems according to the retention schedule.

Account or Wearer deletion request

You may request deletion of your entire account or of a specific Wearer. After identity verification, we disable access, revoke active device credentials and stop new data collection. Data is then deleted from active production systems without undue delay.

Backups

Data that remains temporarily in encrypted backup copies is placed beyond operational use and is not restored for normal processing. Backup copies expire automatically through our documented backup cycle. If a backup is restored before expiry, outstanding deletion records are reapplied before the restored system returns to service.

Data retained by law

Certain invoices, payment records, fraud-prevention records or information necessary for legal claims may be retained where required or permitted by law. Such data is restricted, stored separately, used only for the relevant legal purpose and deleted when the applicable period expires.

Invoices, payment confirmations and other records that we are legally required to retain are stored separately for the period required by applicable accounting, tax and legal obligations. These records are not used for monitoring, profiling, product personalisation or marketing and are deleted when the applicable retention period expires.

Anonymised statistics

We may retain statistical information only where it has been irreversibly anonymised so that no individual can be identified or reasonably re-identified. Pseudonymised data, hashed identifiers and datasets that can still be linked to a Wearer remain personal data and continue to follow the applicable retention and deletion schedule.

Processors and recipients

Where applicable, we notify contracted processors and recipients that the relevant data must be erased or restricted, unless this is impossible or would involve disproportionate effort.

Response time

We acknowledge deletion requests promptly and respond without undue delay and within the legally applicable period, normally one month after receipt. Identity verification may be required before deletion is carried out.

AlvoTriX conducts and updates data-protection risk assessments, including a DPIA where required by applicable law.

8. Your Privacy Rights

Depending on your jurisdiction, you have the following rights:

  • Right of Access (GDPR Art. 15, CCPA §1798.100): Obtain a copy of all personal data we hold about you.
  • Right to Rectification (GDPR Art. 16): Correct inaccurate or incomplete data.
  • Right to Erasure (GDPR Art. 17, CCPA §1798.105): Request deletion of your personal data.
  • Right to Restrict Processing (GDPR Art. 18): Limit how we use your data.
  • Right to Data Portability (GDPR Art. 20): Receive your data in a structured, machine-readable format (JSON/CSV).
  • Right to Object (GDPR Art. 21): Object to processing based on legitimate interest or direct marketing.
  • Right to Withdraw Consent: Withdraw consent at any time without affecting prior lawful processing.
  • Right Not to Be Discriminated (CCPA §1798.125): We will not discriminate against you for exercising your rights.
  • Notification Obligation (Art. 19): We will inform each recipient to whom your data has been disclosed of any rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort. We will inform you about those recipients upon request.

To exercise any right, email [email protected]. We respond within 30 days (GDPR) or 45 days (CCPA). Identity verification required. No fee is charged for exercising your rights. A reasonable administrative fee may be charged only for manifestly unfounded or excessive requests, in accordance with GDPR Article 12(5).

9. International Data Transfers

Your data is primarily stored within the EU/EEA. Where data is transferred outside the EU/EEA, we ensure protection through: EU Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTAs) where applicable, and adequacy decisions (GDPR Art. 45). We do not transfer biometric data outside the EU/EEA under any circumstances.

10. Cookies & Tracking

We use cookies managed by Cookiebot (ID: 682881ac-4051-48c2-b148-7960577dd716). Categories: Necessary (session, language — no consent required), Statistics (Google Analytics — requires consent), Marketing (Facebook Pixel — requires consent). Manage preferences via the Cookie Settings link in the footer.

11. Children's Privacy

AlvoTriX does not knowingly create or activate Wearer profiles for children under 4 years of age. For a minor Wearer, the Account Holder must confirm their parental, guardianship or other lawful authority before AlvoTriX begins processing the Wearer's sensor, location or profile data. Age information is used only to verify eligibility, configure age-appropriate settings and apply device or module-specific restrictions. If we learn that a profile was created for an ineligible Wearer, we may suspend monitoring, contact the Account Holder and delete or restrict the associated data according to our retention and legal obligations.

AlvoTriX may monitor minors as Wearers, but only with verified parental or legal guardian consent. We comply with: GDPR Article 8, UK DPA 2018 Section 9, US COPPA (under 13), and Brazilian LGPD Article 14. We do not knowingly collect data from children without parental consent. Unauthorized collection is deleted immediately.

COPPA (United States): Where AlvoTriX processes personal information of children under 13 who are in the United States, AlvoTriX complies with the mandatory data-protection and consumer-law requirements applicable to the service and the relevant processing activity, including obtaining verifiable parental consent before collection. Parents and legal guardians may review the personal information collected from their child, request its deletion, refuse further collection or use, and decline consent to collection beyond what is reasonably necessary. To exercise these rights, contact [email protected] or write to Rolaxit Innovation SRL, Str. Știubei 38, Sector 3, București, România.

12. Data Security

We implement: encryption in transit using industry-standard transport encryption, access controls and role-based authentication, regular security audits, intrusion detection systems, secure EU/EEA backups, employee confidentiality agreements, and incident response procedures compliant with the breach-notification requirements of GDPR Article 33.

13. Data Breach Notification

In the event of a breach: we notify the relevant supervisory authority in accordance with the notification timeframe required by GDPR Art. 33, notify affected individuals without undue delay where there is a high risk (GDPR Art. 34), and provide clear information about the breach nature, data affected, actions taken, and recommendations.

14. Jurisdiction-Specific Provisions

California (CCPA/CPRA): Right to know, delete, correct, opt out of sale/sharing. We do NOT sell personal information.

Right to Limit Use of Sensitive Personal Information: Under CPRA, you have the right to limit our use and disclosure of sensitive personal information (including biometrics and precise geolocation) to uses necessary to provide the AlvoTriX service. We do not use sensitive personal information for any purpose other than service delivery. Do Not Sell or Share: We do not sell or share your personal information as defined under CCPA/CPRA. Authorized Agent: You may designate an authorized agent to submit CCPA requests on your behalf by providing written authorization to [email protected].

Biometric Privacy: AlvoTriX complies with the mandatory data-protection and consumer-law requirements applicable to the service and the relevant processing activity. Written informed consent is obtained before biometric data is collected, and biometric data is never sold.

Brazil (LGPD): We process data under LGPD Art. 7 legal bases including consent (Art. 7(I)) and contract performance (Art. 7(V)). Our privacy contact for LGPD matters (Encarregado) is reachable at [email protected]. Children's data is processed under Art. 14 with specific and prominent parental consent. International transfers comply with LGPD Art. 33 through standard contractual clauses approved by the ANPD and adequacy assessments. You may petition the Autoridade Nacional de Protecao de Dados (ANPD) at gov.br/anpd. Response timeframe: 15 days for simplified requests per Art. 18 §5.

Canada (PIPEDA): We comply with the Personal Information Protection and Electronic Documents Act and applicable provincial legislation including Quebec's Law 25. Our designated privacy accountability officer is reachable at [email protected]. We adhere to PIPEDA's 10 fair information principles including accountability, consent, limiting collection, limiting use, accuracy, safeguards, openness, individual access, challenging compliance, and purpose identification. You may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca. Cross-border transfers: your data may be processed in the EU/EEA; we ensure a comparable level of protection through contractual safeguards.

Australia (Privacy Act 1988 / APPs): We comply with the Australian Privacy Principles. APP 1: This privacy policy is freely accessible from our website. APP 5: We notify you of collection purposes at the time of collection. APP 6: We use data only for the primary purpose of service delivery. APP 8: Your data is primarily stored in the EU/EEA and may be processed by sub-processors in the United States (Stripe, Google Analytics). We ensure overseas recipients comply with obligations substantially similar to the APPs. APP 11: We maintain reasonable security safeguards. APP 12-13: You have the right to access and correct your data. Complaints may be lodged with the OAIC at oaic.gov.au. Response timeframe: 30 days.

Supervisory Authority: Rolaxit Innovation SRL is established in Romania. For matters relating to processing under the EU GDPR, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing — ANSPDCP. You may also lodge a complaint with the supervisory authority in the EU or EEA Member State of your habitual residence, place of work or place of the alleged infringement.

15. Changes to This Policy

Material changes are communicated at least 30 days in advance via email and a prominent notice on the Platform.

16. Contact

Rolaxit Innovation SRL
Str. Știubei 38, Sector 3, București, România
CUI 42351163, J40/3171/2020
Privacy contact: [email protected]
General: [email protected]
Web: www.alvotrix.com

AlvoTriX AlvoTriX

The guardian that never sleeps, never blinks, never leaves.

AlvoTriX is not a medical device and does not provide clinical diagnoses. In any life-threatening situation, contact emergency services immediately.

Platform
The 10 Modules Core & Gateway Apps For Institutions FAQ
Legal
Privacy Policy Terms of Service GDPR & Data Protection Disclaimer Refund Policy Legal Notice Contact Delete My Account
© 2026 AlvoTriX. All rights reserved.
Language:
English