1. Scope and roles
This policy applies to HALISI websites and applications. HALISI acts as the controller for account, security and product-operation data. When an organization uses HALISI for its own work, that organization may be the controller of the records its members submit and HALISI may act as its processor.
2. Data we collect
We collect account and profile details, language preferences, organization membership, Thing identifiers and attributes, event descriptions, timestamps, custody requests and responses, evidence photos, file metadata, review decisions, device diagnostics and security logs. If a feature requests location or camera access, the device asks for permission first.
3. How we use data
We use data to authenticate users, create and display records, preserve event history, coordinate handovers, sync offline entries, secure the service, investigate abuse, provide support and improve reliability. We process data where needed to provide the service, protect legitimate interests, meet legal duties or act with consent where required.
4. Evidence and AI
Evidence photos may include people, property, device details or location metadata. Users must have a lawful basis and appropriate permission to upload them. When a user requests an AI summary, HALISI sends the description and a short-lived private link to the photo to our AI processing provider. The output may be incomplete or wrong. It is labelled and reviewable, and the original event and evidence remain authoritative. HALISI does not use this feature to make automated decisions about legal rights.
5. Sharing
Records are shared with people who are entitled to access the related Thing, including owners, custodians, invited counterparties and authorized organization members. A Thing's permitted history may travel to a new custodian because continuity is central to provenance. We also use contracted providers for hosting, storage, authentication, security and AI processing. We do not sell personal data.
6. International transfers
HALISI and its providers may process data in countries other than the user's own. Where required, we use contractual safeguards and other lawful transfer mechanisms appropriate to the countries involved.
7. Retention
We retain account information while the account is active and as needed for security, legal and operational purposes. Shared event history may need to remain after one account closes to preserve another user's legitimate record. Where full deletion would damage that chain, we may restrict or anonymize personal details instead, subject to applicable law.
8. Rights and choices
Depending on location, users may request access, correction, export, deletion, restriction or objection, and may withdraw consent. We verify requests and may retain limited information where law or the rights of other record participants require it. Users may complain to their local data protection authority.
9. Children
HALISI is not intended for children to hold accounts. A guardian or organization that records an asset associated with a child remains responsible for the account and must avoid unnecessary personal details about the child.
Questions
Contact our privacy and legal team through the contact page. These terms are an international baseline and should be reviewed by qualified local counsel before HALISI launches in a specific country.
