Privacy Policy
Last updated: 1 June 2025
GDPR COMPLIANT1. Data Controller
The data controller responsible for the processing of personal data collected through this website (thetechnicianapp.com) is:
Sapphire Oasis Consulting Group
Meydan Grandstand, 6th floor
Meydan Road, Nad Al Sheba
Dubai, UAE
Trade License No.: 2422620.01 (Dubai, UAE)
VAT: Available on request at welcome@sapphco.ae
Privacy contact: privacy@thetechnicianapp.com
This Privacy Policy explains what personal data we collect when you use this website, why we collect it, how we use it, and what rights you have in relation to that data. It applies exclusively to data collected via this website. Processing of data within The Technician App product is governed by separate Data Processing Agreements concluded with each client organisation.
2. Data We Collect
We collect personal data only through the contact and demo request form on this website. The data fields are:
| Data field | Required | Purpose |
|---|---|---|
| Full name | Yes | Personalised reply and business identification |
| Company name | Yes | Confirming B2B context and preparing relevant demo |
| Business email | Yes | Delivering response and follow-up communications |
| Country | Yes | Routing request to the relevant team and assessing language/integration needs |
| Message / context | No | Understanding your specific question or environment |
| Consent timestamp | Auto | Recording that consent was given and when (GDPR Art. 7(1)) |
| IP address | Auto | Used by our server for rate limiting and spam prevention; not retained after the session |
We do not collect: special categories of personal data (Art. 9 GDPR), payment card data, government identifiers, biometric data, location data, or data from minors. We do not operate registered user accounts on this website.
We do not use third-party tracking pixels, social media embeds, or advertising cookies that collect data about your browsing behaviour across other websites.
3. Purpose and Legal Basis of Processing
We process your personal data for one primary purpose, on one lawful basis:
3.1 Responding to your demo request or enquiry
Legal basis: Consent - GDPR Article 6(1)(a).
When you submit the contact form, you explicitly tick a consent checkbox confirming that you agree to the processing of your submitted data for the purpose of receiving a response to your request. This constitutes freely given, specific, informed, and unambiguous consent as required by GDPR Article 4(11) and Article 7.
The consent is recorded with a timestamp. You may withdraw your consent at any time by contacting us at privacy@thetechnicianapp.com. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal (Art. 7(3)).
3.2 Legitimate interest - website security and abuse prevention
Legal basis: Legitimate interest - GDPR Article 6(1)(f).
Our own web server uses submitted IP addresses for rate limiting and abuse prevention (maximum one submission per 30 seconds per session). This processing is necessary for our legitimate interest in maintaining a functional and secure contact mechanism. IP addresses are held only within the server session and are not recorded in any log files or databases.
3.3 Principles applied to all processing (Art. 5)
In all processing activities we comply with GDPR Article 5 principles:
- Lawfulness, fairness and transparency (Art. 5(1)(a)): We process data only on a clear legal basis and inform you through this policy.
- Purpose limitation (Art. 5(1)(b)): Data is collected for the specific purpose of responding to your request and is not used for unrelated purposes.
- Data minimisation (Art. 5(1)(c)): We collect only the fields necessary for the stated purpose.
- Accuracy (Art. 5(1)(d)): We process the data as submitted; you are responsible for its accuracy.
- Storage limitation (Art. 5(1)(e)): Data is deleted after 12 months (see Section 4).
- Integrity and confidentiality (Art. 5(1)(f)): Data is transmitted over TLS-encrypted connections and stored on access-controlled servers.
- Accountability (Art. 5(2)): We document our processing activities and can demonstrate compliance.
4. Data Retention
4.1 Website contact form data
Personal data collected through the contact form is retained for a maximum of 12 months from the date of submission. After this period, the data is deleted from our records, unless:
- A commercial relationship has been established, in which case data relevant to that relationship is retained for the duration of the contract plus the period required by Belgian accounting law (currently 7 years); or
- A longer retention period is required by applicable law or a legitimate legal claim.
You may request early deletion at any time by exercising your right to erasure (Section 8).
4.2 In-app data (The Technician App product)
The app does not store data permanently.
Data is retained on the device only for as long as it is necessary to complete active work orders. Upon logout, all pending work orders are synchronised to the server and the local data is removed from the device. No residual job data remains on a technician's device after a session ends.
This design minimises the risk of personal or operational data being retained on field devices beyond its operational purpose, in line with the GDPR data minimisation principle (Art. 5(1)(c)) and storage limitation principle (Art. 5(1)(e)).
5. Infrastructure Provider
We do not use a third-party form processing service. Contact form submissions are handled directly by our own PHP script running on our web server. The following hosting provider supplies the server infrastructure on which our website operates:
Hostinger International Ltd.
Role: Hosting provider (server infrastructure only — does not access form data)
Server location: European Union
Privacy policy: hostinger.com/privacy-policy
We do not sell, rent, or share your personal data with any other third parties for marketing, advertising, or commercial purposes. We do not use data brokers or data enrichment services.
6. International Data Transfers
All personal data collected through this website is stored and processed exclusively within the European Economic Area (EEA). We do not transfer personal data to third countries (outside the EEA). Our web server is hosted by Hostinger on servers located within the European Union.
If this changes in the future, we will update this policy and ensure that any transfer is protected by appropriate safeguards under GDPR Chapter V (Standard Contractual Clauses or equivalent mechanism).
7. Cookies and Analytics
7.1 Strictly necessary cookies
This website sets one strictly necessary cookie to store your selected language preference. This cookie contains no personal data and does not track you. It is set automatically and does not require consent under GDPR or the ePrivacy Directive.
It also stores your cookie consent preference so you are not shown the consent banner on repeat visits.
7.2 Analytics cookies - opt-in only
We use Google Analytics 4 (GA4) with IP anonymisation enabled (anonymize_ip: true). Analytics cookies are set only if you explicitly click "Accept all" in the cookie consent banner. If you click "Reject non-essential" or do not respond, no analytics cookies are set and no data is sent to Google's servers.
This implementation is consistent with the ruling of the Landgericht München I (LG München I, 3 O 17493/20, January 2022) on self-hosted fonts and the guidance of national DPAs including the CNIL (France) and GBA (Belgium) regarding consent-prior-to-analytics requirements.
You can change your cookie preferences at any time by clearing your browser cookies for this site and reloading the page, which will redisplay the consent banner.
7.3 No other tracking
We do not embed social media buttons, advertising pixels, LinkedIn Insight tags, Facebook Pixel, or any other third-party tracking scripts. All fonts are self-hosted - no external font CDN (including Google Fonts) is loaded, in compliance with LG München I 2022.
8. Your Rights Under GDPR
As a data subject under the General Data Protection Regulation, you have the following rights. To exercise any of them, contact us at privacy@thetechnicianapp.com. We will respond within 30 days (Art. 12(3)).
- Right of access (Art. 15): You may request confirmation of whether we hold personal data about you, and receive a copy of that data together with information about how it is processed.
- Right to rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.
- Right to erasure / "right to be forgotten" (Art. 17): You may request deletion of your personal data where it is no longer necessary for the purpose collected, where you withdraw consent, or where processing is unlawful. Exceptions apply where retention is required by law.
- Right to restriction of processing (Art. 18): You may request that we limit how we use your data while a dispute about accuracy or lawfulness is resolved.
- Right to data portability (Art. 20): Where processing is based on consent and carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format (e.g. CSV or JSON) and have it transmitted to another controller.
- Right to object (Art. 21): You may object to processing based on legitimate interest (Art. 6(1)(f)). We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent (Art. 7(3)): You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right not to be subject to solely automated decision-making (Art. 22): No automated profiling or automated decision-making that produces legal or similarly significant effects is carried out. See Section 9.
9. Automated Decision-Making and Profiling
We do not carry out automated decision-making (Art. 22 GDPR), including profiling, that produces legal effects or similarly significantly affects you. Contact form data is reviewed and responded to by a human member of our team.
10. Data Security
We implement technical and organisational measures appropriate to the risk to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access (Art. 32 GDPR). These measures include:
- TLS encryption in transit: All data transmitted to and from this website is encrypted via HTTPS/TLS.
- EU-hosted infrastructure: All data is stored on servers located within the European Union.
- Access control: Contact form submission data is accessible only to authorised personnel with a business need.
- Hosting security: Hostinger applies industry-standard security measures to the server infrastructure, including firewall protection and encrypted storage.
- No plaintext data storage: We do not store raw contact submissions in unencrypted flat files or spreadsheets.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Art. 33) and you directly where required (Art. 34).
11. Children's Data
This website is directed exclusively at business professionals. We do not knowingly collect personal data from individuals under the age of 16. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@thetechnicianapp.com and we will delete it without undue delay.
12. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our data processing practices, applicable law, or supervisory authority guidance. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we may also display a notice on the website.
We encourage you to review this page periodically. Continued use of the website after a policy update constitutes acknowledgement of the updated policy.
13. Contact and Right to Lodge a Complaint
For any questions about this Privacy Policy, to exercise your GDPR rights, or to report a concern about our data processing practices, contact our privacy team:
Email: privacy@thetechnicianapp.com
Postal: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, UAE
You also have the right to lodge a complaint with the data protection supervisory authority in your country of residence or the country in which the alleged infringement occurred (Art. 77 GDPR):
- Belgium - Gegevensbeschermingsautoriteit (GBA):
Drukpersstraat 35, 1000 Brussel | dataprotectionauthority.be | contact@apd-gba.be - France - Commission nationale de l'informatique et des libertés (CNIL):
3 Place de Fontenoy, 75007 Paris | cnil.fr - Germany - Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI):
Graurheindorfer Str. 153, 53117 Bonn | bfdi.bund.de - Netherlands - Autoriteit Persoonsgegevens (AP):
Hoge Nieuwstraat 8, 2514 EL Den Haag | autoriteitpersoonsgegevens.nl