SafeguardMDM ("we", "us", "our") is committed to protecting the privacy of our users and the individuals whose devices are managed through our platform. This Privacy Policy explains what data we collect, how we use it, how it is stored, and your rights regarding that data.
1. Data We Collect
1.1 Account Data
When you create an account, we collect:
- Email address and display name
- Account type (parent, caregiver, or admin)
- Authentication credentials (securely hashed, never stored in plain text)
- Verification tier and identity verification documents (if applicable)
1.2 Device Monitoring Data
When devices are enrolled in SafeguardMDM, we collect the following data from monitored devices:
1.3 Communication Data
If messaging features are enabled between parent and child devices, we store message content to facilitate delivery. Messages are encrypted in transit and at rest.
1.4 Abuse Report Data
Abuse reports submitted through the platform are stored in an isolated, access-restricted collection. This data is never visible to the account holder under investigation and is only accessible by authorized abuse review administrators.
2. How Data Is Stored
- Cloud Infrastructure: All data is stored in Google Firebase (Firestore and Firebase Storage) with server-side encryption at rest
- Encryption in Transit: All data transmitted between devices and our servers uses TLS 1.2 or higher
- Encryption at Rest: Sensitive data fields (photos, audio, location history) are encrypted using AES-256 before storage
- Access Controls: Firestore security rules enforce strict role-based access. Parents can only access data for their own enrolled devices
- Abuse Data Isolation: Abuse reports are stored in a separate Firestore collection with dedicated security rules that prevent access by regular users, including the reported account holder
3. Who Can Access Your Data
- Account Holder (Parent/Caregiver): Full access to monitoring data for their enrolled devices only
- Monitored Individuals: Can view that monitoring is active; cannot access collected data
- SafeguardMDM Administrators: Access limited to abuse review, technical support, and system maintenance
- Law Enforcement: Only in response to valid legal process (subpoena, court order, or warrant)
- Third Parties: We do not sell, rent, or share personal data with third parties for marketing purposes
4. Data Retention and Deletion
We retain data only as long as necessary to provide the Service:
- Photos and audio recordings are automatically deleted after 72 hours
- Location and usage data follow configurable retention periods (default 90 days)
- Account data is retained until the account is deleted
- Upon account deletion, all associated monitoring data is permanently removed within 30 days
- Abuse report records may be retained for up to 3 years for legal compliance
5. Your Rights (GDPR and Global Privacy)
If you reside in the European Economic Area, United Kingdom, or other jurisdictions with applicable privacy laws, you have the following rights:
- Right of Access: Request a copy of all personal data we hold about you
- Right to Rectification: Request correction of inaccurate personal data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Data Portability: Request an export of your data in a machine-readable format (JSON)
- Right to Restrict Processing: Request that we limit how we use your data
- Right to Object: Object to data processing based on legitimate interests
- Right to Withdraw Consent: Withdraw previously given consent at any time
To exercise any of these rights, use the Export Data or Delete Account options in your dashboard settings, or contact our Data Protection Officer at the address below.
6. Children's Privacy (COPPA Compliance)
- Children cannot create SafeguardMDM accounts; only parents/guardians can enroll devices
- The child app displays a persistent notification that monitoring is active
- Children have access to an abuse reporting feature that is fully isolated from the parent account
- We do not use children's data for advertising, profiling, or any purpose beyond parental monitoring
- Parents can review and delete all collected data for their children at any time through the dashboard
7. Elder Care Data
For elder care accounts (caregiver monitoring elderly dependents):
- Monitoring requires documented consent from the elder or their legal representative
- Elder care data receives the same encryption and access controls as child monitoring data
- Location tracking for elder care includes additional safety features such as geofence alerts and SOS capabilities
- Health-related data (medication reminders, emergency contacts) is stored with heightened access restrictions
- Caregivers can share limited monitoring access with authorized healthcare providers
8. Abuse Report Data Isolation
- Abuse reports are assigned unique case IDs accessible only to the reporter
- Reporter identity is protected and never disclosed to the reported account holder
- Abuse metadata is stored in a dedicated Firestore collection with strict security rules
- Report status updates are available only via the case ID lookup system
9. Cookies and Local Storage
The SafeguardMDM web dashboard uses:
- Essential Cookies: Session authentication and locale preferences (always active)
- Preference Storage: Language and theme preferences stored in localStorage
- No Tracking Cookies: We do not use third-party tracking, advertising, or analytics cookies
For more details, see the cookie consent banner on the dashboard.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and a prominent notice on the dashboard at least 14 days before taking effect. The "Last Updated" date at the top of this page reflects the most recent revision.
11. Contact Us
Data Protection Officer
Email: dpo@safeguardmdm.it
Subject Rights Requests: privacy@safeguardmdm.it
General Support: support@safeguardmdm.com
Italian Supervisory Authority: Garante per la Protezione dei Dati Personali
Abuse Reports: Submit an Abuse Report