1. Who this policy covers
Creatinnos is a configurable business-operations platform. Each customer organization operates its own instance of the platform and decides what data is stored in it and who may access it. For the business records held in an instance, your organization is the data controller and Creatinnos Software Solution acts as a data processor on that organization's instructions. For a limited set of information described below (for example, account and technical data needed to run and secure the service), Creatinnos Software Solution is the controller.
The Creatinnos Mobile app is a companion client for the same platform. Accounts are created and managed by your organization's administrator; the app has no public sign-up. You sign in with credentials your organization issues to you.
2. Information we process
Account and sign-in
- Your username or email address and password, submitted to authenticate you. The password is used to sign in and is not stored on your device.
- A one-time verification code if your organization enables two-factor authentication.
- Your "default login" preference when your account is linked to more than one profile.
- A session token returned after sign-in, stored encrypted on your device using the platform keystore (Android Keystore / iOS Keychain) and available only while the device is unlocked. It is removed when you log out or uninstall the app.
Operational content
- The business records you open, create, or edit through screens your organization has configured — for example customers, appointments, job cards, tickets, invoices, inventory movements, and their attachments and comments. This content belongs to and is controlled by your organization.
- Images you capture with the camera or select from your photo library and choose to attach to a record. Attached images are uploaded to your organization's instance.
- Barcode and QR values scanned through the app. These are decoded on the device and sent to the server only as a lookup term for the record you are searching.
Notifications
- A device push token, registered with your organization's instance so it can deliver workflow and record notifications. Push delivery uses Expo's push service and Google Firebase Cloud Messaging. Firebase issues an app-instance identifier that is required for messaging to function.
Technical and diagnostic information
- Information incidental to each request to your organization's server — app version, device model and operating-system version, language, IP address (in server logs), and timestamps — used to operate, secure, and troubleshoot the service.
- The platform keeps an audit trail of changes to records (who changed what and when) as a security and accountability feature controlled by your organization.
We do not use advertising SDKs or third-party analytics/tracking SDKs in the app, and we do not collect location, contacts, SMS, call logs, or health data.
3. Device permissions the app requests
Each permission is requested only when a feature needs it, and on Android/iOS you can grant or decline it at that point and change it later in system settings.
| Permission | Why it is used |
|---|---|
| Camera | Scan configured barcodes/QR codes and capture photos to attach to records. |
| Photos / media selection | Let you pick an existing image to attach to a record. The app uses the system photo picker and does not request broad access to your gallery. |
| Notifications | Show workflow and record alerts sent by your organization's instance. |
| Microphone | Declared by the camera component. The app does not record audio. |
| Internet / network state | Connect securely to your organization's server. |
| Biometric / device keystore | Protect the encrypted on-device session. |
| Vibrate, run after restart, wake lock | Support reliable delivery and display of notifications only. |
4. How we use the information
- Authenticate you and keep you signed in on your device.
- Show, create, and update the records your role permits, applying the organization, branch, and role access rules that are enforced on the server.
- Attach and display images on records.
- Deliver operational notifications you or your organization have enabled.
- Maintain security, prevent abuse, diagnose problems, and keep the audit trail.
Where data-protection law applies, our legal bases are performance of the contract with your organization, our legitimate interests in operating and securing the service, and — for content in your organization's instance — that organization's instructions as controller.
5. When information is shared
- Within your organization. Administrators and other authorized users of your organization's instance can see data according to its configured access rules.
- Service providers acting for us. Cloud hosting and database infrastructure for the backend; Google Firebase Cloud Messaging and the Expo push service for notification delivery; and any email, SMS, or messaging gateway your organization configures for notifications.
- Legal and safety. Where required by law, or to protect the rights, safety, and security of users, the public, or Creatinnos Software Solution.
- Business transfer. In connection with a merger, acquisition, or sale of assets, subject to this policy.
We do not sell personal information and we do not share it for advertising or cross-context behavioural targeting.
6. International processing
Information may be processed in the country where your organization's instance is hosted and where the messaging providers operate. Where required, we rely on appropriate safeguards for cross-border transfers.
7. How long it is kept
- On your device: the session token until you log out or uninstall; cached data cleared by logging out.
- On the server: account and business records are retained while your organization's account is active and according to that organization's own retention settings, after which they are deleted or anonymized on our regular cycle, including backups.
- Server logs and audit records are kept for a limited period for security and accountability.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal data, and to object to certain processing.
- Records in your organization's instance: contact your organization's administrator, who controls that data. You can also email us at creatinnos@gmail.com and we will assist the organization in responding.
- Account deletion / data deletion: because your account is created and managed by your organization, ask your administrator to deactivate or delete it. You may also email creatinnos@gmail.com with the subject "Data deletion request" and the account email address; we will delete the personal data we hold as controller and forward the request to the controlling organization. We aim to respond within 30 days.
- Notifications: turn them off in your device settings, or by logging out.
- Camera and photo access: decline or revoke it in device settings; the related features will be unavailable until it is granted.
9. Security
- Traffic between the app and the server is encrypted with TLS. Production builds of the app refuse to connect to a non-HTTPS server.
- The on-device session is stored in the platform keystore, not in plain storage.
- Passwords are stored using industry-standard one-way hashing; sign-in attempts are rate-limited.
- Access to records is enforced on the server by organization, branch, and role, not only hidden in the interface.
No method of transmission or storage is completely secure, but we work to protect information using measures appropriate to its sensitivity.
10. Children
Creatinnos is a workplace tool and is not directed to children. Do not use it unless you are at least 16 years old (or the age of majority in your jurisdiction) and an authorized user of an organization.
11. Changes to this policy
We may update this policy from time to time. We will change the "Last updated" date above and, for material changes, provide a notice through the service. Continued use after an update means you accept the revised policy.
12. How to contact us
Creatinnos Software Solution
Email: creatinnos@gmail.com