Pillarix Platform Privacy Notice

Last updated: 11 August 2026

1. Scope of This Notice

This Platform Privacy Notice explains how Pillarix ("Pillarix", "we", "us", or "our") handles personal data when Pillarix Hub and its connected services are used.

It applies to Pillarix Hub for iOS and Android, related Apple Watch features, the web dashboard, Pillarix APIs and real-time services, public Digital Product Passport pages, ownership-verification flows, and optional modules enabled by a customer organisation.

The separate Website Privacy Policy applies to the pillarix.io marketing website, demo requests, website analytics, reCAPTCHA, and website cookies.

2. Who We Are and Our Role

Pillarix operates Pillarix Hub. You can contact us about privacy at contact@pillarix.io.

A customer organisation normally decides why and how personal data in its Pillarix tenant is used. For that data, the customer organisation normally acts as controller and Pillarix processes the data on its instructions.

Pillarix generally acts as controller for data processed for our own service relationship and purposes, including authentication, direct support, service security, abuse prevention, operational telemetry, and legal compliance. The exact roles may depend on the deployment and processing context.

3. Personal Data We Process

The data available to Pillarix depends on the modules enabled by the customer organisation, the user's role and permissions, and the features the user chooses to use. Not every category below is processed for every user.

Account, identity, and profile data

This may include user and identity-provider identifiers, name, username, email address, phone numbers, profile photo, language, time zone, address, job title, company, department, manager details, organisation memberships, roles, permissions, and assigned stores or zones.

Operational and customer content

This may include organisations, products, Digital Product Passports, assets, devices, stores, locations, zones, alerts, access credentials and events, tasks, tickets, comments, messages, attachments, service records, product documents, certificates, technical information, and lifecycle information.

Visitor and access data

Where the visitor or access module is enabled, data may include visitor and host names and contact details, company, visit purpose and date, access areas, check-in events, NDA acceptance, visitor photos, and access or device events.

Identity-document and attachment data

Where an authorised user uses identity-document or attachment features, data may include a document or passport number, nationality, date of birth, gender, expiry date, issuing country, MRZ data, an identity-document portrait, invoices, receipts, purchase orders, service orders, site photos, and extracted document metadata.

Device capabilities and sensor-related data

Depending on the platform and feature, the app may access camera or photo content, QR and barcode values, NFC tags or compatible identity-document chips, foreground precise or approximate location, Bluetooth connectivity information, and motion or orientation readings. Some of this processing takes place only on the device and is not uploaded unless the user saves, submits, or shares the resulting data through Pillarix.

Technical and diagnostic data

This may include IP address, request time, API route, device and app information, identifiers needed for authentication or real-time connections, error events, security events, and diagnostic logs. Mobile debug logs are kept locally by default and may be shared with Pillarix if the user chooses to export them for support.

4. Sources of Personal Data

  • The user, when signing in, editing a profile, capturing or selecting content, scanning a tag or document, or submitting operational information
  • The user's customer organisation, its administrators, hosts, colleagues, devices, and connected business systems
  • Public DPP visitors and people using optional ownership-verification or service-request flows
  • The app, device, APIs, hosting infrastructure, and security or diagnostic systems when the service is used

5. How We Use Personal Data

  • To authenticate users and provide the platform and modules authorised by their organisation
  • To save and synchronise customer content and perform product, DPP, asset, access, visitor, task, ticket, notification, and device workflows
  • To provide QR, barcode, NFC, identity-document, attachment, and AI-assisted document-extraction features requested by authorised users
  • To send requested verification codes and enabled operational notifications
  • To provide support, diagnose errors, secure the service, prevent abuse, and maintain performance and availability
  • To comply with applicable law, respond to lawful requests, and enforce agreements

Where Pillarix acts as controller, the legal basis depends on the purpose and context. Where Pillarix acts as processor, the customer organisation determines the applicable legal basis and provides relevant notices to its users and other data subjects.

  • Performance of a contract or steps requested before entering into a contract, where processing is necessary to provide an account or requested service
  • Our legitimate interests in operating, supporting, securing, and improving the reliability of Pillarix, provided those interests are not overridden by individual rights
  • Consent, where applicable, including for an optional feature that requires consent; device permissions are also controlled through the operating system
  • Compliance with a legal obligation

7. Mobile Apps and Device Features

Protected device capabilities are requested only when a related feature is used. A user can revoke permissions through the device settings, although the related feature may then stop working.

iOS and Apple Watch

Depending on enabled features, the iOS app may request access to the camera or selected photos, NFC, Bluetooth, foreground location, and motion or orientation data. Authentication tokens may be stored in the iOS Keychain.

MRZ text recognition from an identity-document photo uses Apple's Vision framework on the device. Recognised fields or a captured visitor photo may later be saved to the organisation's Pillarix tenant when the user completes the workflow.

When Apple Watch features are used, selected profile, organisation, store, zone, task, access, and workflow data may be sent to the paired watch.

Android

Depending on enabled features, the Android app may use network access, NFC, foreground precise or approximate location, camera capture, and user-selected files or photos.

Android MRZ text recognition uses Google ML Kit on the device. Google states that ML Kit does not send the input image or recognised text to Google. The ML Kit SDK may send device and app information, per-installation identifiers, performance data, API configuration, usage events, and error codes to Google for diagnostics and usage analytics.

On-device processing

Location and motion readings used by the reviewed hardware-test flows are processed on the device and are not automatically transmitted to Pillarix. Data that a user intentionally saves, submits, or shares through an enabled workflow may be transmitted to the organisation's Pillarix tenant.

8. AI-Assisted Document Processing

Where the visitor-document module and its Azure configuration are enabled, a document image uploaded by an authorised user may be sent to Azure OpenAI to classify the document and extract structured metadata such as document type, vendor, dates, amounts, or notes.

The extracted fields assist data entry and can be reviewed or corrected by an authorised user. This extraction service returns structured metadata and does not itself make decisions that produce legal or similarly significant effects about a person.

9. Public Digital Product Passports

A public Digital Product Passport can be viewed without a Pillarix account. The publishing customer chooses the product information made public. Pillarix processes IP address and technical request data to deliver and protect the page.

If optional ownership verification is used, Pillarix processes the phone number provided by the user, sends a one-time SMS code through Twilio, and may store authorised owner or contact details and lifecycle information. Public views may display masked contact information rather than the full value.

10. Sharing and Service Providers

Pillarix does not sell personal data and does not use platform data for third-party advertising or cross-app advertising tracking.

  • The user's customer organisation and its authorised users or administrators, according to roles and permissions
  • Microsoft Azure services used for hosting, storage, authentication, real-time messaging, diagnostics, and optional AI document processing, including Azure AD B2C, Cosmos DB, Blob Storage, SignalR, Application Insights, and Azure OpenAI where enabled
  • Twilio for SMS verification and enabled notifications
  • Google ML Kit for Android SDK diagnostic and usage metrics; MRZ image and text recognition remain on-device
  • Apple and Google for their own app distribution, operating-system, device, and store services under their own privacy terms
  • Professional advisers, a successor to the service, or public authorities where reasonably necessary for a lawful transaction, legal obligation, or valid request

11. International Transfers

Pillarix and its service providers may process personal data in countries outside the user's country or the European Economic Area. Where GDPR applies, transfers are protected by an applicable adequacy decision, contractual safeguards such as the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism.

12. Retention and Deletion

Customer-controlled tenant data is retained according to the customer organisation's configuration, agreement, instructions, and applicable law. Pillarix-controlled account and operational data is retained while needed to provide and secure the service and for a limited period afterward where necessary for support, security, backup recovery, disputes, or legal obligations.

One-time verification codes and short-lived tokens expire automatically. Deleted data may remain in backups or security logs until normal rotation, and some information may be retained where required by law.

For organisation-controlled data, users should first contact their organisation. Requests concerning Pillarix-controlled data or requests for assistance can be sent to contact@pillarix.io.

13. Rights and Choices

Rights depend on the user's location, the processing context, and whether Pillarix or the customer organisation is the controller. Subject to applicable conditions and exceptions, a person may have the following choices and rights:

  • Update profile or operational information where the user's permissions allow
  • Revoke camera, photo, NFC, Bluetooth, location, or other protected permissions in the device settings
  • Request access, correction, deletion, restriction, objection, or portability where applicable
  • Withdraw consent where processing relies on consent, without affecting earlier lawful processing
  • Lodge a complaint with an applicable data protection supervisory authority

14. Security

Pillarix uses technical and organisational measures designed to protect personal data, including encryption in transit, access controls, tenant-aware authorisation, secure token storage on supported devices, monitoring, and reputable cloud infrastructure.

No transmission or storage method is completely secure, so Pillarix cannot guarantee absolute security.

15. Children

Pillarix Hub is an organisation-managed business and operations platform and is not directed to children. An App Store age rating describes content suitability and does not change the intended business audience.

16. Changes to This Notice

Pillarix may update this notice when the platform, service providers, or legal requirements change. The updated version will be posted on this page with a revised last-updated date. Material changes may also be communicated through the platform or the relevant customer organisation where appropriate.

17. Contact

For questions, privacy requests, or concerns about this notice, contact Pillarix at contact@pillarix.io. For data controlled by a customer organisation, contacting that organisation first is usually the fastest way to exercise a right.