1. Who we are and scope
UVION (“UVION”, “we”, “us”, or “our”) provides Uvion T-max Dashboard and the related T-Max Cloud Platform (the “Service”). This Privacy Policy applies to personal information processed through the public website, dashboard, authentication flows, support interactions, and connected T-Max operations.
Where your employer, location owner, or another organisation provides your access, that organisation may also control how your account and operational information are used. You should contact its administrator for organisation-specific questions.
2. Information we collect
Depending on how you use the Service, we process:
- Account information: name, email address, profile image, authentication provider, account identifiers, and assigned organisation or location.
- Authentication and security data: session information, login times, security events, IP address, browser or device information, and necessary authentication cookies.
- Installation and operational data: device identifiers, Agent version and connectivity, bed names and configuration, status, timers, commands, command outcomes, activity history, licensing state, and diagnostic information.
- Support information: messages, contact details, attachments, and troubleshooting information you provide.
- Service logs: requests, errors, performance, audit events, and usage needed to operate, secure, and improve the Service.
We do not use the dashboard to intentionally collect special-category personal data, payment card numbers, or the identity of end customers using physical equipment. Please do not submit information that is not needed for operating or supporting your installation.
3. Google sign-in data
If you choose “Continue with Google”, we request only the standard openid, email, and profile permissions. Google may provide your Google Account identifier, name, email address, profile image, and email verification status. We use this information to authenticate you, create or link your T-Max account, display your profile, and protect the Service.
We do not request access to Gmail, Google Drive, contacts, calendars, or other Google content. We do not sell Google user data, use it for advertising, or allow humans to read it except when necessary for security or support, with your permission, or as required by law.
You can revoke the Service’s access from your Google Account connections. Revocation stops future Google sign-in access but does not automatically delete the T-Max account or information we must retain. See section 9 for deletion requests.
4. How we use information
We use personal information to:
- authenticate users and manage accounts, sessions, permissions, and licences;
- provide device onboarding, monitoring, configuration, command, history, and support features;
- keep tenant data isolated and detect, investigate, and prevent abuse or security incidents;
- maintain, troubleshoot, measure, and improve reliability and user experience;
- send essential account, security, operational, and service communications; and
- comply with law, enforce our Terms of Service, and establish or defend legal claims.
5. Legal bases
Where UK or European data protection law applies, we process information as necessary to perform a contract with you or the customer organisation, pursue legitimate interests in operating and securing the Service, comply with legal obligations, and, where required, based on consent. You may withdraw consent at any time, although this does not affect prior lawful processing.
7. Retention and deletion
We keep account information while the account is active and for a reasonable period afterwards to support reactivation, security, dispute resolution, and legal obligations. Operational and audit records may be retained for the customer’s configured history period and longer where required for security, licensing, legal claims, or regulatory compliance. Backup copies are deleted on their normal rotation schedule.
When information is no longer needed, we delete it or de-identify it. Disconnecting Google does not itself delete your T-Max account. You may request deletion as described in section 9; some records may be retained where law or legitimate security and audit requirements allow.
8. Security and international transfers
We use technical and organisational safeguards appropriate to the information processed, including encrypted transport, access controls, tenant isolation, short-lived credentials, audit logging, and restricted administrative access. No system is completely secure, so you must also protect your account and promptly report suspected compromise.
Our providers may process information in countries other than yours. Where required, we use recognised safeguards for international transfers, such as adequacy decisions or approved contractual clauses.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to complain to a data protection authority. You can update some profile information in the dashboard. If an organisation manages your account, we may direct the request to that organisation.
To make a privacy request, email [email protected]. We may need to verify your identity and authority before completing a request. UK users may also complain to the Information Commissioner’s Office.
11. Children
The Service is intended for authorised business users and is not directed to children. We do not knowingly collect personal information from children through the Service. Contact us if you believe a child has provided personal information.
12. Changes and contact
We may update this policy as the Service, law, or our practices change. We will publish the updated version here, revise the effective date, and provide additional notice where required.
For questions or requests, contact [email protected] or use the Support area after signing in.