This policy explains what personal data the Xibernetix platform collects, why we collect it, how long we keep it, and the choices you have. It covers the Xibernetix website and the Xibernetix Android application, which share the same backend.
The service is operated by TODO , TODO ("Xibernetix", "we", "us"). We are the data controller for the data described below.
1. Who uses this service
Xibernetix is a business-to-business platform. Accounts are held by Makers (organisations that manufacture and enrol devices) and Operators (people authorised by a Maker to work with those devices and their NFC tags). We do not offer consumer accounts, and the service is not directed at children.
2. What we collect
2.1 Account information
You provide this when a Maker or Operator account is created:
- Name
- Phone number
- Email address
- City and country
- A password, which we store only as a salted one-way hash — never in plain text
- An internal Maker ID (MID) or Operator ID (OID) that we generate
- Timestamps for when the record was created, last modified, and last used, and which account performed those actions
2.2 Passkey (WebAuthn) credentials
When you register a passkey, your device generates a key pair. The private key never leaves your device, and we never receive it. We also never receive your fingerprint, face scan, PIN, or any other biometric data — your device verifies you locally and only tells us that verification succeeded.
What we do store for each passkey:
- The credential ID and the public key
- The credential type and the signature counter
- Whether user verification was performed, and whether the credential is backup-eligible or backed up
- The transports the authenticator reported (for example USB, NFC, internal)
- The attestation object and attestation client data returned by your authenticator
- The relying-party identifier and a human-readable label for the credential
- Creation, modification, and last-used timestamps
2.3 Device and browser information
Passkeys are scoped to a single browser or app installation, so we need a stable way to tell your installations apart. We store:
-
An installation identifier (
mobileDeviceId). In a browser this is generated once and kept in your browser'slocalStorage. It is derived from your user-agent string, language, reported CPU core count, reported device memory, screen width, height and colour depth, and timezone offset, combined with a random value. The random component means the identifier is specific to that one installation and is not a portable fingerprint of you across sites. -
Device description (
mobileDeviceInfo): user-agent string, language, platform, browser vendor, and screen width and height.
Clearing your browser storage or reinstalling the app resets the installation identifier. Doing so means the passkeys tied to the old installation are no longer matched to it, and you will need to register a new passkey.
2.4 Operational data you enter
In the course of using the platform you record data about hardware rather than about people — device identifiers (DIDs), device metadata, NFC tag identifiers, serial numbers, vendor codes, counters, and any custom attributes you attach. This is business data belonging to your organisation. Where you choose to put personal data into a free-text attribute, you are responsible for that content and for having a lawful basis to store it.
2.5 Server logs and diagnostics
Our servers produce operational logs and performance metrics covering request paths, response codes, timings, and error traces. These may incidentally include IP addresses and user-agent strings. They are used to keep the service running and secure, not to profile you.
3. What we do not do
- We do not sell or rent personal data.
- We do not share personal data with advertisers or data brokers.
- We do not run advertising networks, analytics SDKs, or third-party tracking pixels on this site or in the Android app.
- We do not use your data to build advertising profiles or to make automated decisions with legal effects.
4. Cookies and local storage
| Name | Type | Purpose |
|---|---|---|
authToken |
Cookie | Keeps you signed in after authentication. Required for the service to work. |
passkeyOptionsToken |
Cookie | Short-lived. Ties a single passkey registration or login attempt to the challenge issued for it, then expires. |
JSESSIONID |
Cookie | Standard server session cookie used during sign-in. |
xibernetixBrowserInstallationId |
Local storage | Holds the installation identifier described in section 2.3 so your passkeys stay matched to this browser. |
All of these are strictly necessary for authentication. We set no advertising or analytics cookies, so there is no consent banner to dismiss.
5. Why we may process your data
- To provide the service — creating accounts, authenticating you, and binding passkeys to the correct account and installation. This is necessary to perform our contract with you or your organisation.
- To keep the service secure — detecting credential reuse, replay, and abuse. This is our legitimate interest in protecting the platform and its users.
- To meet legal obligations — where we are required to retain records.
6. Who we share data with
We share personal data only with service providers who process it on our behalf and under contract, and only as far as needed to run the platform:
- Our database and cloud hosting providers (TODO).
- Google Play, when you install the Android application. Google's handling of that install is governed by Google's own privacy policy, not this one.
We may also disclose data where legally compelled, or as part of a merger or acquisition, in which case we will notify affected account holders.
International transfers: TODO.
7. How long we keep it
- Account records — for as long as the account is active, and afterwards for TODO to handle disputes and meet legal obligations.
- Passkey credentials — until you or your administrator delete the passkey, or the account is closed.
- Server logs and metrics — TODO .
8. How we protect it
- All traffic to the platform is served over HTTPS.
- Authentication uses WebAuthn passkeys, which are resistant to phishing and credential reuse. Passwords, where used, are stored only as salted one-way hashes.
- Access to production data is restricted to personnel who need it.
No system is perfectly secure. If a breach affects your personal data, we will notify you and any relevant regulator as required by law.
9. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, obtain a portable copy, restrict or object to certain processing, and withdraw consent where we rely on it. You also have the right to complain to your local data protection authority.
To exercise any of these, contact us at the address in section 11. We will respond within the period required by applicable law. We may ask you to verify your identity before we act, so that we do not disclose your data to someone else.
If you hold an Operator account created by a Maker, that Maker administers your account. We will forward requests to them where they are the appropriate party.
10. Deleting your data
You can remove an individual passkey at any time from your account page; that deletes the stored public key and its associated device information. To close an account and delete the associated personal data, contact us using section 11 — or, for Operator accounts, ask your Maker administrator. We will delete or anonymise the data except where we are required to retain it.
11. Contact us
Email: TODO
Post: TODO
12. Changes to this policy
We may update this policy as the service changes. The "last updated" date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will notify account holders by email or through the application before it takes effect.