Alpik Forwarder — Privacy Policy
Effective date: 2026-06-24
Version: 1.0
1. Introduction
This Privacy Policy describes how Alpik ("we", "us", "our") collects, uses and shares personal data when you use the Alpik Forwarder mobile application ("the App") on iOS or Android.
We are committed to processing personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national data protection legislation.
2. Data Controller
| Company | Alpik |
| Contact | privacy@alpik.fr |
3. Data Collected
3.1 BLE scan data
While the App is running (including in the background), it continuously scans for Bluetooth Low Energy (BLE) advertisements. For each detected Alpik device it collects:
- Device identifier — the unique ID broadcast by the Alpik device
- Payload — the raw data packet broadcast by the Alpik device
- RSSI — received signal strength indicator (approximate proximity)
- Timestamp — the date and time the advertisement was received
This data is forwarded to the Alpik backend immediately and is not stored permanently on your device (beyond a short-lived retry buffer of up to 100 packets).
3.2 Network data
When the App sends payloads to the backend, the following data is incidentally processed:
- IP address of your device
- HTTPS request metadata (timestamp, device model, App version, OS version)
4. Purpose and Legal Basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Forward BLE device data to the Alpik backend for IoT processing | BLE scan data | Performance of contract (Art. 6(1)(b) GDPR) |
| Maintain service reliability and security | Network data, diagnostic data | Legitimate interest (Art. 6(1)(f) GDPR) |
5. Data Retention
| Data | Retention |
|---|---|
| BLE payloads (retry buffer) | Maximum 24 hours on-device; deleted after successful forwarding or session end |
| Forwarded payload data on the backend | As defined by your organisation's Alpik data retention policy |
| Network / request logs on the backend | Maximum 7 days |
You can clear all on-device data at any time via Settings → Account → Sign out (clears authentication data and cached payloads) or by uninstalling the App.
6. Data Sharing and Sub-Processors
We do not sell your personal data. We share data with the following sub-processors solely to operate the service:
| Sub-processor | Role | Location |
|---|---|---|
| Scaleway SAS | Cloud infrastructure (servers, storage) | Paris, France (EU) |
All data is stored and processed within the European Union.
We may also disclose personal data if required by law, court order, or to protect the rights and safety of Alpik or its users.
7. International Transfers
All personal data is processed within the European Economic Area (EEA). No transfers outside the EEA take place.
8. Your Rights
Under GDPR, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Request correction of inaccurate data |
| Erasure (Art. 17) | Request deletion of your data where it is no longer necessary |
| Restriction (Art. 18) | Request that we restrict processing in certain circumstances |
| Portability (Art. 20) | Receive your data in a structured, machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interests |
To exercise any of these rights, contact us at privacy@alpik.fr. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority (in France: CNIL).
9. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. All data transmitted between the App and the backend is encrypted using TLS 1.2 or higher.
10. Children
The Alpik Forwarder does not collect any personal data about the person using the app. It collects only the data broadcast by Alpik devices (BLE payloads) and the minimum network data required to forward those payloads to the backend. No name, age, contacts, precise location, or other personal identifying information about the user is collected.
The app may be used in safety contexts involving children — for example, to forward data from an Alpik tracking device carried by a child. In such cases, the data processed by the app relates to the Alpik device, not to the child personally.
11. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by updating the effective date above. Continued use of the App after changes are posted constitutes acceptance of the revised policy.
12. Contact
For any questions regarding this Privacy Policy or to exercise your data subject rights:
- Email: privacy@alpik.fr
This document was last reviewed on 2026-06-24.