PRIVACY POLICY

Last Updated: June 15, 2026

 

1. INTRODUCTION

ALTU ALGORITMO, LDA, a company incorporated under the laws of Portugal, with registered offices at Avenida Infante D. Henrique, 26, 1149-096 Lisboa, Portugal, NIF 518506622 (“MiaSentry”, “we”, “our” or “us”), is committed to protecting the privacy and security of Personal Data entrusted to us.

This Privacy Policy explains how MiaSentry collects, uses, stores, transfers, discloses and otherwise processes Personal Data in connection with:

  • The MiaSentry website located at https://miasentry.com;
  • Mobile applications operated by MiaSentry;
  • Cloud-based software platforms operated by MiaSentry;
  • Water monitoring, leak detection and water management solutions;
  • Connected hardware devices and sensors;
  • Customer support, onboarding and account management services;
  • Any related products, applications, software, integrations or services offered by MiaSentry (collectively, the “Services”).

This Privacy Policy is intended to satisfy the transparency requirements of Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), together with applicable Portuguese data protection legislation and other applicable privacy laws.

By accessing or using the Services, you acknowledge that your Personal Data may be processed in accordance with this Privacy Policy.

 

2. DEFINITIONS

For the purposes of this Privacy Policy:

“Personal Data”

Means any information relating to an identified or identifiable natural person.

“Processing”

Means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, disclosure, transmission, analysis, deletion or destruction.

“Direct Consumer”

Means an individual customer who enters into a contractual relationship directly with MiaSentry.

“Indirect Consumer”

Means an individual whose Personal Data is processed through the Services by a distributor, installer, property manager, utility provider, business customer or other third party that has entered into a contractual relationship with MiaSentry.

“Business Contact”

Means an employee, representative, contractor, consultant, agent or authorized user of a business customer, distributor, installer, supplier, partner or service provider.

“Website Visitor”

Means any individual accessing or interacting with our Website.

 

3. DATA CONTROLLER AND DATA PROCESSOR ROLES

The GDPR distinguishes between:

  • A Data Controller, who determines the purposes and means of processing Personal Data; and
  • A Data Processor, who processes Personal Data on behalf of a Data Controller.

Depending on the circumstances, MiaSentry may act as either a Controller or a Processor.

3.1 Direct Consumers

Where an individual enters into a service agreement directly with MiaSentry, MiaSentry acts as the Data Controller.

In these circumstances MiaSentry determines:

  • What Personal Data is collected;
  • Why the Personal Data is collected;
  • How the Personal Data is used;
  • How long the Personal Data is retained;
  • With whom the Personal Data is shared.

3.2 Business Contacts

MiaSentry acts as Data Controller in relation to Business Contact Data.

This includes Personal Data relating to:

  • Prospective customers;
  • Existing customers;
  • Partners;
  • Installers;
  • Distributors;
  • Utility providers;
  • Suppliers;
  • Service providers.

3.3 Indirect Consumers

Where the Services are provided through a distributor, installer, utility provider, property manager, building owner or other business customer, MiaSentry generally acts as a Data Processor on behalf of the relevant business customer.

In such circumstances:

  • The relevant business customer determines the purposes and means of processing;
  • MiaSentry processes Personal Data only in accordance with documented instructions;
  • MiaSentry enters into data processing agreements where required by law.

3.4 Independent Controller Activities

Notwithstanding Section 3.3, MiaSentry may act as an independent Data Controller for certain limited purposes, including:

  • Cybersecurity;
  • Fraud prevention;
  • Platform security;
  • Service integrity;
  • Compliance monitoring;
  • Legal claims;
  • Regulatory obligations;
  • Corporate governance;
  • Internal audits.

 

4. CATEGORIES OF PERSONAL DATA

Depending on how you interact with the Services, MiaSentry may collect the following categories of Personal Data.

Identification Data

  • First name;
  • Last name;
  • Apartment number;
  • Unit identifier;
  • Property identifier;
  • Customer reference numbers.

Contact Data

  • Email address;
  • Postal address;
  • Telephone number.

Account Data

  • Username;
  • Password credentials;
  • Authentication records;
  • Account preferences;
  • Notification preferences.

Authentication Data

Where available, users may authenticate using:

  • Email and password;
  • Sign in with Apple;
  • Sign in with Google.

MiaSentry may receive identifiers associated with such authentication providers.

Technical Data

  • IP addresses;
  • Browser information;
  • Device information;
  • Operating system information;
  • Application version information;
  • Diagnostic information;
  • Error logs.

Location Data

Where permitted by the user and required for service functionality, MiaSentry may process approximate or precise location information associated with the Services.

Location processing is limited to purposes related to service functionality, installation support, property identification, device configuration and customer support.

Notification Data

MiaSentry may process push notification tokens and associated metadata in order to deliver:

  • Leak alerts;
  • System alerts;
  • Service notifications;
  • Security notifications.

Payment Data

Where applicable, MiaSentry may process payment-related information necessary to administer subscriptions, invoices and payments.

MiaSentry does not intentionally store complete payment card details unless required by the applicable payment solution.

Water Telemetry Data

The Services may process:

  • Water consumption measurements;
  • Water flow readings;
  • Leak detection events;
  • Water usage trends;
  • Historical consumption records;
  • Device operational status;
  • Alert history;
  • Sensor telemetry;
  • System diagnostics.

Communications Data

  • Support requests;
  • Emails;
  • Service tickets;
  • Customer communications;
  • Feedback submissions.

 

5. SOURCES OF PERSONAL DATA

MiaSentry may obtain Personal Data:

  • Directly from users;
  • Through mobile applications;
  • Through website forms;
  • Through connected devices;
  • Through distributors and installers;
  • Through business customers;
  • Through utility providers;
  • Through customer support interactions;
  • Through automated telemetry generated by the Services.

 

 

6. PURPOSES OF PROCESSING AND LEGAL BASES

MiaSentry processes Personal Data only where a valid legal basis exists under Article 6 GDPR.

Depending on the circumstances, processing may be based on:

  • Performance of a contract;
  • Compliance with a legal obligation;
  • Legitimate interests pursued by MiaSentry. Legitimate Interests, including maintaining platform and network security, preventing fraud, ensuring service reliability, protecting the rights and interests of MiaSentry and its users, improving products and services, enforcing contractual rights, and establishing, exercising or defending legal claims;
  • Consent provided by the data subject.

6.1 DIRECT CONSUMER DATA

Where MiaSentry acts as Data Controller, Personal Data may be processed for the following purposes:

Purpose

Categories of Data

Basis

Account registration and management

Identification Data, Contact Data, Account Data

Performance of Contract

User authentication

Account Data, Authentication Data

Performance of Contract

Provision of Services

Identification Data, Water Telemetry Data

Performance of Contract

Water monitoring and reporting

Water Telemetry Data

Performance of Contract

Leak detection and alert generation

Water Telemetry Data, Notification Data

Performance of Contract

Historical usage reporting

Water Telemetry Data

Performance of Contract

Customer support

Contact Data, Communications Data

Performance of Contract and Legitimate Interests

Subscription administration

Account Data, Payment Data

Performance of Contract

Fraud prevention

Technical Data, Account Data

Legitimate Interests

Platform security

Technical Data

Legitimate Interests

Regulatory compliance

Any relevant Personal Data

Legal Obligation

Legal claims and dispute resolution

Any relevant Personal Data

Legitimate Interests

6.2 BUSINESS CONTACT DATA

MiaSentry processes Business Contact Data for:

Purpose

Basis

Contract negotiations

Legitimate Interests

Partner onboarding

Legitimate Interests

Distributor management

Legitimate Interests

Utility and installer management

Legitimate Interests

Account administration

Performance of Contract

Regulatory compliance

Legal Obligation

Protection of legal rights

Legitimate Interests

6.3 WEBSITE VISITOR DATA

Website Visitor Data may be processed for:

Purpose

Basis

Website operation

Legitimate Interests

Website security

Legitimate Interests

Analytics and service improvement

Consent or Legitimate Interests, where permitted

Responding to enquiries

Legitimate Interests

Preventing misuse

Legitimate Interests

Compliance obligations

Legal Obligation

6.4 INDIRECT CONSUMER DATA

Where MiaSentry acts as Data Processor on behalf of a business customer, distributor, installer, utility provider or property manager, the relevant customer determines the purposes and legal basis for processing.

MiaSentry processes such Personal Data solely in accordance with documented instructions and applicable contractual obligations.

6.5 INDEPENDENT CONTROLLER ACTIVITIES

Regardless of the contractual structure, MiaSentry may process Personal Data as an independent Controller for:

  • Maintaining service integrity;
  • Detecting cybersecurity threats;
  • Monitoring system abuse;
  • Fraud prevention;
  • Investigating incidents;
  • Complying with legal obligations;
  • Establishing, exercising or defending legal claims.

The legal basis for such processing is MiaSentry’s legitimate interests and, where applicable, compliance with legal obligations.

 

7. WATER TELEMETRY, ANALYTICS AND LEAK DETECTION

MiaSentry provides water monitoring and leak detection services through connected devices, cloud infrastructure and software applications.

To provide these Services, MiaSentry may process:

  • Water consumption measurements;
  • Water flow rates;
  • Device telemetry;
  • Device health indicators;
  • Alert history;
  • Leak detection events;
  • Water usage trends;
  • Historical reporting data;
  • System diagnostics;
  • Configuration settings.

7.1 Purpose of Telemetry Processing

Telemetry data is processed to:

  • Detect water leaks;
  • Identify abnormal consumption patterns;
  • Generate alerts and notifications;
  • Produce historical reports;
  • Improve operational efficiency;
  • Support troubleshooting activities;
  • Monitor device health;
  • Improve service reliability.

7.2 Historical Reporting

MiaSentry may retain historical telemetry information to provide:

  • Usage dashboards;
  • Historical comparisons;
  • Trend analysis;
  • Water efficiency reporting;
  • Leak investigation support.

7.3 Automated Processing

MiaSentry uses automated systems to identify:

  • Potential leaks;
  • Abnormal water usage patterns;
  • Device anomalies;
  • System failures.

These automated systems generate recommendations, alerts and notifications.

However, MiaSentry does not make solely automated decisions producing legal effects or similarly significant effects within the meaning of Article 22 GDPR.

 

8. MOBILE APPLICATION FEATURES

The MiaSentry mobile application may process certain information required to provide mobile functionality.

Push Notifications

Users may choose to receive push notifications regarding:

  • Leak alerts;
  • Device alerts;
  • Service notifications;
  • Security notifications.

To deliver such notifications, MiaSentry may process push notification tokens and associated technical identifiers.

Location Services

Where enabled by the user, location information may be processed for:

  • Property identification;
  • Device installation assistance;
  • Service configuration;
  • Customer support.

Users may disable location permissions through their device settings, although certain features may become unavailable.

Authentication Services

Users may authenticate using:

  • Email and password;
  • Apple Sign-In;
  • Google Sign-In.

Where these authentication services are used, MiaSentry may receive account identifiers and authentication metadata from the relevant provider.

MiaSentry does not receive user passwords associated with third-party authentication providers.

 

9. COMMUNICATIONS

MiaSentry may communicate with users regarding:

  • Service operation;
  • Security matters;
  • Account administration;
  • Technical support;
  • Contractual obligations.

MiaSentry does not send marketing communications unless a lawful basis exists under applicable law.

Users may continue to receive service-related communications even where marketing communications are not permitted or have been opted out of.

 

10. COOKIES AND SIMILAR TECHNOLOGIES

MiaSentry may use cookies, pixels, local storage technologies and similar tracking technologies on its Website and, where applicable, within certain Services.

Cookies are small text files placed on a user’s device that allow the Website to recognize a browser, remember preferences and improve the user experience.

10.1 Categories of Cookies

Strictly Necessary Cookies

These cookies are required for the operation, security and functionality of the Website and cannot be disabled through our consent management tools.

MiaSentry applies cookies and similar technologies in accordance with applicable data protection and ePrivacy laws. Non-essential cookies, including analytics, performance, advertising and measurement technologies, are only deployed where the user has provided valid consent where required by law. Users may withdraw or modify their consent preferences at any time through the cookie management tool.

Examples include:

  • Session management;
  • Authentication;
  • Security controls;
  • Load balancing;
  • Fraud prevention.

Legal Basis: These cookies are necessary for the provision, security and functionality of the Website and Services requested by the user and do not require consent under applicable law.

Functional Cookies

Functional cookies remember user preferences and settings.

Examples include:

  • Language preferences;
  • User interface settings;
  • Accessibility preferences.

Legal Basis: Consent where required by applicable law.

Analytics Cookies

Analytics cookies help MiaSentry understand how visitors interact with the Website.

Examples include:

  • Page visits;
  • Navigation paths;
  • Time spent on pages;
  • Device and browser information;
  • User engagement metrics.

MiaSentry may use Google Analytics or equivalent analytics technologies.

Legal Basis: Consent where required by applicable law.

Advertising and Measurement Technologies

Where implemented, MiaSentry may use advertising and conversion measurement technologies to understand the effectiveness of online campaigns and improve Website performance.

Legal Basis: Consent where required by applicable law.

10.2 Managing Cookie Preferences

MiaSentry applies cookies and similar technologies in accordance with applicable data protection and ePrivacy laws. Non-essential cookies, including analytics, performance, advertising and measurement technologies, are only deployed where the user has provided valid consent where required by law. Users may withdraw or modify their consent preferences at any time through the cookie management tool.

Users may manage cookie preferences through the cookie management tool available on the Website.

Consent may be withdrawn at any time without affecting the lawfulness of processing conducted prior to withdrawal.

 

11. SHARING OF PERSONAL DATA

MiaSentry may disclose Personal Data only where necessary to operate the Services, comply with legal obligations or protect legitimate interests.

Recipients may include:

Service Providers

  • Cloud hosting providers;
  • Infrastructure providers;
  • Analytics providers;
  • Monitoring providers;
  • Customer support providers;
  • Authentication providers;
  • Communication providers;
  • Professional advisors.

Business Customers and Partners

Where Services are delivered through:

  • Installers;
  • Property managers;
  • Utilities;
  • Distributors;
  • Resellers;
  • Business customers;

Personal Data may be shared as necessary to provide and support the Services.

Corporate Transactions

Personal Data may be disclosed in connection with:

  • Mergers;
  • Acquisitions;
  • Investments;
  • Corporate reorganizations;
  • Asset sales;
  • Financing transactions.

Legal and Regulatory Disclosures

MiaSentry may disclose Personal Data where required by:

  • Applicable law;
  • Court orders;
  • Regulatory requests;
  • Government authorities;
  • Law enforcement agencies.

 

12. SUBPROCESSORS

MiaSentry may engage third-party subprocessors to assist in the delivery of the Services.

These subprocessors may provide:

  • Infrastructure hosting;
  • Cloud computing;
  • Data storage;
  • Monitoring;
  • Analytics;
  • Authentication;
  • Customer support;
  • Security services.

Examples may include providers operating infrastructure on:

  • Amazon Web Services (AWS);
  • Microsoft Azure;
  • Google Cloud Platform (GCP);
  • Equivalent enterprise cloud environments.

Subprocessors may change from time to time based on operational requirements.

All subprocessors are subject to:

  • Data Processing Agreements;
  • Confidentiality obligations;
  • Security requirements;
  • GDPR-compliant contractual safeguards.

 

13. INTERNATIONAL TRANSFERS OF PERSONAL DATA

MiaSentry operates internationally and may transfer Personal Data to countries outside the European Economic Area (“EEA”).

Where such transfers occur, MiaSentry implements appropriate safeguards in accordance with Chapter V GDPR.

13.1 Adequacy Decisions

Transfers may occur to jurisdictions recognized by the European Commission as providing an adequate level of protection.

13.2 Standard Contractual Clauses

Where no adequacy decision exists, MiaSentry may rely on Standard Contractual Clauses approved by the European Commission.

13.3 Supplementary Safeguards

Where required, MiaSentry may implement supplementary measures including:

  • Encryption;
  • Access controls;
  • Data minimization;
  • Transfer impact assessments;
  • Contractual restrictions.

Copies of applicable safeguards may be requested by contacting app@miasentry.com.

 

14. DATA RETENTION

MiaSentry retains Personal Data only for as long as necessary to fulfill the purposes described in this Privacy Policy.

Retention periods may vary depending on:

  • Legal obligations;
  • Contractual obligations;
  • Operational requirements;
  • Security requirements;
  • Dispute resolution requirements.

Where retention is no longer required, Personal Data will be:

  • Deleted;
  • Anonymized; or

 

15. INFORMATION SECURITY

MiaSentry implements appropriate technical and organizational measures designed to protect Personal Data against:

  • Unauthorized access;
  • Unauthorized disclosure;
  • Accidental loss;
  • Destruction;
  • Alteration;

Security measures may include:

Technical Controls

  • Encryption in transit;
  • Network security controls;
  • Access management systems;
  • Authentication mechanisms;
  • Security monitoring;
  • Vulnerability management;
  • Logging and auditing.

Organizational Controls

  • Confidentiality obligations;
  • Access restrictions;
  • Security policies;
  • Staff training;
  • Incident response procedures.

Personal Data Breaches

MiaSentry maintains incident response and breach management procedures designed to identify, assess, contain and remediate security incidents affecting Personal Data.

Where a personal data breach occurs, MiaSentry will comply with Articles 33 and 34 GDPR and applicable Portuguese law, including notification to the competent supervisory authority and affected individuals where such notification is legally required.

While MiaSentry takes reasonable steps to protect Personal Data, no system can be guaranteed to be completely secure.

Users are responsible for maintaining the confidentiality of their account credentials and for promptly notifying MiaSentry of any suspected unauthorized access.

 

16. YOUR RIGHTS REGARDING PERSONAL DATA

Subject to applicable law, individuals may exercise the following rights in relation to their Personal Data.

Right of Access

You have the right to obtain confirmation as to whether MiaSentry processes your Personal Data and, where applicable, obtain access to such Personal Data together with information regarding:

  • The purposes of processing;
  • Categories of Personal Data processed;
  • Recipients of Personal Data;
  • Retention periods;
  • Sources of Personal Data;
  • International transfers;
  • Automated decision-making activities.

Right to Rectification

You have the right to request correction of inaccurate Personal Data and completion of incomplete Personal Data.

Right to Erasure

In certain circumstances, you may request deletion of your Personal Data.

This right may apply where:

  • Personal Data is no longer necessary;
  • Consent has been withdrawn;
  • Processing is unlawful;
  • Applicable law requires deletion.

This right is not absolute and may be limited where retention is required by law or necessary for legal claims.

Right to Restrict Processing

You may request restriction of processing in circumstances permitted by Article 18 GDPR.

Right to Object

You may object to processing based upon MiaSentry’s legitimate interests.

Where an objection is submitted, MiaSentry will cease processing unless compelling legitimate grounds exist which override the interests, rights and freedoms of the individual or where processing is required for legal claims.

Right to Data Portability

Where processing is based upon consent or contract and carried out by automated means, you may request a copy of your Personal Data in a structured, commonly used and machine-readable format.

Right to Withdraw Consent

Where processing is based upon consent, consent may be withdrawn at any time.

Withdrawal does not affect processing conducted prior to the withdrawal.

Right Not To Be Subject To Certain Automated Decisions

MiaSentry does not currently make solely automated decisions producing legal effects or similarly significant effects within the meaning of Article 22 GDPR.

Right To Lodge A Complaint

You may lodge a complaint with:

  • The Portuguese Data Protection Authority (CNPD); or
  • Your local supervisory authority within the EEA.

 

17. EXERCISING YOUR RIGHTS

Requests relating to Personal Data may be submitted to:

Email: app@miasentry.com

To protect Personal Data, MiaSentry may require reasonable identity verification before responding to requests.

MiaSentry will respond within the time periods required by applicable law.

Additional Information Requests

Where a request is unclear or excessively broad, MiaSentry may request additional information to clarify the request.

Repeated or Excessive Requests

Where permitted by law, MiaSentry may refuse or charge a reasonable administrative fee for manifestly unfounded, excessive or repetitive requests.

 

18. RIGHTS REQUESTS WHERE MIASENTRY ACTS AS PROCESSOR

Where MiaSentry processes Personal Data solely on behalf of a distributor, installer, property manager, utility provider, business customer or other controller, MiaSentry may not be legally responsible for responding directly to certain rights requests.

In such circumstances:

  • The relevant controller remains responsible for responding;
  • MiaSentry may forward the request to the controller;
  • MiaSentry may assist the controller in responding where required by contract or applicable law.

Individuals may also contact the relevant controller directly.

 

19. CHILDREN’S PRIVACY

The Services are not intended for children under the age of sixteen (16). Where consent is relied upon as the legal basis for processing, MiaSentry will comply with the minimum age requirements established by applicable law, including the GDPR and applicable Portuguese legislation.

MiaSentry does not knowingly collect Personal Data from children under the age of sixteen (16).

If MiaSentry becomes aware that Personal Data has been collected from a child in violation of applicable law, reasonable steps will be taken to delete such information.

Parents or guardians who believe a child has provided Personal Data may contact:

app@miasentry.com

 

20. CHANGES TO THIS PRIVACY POLICY

MiaSentry may update this Privacy Policy from time to time.

Changes may be made to:

  • Reflect changes in legal requirements;
  • Reflect changes in Services;
  • Reflect changes in processing activities;
  • Improve clarity and transparency.

Where required by law, MiaSentry will provide appropriate notice regarding material changes.

The updated version will be published on the Website together with the revised “Last Updated” date.

MiaSentry has not appointed a Data Protection Officer pursuant to Article 37 GDPR because it is not currently required to do so. Privacy-related enquiries may be directed to app@miasentry.com

 

21. CONTACT INFORMATION

For questions regarding this Privacy Policy or the processing of Personal Data, please contact:

Data Controller

ALTU ALGORITMO, LDA

NIF: 518506622

Address: Avenida Infante D. Henrique, 26 1149-096 Lisboa Portugal

Email: app@miasentry.com

Website: https://miasentry.com

 

22. VERSION CONTROL

Privacy Policy Version: 1.0

Effective Date: June 15, 2026

Last Updated: June 15, 2026

Copyright © 2026 ALTU ALGORITMO, LDA. All rights reserved.