GDPR Policy - AVM 360

GDPR & GLOBAL DATA PROTECTION POLICY

AVM-360 — Zapperr Software Solutions Pty Ltd (ABN: 78 674 087 499)
Effective Date: June 2026
Last Updated: June 2026

1. Introduction and Scope

This policy governs the processing of personal data and technical telemetry by the AVM-360 Hybrid Monitoring Platform operated by Zapperr Software Solutions Pty Ltd.

AVM-360 adheres to Privacy by Design and Privacy by Default principles as mandated by the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the California Consumer Privacy Act (CCPA) where applicable.

This policy is addressed to enterprise clients, partner organisations, and any data subject whose personal data is processed in connection with the AVM-360 platform.

2. Role Definition: Controller and Processor

This distinction is critical for enterprise clients and must be clearly understood before deployment:

  • AVM-360 / Zapperr acts as the Data Processor. We process technical telemetry and the minimum personal data necessary to operate the platform, strictly on the documented instructions of the client.
  • The Client (the deploying organisation) is the Data Controller. The client determines the purposes for which the AV estate is monitored, retains full ownership of all data generated by their estate, and is responsible for ensuring that their deployment of AVM-360 is compliant with applicable data protection laws in their jurisdiction.
  • Where a partner (reseller or integrator) deploys AVM-360 on behalf of an end client, the partner takes on the responsibilities of the Controller in their relationship with Zapperr, and is responsible for ensuring appropriate data processing agreements exist with their end clients.

3. Data Processing Agreement

Enterprise clients subject to GDPR or UK GDPR may require a formal Data Processing Agreement (DPA) as required under Article 28 GDPR. Zapperr will execute a DPA with any enterprise client on request.

The DPA sets out the subject matter and duration of processing, the nature and purpose of processing, the type of personal data and categories of data subjects, and the obligations and rights of the Controller.

To request a DPA, contact info@avm-360.com.

4. What AVM-360 Processes — and What It Does Not

In scope — technical telemetry (not personal data):

Device manufacturer, model, serial number, firmware version, IP address, MAC address, system heartbeat, operational logs, temperature, fan speed, lamp hours, display power state, Dante channel status, Cresnet link state, and room utilisation metadata (meeting start/end time, occupancy state via API).

IP addresses and MAC addresses are used solely for device identification within the client’s network. They are not used to identify, track, or profile individuals.

In scope — minimal personal data:

Account administrator name, business email address, job title, and login credentials (hashed). This is the minimum necessary to provide authenticated access to the platform.

Strictly out of scope — never collected:

Audio content, video content, screen-share content, meeting chat logs, meeting subject lines or titles, names of meeting participants, personal identifiable information of room occupants, biometric data, and any content from within meetings.

AVM-360’s technical architecture makes it structurally impossible to capture meeting content. The Collector operates at the device management layer only — it does not sit in the media or communication path.

5. Legal Basis for Processing

  • Article 6(1)(b) — Contract: Processing of account data and delivery of the platform are necessary for the performance of the subscription agreement with the client.
  • Article 6(1)(f) — Legitimate Interests: Operational telemetry processing (device health, fault detection, uptime monitoring) is necessary for the legitimate interests of the client in maintaining secure and reliable corporate infrastructure. Zapperr has conducted a Legitimate Interests Assessment (LIA) covering this processing basis. The LIA concludes that: the processing serves a clear purpose (infrastructure security and reliability); it is necessary and proportionate; and given that it involves device metadata rather than personal data about individuals, the impact on individual privacy is minimal and does not override the legitimate interests of either party. The LIA is available to enterprise clients on request.
  • Article 6(1)(c) — Legal Obligation: Where processing is required to comply with applicable law (e.g. data retention for financial or legal purposes), we process on this basis.
  • Article 6(1)(a) — Consent: Where processing is based on consent (analytics cookies, marketing communications), we obtain explicit, freely given, informed, and unambiguous consent and provide a simple mechanism to withdraw it.

6. Technical and Organisational Security Measures (Article 32)

Zapperr has implemented the following measures to ensure security appropriate to the risk:

  • Encryption in transit: TLS 1.2 minimum, TLS 1.3 preferred, for all data transmitted between the Collector and the cloud platform. All web access to the dashboard is via HTTPS.
  • Encryption at rest: Azure Transparent Data Encryption (TDE) on the cloud database. Collector-side local storage encrypted at operating system level.
  • Access controls: Role-based access control (RBAC) within the platform. Internal access to client data is restricted to personnel who require it for service delivery. Principle of least privilege is enforced.
  • Authentication: Passwords hashed with bcrypt. Login forms protected with CAPTCHA. Account lockout after 5 failed attempts (15-minute lockout).
  • API security: Each Collector is issued a unique Bearer token. All payloads are signed with HMAC-SHA256. Replay attacks are mitigated via unique request IDs and UTC timestamp validation (requests older than 5 minutes are rejected automatically).
  • Network isolation: The Collector resides inside the client’s VLAN. It operates on an outbound-only model — no inbound ports are required. There is no inbound network exposure created by the AVM-360 deployment.
  • Penetration testing: The AVM-360 codebase undergoes periodic security audits and static code analysis. Critical findings are remediated prior to deployment. Enterprise clients may request evidence of the most recent audit findings summary.
  • Subcontractor security: All development personnel, including offshore contractors, are subject to confidentiality agreements. Access to production systems is scoped to the minimum necessary and reviewed periodically.

7. Sub-Processors

As required under Article 28(2) GDPR, Zapperr maintains a list of sub-processors used in the delivery of the AVM-360 platform. Current sub-processors include:

  • Microsoft Azure (cloud hosting, database, and infrastructure) — data residency configurable by region
  • Development and engineering contractors (India-based) — access is scoped to development and test environments only; no access to production client data without a specific written authorisation

The current full sub-processor list is available on request from info@avm-360.com. Zapperr will notify clients of any material changes to sub-processors with at least 30 days’ notice, giving clients the opportunity to object.

8. Data Subject Rights (Articles 15–22)

Although AVM-360 processes minimal personal data, Zapperr supports the Data Controller in fulfilling data subject rights. Where a data subject makes a request directly to Zapperr, we will promptly refer it to the relevant Controller.

The following rights are supported:

  • Right of Access (Article 15): Clients can request a full export of personal data held within their account. This is available via the platform’s data export function (CSV/JSON) or by request to info@avm-360.com.
  • Right to Rectification (Article 16): Inaccurate user account data can be corrected directly within the platform by the account administrator. Requests for Zapperr-held data corrections should be directed to info@avm-360.com.
  • Right to Erasure (Article 17): Clients can request deletion of their account and all associated data. Upon receipt of a verified written request, Zapperr will delete all Client Data within 30 days and provide written confirmation. Note: data subject to a legal retention obligation (e.g. financial records) will be retained only for the minimum period required by law.
  • Right to Restriction (Article 18): Monitoring can be suspended for specific rooms designated as high-security or sensitive (e.g. executive meeting rooms, legal conference rooms) without affecting visibility for the rest of the estate.
  • Right to Data Portability (Article 20): All asset and telemetry data can be exported in CSV or JSON format at any time via the platform. Historical data exports can be requested from info@avm-360.com.
  • Right to Object (Article 21): Data subjects may object to processing based on legitimate interests. Objections should be directed to info@avm-360.com and will be assessed within 30 days.
  • Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, withdrawal can be effected at any time without affecting the lawfulness of prior processing.

9. Data Retention

Zapperr retains data in accordance with the following schedule:

  • Device telemetry and operational logs: 90 days default; configurable to 12 months on request
  • AI health summaries and trend data: up to 52 weeks (required for longitudinal trend analysis and historical comparison)
  • User account data: duration of subscription plus 12 months post-termination
  • Support and correspondence records: 3 years from resolution
  • Financial records: 7 years (Australian tax law requirement)

On termination of a client subscription, all Client Data is made available for export for 30 days. After this period, data is securely deleted from all Zapperr systems. Written confirmation of deletion is provided on request.

Data is not retained beyond these periods unless there is a specific legal obligation or the client has requested extended retention in writing.

10. International Data Transfers

AVM-360 is operated by an Australian company and uses Microsoft Azure infrastructure that can be provisioned within the client’s preferred data residency region (Australia, EU, UK, or US).

Where data is transferred outside the originating jurisdiction, Zapperr ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) for transfers to non-adequate third countries under GDPR, and compliance with the Australian Privacy Principle 8 requirements for cross-border disclosure.

Enterprise clients with specific data residency requirements should confirm their preferred hosting region at onboarding. Zapperr will confirm the agreed data residency in writing.

11. Breach Notification

In the event of a personal data breach, Zapperr will:

  • Notify the affected client without undue delay and in any event within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR
  • Provide in that notification: the nature of the breach; the categories and approximate number of data subjects affected; the categories and approximate number of records affected; the likely consequences of the breach; and the measures taken or proposed to address the breach
  • Support the client in fulfilling their own notification obligations to supervisory authorities and affected data subjects under Article 34 GDPR where the breach is likely to result in high risk to individuals

Breach notifications should be sent to the client’s designated security contact as recorded at onboarding. Clients should notify Zapperr of any suspected breach on their side that may involve Platform data by contacting info@avm-360.com immediately.

12. Australian Privacy Act Compliance

As an Australian entity, Zapperr complies with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), including:

  • APP 1: Having an open and transparent privacy policy (this document)
  • APP 3: Collecting only personal information that is reasonably necessary for our functions
  • APP 5: Notifying individuals of the purposes of collection at or before the time of collection
  • APP 6: Using and disclosing personal information only for the primary purpose of collection or a directly related secondary purpose
  • APP 8: Ensuring cross-border disclosure is subject to equivalent privacy protections
  • APP 11: Taking reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access
  • APP 12 and 13: Providing individuals access to and the ability to correct their personal information

Complaints under the Privacy Act 1988 can be directed to the Office of the Australian Information Commissioner at oaic.gov.au or to info@avm-360.com in the first instance.

13. Policy Review

This policy is reviewed annually and updated whenever there are material changes to our platform, sub-processors, or applicable law. The current version is always available at avm-360.com/privacy-policy and avm-360.com/gdpr-policy. Enterprise clients will be notified of material changes by email with at least 30 days’ notice.

14. Contact

For all data protection enquiries, DPA requests, sub-processor lists, LIA requests, or to exercise data subject rights:

Zapperr Software Solutions Pty Ltd
Email: info@avm-360.com
Website: avm-360.com/privacy-policy
ABN: 78 674 087 499