PRIVACY POLICY
AVM-360 — Zapperr Software Solutions Pty Ltd (ABN: 78 674 087 499)
Last Updated: June 2026
Effective Date: June 2026
1. Who We Are
AVM-360 is a cloud-hosted AV monitoring platform operated by Zapperr Software Solutions Pty Ltd, a company incorporated in Victoria, Australia (ABN: 78 674 087 499). Our registered address is Hoppers Crossing, Victoria, Australia.
We provide AV estate monitoring, telemetry, diagnostics, and reporting services to enterprise clients, managed service providers, and AV integrators globally.
For all privacy-related enquiries, contact us at:
Email: info@avm-360.com
Website: avm-360.com/privacy-policy
2. Scope of This Policy
This Privacy Policy explains how Zapperr Software Solutions Pty Ltd collects, uses, stores, shares, and protects information when you use the AVM-360 platform, visit our website, engage with our managed services, or interact with us as a prospective or current client or partner.
This policy applies to:
- End users and administrators who access the AVM-360 dashboard
- Employees and representatives of client organisations
- Employees and representatives of partner organisations (resellers, integrators)
- Visitors to avm-360.com
- Prospective clients who submit enquiries or use our online tools
This policy does not apply to the personal data of meeting participants in rooms monitored by AVM-360. AVM-360 is technically architected to not capture, record, or process any audio, video, screen content, or meeting chat logs. We monitor device metadata only — not people or meeting content.
3. Information We Collect
3.1 Technical Device Telemetry (from deployed Collectors)
When the AVM-360 Collector is installed on a client’s network, we collect the following categories of device metadata from network-connected AV hardware:
- Device identifiers: manufacturer, model, serial number, asset tag
- Network identifiers: IP address, MAC address (used for device identification within the client’s network only; not used for tracking individuals)
- Firmware and software: current firmware version, available firmware version
- Operational state: online/offline status, uptime, last-seen timestamps, system heartbeat
- Performance metrics: internal temperature, fan speed, lamp hours, CPU/memory load (where available via device API)
- Connectivity data: Dante audio channel status, Cresnet/Q-LAN link state, HDMI input detection, display power state
- Fault and event logs: device error codes, offline events, trigger activations, alert history
- Room utilisation metadata: display sleep/wake timestamps, scheduled vs actual power-down compliance, occupancy state (Occupied/Vacant via API integration only — no sensor data is processed directly by AVM-360)
None of the above constitutes personal data about individuals. It is exclusively device-level operational metadata.
3.2 Account and User Information
When a client organisation is onboarded, we collect:
- Full name and job title of authorised administrators and users
- Business email address
- Organisation name and address
- Phone number (optional)
- Login credentials (passwords are stored as bcrypt hashes; plaintext passwords are never stored or accessible)
- User access role and permission level within the platform
3.3 Website and Enquiry Data
When you visit avm-360.com or submit an enquiry, we may collect:
- Name, email address, company, and role submitted via contact or enquiry forms
- Pages visited, time on site, and referring URL (via analytics cookies — see Section 10)
- IP address (for security and spam prevention only; not linked to individual identity for marketing purposes)
- Any information you voluntarily provide in a contact form or free-text field
3.4 Support and Communications Data
When you contact us for support or engage with our team, we may collect:
- Email and chat correspondence
- Support ticket content and resolution history
- Any diagnostic information you share with us voluntarily
3.5 Integration Data
Where clients connect AVM-360 to third-party platforms (Microsoft Teams Pro Portal, Zoom, ServiceNow, Jira), we collect only the minimum data required to deliver the integration:
- Microsoft Teams Rooms: device health status and call record metadata accessed via Microsoft Graph API (teamwork/devices and communications/callRecords endpoints only). We do not request or access calendar subject lines, meeting participant names, or chat content.
- Zoom Rooms: room health and device status only. No meeting content, participant data, or recordings.
- ServiceNow/Jira: ticket identifiers and status for incident correlation. No personal case data beyond what the client configures.
4. How We Use Your Information
We use the information we collect for the following purposes:
4.1 Platform Delivery
- Monitor and report on the health, uptime, and telemetry of the client’s AV estate
- Generate Site Pulse alerts, fault notifications, and trigger-based automations
- Produce AI-generated room health summaries, firmware comparison reports, and asset tracking views
- Enable remote troubleshooting workflows by surfacing fault context to authorised AV engineers
4.2 Account Management
- Create and manage user accounts and access permissions
- Authenticate users and enforce role-based access controls
- Send essential service communications (billing, security alerts, policy updates)
4.3 Platform Improvement
- Analyse aggregated, anonymised usage data to improve platform features and performance
- Improve AI diagnostic models using anonymised telemetry patterns
- We do not use identifiable client data for product training or benchmarking without explicit written consent
4.4 Legal and Compliance
- Comply with applicable laws, regulations, and lawful requests from government authorities
- Enforce our agreements and protect our legal rights
- Investigate and respond to security incidents
4.5 Marketing (with consent)
- Send marketing and product update communications where you have opted in or where a legitimate interest exists under applicable law
- You may opt out at any time by contacting info@avm-360.com or using the unsubscribe link in any marketing email
5. Legal Basis for Processing
We process personal data under the following legal bases depending on the nature of the processing and the jurisdiction:
5.1 Contract (Article 6(1)(b) GDPR / Australian Privacy Act)
Processing necessary to deliver the AVM-360 platform and professional services under a signed agreement with the client.
5.2 Legitimate Interests (Article 6(1)(f) GDPR)
Processing necessary for our legitimate interest in operating a secure and reliable platform, including fraud prevention, security monitoring, and improving platform performance. We have conducted a Legitimate Interests Assessment (LIA) for all processing under this basis and have determined that our interests are not overridden by data subjects’ rights. The LIA is available on request from info@avm-360.com.
5.3 Legal Obligation (Article 6(1)(c) GDPR)
Processing necessary to comply with applicable law, including tax, financial reporting, and law enforcement obligations.
5.4 Consent (Article 6(1)(a) GDPR)
Where we rely on consent (e.g. for marketing communications or optional analytics cookies), we will always obtain explicit consent and provide a straightforward mechanism to withdraw it.
For data subjects in Australia, processing is conducted in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). For California residents, we comply with the California Consumer Privacy Act (CCPA). For UK data subjects post-Brexit, we comply with the UK GDPR and the Data Protection Act 2018.
6. Data Storage, Security, and Architecture
6.1 Architecture
AVM-360 uses a hybrid architecture designed to minimise data exposure:
- A local Collector is deployed within the client’s network. It resides inside the client’s VLAN and performs local device discovery. Sensitive network configuration data never leaves the client’s network.
- Only operational telemetry (device status, metrics, logs) is transmitted outbound to the AVM-360 cloud platform via HTTPS over port 443 using TLS 1.2 minimum, TLS 1.3 preferred.
- The cloud-hosted consolidator and dashboard are hosted on Microsoft Azure within the client’s preferred region where applicable.
6.2 Security Controls
We implement the following technical and organisational security measures:
- All data in transit: encrypted via TLS 1.2/1.3
- All data at rest: encrypted via Azure Transparent Data Encryption (TDE) on the consolidator database
- Collector-side storage: encrypted at the operating system level (BitLocker or equivalent) where applicable
- Authentication: password hashing via bcrypt; CAPTCHA on login forms; account lockout after 5 failed attempts with a 15-minute lockout window
- Access control: role-based access control (RBAC) enforced at the platform level; principle of least privilege applied to all internal access
- API security: unique Bearer token per Collector; HMAC-SHA256 payload signing; replay protection via unique request IDs and UTC timestamps (requests older than 5 minutes are rejected)
- Penetration testing: the AVM-360 codebase undergoes regular static code analysis and periodic third-party VAPT. Findings are remediated before each major release.
- Subcontractor security: all development contractors (including offshore personnel) are subject to confidentiality agreements and access is scoped to the minimum required for their role
6.3 Data Location
Primary cloud hosting is on Microsoft Azure. Data residency region is confirmed with each enterprise client at onboarding. We do not transfer data outside the agreed region without written client consent, except where required by law.
7. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this policy or as required by law:
- Device telemetry and fault logs: retained for 90 days by default; configurable up to 12 months on request; automatically purged or anonymised at the end of the agreed retention period
- AI health summaries and trend data: retained for up to 52 weeks to support longitudinal analysis
- Account data (user records, login history): retained for the duration of the subscription plus 12 months, then deleted
- Support correspondence: retained for 3 years from resolution
- Financial records (invoices, payment records): retained for 7 years in compliance with Australian tax law
- Website enquiry data: retained for 24 months from last contact, then deleted
On termination of a subscription, Client Data is made available for export for 30 days. After this period, all client data is securely deleted from our systems and we will confirm deletion in writing on request.
8. Data Sharing and Third Parties
We do not sell your data under any circumstances.
We may share data in the following limited circumstances:
8.1 Service Delivery Subcontractors
We use a small number of trusted subcontractors to operate and maintain the Platform, including cloud hosting providers (Microsoft Azure) and development personnel. All subcontractors are bound by confidentiality agreements and data processing agreements and may only process data in accordance with our instructions. A current list of sub-processors is available on request from info@avm-360.com.
8.2 Partner Organisations
Where a client has engaged an AV integrator or managed service provider as a partner, that partner may have access to the client’s dashboard data in accordance with the client’s configured access permissions. Zapperr is not responsible for how partner organisations use data they access within their own authorised scope.
8.3 Legal Requirements
We may disclose data if required to do so by law, court order, or lawful government authority request. Where legally permissible, we will notify the affected client before complying.
8.4 Business Transfers
In the event of a merger, acquisition, or sale of substantially all assets, client data may be transferred to the acquiring entity, subject to the same privacy protections as set out in this policy. We will notify affected clients in advance where possible.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: request correction of inaccurate or incomplete personal data
- Right to erasure: request deletion of your personal data (subject to legal retention obligations)
- Right to restriction: request that we restrict processing of your data in certain circumstances
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interests or for direct marketing purposes
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing
- Right to lodge a complaint: complain to your relevant data protection authority
- For Australian residents: contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au
- For UK/EU residents: contact your national data protection supervisory authority
- For California residents: you have additional rights under the CCPA, including the right to know, delete, and opt out of sale (we do not sell data)
To exercise any of these rights, contact us at info@avm-360.com. We will respond within 30 days. We may need to verify your identity before processing the request.
10. Cookies
Our website (avm-360.com) uses cookies. We categorise these as follows:
Strictly Necessary Cookies — required for the website to function. These cannot be disabled.
These include session management, security tokens, and load-balancing cookies.
Analytics Cookies — used to understand how visitors use our site (pages visited, time on site, traffic sources). We use Google Analytics (via Google Tag Manager). These are only activated with your consent. You can withdraw consent at any time by adjusting your cookie preferences via the cookie settings link in our website footer.
Functional Cookies — used to remember your preferences (e.g. language or region). These are activated with your consent.
Marketing Cookies — used to deliver relevant advertising. We do not currently operate paid retargeting campaigns on this website. If this changes, this policy will be updated and consent will be sought.
A full cookie declaration including cookie names, purposes, and expiry periods is available via our cookie consent management tool on the website.
11. Children
AVM-360 is a business-to-business platform. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have inadvertently collected such data, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our technology, services, or legal obligations. We will publish the updated policy at avm-360.com/privacy-policy with a revised “Last Updated” date. Where changes are material, we will notify current clients by email.
13. Contact and Complaints
For any privacy-related questions, to exercise your rights, or to raise a complaint, contact us at:
Zapperr Software Solutions Pty Ltd
Email: info@avm-360.com
Website: avm-360.com/privacy-policy
ABN: 78 674 087 499
If you are not satisfied with our response, you may escalate to your relevant supervisory authority (OAIC for Australia, ICO for the UK, relevant EU DPA for European residents).