Legal
Privacy Policy
Last updated: 13 July 2026
This Privacy Policy explains how Avyndo handles personal data across the Avyndo website (avyndo.com) and the Avyndo applications and services, including Avyndo MDM, Avyndo Commerce, and Avyndo OS (together, the “Services”). It applies to the Avyndo apps distributed through the Google Play Store, the Apple App Store, and other channels.
In short: we collect as little as possible, we do not sell personal data, we do not show advertising, and this website sets no cookies and uses no third-party trackers.
1. Who we are
The Avyndo Services are operated by Avyndo, part of Fastlane Grupp OÜ, a company registered in Estonia (the “data controller” for the website and for direct customer relationships). You can reach us about anything in this policy at privacy@avyndo.com.
Managed devices: where your device is enrolled in Avyndo MDM, or you use an Avyndo Commerce terminal deployed by a business, that organization (your employer or the merchant) is the data controller and Avyndo acts as a data processor on their behalf. Questions about how your organization uses these tools should be directed to that organization first.
2. The website
- No cookies. avyndo.com sets no cookies of any kind, which is why you see no cookie banner.
- No analytics or trackers. We use no third-party analytics, advertising, or social plugins. Fonts and all assets are served from our own infrastructure.
- Server logs. Our web server (hosted in the European Union, Frankfurt) keeps standard access logs — IP address, requested URL, timestamp, and browser user agent — for security and abuse prevention. Logs are automatically rotated and deleted within 30 days. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Email. If you email us, we keep the correspondence for as long as needed to handle your request.
3. The Avyndo apps
3.1 Avyndo MDM
Avyndo MDM manages devices (laptops, phones, tablets) on behalf of the organization that enrolls them. Depending on the policies your organization enables, the MDM agent may process:
- Device identity: device model, serial number, OS version, enrollment identifiers, and device name.
- Security and compliance state: encryption status, passcode presence (never the passcode itself), patch level, and policy compliance.
- Installed applications on managed (corporate) profiles.
- Location, only if the managing organization enables lost-device location and the platform surfaces the required consent; personal profiles are not tracked.
- Network configuration relevant to policy (Wi-Fi profiles, VPN state).
The MDM agent clearly discloses that a device is managed. On personally-owned devices with a work profile, management is limited to the work profile and personal data (photos, messages, personal apps, browsing) is not visible to Avyndo or the organization.
3.2 Avyndo Commerce
Avyndo Commerce powers POS, kiosks, self-scan, waiting queues, and payment terminals deployed by merchants. In that context we process, on the merchant’s behalf:
- Transaction data: items, amounts, timestamps, and receipt data.
- Payment data is handled by certified payment providers; Avyndo never stores full card numbers (PAN), PINs, or card security codes.
- Queue and ticket data (e.g. a pharmacy waiting number), kept only as long as operationally necessary.
- Operator accounts: staff logins and roles created by the merchant.
3.3 Avyndo OS
Avyndo OS is an open-source operating system platform currently in development. It does not phone home. Crash reports and diagnostics are strictly opt-in, anonymized where technically possible, and used only to improve stability.
4. App permissions
Avyndo apps request only the permissions needed for the features your organization enables, and each is used solely for the stated purpose:
- Camera — scanning barcodes and QR codes (enrollment, self-scan, inventory). Images are processed on device and not stored.
- Location — lost-device location (MDM, when enabled by the organization) or terminal geofencing. Never used for advertising.
- Bluetooth / NFC — connecting payment terminals, printers, and peripherals; contactless payment flows.
- Notifications — operational alerts (policy changes, queue status, transaction results).
- Device admin / managed provisioning (Android) and MDM profiles (iOS/macOS) — required for device management itself and disclosed during enrollment.
5. Purposes and legal bases (GDPR)
- Providing the Services and fulfilling contracts — Art. 6(1)(b).
- Security, abuse prevention, and service integrity — Art. 6(1)(f) (legitimate interest).
- Compliance with legal obligations (e.g. accounting records for transactions) — Art. 6(1)(c).
- Optional features such as crash reporting or lost-device location — Art. 6(1)(a) (consent), withdrawable at any time.
6. Sharing and subprocessors
We do not sell or rent personal data, and we do not share it with advertisers. Data is shared only with:
- Infrastructure providers hosting our systems in the European Union (currently DigitalOcean, Frankfurt region).
- Certified payment providers, where a merchant has enabled payments — they process payment data under their own certifications (e.g. PCI DSS).
- The organization that manages your device or operates the terminal you use (as controller).
- Authorities, where we are legally required to do so.
7. International transfers
Our infrastructure is located in the European Union. Where any subprocessor processes data outside the EU/EEA, we rely on adequacy decisions or Standard Contractual Clauses (SCCs).
8. Retention
- Website server logs: deleted within 30 days.
- MDM device records: deleted when the device is retired from management, subject to the managing organization’s settings.
- Transaction records: retained as required by applicable accounting and tax law, then deleted.
- Support correspondence: kept no longer than 24 months after the matter is closed.
9. Security
Data in transit is encrypted (TLS). Access to production systems is restricted, key-based, and logged. Secrets are stored in an encrypted vault. Devices and terminals authenticate with per-device credentials that can be revoked instantly.
10. Account and data deletion
You can request deletion of your account and associated personal data at any time:
- In the apps:where an account menu is available, use “Delete account” in settings.
- By email: send a request to privacy@avyndo.com from the address associated with your account.
- Managed devices: if your device is managed by your organization, deletion requests are completed together with that organization as controller.
We confirm and complete deletion requests within 30 days, except for data we must retain by law (e.g. transaction records required for accounting), which is deleted when that obligation ends. This section serves as the data-deletion disclosure for our Google Play and Apple App Store listings.
11. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interest (Art. 21);
- withdraw consent at any time, without affecting prior processing (Art. 7(3)).
To exercise any of these rights, email privacy@avyndo.com. You also have the right to lodge a complaint with a supervisory authority — in Estonia, the Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee), or the authority in your country of residence.
12. Children
The Services are business tools and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We will update this policy as the Services evolve. Material changes are announced on this page with an updated “Last updated” date. Previous versions are available on request.
14. Contact
Avyndo · part of Fastlane Grupp OÜ, Estonia · privacy@avyndo.com