Privacy Policy — Senex Mobile App

Leer esta política en español

Privacy Policy — Senex Mobile App

Last updated: 17 August 2026
Applies to: the Senex mobile app for Android and iOS (package com.avotz.senex).

This policy covers the Senex mobile app only. The senexcr.com website is governed by its separate website privacy policy.

1. Who we are

The Senex app is developed and operated by Ingenelectric S.A., corporate ID 3-101-721867, a company incorporated in Costa Rica, with offices 300 metres east and 30 metres south of the main gate of Edgardo Baltodano Stadium, Liberia, Guanacaste, Costa Rica.

Ingenelectric S.A. is the data controller for the data described here. We also operate the servers where that data is stored.

Privacy contact: privacidad@senexcr.com

2. What Senex is and who uses it

Senex is a security and property management app. It is not available to the general public: it is used under an agreement between Ingenelectric S.A. and the security company, condominium, residential community or property administration that contracts the service. That organisation creates its users’ accounts; nobody self-registers from inside the app.

The app has several user roles, and the data collected depends on the role:

  • Security officer — walks patrol rounds, logs visitor entries at the gate, scans checkpoints and answers Proof-of-Life confirmations. This is the only role from which location data is collected.
  • Resident — pre-registers expected visitors, books amenities and reviews their own log.
  • Foreman, key manager and administrator — manage maintenance orders, key handovers, materials and reports.

3. Location data

This is the most important section of this policy. The app accesses device location only for users with the security officer role, and only in the three situations described below. No other role generates location data.

3.1 Patrol route — background location

What we do. When an officer taps “Start round”, the app begins recording their GPS position continuously in order to reconstruct the route they actually covered, so their supervisor can verify that the perimeter was patrolled. Recording continues while the app is in the background, while the screen is off, and while the app is closed or not in use, because an officer on a round normally keeps the phone pocketed.

When it starts and when it stops. Collection begins only through the explicit act of starting a round, and stops completely when the officer taps “Finish round”. Outside an active round, the app does not collect location in the background. There is no tracking outside working hours, during breaks, or while the user is signed out.

How users are informed. Before the operating system shows its permission dialog, the app displays a disclosure screen explaining that background location will be collected and why. Permission must be granted explicitly and can be revoked at any time in the system settings. On Android, while a round is active, a persistent foreground-service notification (“Senex — round in progress”) is shown so the officer always knows recording is running. On iOS, the system’s own location indicator is displayed.

Exactly what is transmitted. A route point is recorded roughly every 10 metres of movement and contains:

  • Latitude and longitude
  • Estimated accuracy of the reading, in metres
  • Date and time of the reading
  • Speed and heading, when the device reports them
  • An internal point identifier, used to avoid duplicates on upload

What is not transmitted. The app deliberately discards altitude, altitude accuracy and the mock-location flag. Route points do not include battery level, any device identifier, or any advertising identifier.

Temporary storage on the phone. Points are first written to the device and uploaded to the server in batches. This lets a round be recorded correctly in areas without coverage: when connectivity returns, pending points are uploaded automatically. Once uploaded, they are deleted from local storage. This local buffer is also discarded on sign-out.

3.2 Single location reading when logging a checkpoint

When an officer logs a checkpoint — by scanning its QR code or selecting it manually — the app takes a single position reading at that moment and attaches it to the record, together with any photos and notes the officer adds. Its purpose is to evidence that the checkpoint was logged physically on site rather than remotely. It is a one-shot, foreground-only reading; no continuous tracking is associated with this feature. If a round is active at that moment, the last position already recorded by the round is reused instead of taking a new reading.

3.3 Single location reading when confirming Proof of Life

The Hombre Alerta module periodically asks officers to confirm they are safe. On confirmation, the app attaches a single position reading so the supervisor knows where the confirmation came from. This reading is technically optional: if the device cannot obtain it, the confirmation is still submitted without coordinates and is never blocked for that reason.

4. Location visible to other users

Within the Hombre Alerta module, when an officer stops answering Proof-of-Life confirmations, their last known location is shown to other officers of the same company so they can go and check on them. Alongside the location, the app shows the officer’s name, how long they have been silent and how many confirmations they have missed.

To be explicit: this is location data the app displays to other users, not only to supervisors. Visibility is limited to officers belonging to the same company. From that screen an officer can open those coordinates in the map app installed on their own phone; at that point the coordinates are handed to that map app, which is governed by its own privacy policy. Senex bundles no map SDK and no mapping provider.

Location coordinates never travel through the push notification provider: escalation notifications carry only a screen identifier, and coordinates are fetched directly from our server using the officer’s authenticated session.

5. Camera and document scanning

The app uses the device camera for three purposes.

5.1 QR code scanning

Officers scan QR codes on checkpoints and on authorised persons. The code content is sent to our server to resolve which checkpoint or which person it corresponds to.

5.2 National ID and driving licence scanning

In the entry log, the app can read the PDF417 barcode printed on Costa Rican national ID cards (cédula) and driving licences, so that details do not have to be typed by hand.

Decoding happens entirely on the device, offline, without sending the image or the barcode to any server. The national ID barcode contains identification number, first name, first and second surname, sexdate of birth and document expiry date. The driving licence barcode contains identification number and licence class.

Of all those fields, only those needed to complete the entry record are sent to our servers: identification number, name and document type. Sex, date of birth and expiry date are discarded on the device and are neither stored nor transmitted.

5.3 Photos

Users can take photos with the camera and attach them to: checkpoint records, commercial entry records (where the photo may include the visitor or their vehicle), incident reports, maintenance orders, key handovers, material releases and water meter readings. These photos are uploaded to our server against the corresponding record and are visible to authorised staff of the contracting organisation.

Photos are also held temporarily in the app’s private storage on the device while the record is being completed and submitted.

6. Account and profile data

We process the following data about people who use the app:

  • Identity and contact: name, email address, phone number, national identification number and document type.
  • Sign-in data: email address and password. The password is transmitted encrypted and stored on the server in irreversible form. The app keeps a session credential on the device, which is deleted on sign-out.
  • Password recovery: the recovery code is sent by SMS to the registered phone number.
  • Employment data: company, assigned workstation, roles and permissions, assigned property, account expiry date, and active/inactive status.
  • Profile photo, where the organisation uploads one.
  • Preferred interface language.

Users can edit their own name, email, phone, identification number, document type, password and language from within the app.

7. Notifications and device data

7.1 Push notifications

The app uses OneSignal to deliver push notifications (entry alerts, Proof-of-Life prompts, escalations and announcements). On sign-in, the app obtains a device subscription identifier from OneSignal and sends it to our server so notifications can be routed to the right phone. That identifier is also stored locally on the device.

For delivery on Android, OneSignal relies on Google’s Firebase Cloud Messaging. Both services receive the subscription identifier and the notification content; they do not receive location coordinates or visitor data.

7.2 Device information

We collect the device model and manufacturer, and the platform (Android or iOS). The model is sent at sign-in to identify the device associated with the session.

For the Hombre Alerta module, whose alarms must ring reliably even on a locked screen, we additionally send a technical device diagnostic: whether the notification permission is granted, whether the app is exempt from battery optimisation, the make and model, and the configured priority of the alarm channel. It is used solely so a supervisor can detect that a phone will not ring and fix it before it becomes a problem.

The app does not access the device’s unique identifier, IMEI, MAC address or advertising identifier.

7.3 Alarms and local notifications

The Hombre Alerta module schedules local alarms on the device. These are scheduled and fired locally and involve no data transmission. So they ring at the exact time and survive a phone restart, the app requests the corresponding system permissions.

8. Data about people who are not app users

By the nature of the service, the app records data about people who are not Senex users and have no account: mainly visitors, suppliers and contractors entering a guarded property.

The following may be recorded about them: identification number, name, phone, email, document type, vehicle licence plate, who they are visiting and which unit, entry and exit times, number of accompanying persons, notes, attached documents and photos taken at the gate.

This data is collected on the instructions and on behalf of the organisation that administers the property, as part of its access control, and remains in its custody within the system. The basis for collection is each property’s entry regulations and posted notices, which that administration is responsible for maintaining. Ingenelectric S.A. provides and operates the system in which the data is stored.

If you visited a property that uses Senex and wish to exercise your rights over this data, write to privacidad@senexcr.com indicating the property and approximate date, and we will route your request to the relevant administration.

9. Why we use the data

DataPurpose
Background location during a roundReconstruct and verify the patrol route
Single location reading at checkpointsEvidence physical presence on site
Single location reading on Proof of LifeLocate an unresponsive officer, for their safety
Camera and document scanningMake entry logging faster and more accurate
PhotosDocument entries, incidents and completed work
Account dataAuthentication, permission control and operational communication
Push identifier and device dataDeliver notifications and ensure alarms ring
Visitor dataAccess control and the property’s security log

We do not use any data for advertising, for commercial profiling, or to sell or transfer to third parties for marketing purposes.

10. What the app does not do

We state this explicitly, because absence is relevant information too:

  • It shows no advertising and contains no ad networks.
  • It does not access the device advertising identifier.
  • It embeds no usage analytics or crash reporting tools (no Google Analytics, Firebase Analytics, Crashlytics, Sentry or equivalents).
  • It does not access your address book, calendar, messages or call history. “Contacts” inside Senex are visitor records stored in the system, not the phone’s address book.
  • It does not record audio or video.
  • It does not use facial recognition or biometric data.
  • It does not sell personal data.

11. System permissions we request

PermissionWhy
Precise and approximate locationLog checkpoints and Proof-of-Life confirmations
Background locationRecord the complete route of an active round
Location-type foreground serviceKeep round recording running with a visible notification
CameraScan QR codes and documents, and take photos
NotificationsDeliver operational alerts and Proof-of-Life alarms
Exact alarms and boot completedFire Proof-of-Life alarms on time and restore them after a phone restart
Notification policyAllow the Proof-of-Life alarm to sound even in Do Not Disturb mode
StorageSave and attach photos and documents. Declared for compatibility with older Android versions; on recent system versions it no longer grants access to your gallery

On iOS, the app additionally declares microphone and photo library access for attachment features. Those features are not active in the current version and, while they are not, the app neither records audio nor reads your photo library.

All permissions can be revoked at any time in the operating system settings. Revoking location permission prevents recording rounds and checkpoints, but does not prevent the rest of the app from being used.

12. Who we share data with

  • The contracting organisation. Authorised staff of the security company or property administration can access records from their own operation: rounds, routes, entry logs, incidents and reports.
  • Other users of the same company, in the specific case described in section 4.
  • OneSignal (One Signal, Inc.) and, through it, Firebase Cloud Messaging (Google LLC), to deliver push notifications.
  • Pusher (Pusher Ltd.), to deliver real-time in-app events.
  • Google Play and the App Store, to distribute and update the app.
  • Competent authorities, where there is a legal obligation or court order.

Barcode scanning uses a library that runs on the device itself, and text-to-speech uses the operating system’s own speech synthesiser: in both cases the content is not sent to any external service.

13. Where data is stored

Data is stored on servers operated by Ingenelectric S.A. Each contracting organisation has its own instance of the system, and one organisation’s data is not reachable from another’s instance. Communication between the app and the server is always encrypted using HTTPS.

14. How long we keep data

DataRetention period
Patrol route location points90 days
Round record (start, end, tracking mode)24 months
Checkpoint records and their photos12 months
Entry logs, visitor data and photos12 months
Proof-of-Life confirmations and their coordinates6 months
Account dataWhile the account is active and the agreement with the contracting organisation is in force
Temporary buffer on the deviceUntil the record is uploaded to the server, or until sign-out

When an agreement with a contracting organisation ends, its data is retained for a further 90 days to allow export, and is then deleted.

15. Account and data deletion

Senex accounts are created by the contracting organisation, not by the user, so deletion is handled by request.

You can request it at senexcr.com/eliminar-cuenta/ or by writing to privacidad@senexcr.com. We will verify the request with the contracting organisation and, once confirmed, delete the account and its associated personal data within 30 calendar days.

What is deleted: the account and its credentials, the profile (name, email, phone, identification number, profile photo), the push notification identifier and device diagnostic data.

What is retained and why: operational logs — entry records, checkpoint records, patrol routes, incidents and work orders — form part of the property’s security record and belong to the contracting organisation, not to the individual user. They are kept for the periods set out in section 14 and then deleted. Where technically possible, they are dissociated from the personal profile.

Uninstalling the app erases the data that was held on the phone, but does not delete the account or the data on the server; a deletion request is required for that.

16. Your rights

Under Costa Rica’s Law No. 8968 on the Protection of Individuals with regard to the Processing of their Personal Data and its regulations, and Panama’s Law 81 of 2019 on Personal Data Protection, you have the right to:

  • Know what data of yours we process and for what purpose.
  • Obtain a copy of your data.
  • Request rectification of inaccurate or outdated data.
  • Request deletion of your data, subject to the limits described in section 15.
  • Object to processing or withdraw your consent, where processing is based on it.
  • Lodge a complaint with the competent authority: the Agencia de Protección de Datos de los Habitantes (PRODHAB) in Costa Rica, or the Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI) in Panama.

To exercise any of these rights, write to privacidad@senexcr.com. We will respond within the periods established by applicable law.

17. Children

Senex is a workplace and residential tool intended for adults. It is neither designed for nor directed at children under 18, and we do not knowingly collect data from children as users of the app. If we find that an account was created in the name of a minor, we will delete it.

18. Security

We apply technical and organisational measures to protect the data: encrypted transmission over HTTPS, authentication using expiring session credentials, role- and permission-based access control, separation of each contracting organisation’s data, and irreversible password storage. No system is completely immune, but we work to keep these measures current.

19. Changes to this policy

If we change this policy, we will update the “last updated” date at the top of the document. Where a change materially affects how your data is processed — in particular if it expands location collection — we will notify you inside the app before the change takes effect.

20. Contact

Ingenelectric S.A.
Corporate ID 3-101-721867
300 metres east and 30 metres south of the main gate of Edgardo Baltodano Stadium
Liberia, Guanacaste, Costa Rica

Privacy: privacidad@senexcr.com
General: info@senexcr.com · (506) 8703-4552 · (506) 2665-0244
Commercial contact in Panama: (507) 6511-2222 · (507) 775-2515