Last updated: 17 August 2026
Applies to: the Senex mobile app for Android and iOS (package com.avotz.senex).
This policy covers the Senex mobile app only. The senexcr.com website is governed by its separate website privacy policy.
The Senex app is developed and operated by Ingenelectric S.A., corporate ID 3-101-721867, a company incorporated in Costa Rica, with offices 300 metres east and 30 metres south of the main gate of Edgardo Baltodano Stadium, Liberia, Guanacaste, Costa Rica.
Ingenelectric S.A. is the data controller for the data described here. We also operate the servers where that data is stored.
Privacy contact: privacidad@senexcr.com
Senex is a security and property management app. It is not available to the general public: it is used under an agreement between Ingenelectric S.A. and the security company, condominium, residential community or property administration that contracts the service. That organisation creates its users’ accounts; nobody self-registers from inside the app.
The app has several user roles, and the data collected depends on the role:
This is the most important section of this policy. The app accesses device location only for users with the security officer role, and only in the three situations described below. No other role generates location data.
What we do. When an officer taps “Start round”, the app begins recording their GPS position continuously in order to reconstruct the route they actually covered, so their supervisor can verify that the perimeter was patrolled. Recording continues while the app is in the background, while the screen is off, and while the app is closed or not in use, because an officer on a round normally keeps the phone pocketed.
When it starts and when it stops. Collection begins only through the explicit act of starting a round, and stops completely when the officer taps “Finish round”. Outside an active round, the app does not collect location in the background. There is no tracking outside working hours, during breaks, or while the user is signed out.
How users are informed. Before the operating system shows its permission dialog, the app displays a disclosure screen explaining that background location will be collected and why. Permission must be granted explicitly and can be revoked at any time in the system settings. On Android, while a round is active, a persistent foreground-service notification (“Senex — round in progress”) is shown so the officer always knows recording is running. On iOS, the system’s own location indicator is displayed.
Exactly what is transmitted. A route point is recorded roughly every 10 metres of movement and contains:
What is not transmitted. The app deliberately discards altitude, altitude accuracy and the mock-location flag. Route points do not include battery level, any device identifier, or any advertising identifier.
Temporary storage on the phone. Points are first written to the device and uploaded to the server in batches. This lets a round be recorded correctly in areas without coverage: when connectivity returns, pending points are uploaded automatically. Once uploaded, they are deleted from local storage. This local buffer is also discarded on sign-out.
When an officer logs a checkpoint — by scanning its QR code or selecting it manually — the app takes a single position reading at that moment and attaches it to the record, together with any photos and notes the officer adds. Its purpose is to evidence that the checkpoint was logged physically on site rather than remotely. It is a one-shot, foreground-only reading; no continuous tracking is associated with this feature. If a round is active at that moment, the last position already recorded by the round is reused instead of taking a new reading.
The Hombre Alerta module periodically asks officers to confirm they are safe. On confirmation, the app attaches a single position reading so the supervisor knows where the confirmation came from. This reading is technically optional: if the device cannot obtain it, the confirmation is still submitted without coordinates and is never blocked for that reason.
Within the Hombre Alerta module, when an officer stops answering Proof-of-Life confirmations, their last known location is shown to other officers of the same company so they can go and check on them. Alongside the location, the app shows the officer’s name, how long they have been silent and how many confirmations they have missed.
To be explicit: this is location data the app displays to other users, not only to supervisors. Visibility is limited to officers belonging to the same company. From that screen an officer can open those coordinates in the map app installed on their own phone; at that point the coordinates are handed to that map app, which is governed by its own privacy policy. Senex bundles no map SDK and no mapping provider.
Location coordinates never travel through the push notification provider: escalation notifications carry only a screen identifier, and coordinates are fetched directly from our server using the officer’s authenticated session.
The app uses the device camera for three purposes.
Officers scan QR codes on checkpoints and on authorised persons. The code content is sent to our server to resolve which checkpoint or which person it corresponds to.
In the entry log, the app can read the PDF417 barcode printed on Costa Rican national ID cards (cédula) and driving licences, so that details do not have to be typed by hand.
Decoding happens entirely on the device, offline, without sending the image or the barcode to any server. The national ID barcode contains identification number, first name, first and second surname, sex, date of birth and document expiry date. The driving licence barcode contains identification number and licence class.
Of all those fields, only those needed to complete the entry record are sent to our servers: identification number, name and document type. Sex, date of birth and expiry date are discarded on the device and are neither stored nor transmitted.
Users can take photos with the camera and attach them to: checkpoint records, commercial entry records (where the photo may include the visitor or their vehicle), incident reports, maintenance orders, key handovers, material releases and water meter readings. These photos are uploaded to our server against the corresponding record and are visible to authorised staff of the contracting organisation.
Photos are also held temporarily in the app’s private storage on the device while the record is being completed and submitted.
We process the following data about people who use the app:
Users can edit their own name, email, phone, identification number, document type, password and language from within the app.
The app uses OneSignal to deliver push notifications (entry alerts, Proof-of-Life prompts, escalations and announcements). On sign-in, the app obtains a device subscription identifier from OneSignal and sends it to our server so notifications can be routed to the right phone. That identifier is also stored locally on the device.
For delivery on Android, OneSignal relies on Google’s Firebase Cloud Messaging. Both services receive the subscription identifier and the notification content; they do not receive location coordinates or visitor data.
We collect the device model and manufacturer, and the platform (Android or iOS). The model is sent at sign-in to identify the device associated with the session.
For the Hombre Alerta module, whose alarms must ring reliably even on a locked screen, we additionally send a technical device diagnostic: whether the notification permission is granted, whether the app is exempt from battery optimisation, the make and model, and the configured priority of the alarm channel. It is used solely so a supervisor can detect that a phone will not ring and fix it before it becomes a problem.
The app does not access the device’s unique identifier, IMEI, MAC address or advertising identifier.
The Hombre Alerta module schedules local alarms on the device. These are scheduled and fired locally and involve no data transmission. So they ring at the exact time and survive a phone restart, the app requests the corresponding system permissions.
By the nature of the service, the app records data about people who are not Senex users and have no account: mainly visitors, suppliers and contractors entering a guarded property.
The following may be recorded about them: identification number, name, phone, email, document type, vehicle licence plate, who they are visiting and which unit, entry and exit times, number of accompanying persons, notes, attached documents and photos taken at the gate.
This data is collected on the instructions and on behalf of the organisation that administers the property, as part of its access control, and remains in its custody within the system. The basis for collection is each property’s entry regulations and posted notices, which that administration is responsible for maintaining. Ingenelectric S.A. provides and operates the system in which the data is stored.
If you visited a property that uses Senex and wish to exercise your rights over this data, write to privacidad@senexcr.com indicating the property and approximate date, and we will route your request to the relevant administration.
| Data | Purpose |
|---|---|
| Background location during a round | Reconstruct and verify the patrol route |
| Single location reading at checkpoints | Evidence physical presence on site |
| Single location reading on Proof of Life | Locate an unresponsive officer, for their safety |
| Camera and document scanning | Make entry logging faster and more accurate |
| Photos | Document entries, incidents and completed work |
| Account data | Authentication, permission control and operational communication |
| Push identifier and device data | Deliver notifications and ensure alarms ring |
| Visitor data | Access control and the property’s security log |
We do not use any data for advertising, for commercial profiling, or to sell or transfer to third parties for marketing purposes.
We state this explicitly, because absence is relevant information too:
| Permission | Why |
|---|---|
| Precise and approximate location | Log checkpoints and Proof-of-Life confirmations |
| Background location | Record the complete route of an active round |
| Location-type foreground service | Keep round recording running with a visible notification |
| Camera | Scan QR codes and documents, and take photos |
| Notifications | Deliver operational alerts and Proof-of-Life alarms |
| Exact alarms and boot completed | Fire Proof-of-Life alarms on time and restore them after a phone restart |
| Notification policy | Allow the Proof-of-Life alarm to sound even in Do Not Disturb mode |
| Storage | Save and attach photos and documents. Declared for compatibility with older Android versions; on recent system versions it no longer grants access to your gallery |
On iOS, the app additionally declares microphone and photo library access for attachment features. Those features are not active in the current version and, while they are not, the app neither records audio nor reads your photo library.
All permissions can be revoked at any time in the operating system settings. Revoking location permission prevents recording rounds and checkpoints, but does not prevent the rest of the app from being used.
Barcode scanning uses a library that runs on the device itself, and text-to-speech uses the operating system’s own speech synthesiser: in both cases the content is not sent to any external service.
Data is stored on servers operated by Ingenelectric S.A. Each contracting organisation has its own instance of the system, and one organisation’s data is not reachable from another’s instance. Communication between the app and the server is always encrypted using HTTPS.
| Data | Retention period |
|---|---|
| Patrol route location points | 90 days |
| Round record (start, end, tracking mode) | 24 months |
| Checkpoint records and their photos | 12 months |
| Entry logs, visitor data and photos | 12 months |
| Proof-of-Life confirmations and their coordinates | 6 months |
| Account data | While the account is active and the agreement with the contracting organisation is in force |
| Temporary buffer on the device | Until the record is uploaded to the server, or until sign-out |
When an agreement with a contracting organisation ends, its data is retained for a further 90 days to allow export, and is then deleted.
Senex accounts are created by the contracting organisation, not by the user, so deletion is handled by request.
You can request it at senexcr.com/eliminar-cuenta/ or by writing to privacidad@senexcr.com. We will verify the request with the contracting organisation and, once confirmed, delete the account and its associated personal data within 30 calendar days.
What is deleted: the account and its credentials, the profile (name, email, phone, identification number, profile photo), the push notification identifier and device diagnostic data.
What is retained and why: operational logs — entry records, checkpoint records, patrol routes, incidents and work orders — form part of the property’s security record and belong to the contracting organisation, not to the individual user. They are kept for the periods set out in section 14 and then deleted. Where technically possible, they are dissociated from the personal profile.
Uninstalling the app erases the data that was held on the phone, but does not delete the account or the data on the server; a deletion request is required for that.
Under Costa Rica’s Law No. 8968 on the Protection of Individuals with regard to the Processing of their Personal Data and its regulations, and Panama’s Law 81 of 2019 on Personal Data Protection, you have the right to:
To exercise any of these rights, write to privacidad@senexcr.com. We will respond within the periods established by applicable law.
Senex is a workplace and residential tool intended for adults. It is neither designed for nor directed at children under 18, and we do not knowingly collect data from children as users of the app. If we find that an account was created in the name of a minor, we will delete it.
We apply technical and organisational measures to protect the data: encrypted transmission over HTTPS, authentication using expiring session credentials, role- and permission-based access control, separation of each contracting organisation’s data, and irreversible password storage. No system is completely immune, but we work to keep these measures current.
If we change this policy, we will update the “last updated” date at the top of the document. Where a change materially affects how your data is processed — in particular if it expands location collection — we will notify you inside the app before the change takes effect.
Ingenelectric S.A.
Corporate ID 3-101-721867
300 metres east and 30 metres south of the main gate of Edgardo Baltodano Stadium
Liberia, Guanacaste, Costa Rica
Privacy: privacidad@senexcr.com
General: info@senexcr.com · (506) 8703-4552 · (506) 2665-0244
Commercial contact in Panama: (507) 6511-2222 · (507) 775-2515