Privacy Policy

Last updated 28 July 2026

This policy explains what personal data CMMSAI processes, why, who we share it with, and the choices you have. It covers the CMMSAI application at cmmsai.cloud and this website.

1.Who we are

CMMSAI (“CMMSAI”, “we”, “us”) provides a maintenance-management service to organizations. Two relationships matter for privacy:

  • Customer data. When your employer uses CMMSAI, they decide what data goes into the system and why. They are the controller; we process it on their instructions under our agreement with them. If you want your data corrected or removed, start with your organization's CMMSAI administrator.
  • Our own data. When you request a demo or correspond with us, we are the controller for that information.

2.What we process

  • Account data — name, work email, phone number, job title, role and permissions, organization, and login history.
  • Operational data you enter — assets, work orders, preventive-maintenance plans, inspections, inventory, vendors, knowledge-base articles, comments, photos and attachments. This can incidentally include personal data, for example the name of the technician assigned to a job.
  • Sensor and device data — telemetry from IoT devices you connect (for example temperature, humidity, door state, mains power, signal strength), plus the alerts derived from it.
  • Audit and security records — a tamper-evident log of create, update and delete actions, electronic signatures, authentication events, failed logins and session activity, including IP address and browser user agent.
  • Demo requests — the name, work email, company, phone, team size and message you submit through the demo form on this site.
  • Support correspondence — messages you send us and our replies.

We do not run advertising or third-party analytics trackers on this site, and we do not buy personal data from brokers.

3.Why we process it

  • To provide the service — authenticating you, showing your organization's data, generating work orders, sending notifications and alerts, and producing reports.
  • To keep the service secure — detecting and investigating abuse, enforcing access control, and maintaining the audit trail your organization may be required to keep.
  • To support and bill customers — responding to requests, issuing invoices, and managing subscriptions.
  • To respond to enquiries — following up on demo requests you submit.

Where the law requires a lawful basis, we rely on performance of a contract, our legitimate interest in operating and securing the service, and consent where you have given it. You can withdraw consent for marketing contact at any time.

4.Cookies and local storage

CMMSAI does not use advertising or analytics cookies. The application stores a small number of values in your browser's local storage so the product works:

  • your access and refresh tokens, and your active organization, so you stay signed in;
  • interface preferences — whether the sidebar is collapsed, display density, and your saved IoT widget layouts.

Signing out clears your session tokens. Clearing site data in your browser removes the rest.

5.Who processes data on our behalf

We use a small number of subprocessors to run the service:

  • Hosting — our application, database and object storage run on dedicated servers we control.
  • Network and DNS — Cloudflare, for DNS, TLS termination at the edge and protection against attack traffic.
  • Transactional email — Scaleway Transactional Email, to deliver invitations, password resets, alerts and notifications.
  • AI features — where you use the AI assistant or work-order guidance, the relevant prompt (which may include work-order, asset and knowledge-base context) is sent to our model provider, OpenRouter, and the underlying model vendor, to generate a response. Content sent for this purpose is not used by us to train models.

We do not sell personal data. We disclose it only to these processors, to your own organization, and where we are legally required to do so.

6.Where data is stored

Customer data is stored on servers in Europe. Some subprocessors listed above may process data in other countries; where that happens we rely on the safeguards in their terms, including standard contractual clauses where applicable. Specific hosting regions can be agreed per contract — ask us before you sign.

7.How long we keep it

  • While your subscription is active — operational data is retained so the service works and your history stays intact.
  • Audit records — retained for the period your organization's compliance obligations require, and deliberately not editable, since their value depends on being complete.
  • Backups — encrypted database backups are taken nightly and expire on a rolling retention schedule, so deleted data can persist in backups for a short period after deletion.
  • Demo requests — kept while we are in contact with you and for a reasonable period afterwards.

On termination, customer data is deleted or returned in line with the customer agreement.

8.How we protect it

  • Each organization runs in an isolated tenant, enforced in the application layer.
  • Access is invitation-only, with role-based permissions and optional organization-wide multi-factor authentication.
  • Traffic is encrypted with TLS; application secrets and sensitive fields are encrypted at rest.
  • Changes are written to a cryptographically hash-chained audit trail that can be independently verified.
  • Approvals can require password re-authentication and are bound to the exact record signed.
  • Failed-login lockout, session revocation and a password policy with reuse prevention are enforced.

No service is perfectly secure. If we become aware of a breach affecting your data, we will notify affected customers without undue delay.

9.Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a copy in a portable format, and to complain to a supervisory authority.

If your data is in a customer's workspace, contact that organization's administrator — we will support them in responding. For data we control, contact us directly using the details below.

10.Changes and contact

We will update this policy as the service changes, and will revise the date at the top. Material changes will be communicated to customers.

Questions about this policy, or a request about your data? Email privacy@cmmsai.cloud. Security questions, including our controls overview, can go to the same address.