Effective date: July 7, 2026 · Last updated: July 7, 2026
This Privacy Policy explains how Arosys, S.A., operating as Access and Perimeter Control ("APC," "we," "us," or "our"), collects, uses, discloses, and safeguards information when you use the APC mobile application (com.aroaero.apc_mobile, the "App") and the related visitor-management services (together, the "Service").
The App is a professional visitor- and access-management tool used at airport, hangar, and other controlled-access facilities. It is intended for use by registered residents/sponsors, security personnel, facility administrators, and authorized visitors. By creating an account or using the App, you agree to this Privacy Policy.
1. Who we are (Data Controller)
The Service is operated by Arosys, S.A. ("APC"), a company organized under the laws of the Republic of Guatemala. For any privacy question, request, or complaint, contact us at:
Where APC provides the Service to a facility operator (for example, an airport or hangar operator), that operator may act as an independent or joint controller of visitor data processed through their site. In those cases this policy describes our processing; the operator's own notices govern their use of the data.
2. Information we collect
We collect only the information needed to operate a secure access-control system. Categories include:
2.1 Account and profile information
Name, email address, and phone number
Role (resident/sponsor, guard, administrator, visitor)
Password (stored only as a salted hash — never in plain text)
Contact preferences (e.g., WhatsApp opt-in) and referral source
2.2 Identity and verification data
Government identification numbers you or a facility provide, which may include a Guatemalan DPI (national ID) number or passport number
Photographs of identity documents that you or a guard capture for verification
2.3 Visitor and access records
Visitor name, phone number, visit purpose, and authorized time window
Sponsor/host relationship and approval status
Entry and exit timestamps and on-site / off-site status
Gate, hangar, and facility associated with an access event
2.4 Vehicle data
License-plate number, entered manually or read on-device by our automated license-plate recognition (ALPR) feature
Vehicle year, make, model, and color
Owner-to-vehicle relationships
2.5 Camera, photos, and scans
The App uses the device camera to scan QR access codes, read license plates, and capture ID or vehicle photos. Images used purely for on-device recognition (QR/plate detection) are processed locally and are not stored unless a record is created.
2.6 Communications content
Text, voice messages, and video messages you send through the in-app chat
Real-time audio/video when you place or receive an in-app call (processed through our video provider; see Section 5)
2.7 Device authentication (biometrics)
If you enable biometric unlock (fingerprint or face), that verification is performed entirely on your device by the operating system. We never receive, store, or transmit your biometric data — we only receive a success/failure signal from the OS.
2.8 Device and technical data
Push-notification token, device platform, and app version
IP address and security/audit metadata (action performed, target, timestamp)
Approximate location only in the sense of which facility gate an access event occurs at. The App does not perform continuous GPS/background location tracking.
2.9 Diagnostics
Crash reports and basic diagnostic data via Firebase Crashlytics to keep the App stable.
We do not knowingly collect data from children (see Section 9), and we do not use your personal data for third-party advertising.
3. How we use information
We process the information above to:
Create and manage your account and authenticate you securely
Register, approve, deny, and log visitors and vehicles
Verify identity at controlled-access gates
Read QR codes and license plates to speed entry/exit
Send operational notifications (e.g., a visitor is waiting, an approval is needed, an access decision)
Enable in-app messaging and video calls between residents, guards, and staff
Maintain a tamper-evident security audit trail
Detect, prevent, and investigate fraud, security incidents, and misuse (including blacklist enforcement)
Provide support, fix bugs, and improve reliability
Comply with legal obligations and enforce our Terms
Legal bases
Depending on the applicable law, we rely on: your consent (e.g., camera, notifications, optional communications); performance of a contract (running the access-control service you signed up for); our legitimate interests (facility security, fraud prevention, service improvement); and legal obligation (retention of security records where required). You can withdraw consent at any time — see Section 8.
4. Aggregated and de-identified data
We may create aggregated or de-identified statistics (for example, hourly gate throughput or facility occupancy trends) for facility operators. This data is combined so that it does not identify any individual, and we do not re-link it to you. Where such reporting is shared with operators or third parties, it is aggregated with a minimum group size so individuals cannot be singled out.
5. How we share information
We do not sell your personal information. We share it only as follows:
With your facility operator and its authorized staff — residents/sponsors, guards, and administrators at the site see the visitor, vehicle, and access data necessary to do their jobs.
Service providers (processors) who help us run the Service under contract:
LiveKit — real-time audio/video transport for in-app calls.
Cloud hosting and database infrastructure that stores the records above.
Legal and safety — when required by law, subpoena, or regulator, or to protect the rights, safety, and security of users, the public, or APC.
Business transfers — if APC is involved in a merger, acquisition, or asset sale, data may transfer as part of that transaction, subject to this policy.
Some providers (e.g., Google) may process data on servers outside Guatemala. Where data crosses borders, we rely on appropriate safeguards offered by those providers.
6. Data retention
We keep personal data only as long as necessary for the purposes above:
Account data — for the life of your account, then deleted or de-identified after closure (subject to the exceptions below).
Visitor and access records — retained for the operating and security needs of the facility; as a default we retain raw records for up to 12 months unless the operator or law requires a different period.
Security audit logs — retained longer where needed for security and legal compliance; these are tamper-evident by design.
Aggregated/de-identified data — may be kept indefinitely.
When retention expires, data is deleted or irreversibly anonymized.
7. How we protect information
Passwords are salted and hashed; sensitive fields are access-controlled.
Data in transit is encrypted with HTTPS/TLS.
Edge/gate devices use encrypted local storage and HMAC-signed audit logs.
Access is restricted by role, and security events are logged in a hash-chained audit trail.
No system is perfectly secure, but we work to protect your data using industry-standard measures.
8. Your rights and choices
Depending on your jurisdiction, you may have the right to:
Access the personal data we hold about you
Correct inaccurate data
Delete your data ("right to be forgotten")
Object to or restrict certain processing
Withdraw consent for camera, notifications, or optional features (via your device settings) at any time
Port your data to another service
To exercise any right, email contact@arosyssa.com from the address on your account. We will respond within the period required by applicable law.
Some data — such as security audit records or a visitor log the facility is legally required to keep — may be retained even after an account deletion request, to the extent the law permits or requires.
Account and data deletion
To request deletion of your account and associated personal data, email contact@arosyssa.com with the subject line "Data Deletion Request," or use the in-app account settings where available. We will verify your identity and process the request as described above.
9. Children's privacy
The Service is intended for adults and authorized personnel and is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their data. If you believe a child has provided us personal information, contact us and we will delete it.
10. Permissions the App requests
The App requests these device permissions; each is used only for the stated purpose and can be managed in your device settings:
Permission
Why
Camera
Scan QR codes, read license plates, capture ID/vehicle photos
Microphone
Record voice messages and place in-app audio/video calls
Photos / Files
Attach or upload documents and images
Notifications
Deliver operational access alerts
Biometrics
On-device fingerprint/face unlock (data never leaves the device)
Network state
Detect connectivity for offline sync
Denying a permission may disable the related feature but otherwise lets you use the App.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be posted here with a new "Last updated" date and, where appropriate, announced in the App. Continued use after changes take effect constitutes acceptance.
12. Governing law
This Privacy Policy is governed by the laws of the Republic of Guatemala, including its constitutional privacy protections, without regard to conflict-of-law rules.