Access and Perimeter Control

Privacy Policy

Effective date: July 7, 2026  ·  Last updated: July 7, 2026

This Privacy Policy explains how Arosys, S.A., operating as Access and Perimeter Control ("APC," "we," "us," or "our"), collects, uses, discloses, and safeguards information when you use the APC mobile application (com.aroaero.apc_mobile, the "App") and the related visitor-management services (together, the "Service").

The App is a professional visitor- and access-management tool used at airport, hangar, and other controlled-access facilities. It is intended for use by registered residents/sponsors, security personnel, facility administrators, and authorized visitors. By creating an account or using the App, you agree to this Privacy Policy.

1. Who we are (Data Controller)

The Service is operated by Arosys, S.A. ("APC"), a company organized under the laws of the Republic of Guatemala. For any privacy question, request, or complaint, contact us at:

Email: contact@arosyssa.com

Where APC provides the Service to a facility operator (for example, an airport or hangar operator), that operator may act as an independent or joint controller of visitor data processed through their site. In those cases this policy describes our processing; the operator's own notices govern their use of the data.

2. Information we collect

We collect only the information needed to operate a secure access-control system. Categories include:

2.1 Account and profile information

2.2 Identity and verification data

2.3 Visitor and access records

2.4 Vehicle data

2.5 Camera, photos, and scans

2.6 Communications content

2.7 Device authentication (biometrics)

2.8 Device and technical data

2.9 Diagnostics

We do not knowingly collect data from children (see Section 9), and we do not use your personal data for third-party advertising.

3. How we use information

We process the information above to:

Legal bases

Depending on the applicable law, we rely on: your consent (e.g., camera, notifications, optional communications); performance of a contract (running the access-control service you signed up for); our legitimate interests (facility security, fraud prevention, service improvement); and legal obligation (retention of security records where required). You can withdraw consent at any time — see Section 8.

4. Aggregated and de-identified data

We may create aggregated or de-identified statistics (for example, hourly gate throughput or facility occupancy trends) for facility operators. This data is combined so that it does not identify any individual, and we do not re-link it to you. Where such reporting is shared with operators or third parties, it is aggregated with a minimum group size so individuals cannot be singled out.

5. How we share information

We do not sell your personal information. We share it only as follows:

Some providers (e.g., Google) may process data on servers outside Guatemala. Where data crosses borders, we rely on appropriate safeguards offered by those providers.

6. Data retention

We keep personal data only as long as necessary for the purposes above:

When retention expires, data is deleted or irreversibly anonymized.

7. How we protect information

No system is perfectly secure, but we work to protect your data using industry-standard measures.

8. Your rights and choices

Depending on your jurisdiction, you may have the right to:

To exercise any right, email contact@arosyssa.com from the address on your account. We will respond within the period required by applicable law.

Some data — such as security audit records or a visitor log the facility is legally required to keep — may be retained even after an account deletion request, to the extent the law permits or requires.

Account and data deletion

To request deletion of your account and associated personal data, email contact@arosyssa.com with the subject line "Data Deletion Request," or use the in-app account settings where available. We will verify your identity and process the request as described above.

9. Children's privacy

The Service is intended for adults and authorized personnel and is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect their data. If you believe a child has provided us personal information, contact us and we will delete it.

10. Permissions the App requests

The App requests these device permissions; each is used only for the stated purpose and can be managed in your device settings:

PermissionWhy
CameraScan QR codes, read license plates, capture ID/vehicle photos
MicrophoneRecord voice messages and place in-app audio/video calls
Photos / FilesAttach or upload documents and images
NotificationsDeliver operational access alerts
BiometricsOn-device fingerprint/face unlock (data never leaves the device)
Network stateDetect connectivity for offline sync

Denying a permission may disable the related feature but otherwise lets you use the App.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted here with a new "Last updated" date and, where appropriate, announced in the App. Continued use after changes take effect constitutes acceptance.

12. Governing law

This Privacy Policy is governed by the laws of the Republic of Guatemala, including its constitutional privacy protections, without regard to conflict-of-law rules.

13. Contact us

Arosys, S.A. (Access and Perimeter Control)
Email: contact@arosyssa.com