Privacy policy · Licence terms · Terms of use · Account deletion
LF Software develops and licenses software solutions for security operations, situational intelligence, intelligent video surveillance and business management.
Most LF Software products are designed to be installed and operated on infrastructure owned or controlled by the customer. In these cases, the organization operating the installation is generally responsible for the processing of personal data.
This Privacy Policy explains how personal data is processed by LF Software and by organizations operating LF Software installations, in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR).
In customer-owned deployments, the organization operating the installation acts as the data controller and determines which accounts are created, which data is collected, how the data is used and how long it is retained. LF Software does not routinely access data stored within customer-operated installations.
LF Software acts as a data controller only for personal data processed directly through licensing, sales enquiries, demonstration requests, technical support and direct communication by email.
If you are using one of our applications through your employer, a client, a security company or another organization, that organization is usually responsible for the processing of your personal data.
Account information: user identifier, encrypted password, assigned role, and two-factor authentication data when enabled.
Operational information: incident records, geographical information associated with occurrences, reports and analytical data.
Location data: device location used for operational mapping, and background location sharing when explicitly enabled by the user.
Notifications: Firebase Cloud Messaging (FCM) notification token.
Biometric authentication: fingerprint and device-based authentication are processed locally by the device’s operating system. LF Hawk Watch does not collect or store biometric data.
Account and shift information: employee identifier, encrypted password, assigned role and shift records.
Location data: real-time device location, background location during active shifts, and patrol records.
Voice communications: push-to-talk audio transmitted between authorized devices.
Patrol records: NFC checkpoint records, date and time of patrol activities.
Notifications: Firebase Cloud Messaging notification token.
Account information: email address and encrypted password.
Video events: images or video clips associated with alert events, event classifications and timestamps.
Configuration data: installations, zones, alert rules and surveillance modes.
Notifications: Firebase Cloud Messaging notification token.
Account information: user identifier, encrypted password, permissions profile and two-factor authentication data.
Management information: business data recorded by the organization, including information relating to customers, employees, contracts, invoices, projects and operational activities.
Audit records: user activity, timestamps and change history.
Depending on the context, personal data is processed on one or more of the following legal bases under Article 6 of the GDPR: performance of a contract, compliance with legal obligations, legitimate interests, and user consent where applicable.
Processing activities associated with authentication, system security, audit logs and licence management are generally based on contractual necessity and legitimate interests.
LF Software applications may use third-party services to provide specific functionality.
Firebase Cloud Messaging (Google) is used exclusively to deliver push notifications. Only the technical information required for notification delivery, such as the device notification token, is shared with the service.
Mapping services: applications may use map services and publicly available geographical data to provide mapping functionality. Additional information about third-party data processing can be found in the privacy policies of those providers.
Certain third-party services used by the applications may process information outside the European Economic Area. Where international transfers occur, they are subject to the safeguards required under the GDPR, including contractual and organizational measures designed to protect personal data.
In customer-operated installations, data-retention periods are determined by the organization acting as the data controller.
Personal data processed directly by LF Software, including support requests and licensing information, is retained only for as long as necessary to provide services, fulfil contractual obligations, comply with applicable legal requirements and resolve disputes.
LF Software implements technical and organizational measures designed to protect personal data, including encrypted communications (HTTPS), password hashing, authentication controls, role-based access control, audit logging and two-factor authentication where available.
For customer-owned installations, customers are responsible for maintaining the security of their own infrastructure.
LF Hawk Watch and LF Vision include automated classification technologies designed to support operational activities. These technologies assist users by classifying events and generating recommendations. They are not intended to produce legal effects or similarly significant decisions concerning individuals within the meaning of Article 22 of the GDPR.
Subject to applicable law, you have the right to access your personal data, correct inaccurate information, request deletion, restrict processing, object to processing, request data portability, and withdraw consent where processing is based on consent.
If your data is stored within a customer-operated installation, requests should be directed to the organization responsible for that installation. If you are unable to identify the appropriate organization, you may contact LF Software for assistance.
You have the right to lodge a complaint with the competent supervisory authority responsible for data protection in your jurisdiction. Residents of Portugal may contact the Portuguese Data Protection Authority.
Information about account deletion can be found on the Account Deletion page.
This Privacy Policy may be updated periodically. When material changes are made, the date shown at the top of this page will be updated, and customers may be notified through the applications or by email.
Privacy and data protection enquiries: privacidade@lf-softwares.com
General enquiries: geral@lf-softwares.com