IoT Manager Privacy Policy
Last updated: August 16, 2026
Contents
- About this Privacy Policy
- Who operates IoT Manager
- Information we collect
- Google Sign-In
- Organizations, projects, devices, and telemetry
- Technical data and push notifications
- Subscription and billing information
- How we use information
- Legal and operational grounds for processing
- How information is shared
- Infrastructure and international processing
- Data security
- Data retention
- Account deletion
- Organization data and organization deletion
- Cookies and similar technologies
- Third-party services
- Your privacy choices and rights
- Children
- Changes to this Privacy Policy
- Contact
1. About this Privacy Policy
This Privacy Policy explains how IoT Manager collects, uses, stores, protects, and otherwise processes information when you use the IoT Manager Android application, website, APIs, dashboards, notification services, and related services.
IoT Manager is an Internet of Things ("IoT") monitoring platform. Its core purpose is to allow users and organizations to connect projects and devices, receive telemetry, visualize operational data, configure dashboards, and receive alerts and notifications.
This Privacy Policy applies specifically to IoT Manager. It supplements Luminatti's general privacy information. If there is a conflict between a general Luminatti privacy statement and this Privacy Policy regarding the operation of IoT Manager, this Privacy Policy governs for IoT Manager.
2. Who operates IoT Manager
IoT Manager is developed and operated exclusively by:
Luminatti Sistemas Informáticos, C.A.
RIF: J-406773107
Country: Venezuela
Email: ****@luminatti.online
Corporate website: https://luminatti.online
IoT Manager: https://iot.luminatti.online
In this Privacy Policy, "Luminatti," "we," "us," and "our" refer to Luminatti Sistemas Informáticos, C.A.
3. Information we collect
The information we process depends on how you use IoT Manager and which features are enabled for your account or organization.
3.1 Account information
We may process information such as:
- Name.
- Email address.
- Internal account identifier.
- Identifier received from an authentication provider.
- Profile image, when made available by the authentication provider.
- Account creation date.
- Last sign-in or account activity information.
- Language and interface preferences.
- User-specific settings.
- Organization memberships.
- Roles and permissions.
IoT Manager does not need to receive or store your Google Account password.
3.2 Access, security, and audit information
To secure and operate the service, we may process:
- IP address.
- Date and time of access.
- Sign-in and session events.
- Failed or suspicious authentication attempts.
- Account and administrative changes.
- Security events.
- Audit records.
- Actions taken within organizations, projects, and other protected areas when logging is necessary for security, accountability, or troubleshooting.
3.3 Information you provide to us
If you contact Luminatti for support, billing, privacy, or other requests, we may process the information you choose to provide, such as your name, email address, organization, message content, and information reasonably necessary to respond to your request.
4. Google Sign-In
IoT Manager uses Sign in with Google as an authentication method.
When you sign in with Google, we may receive basic account information authorized through the sign-in process, such as:
- Your Google account identifier.
- Your name.
- Your email address.
- Your profile image, when available.
We use this information to:
- Create or identify your IoT Manager account.
- Authenticate you.
- Associate your account with the correct organizations, projects, roles, and permissions.
- Display basic profile information.
- Protect the security of your account and the service.
We do not use information obtained through Google Sign-In for advertising, advertising profiling, or sale to third parties.
We do not receive your Google password.
If IoT Manager later requests access to additional Google data or scopes, this Privacy Policy will be updated as appropriate before or when those features are made available.
5. Organizations, projects, devices, and telemetry
IoT Manager can be used by individuals and by organizations. Organizations may contain projects, dashboards, devices, datastreams, widgets, members, roles, alerts, configurations, and operational history.
5.1 Device and telemetry data
Depending on how a customer configures IoT Manager and its connected devices, we may process:
- Device identifiers and names.
- Connectivity status.
- Datastream identifiers and configuration.
- Sensor measurements.
- Electrical, mechanical, environmental, industrial, or other operational measurements.
- Digital states.
- Counters.
- Timestamps.
- Device events.
- Alert conditions.
- Active and resolved alerts.
- Alert acknowledgement status.
- Alert pause settings.
- Dashboard and widget configuration.
- Historical telemetry and derived operational information.
The specific meaning and sensitivity of telemetry are determined by the customer and the devices the customer chooses to connect.
5.2 Customer responsibility for telemetry
Customers decide what their devices transmit to IoT Manager. Luminatti does not independently determine the real-world meaning of each sensor value or datastream.
If a customer configures a device or integration to transmit personal data, location information, information about employees, customers, visitors, or any other information relating to identifiable individuals, the customer is responsible for ensuring that it has the necessary notices, permissions, legal grounds, and safeguards to collect and transmit that information.
5.3 Organization data
A user's membership in an organization gives that user access according to the permissions assigned by the organization.
Organization data is not treated as the personal property of each individual member. Deleting an individual user account does not automatically delete the organization's projects, devices, telemetry, dashboards, alerts, or other shared operational records.
6. Technical data and push notifications
To provide and protect IoT Manager, we may process limited technical information, including:
- Application version.
- Operating system and device platform information.
- Network and connection information.
- Session information.
- Technical error information.
- Service and security logs.
- Installation identifiers or push notification tokens required to deliver notifications.
6.1 Firebase Cloud Messaging
IoT Manager may use Firebase Cloud Messaging (FCM), a Google service, to deliver operational notifications such as device alerts, project alerts, critical events, and other service-related notices.
Push notification tokens and related technical identifiers are used to route messages to the appropriate installation. Luminatti does not use those identifiers for advertising.
Delivery of a push notification also depends on third-party infrastructure, device settings, network availability, and operating-system behavior.
7. Subscription and billing information
IoT Manager offers a free tier and may offer paid monthly or annual plans with higher limits, additional capabilities, and/or enhanced performance.
Paid plans are contracted through the official IoT Manager website at:
https://iot.luminatti.online
We may process subscription-related information such as:
- Plan name.
- Subscription status.
- Billing period.
- Start, renewal, cancellation, and expiration dates.
- Invoice or transaction identifiers.
- Amounts charged or refunded.
- Information needed to provide billing support.
Where a third-party payment processor is used, that provider may process payment card or financial information directly under its own terms and privacy practices. IoT Manager does not need to store full payment card details when payment processing is handled by such a provider.
8. How we use information
We use information for purposes that include:
8.1 Providing IoT Manager
- Creating and maintaining accounts.
- Authenticating users.
- Managing organizations, projects, roles, and permissions.
- Registering and organizing devices.
- Receiving and processing telemetry.
- Displaying dashboards and widgets.
- Maintaining telemetry history according to applicable plan limits or agreements.
- Generating and managing alerts.
- Sending operational notifications.
- Synchronizing supported information in real time.
- Providing customer support.
8.2 Security, fraud prevention, and service integrity
- Detecting unauthorized access.
- Investigating suspicious activity.
- Preventing abuse and fraud.
- Protecting accounts, organizations, devices, and infrastructure.
- Maintaining audit trails where appropriate.
- Diagnosing security and operational incidents.
8.3 Service operation and improvement
- Troubleshooting errors.
- Measuring service reliability and performance.
- Planning infrastructure capacity.
- Improving usability and stability.
- Developing and testing new features.
- Maintaining and updating the service.
8.4 Billing and administration
- Managing subscriptions.
- Issuing invoices or billing records.
- Processing or documenting refunds.
- Responding to billing requests.
- Enforcing plan limits and contractual entitlements.
We do not sell our users' personal information.
9. Legal and operational grounds for processing
Depending on the circumstances and applicable law, we process information because it is necessary to provide the service you or your organization requested, to perform or administer a contract, to comply with legal obligations, to protect the security and integrity of IoT Manager, to pursue legitimate operational interests, or because you have provided consent where consent is required.
Where IoT Manager processes data on behalf of an organization, the organization may determine the purpose for which that data is collected and used. In those situations, users should also review the privacy notices and policies of the organization responsible for the connected devices or project.
10. How information is shared
We do not sell personal information.
We may share or make limited information available when reasonably necessary to operate, secure, support, or administer IoT Manager.
This may include:
- Google, in connection with Google Sign-In.
- Google Firebase, in connection with Firebase Cloud Messaging.
- Data-center, network, infrastructure, backup, and hosting providers.
- Payment processors or billing service providers used for paid plans.
- Professional advisers or service providers when reasonably necessary for legal, accounting, security, or operational purposes.
We may also disclose information when reasonably necessary to:
- Comply with applicable law or a valid legal process.
- Respond to a competent governmental or judicial authority.
- Investigate suspected fraud, abuse, or unlawful activity.
- Protect users, customers, Luminatti, or the public from a security threat.
- Establish, exercise, or defend legal claims.
- Protect the rights, property, systems, and infrastructure of Luminatti.
Service providers are given access only to information reasonably necessary for the services they provide and are expected to handle that information consistently with their contractual and legal obligations.
11. Infrastructure and international processing
Luminatti contracts rack and server infrastructure from third-party infrastructure providers operating robust facilities located in the United States and Canada.
As a result, information processed by IoT Manager may be stored or processed in the United States, Canada, Venezuela, or another location used by a necessary service provider.
We may use more than one infrastructure location for availability, redundancy, backup, performance, business continuity, or security.
Where information is transferred across borders, we take reasonable steps to protect it in accordance with this Privacy Policy and applicable legal obligations.
12. Data security
We use technical and organizational measures designed to reduce the risk of unauthorized access, disclosure, alteration, misuse, or loss of information.
Depending on the system and context, these measures may include:
- Encrypted network communications using HTTPS/TLS.
- Authentication and authorization controls.
- Role-based access.
- Separation of customer and organization access.
- Restricted administrative access.
- Logging and audit mechanisms.
- Infrastructure monitoring.
- Security updates and patching.
- Backup and recovery procedures.
- Protection of credentials and service secrets.
No Internet-connected service or storage system can guarantee absolute security. Customers also play an important role in security by controlling organization memberships, permissions, devices, integrations, and access to their own systems.
13. Data retention
We keep information only for as long as reasonably necessary for the purposes described in this Privacy Policy, for the applicable subscription or service, or as required for security, billing, contractual, dispute-resolution, or legal reasons.
Retention may vary by type of information.
13.1 Account information
Account information is normally retained while the account is active and during any applicable account-deletion period.
13.2 Telemetry and organization data
Telemetry and historical data retention may depend on:
- The customer's plan.
- Capacity and retention limits.
- Project configuration.
- The applicable business agreement.
- Technical or legal requirements.
13.3 Security and audit records
Security, diagnostic, and audit records may be retained for a reasonable period when needed to investigate incidents, prevent abuse, maintain accountability, or comply with legal obligations.
13.4 Backups
Information removed from active systems may remain for a limited period in protected backups until those backups are rotated, overwritten, or deleted through normal backup-retention procedures.
14. Account deletion
Users can request deletion of their IoT Manager personal account.
A deletion request may be initiated:
- Through the account-deletion option provided within IoT Manager when available.
- Through the public account-deletion resource at https://iot.luminatti.online/account-deletion.
- By contacting ****@luminatti.online.
We may require reasonable identity verification before processing a deletion request.
14.1 30-day deletion period
When a valid deletion request is accepted, the account is normally scheduled for permanent deletion after 30 days.
This period is intended to allow secure processing of the request and help prevent irreversible deletion caused by error, abuse, or unauthorized activity.
Where the product provides a cancellation mechanism for a pending deletion request, a verified user may be able to cancel the request during this period.
14.2 What is deleted or anonymized
After the deletion period, we will delete or anonymize, as appropriate, information exclusively associated with the personal account, which may include:
- Personal profile information.
- Google authentication association.
- Personal preferences.
- Active sessions and session credentials.
- Push notification tokens.
- Other data that belongs exclusively to the deleted user account.
We may retain limited information when required by law or when reasonably necessary for fraud prevention, security, accounting, dispute resolution, or enforcement of legal rights.
14.3 Organization records are not deleted with a member account
Deleting a user's personal account does not automatically delete data controlled by an organization the user belonged to.
For example, it does not automatically delete:
- Organization projects.
- Devices.
- Telemetry.
- Dashboards.
- Alerts.
- Shared configurations.
- Operational history.
Where historical or audit records need to preserve the fact that an action occurred, the deleted user's identity may be anonymized or replaced with a non-identifying reference when reasonably possible.
15. Organization data and organization deletion
Organization owners or authorized administrators may request deletion of an organization and the data controlled exclusively by that organization.
A valid organization-deletion request is normally scheduled for permanent deletion after 30 days, subject to identity and authority verification.
Once the deletion becomes final, organization-controlled data will be removed from active systems according to the service's deletion process, subject to limited retention required by law, security, accounting, dispute resolution, or protected backup rotation.
Deletion of an individual member's account does not authorize that member to delete organization-owned data unless that member separately has the required organization authority.
16. Cookies and similar technologies
The IoT Manager website may use cookies or similar technologies that are reasonably necessary to:
- Maintain authenticated sessions.
- Protect forms and requests.
- Remember language or interface preferences.
- Maintain security.
- Prevent abuse.
If analytics, marketing, or other non-essential technologies are introduced in the future, we will update our notices and consent mechanisms as required.
17. Third-party services
IoT Manager depends on certain third-party services and infrastructure.
Those providers may process limited information necessary to perform their services. Their independent handling of information is also subject to their own legal obligations, policies, and contractual terms.
A customer may also choose to connect third-party devices, services, or integrations to IoT Manager. Luminatti does not control the independent privacy practices of third parties selected and controlled by the customer.
18. Your privacy choices and rights
Depending on applicable law and the context in which your information is processed, you may be entitled to request access, correction, deletion, restriction, portability, or information about how your personal data is processed, or to object to certain processing.
You may also withdraw consent where processing is based on consent, without affecting processing that was lawful before withdrawal.
To make a privacy request, contact:
****@luminatti.online
We may request reasonable information to verify your identity and, where relevant, your authority to act for an organization before fulfilling a request.
If your data is controlled by an organization using IoT Manager, some requests may need to be directed to that organization.
19. Children
IoT Manager is intended primarily for professional, technical, commercial, and industrial use and is not directed to children under 18.
We do not knowingly offer IoT Manager directly to children as a consumer service. If we learn that a child's personal information has been collected in circumstances where it should not have been, we will take reasonable steps to address the matter.
20. Changes to this Privacy Policy
We may update this Privacy Policy when IoT Manager changes, when new features or providers are introduced, when our data practices change, or when legal or regulatory requirements make an update appropriate.
The current version will be published at:
https://iot.luminatti.online/privacy
The "Last updated" date will identify the most recent revision. Where a change is material, we will take reasonable steps to notify affected users when appropriate.
21. Contact
Questions about this Privacy Policy, privacy requests, or account/data deletion can be sent to:
Luminatti Sistemas Informáticos, C.A.
RIF: J-406773107
Venezuela
Email: ****@luminatti.online
Corporate website: https://luminatti.online
IoT Manager: https://iot.luminatti.online