VYSE Privacy Notice
Version 2026-08-24 · GDPR-oriented draft for owner and legal review
1. Who this notice covers
This notice explains how the FTH legal entity identified in the applicable Order Form processes personal data for VYSE. Its legal name, registered office and privacy contact must be confirmed before launch. VYSE is a business service for organisations and adult professional users, not children or consumers.
2. Our two data-protection roles
FTH as controller: FTH determines purposes for public signup/account data, sales and commercial contacts, billing metadata, support interactions, service security, fraud prevention, product administration and legally required records.
Customer as controller; FTH as processor: the Customer ordinarily determines purposes for maintenance records, employee or contractor data it enters, work orders/requests, assets or locations containing personal data, documents, attachments, activity/audit records, and imported or integrated operational data. FTH processes this on documented Customer instructions under the DPA unless law requires otherwise.
3. People and data categories
- Prospects, account holders, Administrators, Authorized Users, invitees, billing and support contacts.
- Identity data: name, business contact details, provider identifiers, validated issuer/tenant context, authentication method and account status.
- Organisation/access data: Company, Site, role, Security Group, permissions, invitations and legal acceptance.
- Commercial data: plan, capacity, term, billing contact, PO/invoice references and safe provider references—not full card numbers or CVV.
- Technical/security data: IP, browser/device, timestamps, session/security events, audit and diagnostics.
- Customer-controlled data: people named in work, maintenance, asset, location, document, attachment, inventory, notification, report, IoT or imported records.
4. Sources
Data may come from the individual, Customer Administrator, identity provider, payment or communications provider, configured integration, imported Customer data, device/browser activity, support interaction or VYSE use. We do not infer Company membership from a shared email domain.
5. Controller purposes and lawful bases
- Contract: accounts, authentication, subscriptions, billing and service requests.
- Legitimate interests: security, troubleshooting, improvement, misuse prevention, business relationships and proportionate audit evidence, balanced against rights.
- Legal obligation: tax, accounting, sanctions, lawful requests and mandatory records.
- Consent: only for specific optional processing that genuinely requires it; it may then be withdrawn without affecting earlier lawful processing.
Where FTH is processor, the Customer determines lawful bases and notices for Customer-controlled data.
6. Recipients and providers
Data may be available to authorised Customer users, authorised FTH personnel and providers needed to operate VYSE. Current architecture can involve Microsoft Entra and customer identity, Google identity federated through External ID, Microsoft Azure/cloud services, Stripe or another configured payment provider, SMTP/email communications, support providers and Customer-selected integrations. The definitive Subprocessor List must identify contracted entities, roles and locations after verification.
We do not sell personal data. Providers receive only data reasonably required and are subject to appropriate obligations.
7. Identity, payment and communications
Microsoft or Google may process authentication data under their notices. Google sign-in is federated through Microsoft Entra External ID; VYSE has no separate Google OAuth stack. Hosted checkout data is processed by the configured payment provider. Service and security messages use configured communications providers. Tokens, codes, secrets and full card security data are not intended for Customer records.
8. Cookies and similar technology
VYSE uses necessary cookies or equivalent storage for authentication, session continuity, security, anti-forgery, language and interface preferences. A consent mechanism is required before non-essential analytics or advertising technology. Launch review must confirm whether any is enabled and whether a separate Cookie Notice is needed.
9. Retention
Account/signup data is retained for service administration and legitimate records; billing/tax records for legal obligations; security/audit and support records for proportionate evidence; Customer operational data under Customer instructions; and backups until managed expiry. The owner and adviser must approve actual periods, export window, deletion timetable, backup expiry, legal holds and exceptions.
10. International transfers
Providers or configurations may process data outside Ireland or the EEA; we do not claim Ireland-only storage. Where GDPR restricts transfer, an adequacy decision or safeguards such as European Commission Standard Contractual Clauses will be used with transfer assessments and supplementary measures where required. The final inventory must document actual transfers.
11. Individual rights
Subject to law, individuals may request access, rectification, erasure, restriction, portability or objection, and withdraw consent where relevant. Requests about Customer-controlled data should normally go first to the Customer; FTH assists under the DPA. Identity verification may be required. Individuals may complain to the Irish Data Protection Commission or competent supervisory authority.
12. Automated decisions and future AI
VYSE does not use covered data for solely automated decisions with legal or similarly significant effects. Schedules, reports, alerts and entitlements support defined rules and human administration. Future AI requires separate assessment, transparency and terms before launch.
13. Security and incidents
Measures include tenant/Site scoping, exact permissions, external identity validation, encryption in transit, protected secrets, signed callbacks and audit records. No system is absolutely secure. Customers and users must protect accounts/devices. FTH will investigate suspected breaches and notify Customers, regulators or individuals when law requires.
14. Other systems and integrations
When a Customer configures PEAMC, IBM Maximo, Maintenix or another system, data is processed on Customer instructions. Customers must provide notices, permissions and lawful bases and verify imports/exports. Names are interoperability context only; no affiliation or certified compatibility is implied.
15. Changes and contact
Material changes are versioned and notified or re-acknowledged where required. Exact privacy and support contacts must be confirmed. Until then, use the verified Order Form or business contact and do not include passwords, tokens or payment-card data.