1. Data Controller
The data controller responsible for your personal data is:
EpiSensor Ltd
International Science Centre, National Technology Park, Limerick, V94 C61W, Ireland
Registered in Ireland, company number 438937. VAT number IE9655800Q.
Email: info@episensor.com
This policy covers this Website, your EpiSensor account, and the parts of the EpiSensor Edge application that talk to episensor.com: licence checks, feedback reports, and the daily usage summary described in sections 2.9 and 2.10. Data that stays inside your own Edge installation, such as sensor readings and device configuration, is yours and is never sent to us by Edge.
2. Data We Collect
We collect and process the following types of personal data:
2.1 Website Analytics
We use Plausible Analytics to count visits to the public pages of this Website. Plausible is hosted in the EU, sets no cookies, and does not track visitors across websites. Each page view sends the page address, the address of the page that referred you, and the country, browser, operating system and device type that Plausible works out from your request. Some actions on the site are counted as named events: clicks on a small number of tagged buttons, on links to other websites and on document downloads, starting or submitting a form (the name of the form only, never what you typed into it), adding an item to the basket, starting checkout, requesting a quote, placing an order by purchase order or by bank transfer (the destination country only), completing sign-in, starting a software download, and submitting a job application (the role only). A click on a link to another website also records the address of the page it goes to. Plausible uses your IP address only to work out whether a visit is a repeat visit that day, and does not store it. We do not send Plausible your name, your email address, or anything you type into a form.
Analytics run only on episensor.com. Our staging site is not measured, and account, sign-in, administration, API and order-confirmation pages are excluded.
2.2 Contact Form Submissions
When you submit a contact, configuration, demo, or partner enquiry form on our Website, the form is processed through EpiSensor's own website infrastructure. We collect the information you voluntarily provide, which may include your name, email address, company name, phone number, role, project details, the content of your message, and any files you attach. This data is used solely to respond to your enquiry and route it appropriately.
With each submission we also record the page you sent it from, the page that referred you, which button or directory listing the enquiry came from, the time, your IP address, and your browser's user-agent string. The IP address and user agent serve only to spot abuse of the forms, and are deleted 30 days after submission.
2.3 Customer Support Data
When you contact our support team (e.g., for warranty or technical issues), we may collect your name, email address, company name, device serial numbers, and details of your support request. This data is used to provide and improve our support services.
A support request becomes a ticket: the messages between you and our team, any files either side attaches, the severity and category, and the record of who changed what and when. You can reply by email, and your reply is added to the ticket. If you sign in with the same address you can read the ticket in your account. Where your address belongs to a company account, the other people in that account can see the tickets, orders and licences of the account as a whole. Section 2.5 explains how an address comes to belong to one.
2.4 Job Applicants
When you apply for a role on our careers page, or send us a speculative application, we collect the information you provide in the application form: your name, email address, phone number, location, links to your LinkedIn profile or portfolio, the message you write, and your CV. We may add our own notes and a rating as we review your application. We do not record your IP address or browser details with your application.
We use this data to assess your application, to contact you about it, and, if you are successful, to prepare an employment contract. The lawful bases are taking steps at your request prior to entering into a contract, and our legitimate interest in recruiting for our team.
Applications are kept for 12 months from the date you apply so that we can come back to you if a suitable role opens. You can ask us to keep your details on file for longer, or to delete them at any time, by emailing careers@episensor.com and quoting your application reference. Once the retention period has passed, the application and CV are deleted.
2.5 Account Access, Policy Acceptance, and Newsletter Updates
When you request a sign-in code, we use your email address to send the code and may briefly record your IP address to protect the service against abuse. We use Cloudflare Turnstile on this request to distinguish ordinary visitors from automated abuse. The check connects your browser to Cloudflare, which processes technical request data such as your IP address, browser characteristics, and the result of the security check on our behalf. We receive only the short-lived verification result and do not use Turnstile for advertising or cross-site analytics. If you accept our Terms & Conditions and Privacy Policy, we keep the time of acceptance, the versions of the documents you accepted, the source of the acceptance, and the IP address used. This gives both you and EpiSensor a clear record of the agreement.
If you fill in your account profile, we keep the name, job title, company and phone number you enter, and the photo you upload if you choose to add one. Where we hold a company account for your employer and have recorded that company's email domains, your address joins that account automatically the first time you sign in. An administrator can also add or remove an address by hand. A company account is what lets you and your colleagues see the same orders, licences and tickets, and everyone in it can see the names and email addresses of its other members.
If you separately choose to receive EpiSensor updates, the subscription becomes active only after you enter the sign-in code sent to that address. We keep your email address, any name you provide, the time and source of your opt-in, the time and method of verification, and your subscription status. We use this information only to send occasional product and company updates. Newsletter delivery is handled by an email service provider acting on our behalf. Every newsletter includes a way to unsubscribe, and opting out does not affect account access.
2.6 Orders, Payments, and Licences
When you buy from our shop or accept a quote, we keep our own record of the sale: your email address, your company name, the destination country, the items and quantities, the prices and currency, any purchase order number and notes you add, the status of the order, and the identifiers that link it to the payment.
Payment is taken by Stripe. Card details are entered on Stripe's own checkout pages and never reach our servers. Stripe collects your billing details, and for physical goods your delivery address, and holds them under its own privacy policy. From that, we keep only what is needed to explain an invoice later: the VAT or other tax identifiers you gave, whether the sale was treated as tax exempt, and the country, city and postcode of your billing address. Street address lines stay with Stripe.
Orders are copied into EpiSensor's own ERP system, which we host ourselves rather than with a third party, as draft customer, quotation and sales order records, so that the order can be fulfilled, delivered and invoiced. Where a sale includes software, the licence we issue records the Gateway serial number it is bound to, the number of licensed devices, and the expiry date.
The lawful bases are performance of our contract with you, and our legal obligation to keep accounting and tax records.
2.7 Software Downloads and the Edge Application
Some Edge releases are public and some are released to approved customers and partners. When you ask for download access, we record your email address and whatever else you add: your name, company, job title, and what you plan to use Edge for. We record the decision on your request, who made it, and when. Each file downloaded is logged with the release and file, the time, whether it came from the Website, the Edge application, or the automatic updater, and the email address you were signed in with, where you were signed in. We use this to enforce access to pre-release builds and to know which versions are in the field.
When you sign in to the Edge application with an email code, we keep a record of that session: your email address, the name, platform, architecture and version the application reports for the device, the IP address the sign-in came from, and when the session was created, last used and expires. Only a hash of the session token is stored, so our records cannot be used to sign in as you. You can see your Edge sessions, and revoke any of them, from your account.
The lawful bases are performance of our contract with you and our legitimate interest in controlling access to pre-release software and in keeping accounts secure.
2.8 Returns and Warranty Claims
When you raise a return, we record your email address, the Gateway serial number and the serial numbers of the products being returned, your description of the fault, the return address you give us for the goods, your acknowledgement of the warranty terms, any files you attach, and the progress of the return through to completion. Every return is linked to a support ticket, which is handled as described in section 2.3.
The lawful bases are performance of our contract with you and compliance with our warranty obligations.
2.9 Edge Feedback Reports
The Edge application has a feedback form for bug reports and feature requests. Nothing is sent unless you fill it in and press send.
What we receive is the contact email address you enter, whether the report is a bug or a feature request, the title, your description, the steps to reproduce if you add them, and up to three attachments (PNG, JPEG, WebP, text, log or JSON files, 5 MB each and 8 MB in total). If you turn on the option to attach recent Edge logs, Edge takes the most recent log lines, caps them, and removes common credential patterns in your browser before they are uploaded. That redaction is automatic and cannot catch every secret, which is why the option is off until you choose it.
The form also offers to share system information. It is on by default, and you can turn it off before you send. When it is on, the report carries a snapshot of the installation: the Edge, front-end and build versions, the branding and hardware profile, the Gateway serial number, the licensed node count and the number of configured devices, the kinds of network connection in use (ethernet, Wi-Fi, cellular or WireGuard), which kind carries the default route, and whether the connection looks constrained, the names of the enabled integrations and how many are disabled, whether a restart or configuration change is pending, and, for the application itself, whether it is running on the web, desktop or mobile, its language, theme and window size, and the Edge page you were on when you sent the report. It does not include credentials, IP addresses, Wi-Fi network names, sensor readings, or any history of what you did in Edge. Because the snapshot carries the Gateway serial number, we can normally match a report to the customer who bought that Gateway.
A report becomes a support ticket in our support system and is handled exactly like any other ticket (section 2.3): our team is notified, we reply to the address you gave, and if you sign in to episensor.com with that address the ticket appears in your account. Feedback reports are not published and are not used for marketing.
The lawful bases are your consent, given by choosing to send the report and choosing what to attach to it, and our legitimate interest in fixing faults and improving Edge.
2.10 Edge Usage Summaries and Licence Checks
Once per day, the Edge application can send us a short usage summary. It contains a daily identifier, the Edge version, the front-end version, the build profile, whether the application is running on the web, desktop or mobile, the deployment mode, the language, and whether the browser reports a constrained connection, such as mobile data or a slow link. We store those values with the date and time the summary arrived.
The daily identifier is a one-way hash of the installation's own random identifier and the date, so it changes every day. It lets us avoid counting the same installation twice on one day, and it does not let us connect one day to the next, or a summary to you, your company, your account, your Gateway serial number, or your licence. The summary contains no name, no email address, no serial number, no licence key, no IP address, no sensor data, and nothing about your site, your devices, or what you did in Edge. The sending address is used in the moment to rate limit the endpoint and is not written down with the record. The summaries tell us which versions and platforms are in real use, so that we know what to support, what to test against, and what we can retire.
The summary is on by default. You can turn it off at any time in the Edge application under Display settings, and during first-run setup. Some builds never send it at all. We rely on our legitimate interest in maintaining and improving software that is already in the field, on the basis that a summary cannot be traced back to you. Because nothing in a summary identifies you, we cannot find, export or delete an individual summary on request; turning the setting off stops any further summaries being sent.
Separately, a Gateway running Edge checks its licence with episensor.com about once a day, sending its licence key, its Gateway serial number, and its Edge version. We answer from the licence record created when the licence was issued, and we do not keep a record of the check itself.
2.11 Records of Email Sent and Received
We keep an operational record of the email we send you and of the email you send to our support address. For a message we send, we record the address it went to, its subject line, which template produced it and whether it was delivered. For a message that arrives at support, we record the sender's address, the subject line, and what happened to it: matched to an existing ticket, opened as a new one, or held back because the sender could not be authenticated.
These records exist so that we can answer what happened to a message. The content of a support email becomes a ticket message and is handled as described in section 2.3.
The lawful basis is our legitimate interest in running an order and support service we can account for.
3. Legal Basis for Processing
We process your personal data on the following legal bases under the GDPR:
- Consent: where you have given clear consent for us to process your personal data for a specific purpose (e.g., submitting a contact form).
- Contractual necessity: where processing is necessary for the performance of a contract with you or to take pre-contractual steps at your request.
- Legitimate interests: where processing is necessary for our legitimate interests (e.g., improving our products and services), provided these are not overridden by your rights and freedoms.
- Legal obligation: where processing is necessary for compliance with a legal obligation to which we are subject.
Where section 2 names the basis for a particular kind of data, that is the basis we rely on for it.
4. Data Sharing
We do not sell your personal data to third parties. We may share your data with:
- Service providers: third-party services that help us operate our business. These providers are bound by data processing agreements and process data only on our behalf. The main ones are Stripe for payments and invoicing, Resend for sending and receiving our email, Plausible Analytics for website analytics, Cloudflare Turnstile for protecting sign-in-code requests from automated abuse, and FedEx, which receives a destination country and postcode, and never your name or address, when the shop quotes a delivery rate.
- Channel and sales partners: we may share personal information with our channel partners and sales partners for operational purposes, such as order fulfilment and confirming what hardware or software you have purchased. Please note that you may receive marketing communications from these partners based on your relationship with them.
- Legal requirements: where we are required to disclose data by law, regulation, or legal process.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:
- Contact form submissions: retained for up to 2 years from the date of submission, or longer if an ongoing business relationship exists. The IP address and browser details recorded with a submission are deleted after 30 days.
- Customer support data: a ticket and its attachments are deleted 3 years after the ticket is closed. Open tickets are kept for the duration of the customer relationship.
- Edge feedback reports: kept as support tickets, on the same clock.
- Records of email sent and received: the operational record described in section 2.11 is deleted 1 year after the message was sent or arrived.
- Edge usage summaries: deleted once they are more than 400 days old.
- Orders, invoices, and licence records: kept for as long as tax and company law requires us to keep accounting records. These are not deleted on request.
- Returns and warranty claims: kept for the duration of the customer relationship, as evidence of what was returned, repaired or replaced under warranty.
- Download access decisions and download logs: kept while your account exists, and deleted if you ask us to erase your data.
- Edge sign-in sessions: a session expires 180 days after you last used it, and 400 days after it was issued at the latest. The record, including the sign-in IP address, is deleted 30 days after the session expires or is revoked.
- Job applications: retained for 12 months from the date of application, or longer if you ask us to keep your details on file. You can request deletion at any time by emailing careers@episensor.com.
- Access codes: expired and used sign-in-code records, including their IP addresses, are deleted after one day.
- Policy acceptance: retained as evidence of the agreement until you ask us to erase your customer data, subject to any legal obligation to retain it.
- Newsletter subscriptions: retained while you are subscribed. If you unsubscribe, we keep the minimum subscription status needed to honour that choice until you resubscribe or ask us to erase it.
- Website analytics: Plausible retains aggregated, non-personal data only. No personal data is stored.
6. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access. You may request a copy of the personal data we hold about you.
- Right to rectification. You may request that we correct any inaccurate or incomplete data.
- Right to erasure. You may request that we delete your personal data, subject to certain conditions.
- Right to restriction. You may request that we restrict the processing of your data in certain circumstances.
- Right to data portability. You may request to receive your data in a structured, commonly used, machine-readable format.
- Right to object. You may object to the processing of your personal data where we rely on legitimate interests.
- Right to withdraw consent. Where processing is based on consent, you may withdraw that consent at any time.
To exercise any of these rights, please contact us at info@episensor.com from the email address the data is held under, or tell us which address it is.
The limits are worth stating plainly. An erasure request removes your enquiries and the files you attached to them, your support tickets and their attachments, your Edge feedback reports, your access codes and policy acceptance, your profile and profile photo, your Edge sign-in sessions, your download access and download history, our record of the email we sent you and of the email you sent to support, your newsletter subscription, and your place in a company account. It does not remove orders, invoices, licence records or support-plan records, or the records we keep in our own accounting and fulfilment systems, which we are required to keep as accounting records, or the record of a return, which is our evidence of what was repaired or replaced under warranty. It cannot reach an Edge usage summary, because nothing in a summary identifies you.
7. Cookies
This Website sets one first-party cookie, episensor_session. It keeps your basket, your sign-in and your progress through checkout together across pages. It holds no personal data itself, only an identifier for the session stored on our server; it cannot be read by scripts in your browser, and it expires after 14 days without a visit. It is strictly necessary for the features you asked for, so we do not ask for consent to set it. Our analytics provider, Plausible, is cookieless by design and does not track individual visitors.
Your browser also stores things for this Website outside of cookies. While you are checking out, the details you have entered are kept in the browser tab you are using, so that a second attempt is recognised as the same attempt rather than a second order; they are gone when you close the tab. Any display preferences you have set for the site, such as language and currency, are read from the same browser storage. Neither is used to identify you or to follow you between websites, and clearing your browser's site data removes both.
This Website may also embed third-party services such as Google Calendar booking widgets, which may set their own cookies as part of their functionality. These cookies are governed by the respective privacy policies of those services:
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.
11. Contact
For any questions or concerns about this Privacy Policy or our data practices, please contact us at info@episensor.com:
EpiSensor Ltd
International Science Centre, National Technology Park, Limerick, V94 C61W, Ireland
Registered in Ireland, company number 438937.
Email: info@episensor.com
You also have the right to lodge a complaint with the Data Protection Commission (DPC), Ireland's supervisory authority, at www.dataprotection.ie.
Last updated: September 2026