MOBILE APP PRIVACY POLICY
DeskAlerts Mobile Agent Application
At a glance
- Published by
- ToolbarStudio, Inc. (dba DeskAlerts)
- Apps covered
- DeskAlerts Mobile for Android and iOS
- Effective date
- Jul 2, 2026
- Last updated
- Aug 16, 2026
- Version
- 1.2
Table of Contents
- Who we are and what this policy covers
- Who handles your data
- How the App obtains data about you
- Data the App accesses, collects, uses, and shares
- How the data is used
- Who the data is shared with
- Secure data handling
- Data retention
- Account deletion and data deletion
- Permissions, disclosure, and consent
- Children
- EU-U.S., UK, and Swiss Data Privacy Frameworks
- How to contact us
- Changes to this policy
1. Who we are and what this policy covers
This Privacy Policy explains how personal data is accessed, collected, used, handled, shared, retained, and deleted in connection with the DeskAlerts Mobile application (the “App”), published by ToolbarStudio, Inc. (“DeskAlerts”, “we”, “us”, “our”), a company incorporated in the state of Virginia USA with its principal place of business at 205 Van Buren Street, Suite 120-039 Herndon, VA 20170, United States.
The App is an enterprise communication client. It is not a consumer product. It is installed by, or at the direction of, an organisation that has licensed the DeskAlerts platform (your employer or a comparable body — the “Customer”), so that the Customer can deliver notifications, alerts, surveys, and emergency communications to the people it authorises to receive them (“you”, “User”).
The App functions only when connected to a DeskAlerts server operated by or for a Customer, and only when you hold valid credentials for that server.
This policy covers the App. It does not cover the DeskAlerts desktop client, web console, or other platform components; the DeskAlerts corporate website; your Customer’s own internal policies; or your operating system, device manufacturer, app store, or mobile network, each of which handles data under its own terms.
2. Who handles your data
Responsibility for your data depends on how your organisation has deployed DeskAlerts.
2.1 Self-hosted (on-premises)
The Customer installs and operates the DeskAlerts server on infrastructure it controls. Data transmitted by the App travels directly from your device to your Customer’s server. DeskAlerts does not host, receive, store, or have routine access to that data. Questions about what is collected about you, how long it is kept, and who can see it should go to your organisation first. We access Customer systems only when the Customer requests technical support.
2.2 DeskAlerts-hosted (cloud)
DeskAlerts hosts the server on cloud infrastructure and processes User data on behalf of, and under the documented instructions of, the Customer. The Customer decides what is collected, who is targeted, and how long records are kept, within the configuration options the platform provides.
2.3 Data DeskAlerts handles for its own purposes
In either model, DeskAlerts determines the purposes of processing for a narrow set of activities carried out for itself rather than for a Customer: responding to enquiries and requests you send us directly; securing the platform and preventing abuse of it; maintaining the audit records that security work produces; and retaining records needed to meet legal obligations or to establish, exercise, or defend legal claims. Everything else described in section 5 is carried out for, and on the instructions of, the Customer.
3. How the App obtains data about you
- From your organisation. Your Customer provisions your account, typically by synchronising an existing directory such as Microsoft Active Directory.
- From your device. Technical information required to register the device with the server and deliver notifications to it.
- From you, directly. When you sign in, acknowledge an alert, respond to a survey or poll, or activate an emergency alert.
The App does not obtain data about you from data brokers, public records, or any other third-party source. The one technical exception is the push notification token described in section 4, which is issued to the App by the operating system’s push service rather than by you or your organisation.
4. Data the App accesses, collects, uses, and shares
Below is every category of data the App collects about you. Section 4.1 states what the App does not access; 4.2 states what the App can access but doesn’t use. Read together, those three parts are exhaustive.
Account and identity data
- What
- Username or account identifier; display name; email address; phone number; directory identifiers and groups used for targeting.
- Why
- To authenticate you, to identify which alerts you should receive, and to attribute responses and acknowledgements.
- Sensitivity
- Personal data.
Authentication data
- What
- Session or access tokens issued by the server.
- Why
- To keep you signed in securely and to authorise requests to the server.
- Sensitivity
- Personal and sensitive under Google Play policy.
Device and technical data
- What
- Device operating system and version; App version; an installation identifier; the server address the App connects to; connection status.
- Why
- To register your device with the correct server, to route notifications, and to diagnose delivery problems.
- Sensitivity
- Personal data when linked to your account.
Push notification token
- What
- The token issued by Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS).
- Why
- Strictly to deliver notifications to your device. Not used for advertising and not sold.
- Sensitivity
- Personal data. Resettable identifier.
Message and engagement data
- What
- Which alerts were delivered to your device, when, whether and when they were opened, acknowledged, or dismissed, and delivery failures.
- Why
- To let your organisation confirm that critical and emergency communications reached their intended recipients.
- Sensitivity
- Personal data.
Survey, poll, and quiz responses
- What
- Your answers, and any free-text comment or acknowledgement note you submit, with the timestamp and your account identifier unless your organisation configured the survey to be anonymous.
- Why
- To deliver your response to your organisation for the purpose it stated when it issued the survey.
- Sensitivity
- Personal data. May become sensitive depending on the questions asked.
Location data
- What
- Your device’s geographic location which is collected only at the moment you activate an emergency alert template.
- Why
- To include your position in an emergency alert so responders can find you, and, where enabled, to determine whether a geo-targeted alert applies to you.
- Sensitivity
- Personal and sensitive under Google Play policy.
4.1 Data the App does not access
The App does not access, collect, or transmit:
- Your contacts or phonebook. We do not publish or disclose non-public contact information.
- SMS messages, call logs, or call content.
- Camera or microphone input, or files in your device storage.
- An inventory of other applications installed on your device.
- Health, biometric, financial, or payment data, or government identification numbers. No such data is collected, and none is ever publicly disclosed.
- Advertising identifiers. The App displays no advertising.
- Persistent hardware identifiers (IMEI, IMSI, SIM serial number, MAC address).
4.2 Identifiers not requested and not used by the App
- Advertising identifiers (Android Advertising ID / IDFA). The App performs no ad personalisation and no ad measurement.
- The App does not collect the Android App Set ID.
5. How the data is used
Data obtained through the App is used only to provide the App’s functionality and for the purposes disclosed in this policy:
- Delivering alerts and notifications you are targeted to receive.
- Delivering emergency alerts, including your location where you trigger one, so that responders can reach you.
- Confirming to your organisation that critical communications were delivered, opened, and acknowledged.
- Delivering your survey, poll, and quiz responses to your organisation.
- Keeping the service secure, preventing abuse, and maintaining audit records.
- Providing, maintaining, and supporting the platform, and responding to enquiries you send us.
We do not use data obtained through the App for advertising, ad personalisation, ad measurement, or marketing profiling, and we do not use it for any purpose unrelated to enterprise communication. Use is limited to the policy-compliant purposes disclosed above.
6. Who the data is shared with
We do not sell personal and sensitive user data. “Sale” means the exchange or transfer of such data to a third party for monetary consideration.
Data is disclosed only as follows:
- Your organisation. The Customer’s authorised administrators can see every category listed in section 4 that is associated with you: your account and identity data, your device and technical data, your message and engagement statistics, your survey and poll responses, and — where you send an emergency alert, or where geo-targeted alerts are enabled — your location. Visibility is subject to the permissions the Customer configures internally.
- Nobody, in the case of your authentication data. Session and access tokens are exchanged only between the App and the DeskAlerts server that issued them. They are not disclosed to your organisation’s administrators or to any third party.
- Push notification providers. Notification payloads and your push token are transmitted through Google Firebase Cloud Messaging on Android and the Apple Push Notification service on iOS. This is unavoidable for push delivery.
- Service providers. In cloud deployments only, hosting and support providers engaged under service contracts restricting them to processing on our documented instructions: AWS (Amazon Web Services)
- Legal reasons. Where necessary to comply with applicable law or a valid governmental request, or to establish, exercise, or defend legal claims.
- Corporate transactions. In a merger or acquisition, with legally adequate notice to affected Customers and Users.
Each third party with which the App shares user data — Google Firebase Cloud Messaging, the Apple Push Notification service, and our hosting and support providers — is bound by contract to provide the same or equal protection of your data as is stated in this policy.
6.1 Third-party code, SDKs, and AI integrations
Where the App incorporates third-party code, we remain responsible for that code’s handling of your data. We take steps to satisfy ourselves that any third-party component in the App:
- Complies with the Google Play Developer Program policies, including their use, disclosure, and consent requirements.
- Does not sell personal and sensitive user data obtained through the App.
- Does not link persistent device identifiers to personal and sensitive user data or to resettable identifiers.
- Is approved for use in child-directed services, should the App ever be distributed to such an audience.
We remove or replace components that cannot be brought into compliance. Where Google Play requests evidence that a third-party component meets the prominent disclosure and consent requirements, we provide it within the period Google specifies.
Third-party components currently included in the App: none other than the platform push services named above.
Third-party AI products, services, or code integrated into the App: none.
7. Secure data handling
We apply technical and organisational measures appropriate to the risk:
- All data in transit is transmitted using modern cryptography (TLS/HTTPS) — between the App and the server, and between the server and push providers.
- Encryption of data at rest: All data at rest is secured using Transparent Data Encryption (TDE) for database files and volume-level AES-256 encryption for server storage, protected by industry-standard key management practices.
- Role-based access control and least privilege for administrative access.
- Runtime permission requests before accessing any data gated by an operating-system permission, so access cannot occur without your action.
- Logging and monitoring of administrative access: administrative access and privileged sessions are logged and continuously monitored in real time using the Wazuh SIEM platform to audit system activity and detect anomalies.
- Independent assessment and certification: Our security posture is validated through independent assessments, including SOC 2 Type 2 compliance, annual penetration testing, and UK Cyber Essentials certification.
In self-hosted deployments, the security of the server, network, and stored data is the Customer’s responsibility; ours is limited to the App software itself. No system can be guaranteed absolutely secure.
8. Data retention
We retain personal data only as long as necessary for the purposes described in this policy, or as required by law. In self-hosted deployments retention is determined and enforced entirely by the Customer. In cloud deployments it follows the configuration the Customer selects.
Account and identity data
- Retained for
- The duration of the customer contract or until deprovisioned by the customer
- Deleted on
- Deprovisioning by the Customer, or contract termination
Push notification token
- Retained for
- The duration of the active device session.
- Deleted on
- Sign-out, uninstall, or token invalidation by the provider
Message delivery and acknowledgement statistics
- Retained for
- A variable period determined by customer configuration, up to the duration of the contract
- Deleted on
- Customer-configured retention schedule
Survey and poll responses
- Retained for
- A variable period determined by customer configuration, up to the duration of the contract
- Deleted on
- Customer-configured retention schedule
Emergency alert records including location
- Retained for
- A variable period determined by customer configuration, up to the duration of the contract
- Deleted on
- Customer-configured retention schedule
Support correspondence with DeskAlerts
- Retained for
- Up to 3 years after ticket resolution
- Deleted on
- Resolution plus retention period
Backups
- Retained for
- 30 days after contract termination
- Deleted on
- Backup rotation cycle
Where data must be retained after a deletion request for a legitimate reason — security, fraud prevention, resolution of a safety incident, or regulatory compliance — we retain only the minimum necessary, isolate it from active use, and delete it when the reason expires.
Fully anonymised and aggregated data, which can no longer be associated with any individual, may be retained indefinitely.
9. Account deletion and data deletion
When an account is deleted, all personal data associated with it is deleted, other than data retained for the reasons and periods disclosed in section 8. Temporary deactivation, disabling, or freezing of an account is not treated as deletion.
9.1 Accounts provisioned by your organisation
You cannot delete an employer-issued account yourself. Direct your request to your organisation’s IT administrator or privacy contact, who can deprovision the account and remove the associated data. Uninstalling the App stops further data being sent from your device but does not delete records already held on your organisation’s server.
9.2 Requests to DeskAlerts
Where DeskAlerts hosts the service on your organisation’s behalf, you may also send a deletion request to privacy@deskalerts.com. We will forward it to your organisation, which decides on the request, and support them in carrying it out.
10. Permissions, disclosure, and consent
The App requests operating-system permissions only when the corresponding feature requires them, and always through a runtime permission request. Where data is collected in a way you would not otherwise expect — location in particular — a disclosure appears inside the App during normal use, explaining what is collected and how it is used and shared, immediately before we ask for your consent and before the permission prompt is shown. Consent requires an affirmative action on your part; navigating away is not treated as consent.
You may decline or later revoke any permission in your device settings. The App remains usable, but features depending on that permission will not work.
Notifications
- Why
- To display alerts sent by your organisation. This is the App’s core purpose.
- If declined
- You will not receive alerts.
Location
- Why
- To include your position in an emergency alert and, where enabled, to determine whether a geo-targeted alert applies to you. The app requests access to your precise GPS location exclusively in the foreground, meaning coordinates are only captured when you actively use the app to trigger an emergency alert template.
- If declined
- Emergency alerts are sent without your location; geo-targeted alerts may not reach you.
Network and connectivity state
- Why
- To detect connectivity and re-deliver alerts missed while offline.
- If declined
- Delivery reliability is reduced.
11. Children
The App is an enterprise tool intended for use by adults in a workplace or comparable organisational setting. It is not directed to children, is not designed as a child-directed service, and we do not knowingly collect personal data from children. If you believe a child has provided personal data through the App, contact us using section 13 and we will delete it.
12. EU-U.S., UK, and Swiss Data Privacy Frameworks
Where we access, use, or process personal information that directly or indirectly identifies an individual and that originated in the European Economic Area, the United Kingdom, or Switzerland, we:
- Comply with all applicable privacy, data security, and data protection laws, directives, regulations, and rules.
- Access, use, or process that information only for purposes consistent with the consent obtained from, or another lawful basis established in respect of, the individual concerned.
- Implement appropriate organisational and technical measures to protect it against loss, misuse, and unauthorised or unlawful access, disclosure, alteration, and destruction.
- Provide the level of protection required by the Data Privacy Framework Principles or by the applicable transfer mechanism.
- Monitor our compliance with these conditions on a regular basis.
Where personal information is transferred to a country without an adequacy decision, we rely on appropriate safeguards: Standard Contractual Clauses (SCCs) approved by the European Commission, and the UK International Data Transfer Addendum.
Cloud deployments are hosted in the United States, the European Union, the United Kingdom, Australia, and the United Arab Emirates.
13. How to contact us
If you have a question about this policy, or want to make a request about your data, use the contacts below. If your organisation deployed DeskAlerts on its own infrastructure, contact your organisation’s IT or privacy team first — they hold your data and can act directly. Where you contact us about data we handle on a Customer’s behalf, we will pass your request to that Customer and support them in responding.
Contact
- Entity
- ToolbarStudio, Inc. (dba DeskAlerts)
- Privacy enquiries
- privacy@deskalerts.com
- Postal address
- 205 Van Buren Street, Suite 120-039 Herndon, VA 20170, United States
- Account deletion
- https://www.alert-software.com/privacy/mobile-app#account-deletion-and-data-deletion
14. Changes to this policy
We may update this policy to reflect changes in the App, our practices, or the law. The version and effective date appear at the top of this policy. Where a change materially affects how personal data is handled, we will give notice through the App or the store listing and obtain fresh consent where the law requires it.