Last updated: 29 September 2026

1. About this policy

This policy explains how personal information is handled when you use Thello Go for Android (package name cloud.thello.go). Thello Go helps authorised technicians identify and manage equipment associated with Thello services.

The operator of Thello Go is CEL Consulting, based in Belgium. For privacy questions or requests, contact support@thello.cloud.

Where your employer or another organisation determines how customer and equipment records are used, that organisation is responsible for those records. We process those records on its behalf under the applicable service agreement. We are responsible for processing that we independently determine, including account security, authentication, and administration of the Thello Go service itself.

2. Information we handle

We handle the following information to provide the app:

  • Account and authentication information: username/password credentials used to sign in, the current tenant (organisation) selection, and an authentication token issued after login. The token is stored on the device using Android’s secure, encrypted storage (SecureStorage) and is removed when you log out.
  • Equipment and operational information: scanned barcode values (MAC address and serial number), equipment vendor and model, assignment of equipment to handsets/users, and changes you submit (e.g. creating, moving, or removing a phone). These identifiers relate to equipment being managed, rather than necessarily identifying the Android phone running the app.
  • Customer or user records: names of users assigned to handsets within a tenant/organisation, as needed to display and manage equipment assignments.
  • Technical and diagnostic information: standard HTTP request metadata handled by our backend (such as IP address, request time, and endpoint called) needed to serve API requests and maintain security. The app itself does not include any separate analytics or crash-reporting SDK.
  • Information you send to support: information you provide when requesting assistance.

3. Camera and permissions

Thello Go requests camera permission (android.permission.CAMERA) to scan equipment barcodes, and vibration permission (android.permission.VIBRATE) to give haptic feedback on a successful scan. You can refuse or revoke camera permission in Android settings; barcode scanning will then be unavailable.

Camera processing: Camera frames are processed on-device using Google ML Kit barcode scanning (via the BarcodeScanning.Native.Maui library). Camera images and video are not stored or uploaded. Only the decoded barcode text (MAC address / serial number) is sent to Thello services when you complete a scan.

Other permissions or sensitive data: The app does not request location, microphone, contacts, photo/media, or background data collection permissions beyond those listed above.

4. How and why we use information

We use the information described above to authenticate authorised users, enforce access permissions, identify and manage equipment, process technician actions, provide support, and maintain service reliability and security.

Where the GDPR applies and we act as controller, our legal bases are: performance of our service agreement with the organisation you act on behalf of; our legitimate interests in providing, securing, and administering the Thello Go service; and compliance with legal obligations where applicable. Where legitimate interests apply, we consider the impact on your rights and freedoms. An Android permission does not itself determine the GDPR legal basis.

Advertising and sale of data: Thello Go contains no advertising, no advertising trackers, and we do not sell personal data.

5. Who receives information

Information is accessible to authorised users and administrators of the relevant organisation according to their permissions, and to our authorised staff where needed for service operation or support.

We use hosting and infrastructure providers in the European Union to operate the Thello Cloud backend that this app connects to. Providers handling information on our behalf are subject to appropriate contractual requirements. We may disclose information where required by law or necessary to establish, exercise, or defend legal claims.

Third-party app libraries and SDKs: the app uses Google ML Kit (via BarcodeScanning.Native.Maui) for on-device barcode scanning; no scan images are transmitted to Google. See Google’s privacy policy: https://policies.google.com/privacy. No other third-party analytics, advertising, or tracking SDKs are included in the app.

6. Storage, security, and international transfers

Information is stored on servers located in the European Union. We do not transfer personal data outside the European Economic Area.

We protect information using HTTPS/TLS encryption in transit, tenant-scoped access controls so users only see equipment for their own organisation, and secure, encrypted on-device storage for authentication tokens. No storage or transmission method can guarantee absolute security.

7. Retention

We retain information for as long as your organisation’s service agreement with us remains active, and for the following periods or criteria after it ends:

  • Account and authentication records: for the duration of the organisation’s contract with us, then deleted once the contract ends.
  • Customer, equipment, and technician activity records: for the duration of the organisation’s contract with us, in line with the organisation’s own retention requirements for its equipment records.
  • Security logs, diagnostics, and support records: retained only as long as needed to resolve the related issue, and in any case no longer than the organisation’s contract term.
  • Backups: follow the same retention as the underlying records and are rotated out once the contract ends.

We delete or anonymise information when it is no longer required, except where continued retention is necessary to comply with a legal obligation or to establish, exercise, or defend legal claims.

8. Your rights and deletion requests

Where applicable, you can request access to, correction of, or deletion of your personal information, restriction of processing, data portability, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it without affecting prior lawful processing.

Send requests to support@thello.cloud. For organisation-controlled records, you can also contact your organisation’s administrator. We may need to verify your identity and coordinate with the responsible organisation.

Account and data deletion: to request deletion of your account or personal information, email support@thello.cloud from your registered address, describing the request. We will delete or anonymise your account and authentication information once verified, except where equipment and activity records must be retained under your organisation’s own service agreement, or where retention is required to comply with a legal obligation. Uninstalling the app does not by itself delete information already stored on service servers; you must submit a deletion request as described above.

You may lodge a complaint with your competent data protection authority. In Belgium, this is the Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit): https://www.dataprotectionauthority.be/.

9. Intended users

Thello Go is intended for authorised professional users only. It is not directed to children, and we do not knowingly collect personal information from children.

10. Changes and contact

We may update this policy to reflect changes in the app or our data practices. The current version will be available at [PUBLIC PRIVACY POLICY URL — TO BE PUBLISHED]. This app does not currently include an in-app link to this policy; add one (e.g. on the Settings page) before publishing to Google Play. Where required, we will provide additional notice or obtain consent before introducing new processing.

Operator: CEL Consulting
Address: B-5330 ASSESSE, Belgium Privacy contact: support@thello.cloud