1. Controller
Nebo Devices Ltd.
ROOM 606, 6/F, HOLLYWOOD CENTRE, NO. 77-91 QUEEN'S ROAD WEST, SHEUNG WAN, Hong Kong
Privacy contact: support@atmy.ai
Primary GLOBAL personal-data hosting is intended to be in Europe. The exact hosting provider and processing locations must be verified before production.
2. Data we may process
### Account data
Depending on actual implementation: email, display name, account ID, auth/session identifiers, country/service region, language and preferences.
### Device and sensor data
Sensor IDs, model/firmware, connectivity and diagnostics, account-device relationship and configuration.
### Environmental data
Depending on sensor capabilities: PM1, PM2.5, PM10, TVOC, temperature, humidity, pressure, AQI, timestamps and derived trends/forecasts.
### Location data
Private sensor location you configure; reduced-precision public location if you choose to publish; minimum location context needed for requested features such as weather enrichment.
Atmy should not continuously collect device GPS unless a future feature specifically requires it and this policy is updated.
### Usage and security data
IP address, request metadata, auth events, session information, security/abuse-prevention logs and API metadata as necessary for operation/security.
### Integrations
Only when enabled by you: messaging/notification identifiers and other technical identifiers necessary for a chosen integration.
### Optional health personalization
Where enabled, you may optionally provide health-related preferences/conditions such as asthma, COPD, allergies or heart conditions. They are not required for core Atmy use and must not be stored until the separate explicit-consent flow is completed.
3. Why we process data
Purposes may include account creation/security, sensor management, dashboards/history, calculations/forecasts, notifications you enable, public sensor publication you choose, support, abuse/security prevention, legal compliance and service improvement with appropriately aggregated/de-identified information.
4. Legal bases for EEA/UK users
Where GDPR/UK GDPR applies, bases depend on purpose:
- contract — account/core service requested by you;
- legitimate interests — proportionate service security, fraud/abuse prevention and reliability;
- legal obligation — where required by law;
- consent — optional activities where appropriate/required;
- explicit consent — optional health personalization where required for special-category data.
Atmy must not use consent as a cosmetic universal basis.
5. Private sensors
Sensors are private by default. Private account records, identifiers and exact private locations are not intended for public Map/API output.
6. Public sensors
When you intentionally publish a sensor, Atmy creates a separate public environmental projection. It should contain only information necessary for the public environmental function and exclude account/authentication data.
You can later make a sensor private again. This stops future publication through Atmy but cannot guarantee removal of copies already obtained by third parties while it was public.
7. Health data
Health-profile information is optional, requires separate explicit consent where GDPR applies, is not required for core monitoring, must not be included in public APIs or advertising systems, and should not appear in generic logs.
Atmy is not a medical device and does not provide medical advice.
8. Children
Atmy accounts are intended for adults. The current product should not collect a child's identity through the account flow.
9. Service providers and recipients
Atmy uses third-party providers only where needed to operate the service. The verified list, purposes, data categories and locations must be published on the Subprocessors page.
Each integration must follow purpose limitation and data minimization.
10. International processing and access
GLOBAL personal data is intended to be primarily hosted in Europe. Nebo Devices Ltd. is established in Hong Kong, so support, administration or provider access may involve processing outside the EEA/UK.
Where GDPR/UK GDPR requires transfer safeguards, Atmy will use an applicable lawful mechanism and appropriate supplementary protections.
Before production, Atmy must document actual access patterns and the implemented mechanism; this policy must not claim safeguards that do not exist.
11. Retention
Atmy keeps personal data only as long as needed for the described purposes, legal obligations and legitimate security needs.
Production retention periods must come from the verified retention matrix, not guesses. Account deletion removes/de-links data according to that schedule. Backups may expire on a separate cycle.
12. Security
Atmy uses technical and organizational measures intended to protect personal data from unauthorized or accidental access, alteration, disclosure, loss or destruction.
The policy must not promise controls that have not been implemented/verified. No internet-connected service can guarantee absolute security.
13. Your rights
Depending on applicable law, rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and complaint to a competent authority.
Requests: support@atmy.ai
Where GDPR applies, requests will be handled within applicable legal time limits.
14. Export and deletion
Atmy should provide controls to export data in machine-readable form, request/confirm account deletion and manage optional consents.
Deletion cannot require Atmy to erase independent copies of environmental information made by third parties while a sensor was public.
15. Cookies/local storage
See the Cookie & Local Storage Policy. Optional tracking/advertising must not be used unless documented and, where required, activated only after appropriate consent.
16. GDPR representative
Nebo Devices Ltd. is established outside the EU. Before launch to users for whom Article 27 applies, Atmy must determine whether an EU representative is required and, if required, appoint and identify that representative here:
{{EU_REPRESENTATIVE_IF_REQUIRED}}
17. Hong Kong privacy principles
As a Hong Kong company, Nebo Devices Ltd. maintains privacy practices consistent with applicable Hong Kong personal-data requirements, including fair collection, purpose limitation, retention/security and access/correction rights where applicable.
18. Changes
Material changes will be reflected in version/effective date and, where required, communicated or accompanied by a renewed choice.
19. Contact
Privacy: support@atmy.ai
Legal: support@atmy.ai
Controller / operator
Nebo Devices Ltd.
ROOM 606, 6/F, HOLLYWOOD CENTRE, NO. 77-91 QUEEN'S ROAD WEST, SHEUNG WAN, Hong Kong
support@atmy.ai