Information lifecycle

Privacy

Fatti services may process device-linked wireless and location observations and information entered through a venue’s captive portal. The fields, purposes, legal roles, recipients and retention period depend on the venue configuration and agreement.

Information categories

Category Typical service use
Wireless and device-linked observations Estimate presence, movement and patterns within a covered venue
Captive portal information Provide Wi-Fi access and support purposes stated in the venue notice
Derived analytics Produce authorised trends, dashboards and reports
Technical and support records Operate, protect and troubleshoot the service

Device identifiers and location histories can remain personal or pseudonymous even where a person’s name is absent. Fatti therefore does not make a blanket claim that all analytics records are anonymous.

Roles and purposes

The responsible party/controller and operator/processor roles are determined for each processing purpose and client agreement. Fatti may act on a client’s instructions for one activity and have a different role for another. The venue-facing privacy notice should explain the applicable purposes and choices at the point of collection.

Retention, sharing and locations

Retention and deletion requirements are set per dataset and service. Recipients, processing locations and cross-border arrangements are confirmed in the applicable due diligence and contract process. Public wording cannot replace those deployment-specific records.

Individual requests

People can raise privacy questions or requests through the contact route shown in the applicable venue privacy notice or through the relevant Fatti client contact. The responsible organisation will confirm identity, legal role, scope and applicable response requirements.

This trust centre is an assurance summary. It is not a statement of certification or a legal conclusion that every deployment is subject to identical POPIA or GDPR obligations.