Information lifecycle
Privacy
Fatti services may process device-linked wireless and location observations and information entered through a venue’s captive portal. The fields, purposes, legal roles, recipients and retention period depend on the venue configuration and agreement.
Information categories
| Category | Typical service use |
|---|---|
| Wireless and device-linked observations | Estimate presence, movement and patterns within a covered venue |
| Captive portal information | Provide Wi-Fi access and support purposes stated in the venue notice |
| Derived analytics | Produce authorised trends, dashboards and reports |
| Technical and support records | Operate, protect and troubleshoot the service |
Device identifiers and location histories can remain personal or pseudonymous even where a person’s name is absent. Fatti therefore does not make a blanket claim that all analytics records are anonymous.
Roles and purposes
The responsible party/controller and operator/processor roles are determined for each processing purpose and client agreement. Fatti may act on a client’s instructions for one activity and have a different role for another. The venue-facing privacy notice should explain the applicable purposes and choices at the point of collection.
Retention, sharing and locations
Retention and deletion requirements are set per dataset and service. Recipients, processing locations and cross-border arrangements are confirmed in the applicable due diligence and contract process. Public wording cannot replace those deployment-specific records.
Individual requests
People can raise privacy questions or requests through the contact route shown in the applicable venue privacy notice or through the relevant Fatti client contact. The responsible organisation will confirm identity, legal role, scope and applicable response requirements.
This trust centre is an assurance summary. It is not a statement of certification or a legal conclusion that every deployment is subject to identical POPIA or GDPR obligations.