FloraPulse · Privacy
Privacy Policy
How FloraPulse — the Android app and the web platform it works with — handles personal data.
Last updated: September 28, 2026
1. About this policy
This policy explains how personal data is processed in FloraPulse: the FloraPulse mobile app for Android (package pl.ajksoftware.florapulse, “the App”) and the FloraPulse web application and server the App works with (“the Platform”).
FloraPulse is a greenhouse monitoring tool for agricultural businesses. Their employees and contractors use the App to record manual measurements of plants and growing conditions — typically by scanning a QR label placed next to a plant and entering the measured values — and the Platform to review them on charts.
The App and the Platform are developed and published by AJK Software.
2. Who is responsible for your data
The FloraPulse server that publishes this page is operated by AJK Software, the controller of the personal data processed on it.
Organisations may also run their own FloraPulse server. In that case the organisation that created your account — usually your employer or client — decides how the Platform is used and is the controller of your data on its server. AJK Software then acts only as the software supplier and, where it hosts or maintains that server for the organisation, as a processor acting on the organisation’s instructions. Please direct questions about such a server to its administrator.
Contact details are given in section 14.
3. What data we process
- Account data: username, email address, assigned roles, account status and the dates the account was created and last changed. Accounts are created by an administrator — it is not possible to register in the App. Your password is never stored in readable form, only as a salted one-way hash (PBKDF2-HMAC-SHA512).
- Sign-in data: after you sign in, the server issues an access token valid for 15 minutes and a refresh token valid for 7 days. The server stores only a hash of each refresh token, with the times it was created, expires and was revoked.
- Measurements you record: the sensor or plant a reading belongs to, the measured values, the time of measurement and an optional free-text note. Each stored reading is linked to the account that uploaded it and to the time of upload, so that records can be attributed and verified.
- Technical connection data: when the App or a browser connects to the server, the web server writes standard technical logs — IP address, date and time, requested address, response status, amount of data transferred and the user-agent string (browser or app type). These logs are used for security and troubleshooting only.
We do not collect your location, contacts, photos or other files, microphone recordings, phone number, advertising ID or any other device identifier. The App contains no advertising and no analytics or crash-reporting libraries, and it does not track you across other apps or websites.
Please do not enter personal data about yourself or other people in the free-text notes.
4. Device permissions and data stored on your device
- Camera: used only to scan QR labels while the scanner screen is open. Camera frames are analysed on the device to read the code; no photos or videos are saved or sent anywhere. Android asks for your permission the first time you open the scanner. If you refuse, QR scanning is unavailable but the rest of the App keeps working.
- Internet and network state: used to communicate with the FloraPulse server and to check whether a connection is available, so that readings are sent only when that is possible.
- Data kept on the device: so that you can work without a connection, the App stores in its private storage the list of hubs, sensors and metrics you work with, the readings you have captured (including those waiting to be sent), the selected hub and your language setting. Sign-in tokens are kept in Android’s encrypted, Keystore-backed secure storage. Signing out removes the tokens and session settings; readings that have not been sent yet stay on the device so that they are not lost. Uninstalling the App, or clearing its storage in Android settings, removes everything the App has stored.
- QR code recognition uses Google ML Kit, which runs on the device: camera images are processed locally and are not sent to Google. Google states that ML Kit may contact Google servers to receive updates, and may send Google technical information about the device, the app and the performance of the scanning feature, which Google uses to maintain and improve ML Kit. See the ML Kit terms and privacy information at developers.google.com/ml-kit.
- Web application: the browser version stores your sign-in tokens and preferences (language, theme, layout) in the browser’s local storage. It does not use cookies for tracking and does not load third-party scripts, fonts or analytics.
5. Why we process data and on what legal basis
- To provide the Platform — to sign you in, keep you signed in, let you record measurements and show them in charts and reports. Legal basis: performance of the contract under which the Platform is provided to you or your organisation (Art. 6(1)(b) GDPR) and the operator’s legitimate interest in running the Platform (Art. 6(1)(f) GDPR).
- To keep reliable, attributable records of measurements, so that it is possible to verify who recorded them and when. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- To keep the Platform secure, prevent abuse and investigate faults. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
We do not use your data for marketing, advertising or profiling, we do not sell it, and we do not make decisions about you by automated means.
An account is necessary to use the App, except for the public demo described in section 11. Your administrator provides the account data; without it you cannot use the Platform.
6. Who receives your data
- Other users of the same Platform, according to their role — for example, administrators manage accounts and can see which account recorded a reading.
- Service providers that help run the Platform — the provider hosting the server and, where it maintains the Platform, AJK Software — acting on the operator’s behalf, only to the extent necessary and under a data processing agreement.
- Google, only to the limited extent described in section 4 (ML Kit).
- Public authorities, when the law requires it.
We do not sell personal data or share it with third parties for their own purposes. The operator does not transfer personal data outside the European Economic Area; should that ever become necessary, it will happen only with the safeguards required by the GDPR, such as the European Commission’s standard contractual clauses.
7. How long we keep data
- Account data: for as long as the account exists. An account that is no longer needed is deactivated, and its personal data is erased or anonymised on request (see section 10).
- Sign-in tokens: access tokens expire after 15 minutes and refresh tokens after 7 days; expired or revoked tokens can no longer be used.
- Measurements: these are production records of the organisation and are kept for as long as they are needed for that purpose. At your request, the link between the readings and your identity is removed or anonymised, unless keeping it is required by law or necessary to establish, exercise or defend legal claims.
- Server logs: only for as long as needed for security and troubleshooting — normally no longer than 30 days — after which they are deleted automatically.
- Data on your device: until you sign out, clear the App’s storage or uninstall the App, as described in section 4.
8. How we protect data
- All connections between the App or a browser and the server are encrypted with HTTPS (TLS).
- Passwords and refresh tokens are stored only as hashes, and access tokens are short-lived.
- Access is role-based, and only administrators can create accounts.
- The database is not reachable from the internet — only the Platform’s own services connect to it — and backups are stored with access restricted to administrators.
- On the device, sign-in tokens are kept in encrypted storage, and the App’s data sits in its private storage, which other apps cannot read.
No method of transmission or storage is completely secure, but we apply technical and organisational measures appropriate to the risk.
9. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict its processing, to data portability where processing is based on a contract, and to object to processing based on legitimate interests.
You can change your password yourself on the Profile page of the web application. To exercise your other rights, contact the operator using the details in section 14, or ask the administrator of your organisation. We respond without undue delay and in any case within one month.
You also have the right to lodge a complaint with a data protection supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl); you may also contact the authority of the EU country where you live or work.
10. Deleting your account and data
Accounts are created and managed by administrators, so the App has no self-service account deletion. To have your account and the personal data linked to it deleted, send a request to the operator using the contact details in section 14 — preferably from the email address linked to your account — or ask the administrator of your organisation.
Once we have confirmed that the request comes from the account holder, we deactivate the account without delay and erase or anonymise its personal data within 30 days, except data we are required to keep by law (see section 7).
To remove the data stored on your device, sign out and uninstall the App, or clear its storage in Android settings (Settings → Apps → FloraPulse → Storage).
11. Public demo
The App’s sign-in screen offers a public demo that connects to the demonstration server operated by AJK Software (florapulse-demo.ajksoftware.pl) with a shared demo account. No personal data is needed to use it.
Everything entered in the demo is visible to all other demo users and may be deleted at any time. Please do not enter any personal data there.
12. Children
FloraPulse is a professional tool and is not directed at children. We do not knowingly collect personal data of children under 16.
13. Changes to this policy
We may update this policy when the App, the Platform or the law changes. The date at the top of this page shows when it was last updated. Significant changes will be announced on this page.
14. Contact
Questions and requests about personal data processed on this server can be sent to:
- Operator
- AJK Software
- Address
- biuro@ajksoftware.pl
- biuro@ajksoftware.pl
- Website
- ajksoftware.pl
FloraPulse is developed and published by AJK Software.