Effective date: August 4, 2026

1. Who is the controller of personal data

The controller of personal data is:

  • Company / business name: PENTASHOT EU s.r.o.
  • Registered office: Zámecká 2315/9, 702 00 Ostrava, Czech Republic
  • Company ID: 29388937
  • Email for privacy-related questions: contact@pentashot.com

2. What data the app processes

The PS Valinorm app is a professional tool for Pentashot service technicians. It connects to a Pentashot laser meter over Bluetooth, measures the output power of a laser device, and records the result in PS Client, the controller’s own service database. Unlike our other apps, PS Valinorm requires a user account and does send data to the controller’s server.

The app processes the following categories of data in particular:

Sign-in credentials. The email address and password of the technician’s PS Client account. The credentials are sent to the PS Client server with every request in order to authenticate it, and are stored on the device in the operating system’s secure storage (Keychain on iOS, Keystore on Android) so that the technician does not have to sign in repeatedly.

Technician account data. Data returned by PS Client after a successful sign-in, in particular the account identifier, first name, last name, email address, company, and role.

Measurement data. The measured laser output power, energy, UIPM status code, the nine calibration points, the date and time of the measurement, and the label the technician assigns to it. Measurements are stored locally on the device and, when the technician chooses to send them, transmitted to PS Client together with the technician’s account identifier and the identifier of the measured product.

Product registration data. If the technician registers a product that is not yet in PS Client, the app sends the product type, serial number, identificator code, colour, and the first name and last name of the product owner.

Data from the QR code scanner. The app uses the camera to read the identificator code printed on the device. The image is evaluated on the device only; no photograph is stored or sent anywhere.

Technical data about the connected meter. For example the device name and its Bluetooth identifier, if made available by the operating system or Bluetooth layer.

The app does not process payment data, does not create user accounts, and contains no analytics or advertising components.

3. Why we process data

We process data for the following purposes:

  • to authenticate the technician against the PS Client account and to keep the session active on the device,
  • to ensure the main functionality of the app, that is connecting to a Pentashot meter, receiving readings, and evaluating them against the UIPM limits,
  • to store measurements locally so that the technician can keep working without a network connection,
  • to record measurements in PS Client as evidence of the service performed, together with the identity of the technician who carried it out,
  • to register a serviced product and link it to its owner,
  • to verify that the installed version of the app is still supported,
  • to ensure operation, diagnostics, and troubleshooting.

4. Legal basis for processing

Performance of a contract: authenticating the technician, connecting to the meter, evaluating and storing measurements, and recording them in PS Client as part of the service provided.

Legitimate interest: keeping verifiable records of performed measurements and of the products serviced, including the identity of the technician and the owner of the product, and ensuring the security, stability, and proper functioning of the app.

Data on the owner of a serviced product is entered by the technician and processed to the extent necessary to identify the product and its owner in the service records.

5. Where and how data is stored

On the device. Sign-in credentials are stored in the operating system’s secure storage. Measurements are stored in the app’s local database until they are deleted by the user or the app is uninstalled.

On the controller’s server. Measurements sent by the technician and product registrations are stored in PS Client, operated by the controller at client.pentashot.com.

All communication between the app and PS Client takes place over an encrypted HTTPS connection.

The app also downloads a static file from pentashot.com in order to check the minimum supported version. No personal data is sent in that request beyond what is contained in any ordinary web request, such as the IP address.

The app does not use any cloud service, analytics SDK, or advertising network other than the controller’s own server described above.

6. Who data may be disclosed to

Data may be disclosed only to the extent necessary for operation of the app:

  • to PS Client, the controller’s own service database,
  • to the connected Pentashot meter via Bluetooth communication,
  • to the operating system provider and system services to the extent necessary for Bluetooth, camera access, secure credential storage, or permission management,
  • to the provider of the hosting infrastructure on which the controller’s servers operate, as a processor.

Data is not sold and is not passed on to third parties for their own purposes, for advertising, or for profiling.

7. How long we retain data

  • Sign-in credentials are retained on the device until the technician signs out or the app is uninstalled.
  • Measurements stored locally are retained until the user deletes them or uninstalls the app.
  • Measurements and product registrations recorded in PS Client are retained for the period necessary to document the service performed and to meet the controller’s obligations.

8. What permissions the app uses

The app may require the following permissions:

  • Bluetooth permissions to find and connect to a Pentashot meter,
  • Location permission on Android if required by the operating system for Bluetooth Low Energy scanning; the app does not determine or record the user’s location,
  • Camera permission to read the identificator QR code on the serviced device.

The app does not use these permissions for marketing profiling or for tracking the user’s location on a map.

9. What rights the user has

Under applicable laws, the user may in particular have the following rights:

  • the right of access to personal data,
  • the right to rectification of inaccurate data,
  • the right to erasure,
  • the right to restriction of processing,
  • the right to object,
  • the right to data portability,
  • the right to lodge a complaint with a supervisory authority.

Data stored on the device can be removed by signing out, deleting the app’s data, or uninstalling the app. To exercise these rights in relation to data held in PS Client, contact the controller using the details in section 12.

10. Data security

The controller adopts appropriate technical and organizational measures to protect data. Communication with PS Client is encrypted using HTTPS. Sign-in credentials are stored in the secure storage provided by the operating system and are not written to the app’s ordinary database. Access to data in PS Client is limited to authenticated accounts holding the corresponding role.

11. Changes to this policy

This policy may be updated from time to time if the app’s functions, the way data is processed, or legal requirements change. The current version of the policy will always be published through the controller’s currently used distribution and information channels.

12. Contact

If you have any questions regarding personal data protection, contact the controller:

  • Email: contact@pentashot.com
  • Postal address: PENTASHOT EU s.r.o., Briketářská 667/1, 715 00 Ostrava, Czech Republic