Privacy Policy

Last updated: 15 May 2026 | Version: 1.1.1

1. Introduction

POWERENT Ltd. ("we", "us", "our") operates the Helionix platform – a software-as-a-service solution for construction project management, workforce management, and task coordination.

We respect your privacy and are committed to protecting your personal data in accordance with:

  • General Data Protection Regulation (GDPR) – Regulation (EU) 2016/679 of the European Parliament and of the Council
  • Bulgarian Personal Data Protection Act (ЗЗЛД)

This Privacy Policy explains what personal data we collect, the purposes for which we process it, and your rights as a data subject.

2. Who is the data controller?

POWERENT Ltd.

Tax ID (EIN): 202432231

VAT Registration No.: BG202432231

Registered office: Galabovo 6280, 4 Panayot Hitov Str, Bulgaria

Managing Director: Dilyana Simeonova Ilieva

Email: info@powerent-ltd.com

3. What personal data do we collect?

3.1 For Organizations (B2B Clients)

  • Legal entity name
  • Registered business address

3.2 For system users

  • First and last name
  • Email address
  • Position/role in organization
  • Password (hashed, not stored in plain text)

3.3 For construction site workers

  • First and last name
  • Phone number
  • Specialty/profession
  • Hourly rate

3.4 Platform Usage Data

  • Working hours: clock-in and clock-out timestamps (check-in/check-out)
  • Geolocation data: collected ONLY at the time of check-in/check-out for the purpose of verifying the worker's presence at the designated work site. GPS coordinates are not used for continuous tracking and are not stored as a standard server attendance recordthey are processed for validation and may be held temporarily on the device or pending synchronization in offline mode until validation or cleanup is completed.
  • Device identifier: An encrypted unique identifier used to associate one worker with one device
  • IP address: Logged in audit records for security and action tracking purposes

4. Why do we process your data?

Data typeLegal basis
Name, email, phoneContract (Art. 6(1)(b) GDPR)necessary for the performance of a contract
Working timeContract, legitimate interest, and/or legal obligation (Art. 6(1)(b)(c)(f) GDPR), depending on the Controller's use case and applicable employment law
GPS coordinatesLegitimate interest (Art. 6(1)(f) GDPR) and/or consent or worker notice where required by applicable law or the Controller's policy
Device IDLegitimate interest (Art. 6(1)(f) GDPR) – fraud prevention and security
IP addressesLegitimate interest (Art. 6(1)(f) GDPR) – audit trail and security monitoring

How We Use Your Data

We process your personal data for the following purposes:

  • Project Managementcreation and tracking of construction projects, tasks, and phases
  • Time Trackingrecording check-in/check-out times to calculate worked hours and wages
  • GPS Location Validationverifying that workers are at the correct work site at check-in/check-out
  • Security and Fraud Preventiondevice binding, IP logging, and audit trails to prevent unauthorized access
  • Communicationsending service notifications, system alerts, and important updates
  • Billing and paymentssubscription management, payment status, invoices, tax/VAT handling, and billing support. Payment card data is handled by Stripe and is not stored by Helionix.
  • Analytics and Improvementaggregated or technical telemetry used to improve platform performance only when the relevant analytics/performance feature is enabled.

How We Protect Your Data

We implement industry-standard security measures to protect your personal data:

Technical Measures

  • HTTPS/TLSall data in transit is encrypted using TLS 1.3
  • Password Hashingpasswords are hashed using bcrypt with salting
  • Data at Rest Encryptiondatabase encryption using AES-256
  • Row Level Security (RLS)strict tenant isolation in the database
  • Secure CookiesHttpOnly, Secure, SameSite attributes on all cookies
  • Rate Limitingprotection against brute-force and DDoS attacks

Organizational Measures

  • Access Controlrole-based access control (RBAC) with least privilege principle
  • Audit Loggingall sensitive operations are logged for accountability
  • Regular Backupsautomated daily backups with encryption
  • Incident Responsedocumented procedures for security incident handling

5. Who do we share data with?

We DO NOT sell, rent, or trade your personal data. We share personal data only with trusted providers that are necessary to operate, secure, bill, and support the Helionix platform:

ProviderServiceStatus / transferGDPR
Supabase Inc.→ View DPADatabase hosting & authenticationEU West (Frankfurt)SCCs
Vercel Inc.→ View DPAApplication hostingActive; Vercel infrastructure locationsSCCs
Stripe→ View DPASubscriptions, checkout, payments, invoices, tax/VAT evidenceActive; Stripe acts as processor and/or controller depending on the activityDPA / transfer mechanisms
Resend→ View DPATransactional email, notifications, DSAR confirmations, billing and partner messagesActive; email infrastructure and listed subprocessorsDPA / subprocessor list
Vercel Analytics / Speed InsightsWebsite analytics and performance telemetryConditional; used only when explicitly enabledVercel DPA
Google reCAPTCHAAnti-abuse checks for public/auth formsConditional; used only when reCAPTCHA keys are configuredGoogle terms where applicable
MapboxMap and geofence UI when Mapbox is configuredConditionalSubprocessor terms
Upstash RedisRate limiting and abuse prevention when Redis is configuredConditional✅ DPA

Subprocessor updates: The current Subprocessor List is available at /en/subprocessors. We will provide appropriate notice before material additions or replacements of active subprocessors where required by the DPA or applicable law.

List last updated: 15 May 2026

6. Your rights

Under the GDPR, you have the following rights with respect to your personal data:

  • Right of Access (Art. 15)to obtain a copy of your personal data
  • Right to Rectification (Art. 16)to correct inaccurate or incomplete data
  • Right to Erasure (Art. 17) – "Right to be Forgotten"
  • Right to Data Portability (Art. 20)to receive your data in a structured, machine-readable format (JSON/CSV)
  • Right to Object (Art. 21)to object to certain types of processing

How to Exercise Your Rights

Email: info@powerent-ltd.com

Online form: /en/privacy/request

Response timeframe: Within thirty (30) days from receipt of your request, in accordance with Article 12(3) of the GDPR

7. Cookies

By default, and without optional cookie-banner permission, we use only strictly necessary cookies required for the platform to function:

CookiePurposeRetention period
auth-tokenAuthentication30 days
device-idDevice binding1 year
worker-sessionWorker sessionUntil logout

Note: Consent is not required for strictly necessary cookies pursuant to GDPR Recital 30 and the ePrivacy Directive.

If Google reCAPTCHA or analytics/performance telemetry is enabled, it is loaded only after cookie-banner permission, and additional browser, device, interaction, IP, or performance signals may be processed by the relevant provider as described in the Subprocessor List and applicable provider terms.

Data Retention Periods

We retain personal data only for as long as necessary for the purposes set out in this policy, in compliance with GDPR Article 5(1)(e) - Storage Limitation Principle:

Data CategoryRetention PeriodLegal Basis
User account dataUntil account deletionContract
Attendance records5 yearsBulgarian Labor Code
GPS coordinatesStandard server record: not stored after validation; offline/pending sync: temporarily until validation or cleanupData minimization
Security logs2 yearsLegitimate interest
Notifications90 daysOperational necessity
Login attempts90 daysSecurity
Session data30 days after session endOperational necessity

After the retention period expires, data is either securely deleted or anonymized in accordance with our data retention policies.

8. Contact

For questions about privacy:

Email: info@powerent-ltd.com

POWERENT Ltd.

EIN: 202432231

Registered office: Galabovo 6280, 4 Panayot Hitov Str

Managing Director: Dilyana Simeonova Ilieva

Supervisory Authority

If you are not satisfied with our response, you have the right to lodge a complaint with:

Commission for Personal Data Protection (CPDP) of Bulgaria

Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria

Website: https://cpdp.bg

Email: kzld@cpdp.bg

© 2025-2026 POWERENT Ltd. All rights reserved.

Last update: 15 May 2026