ARTIENA CONCIERGE OFFICE · 2026-09-09

Privacy policy

Your office’s operational records stay on its reception device. Purchaser authentication is a separate service that processes limited account and security information.

Who this policy covers

Artiena LLC develops Artiena Concierge Office, a single-location Android reception application. This policy explains the application, purchaser account service and product website. Contact hello@artiena.com for privacy questions.

The office using the app decides why visitor and staff information is collected, who may access it and how long it is kept. Visitors and employees should contact that office first about their operational records. Artiena does not have remote access to the office database.

Information stored on your device

Depending on what reception enters, local records may include visitor names, companies, contact details, ID type/number/nationality/expiry, visit purpose, host, arrival/departure, badge number and return status. The app also holds staff directory details, vehicles and parking allocations, parcel handovers, meeting-room bookings, reception enquiries and office branding.

These records are stored in an encrypted application database, with the database key held through Android secure storage. No automatic synchronisation of those records to Artiena is implemented. Device compromise, unlocked access and exported files remain risks.

Camera ID capture and permissions

Camera access is requested when you choose to scan an ID or capture an image. ID text recognition uses the on-device recognition integration; it is not authoritative identity verification. Reception must review extracted fields before admission.

Google ML Kit processes recognition images and text on the device; it does not send those inputs or recognition results to Google. Separately, the SDK collects technical information, installation identifiers, performance and feature-event diagnostics for usage analytics and diagnostics over HTTPS. This technical collection is separate from the office records stored by Artiena Concierge Office. See https://developers.google.com/ml-kit/android-data-disclosure and https://developers.google.com/ml-kit/terms.

The camera workflow attempts to delete its own temporary ID capture when processing finishes, including failed processing. It does not delete unrelated gallery files. Abrupt termination, device/OS behaviour or a cleanup failure can leave temporary files. Office logos and intentionally retained local files are separate. Do not collect unnecessary ID information.

Purchaser accounts and authentication

When purchaser access is enabled, the secure account service receives the registered email, company, account identifier, installation identifier and activation, login and recovery requests. It stores password verifiers, encrypted authenticator secrets, hashed activation/recovery/session credentials, licence expiry/status and security-attempt records. Credentials are sent over HTTPS.

Account data is needed to verify purchaser access, restrict the registered installation and prevent unauthorised sign-in. The service does not accept visitor, staff, parcel, parking, booking or scanned-ID records. Your IP may appear in hosting/security logs; it is not used as the account’s identity.

The recovery code is shown after confirmed authenticator enrolment and is intended for one use. The server keeps a verifier, not a retrievable copy. Keep the code away from the reception device. It cannot recover a lost office database.

Exports, backups and other applications

CSV extraction and draft-email sharing happen only when someone using the app chooses them. Exported CSV files are readable, may include sensitive ID/contact information, and may be cached temporarily on the device. The selected email, storage or sharing application handles the file under its own privacy practices.

The local snapshot button saves an encrypted copy inside the app; that copy and its key may be lost when the app is uninstalled or its storage is cleared. Separate password-protected export and restore controls require verified purchaser access. Exports are limited to supported local storage or USB destinations, not cloud providers. Restore requires the same purchaser and an empty office. These controls remain unavailable in sample mode and without purchaser sign-in. Keep an external copy and its password securely; a backup on the same device does not protect against device loss. Account recovery does not restore operational records or recover a forgotten backup password.

Website, hosting and payments

The product website has no advertising trackers, analytics scripts or customer-record upload forms. The web host processes technical request information needed to deliver and protect the site. Contacting hello@artiena.com sends the information you choose to include through email providers.

No payment is collected by this pre-launch website or the local test build. A final purchase channel, price and any third-party payment processing will be disclosed before paid launch. Do not assume the local test trial is a verified subscription.

Retention, deletion and your requests

Operational records remain on the device until the office removes them or Android app data is erased. The office should set an appropriate retention policy and safeguard exports and snapshots. Do not uninstall or clear storage until you have considered the permanent data-loss risk.

Account information is retained while needed to provide access and address security/support matters. To request account deletion, contact hello@artiena.com from the registered email. We verify account control, explain any information that must be retained for applicable obligations, and confirm the outcome. Specific hosting-log retention follows the configured hosting service.

You may ask about access, correction, deletion or other privacy rights available under applicable law. Do not send identity-document images, passwords, authenticator setup keys or recovery codes by email. See the Data deletion page for the different request routes.

Changes and contact

This policy is supplied for launch review and must match the released configuration. Material changes to account hosting, payments, retention or data handling require an updated policy and appropriate notice. Last updated 6 September 2026. Privacy contact: hello@artiena.com.