Privacy and Cookie Policy
This document explains which data the LIO SMART PRODUCTION service processes, why it is needed and how long it is retained. It applies to the website, LIO Cloud, the mobile app and connected LIO modules.
Test data
The provider identity, address, registration and contact details in this document are fictitious and intended only for application testing.
Controller and roles
The test provider LIO d.o.o., Testna ulica 1, 1000 Ljubljana, Slovenia, company registration number 0000000 and VAT number SI00000000, is the controller of data needed for user accounts, entering into and performing the contract, support, security and billing. Test privacy contact: privacy@lio.test.
For production, maintenance and employee data, the customer normally determines the purpose and use and acts as controller, while the LIO provider acts as its processor. This relationship is described in the Data Processing Agreement.
Cookies and similar technologies
LIO currently does not use advertising or analytics cookies. The web application uses only necessary browser local and session storage to enable sign-in, language selection, demo mode and the user display preferences. Because this storage is necessary for the requested service to function, no cookie consent banner is shown for it.
Data we process
- Account data: name, email address, protected password record and sign-in sessions.
- Device data: MAC address, machine name, operating mode, module settings and access-sharing data.
- Production data: machine states, part counts, metres, load, alarms, timestamps and operating history.
- Maintenance: service items, intervals, actual wear, completed maintenance and notes.
- Notifications and reports: device push token and email addresses selected by the user for reports.
- Technical data: information needed for operation, diagnostics, security and abuse prevention.
- Acceptance evidence: versions and SHA-256 fingerprints of accepted documents, date and time, user account, company, IP address, forwarded IP, user agent and the confirmed statements.
Legal bases
We process account and service data where necessary to enter into and perform the contract. We process security logs, abuse prevention, acceptance evidence and essential diagnostics for legitimate interests in operating a secure service and establishing, exercising or defending legal claims. Where the law requires processing, the basis is a legal obligation; where consent is required for an optional feature, the user may withdraw it prospectively.
Purpose and retention
| Data | Purpose | Expected retention |
|---|---|---|
| Account and email address | Sign-in, device management, access sharing and notifications. | Until the user account is deleted or the data is no longer required to provide the service. |
| Sign-in session | Maintaining secure sign-in on the website and app. | Until sign-out, session revocation or password change. |
| Machine data and history | Current status, history, reports, targets and maintenance displays. | Until the device, data or user account is deleted. |
| Service items | Maintenance planning according to actual wear. | Until the service item, device or account is deleted. |
| Push token | Sending alarm and downtime alerts. | Until sign-out, device replacement or notification withdrawal. |
| Report email addresses | Sending requested morning and test reports. | Until the user turns off reports or removes the address. |
| Temporary demo data | Providing an interactive trial without sign-in. | Normally up to two hours or until the demo session ends. |
| Legal acceptance evidence | Evidence of the document version, time and scope of acceptance and the user's authority. | For the contractual relationship and afterwards only as long as needed for applicable limitation periods, dispute handling or legal obligations. |
Local and session storage in the web app
| Data group | Purpose | Duration |
|---|---|---|
Secure session cookie lio_session | Maintains sign-in to LIO Cloud. The cookie is protected with HttpOnly, Secure and SameSite settings and is not accessible to JavaScript. | Up to 30 days, or until sign-out or session revocation. |
Language lio_lang | Remembers the user selected language. | Until changed or browser data is cleared. |
Demo mode lio_demo_mode | Separates the demo environment from the real user account. | Until leaving demo mode or clearing browser data. |
| Dashboard settings | Layout, pagination, graph visibility and machine naming. | Until changed or browser data is cleared. |
| Temporary page position | Preserves position while the interactive demo refreshes. | Until the browser tab or browser session ends. |
Data sharing
We share data only with providers necessary for a selected function: the hosting provider, email delivery provider, Firebase for push notifications and an AI service provider when the AI commentary feature is enabled. Other users can access data from a particular machine only when its owner explicitly grants sharing access.
We do not sell data or use it for advertising tracking.
User rights
Depending on the circumstances, individuals may request access, correction, deletion, restriction or portability, object to processing, and withdraw consent without affecting earlier lawfulness. In the test environment, requests may be sent to privacy@lio.test or to the customer where the customer is controller. A complaint may be lodged with the Information Commissioner of the Republic of Slovenia.
Policy changes
We will update this document when the service changes materially, when new providers are introduced or when new tracking technologies are used. The date of the latest change is always shown at the top of this page.