Privacy Policy
CAFM Way Mobile Applications — Technician and Requestor
This version replaces v1.0 of 1 October 2026. It corrects the permissions and data categories described there: the applications do not request or access location, contacts or phone state, and do not read Bluetooth or Wi-Fi signal, battery level, memory or device settings.
1. Introduction
CAFM Way is a workforce and facility-management platform developed by GXPWAY Vision Technologies & Consulting (“GXPWAY”, “we”, “us”). It is sold to organisations and used at work by people whose employer issued them an account.
This policy covers the two CAFM Way mobile applications — CAFM Way Technician and CAFM Way Requestor — on both iOS and Android. It explains what the applications collect, why each permission is needed, how information is used, what GXPWAY does not collect, and the choices available to users.
2. Permissions We Request
| Permission | Why we need it |
|---|---|
| Camera | Used only when a user taps the camera or scan control inside the application, to photograph a fault or completed work and to read an asset or location QR code. The applications cannot activate the camera without a direct user action. |
| Photos & media | Used when a user chooses an existing picture instead of taking one, and to hold photos on the device until they can be uploaded. The applications read only the pictures a user selects. |
| Notifications | Used to tell a technician that a job has been assigned or changed, and a requestor that their request has moved on. |
| Local network (iOS) | Used only where an organisation runs CAFM Way on its own network, so the application can reach that server. |
Every permission is requested the first time it is used and may be refused. The applications keep working without them: refusing the camera means you cannot scan or photograph, and refusing notifications means you check the app yourself. Permission can be withdrawn at any time in device settings.
3. Data We Collect
- Account information created by your organisation's administrator: name, work email, employee number, job title, role, and the organisation you belong to.
- Work data entered in the application: requests raised, jobs assigned, their status and history, notes, readings and observations, parts recorded, and messages about a job.
- Photographs a user attaches to a request, a job or a message.
- The asset or location identified by a QR code a user scans.
- A push notification token issued by Apple or Google so notifications can reach the device, stored with the device platform, time zone and notification preferences.
- Technical and security records needed to operate the service: sign-in attempts, application version, and basic request logs, used to keep accounts secure and to diagnose faults.
4. Data We Do Not Collect
The applications do not request, access or record any of the following:
- Location of any kind — neither while in use nor in the background. The applications do not perform geo-tracking and do not record distance travelled.
- Contacts, phone state, SMS messages, call logs or telephone conversations.
- Bluetooth or Wi-Fi signal data, battery level or charging status, available memory, or device developer settings.
- Photos or media outside those a user explicitly selects, browsing history, or data belonging to other applications on the device.
- Any advertising identifier. The applications contain no advertising, no analytics and no behavioural-tracking software, and do not follow users across other applications or websites.
GXPWAY does not sell personal data, does not use it for advertising or behavioural marketing, and does not use it to train models.
5. How We Use Your Data
Data collected through CAFM Way is used to provide and operate the platform’s workforce and facility-management functions: work assignment, work-order management, work reporting, verification of completion, photo documentation, operational reporting, audit trails, system security and technical support.
It is not used for any purpose the Client Organisation has not commissioned.
6. Data Retention
CAFM Way retains personal and operational data only for as long as reasonably necessary to provide its work-management, reporting, audit and recordkeeping functions.
Active account information, work assignments, work records, submitted photographs and related audit logs are retained while the user remains authorised by the Client Organisation to use CAFM Way.
Following account deactivation, employee departure, or termination of the Client Organisation’s use of CAFM Way, the relevant data will normally be retained for up to 12 months, unless a longer period is required by the Client Organisation, applicable law, contractual requirements, dispute resolution, security, or legitimate business recordkeeping requirements.
Where applicable, the Client Organisation may request earlier deletion, subject to legal, contractual and operational requirements. Data no longer required is securely deleted or anonymised.
Uninstalling a CAFM Way application does not by itself delete information already held on CAFM Way servers or in the Client Organisation’s records. Users should contact their Client Organisation or GXPWAY to request deletion.
7. Data Sharing & Third Parties
CAFM Way does not sell, rent or commercially disclose users’ personal data to third parties.
Within the Client Organisation, colleagues see what their role permits: a technician sees the jobs assigned to them, a supervisor their team’s work, an administrator the workspace. Where an organisation assigns work to a contractor, that contractor sees the job assigned to them.
Apple and Google deliver push notifications and receive the device token and the notification itself. For that reason notification text should never carry sensitive content.
Data may also be processed by authorised service providers supporting the operation, hosting, security, maintenance, backup and technical infrastructure of CAFM Way. Such providers process data only as necessary to provide their contracted services and are expected to maintain appropriate confidentiality and security safeguards.
CAFM Way may disclose information where required by applicable law, regulation, court order or governmental authority, or where reasonably necessary to protect the security and integrity of the service.
8. Data Ownership & Access
CAFM Way is deployed as a business application. The Client Organisation controls the workforce and operational data generated through its use of CAFM Way and is the data controller.
GXPWAY acts as the technology provider and processes such information to provide, maintain, secure and support the service.
Within the Client Organisation, access to an individual user’s work history, photographs, work reports and related records is limited to authorised personnel based on their assigned roles and permissions. GXPWAY personnel access data only where reasonably necessary for technical support, maintenance, security, troubleshooting or service administration.
Client Organisations are responsible for ensuring that access to employee information within their organisation is limited to authorised personnel and used in accordance with applicable law and their internal policies.
9. Security Measures
GXPWAY applies reasonable technical and organisational measures designed to protect CAFM Way data against unauthorised access, alteration, disclosure, loss or destruction. These measures include:
- Encryption of data transmitted between the applications and CAFM Way servers using secure communication protocols.
- Passwords stored only as a one-way hash, which nobody at GXPWAY can read.
- Role-based access control and authentication, with each workspace separated from every other.
- Account lockout after repeated failed sign-in attempts.
- Audit logging of relevant system and administrative activity.
- Regular software maintenance and security updates.
- Backup and recovery procedures.
- Monitoring for unauthorised access or security incidents.
- Controlled access to hosting and server environments.
10. Your Rights
Subject to applicable law, users may have rights regarding their personal data, including the right to request access to, correction of, or deletion of personal data, and the right to object to or withdraw consent for certain processing where applicable.
Users should normally submit requests through their Client Organisation, particularly where the information relates to employment, work assignments, work history or other operational records the Client Organisation controls. Users may also contact GXPWAY using the details in Section 13.
CAFM Way processes personal data in accordance with applicable requirements, including Qatar Law No. (13) of 2016 on Personal Data Privacy Protection, as applicable to the processing activities. Qatar’s law recognises rights including withdrawal of consent, objection to certain processing, deletion in specified circumstances, and correction of personal data.
11. Children's Privacy
CAFM Way is a business and workforce-management application and is not directed to children.
The applications are intended for use by employees, contractors, administrators, supervisors and other authorised personnel of Client Organisations. Users must be 18 years of age or older.
GXPWAY does not knowingly collect personal information from children. If GXPWAY becomes aware that such information has been collected contrary to this policy, appropriate steps will be taken to delete it where required by applicable law.
12. Changes to This Policy
GXPWAY may update this Privacy Policy to reflect changes in CAFM Way, applicable legal requirements, security practices, or data-processing practices.
When material changes are made, GXPWAY will provide reasonable notice through one or more appropriate channels, which may include an in-app notification, an email notification, or an updated notice within the service. The updated policy displays a revised effective date.
13. Contact Us
For questions about this Privacy Policy, or to exercise the rights described in Section 10, please contact GXPWAY.
Contact
GXPWAY Vision Technologies & Consulting
Global Business Center, Corniche Road, Doha, Qatar
- Support email
- Legal / notices email
- Address
- Website
Effective date · Document version · Policy owner · This version replaces v1.0 of 1 October 2026. It corrects the permissions and data categories described there: the applications do not request or access location, contacts or phone state, and do not read Bluetooth or Wi-Fi signal, battery level, memory or device settings.