Privacy and security

Privacy Policy

A structured description of how VTCYBER Security Management processes account, security, communication, device and notification data in the Apple application.

01

Controller and contact

VTCYBER Security Management is an internal communication and notification application connected with the VTCYBER system. The organization operating the VTCYBER system is the controller for account, security and communication data processed in the app. Contact: kontakt@vtcyber.pl.

02

Purpose of processing

The app is used for authenticated access to encrypted VTCYBER communications, private chats, group chats, the general operational chat, device vault activation, pairing of trusted devices, duty information and secure notifications.

03

Data processed by the app

  • Account identifiers: user ID, name, login, e-mail address, role and tenant or organizational context.
  • Security data: authentication token, MFA verification state, device identifier, device label, public cryptographic keys, pairing status, audit events, IP address and user agent in server logs.
  • Communication data: encrypted message payloads, thread identifiers, sender and recipient identifiers, timestamps, read state and unread counters.
  • Duty and activity data: current operator duty, next duty, online status and operational activity timestamps.
  • Diagnostics: technical errors and server logs necessary for security, abuse prevention and support.
04

Encryption and local protection

Where Secure Messaging is active, message content is end-to-end encrypted. The Secure Messaging framework uses a recoverable multi-device E2EE model following a Threema-style design: every trusted device has its own key material, pairing transfers an encrypted activation package, and the server stores encrypted payloads plus delivery metadata needed to synchronize messages. Private keys are stored locally in the device vault and protected by Keychain. Face ID or the device passcode may be used to protect access to the app content.

05

Supported Apple platforms

The app is prepared for iPhone and iPad. It may also be made available on Apple Silicon Macs as an iPhone/iPad app on Mac. Apple Watch is used for notification delivery only: watch notifications state that a message has arrived but do not expose plaintext message content and do not provide a separate chat interface.

06

Notifications

Push and local notifications do not show the plaintext message content. They may state that a private, group or general chat message has arrived. Delivery is handled through Apple Push Notification service where applicable.

07

Apple package and technical materials

The Apple submission package includes the VTCYBER home screen label, the privacy manifest PrivacyInfo.xcprivacy, App Store materials, this privacy policy in Polish and English, and the public privacy URLs for Apple review.

08

Data not collected for advertising

The app does not use advertising identifiers, does not track users across apps or websites, does not sell personal data, and does not use third-party advertising analytics. The app does not request access to contacts, photos, health data, payments or precise location for its core communication function.

09

Retention and archive

Message and security records are retained according to the VTCYBER system configuration and the controller's organizational retention rules. Archiving or removing a chat from the mobile list affects visibility for the signed-in user and does not necessarily delete records required by organizational retention, audit or security obligations.

10

User rights

Users may contact the VTCYBER administrator or the controller at kontakt@vtcyber.pl to request information about data processing, access, correction, restriction or deletion where applicable under law and organizational policy.