Privacy Policy
Last updated: July 2, 2026 (v2026-07-02)
This Privacy Policy explains how AuConsole collects, uses, shares, and protects information when you use our building-operations platform (the “Services”). AuConsole is a business tool: for most data, your organization decides how the data is used (it is the “controller”) and AuConsole acts as its service provider (“processor”).
1. How we classify your data
We work with three kinds of data, and treat each differently:
- Primary Data — the core records you put into AuConsole to run your operations: people and team members, vendors, work orders, equipment and asset records (including model and serial numbers), locations and floor plans, incidents, inventory, and documents. This data is kept isolated to your organization with technical controls designed to enforce that isolation. We do not share it across customers, and we do not sell or license it. We handle Primary Data only to provide and support the Services, acting on your organization’s instructions.
- Secondary Data — sensor telemetry from connected building-automation systems (energy and equipment readings over time). We collect this only where your organization has turned on telemetry. We treat it carefully because usage patterns can sometimes reveal information about people or a specific building.
- Aggregated / De-Identified Data Products — statistics we derive from Secondary Data, such as energy-use benchmarks and percentiles grouped by building type, climate zone, and size band. Before this data leaves our internal analytics, we aggregate it so that each published figure reflects multiple sensors drawn from multiple organizations, we suppress small, single-building, and single-organization groupings, and we remove identifiers, so that it is not designed to identify a person or your organization.
2. How we use data
- to provide, secure, maintain, and support the Services;
- to communicate with you about your account, security, and updates;
- to produce internal, cross-organization benchmarks shown to customers within the Services;
- to comply with law, enforce our terms, and protect the rights and safety of our users;
- with your organization’s separate opt-in, to operate the optional data-licensing program described in Section 3.
3. The optional third-party data-licensing program
If — and only if — your organization turns on the optional third-party data-licensing program (which is off by default), AuConsole may license Aggregated / De-Identified Data Products derived from sensor telemetry to third-party vendors (for example, equipment manufacturers) for their research and development, in exchange for payment. Where this program is enabled:
- we license only the aggregated, de-identified data products described above — never raw sensor readings;
- we do not sell or license Primary Data, personal data, equipment master records, floor plans, or incident history, and the products are designed and tested so they do not identify you, your staff, or your organization;
- before any data product is made available, we aggregate it so that each figure reflects multiple sensors from multiple organizations, with single-building and single-individual data suppressed;
- we commit not to attempt to re-identify the data (except to test that our de-identification works), and we contractually require every recipient to do the same, to not link it to any individual, and to not resell or redistribute it.
Your organization can turn this program off at any time; doing so stops your telemetry from feeding data products created or refreshed afterward. Because published products are aggregated across many organizations, turning it off is prospective and does not require recall of products already delivered.
4. When we share information
- Service providers — vendors who process data on our behalf to run the Services (for example, cloud hosting and email delivery), under contracts that limit them to that purpose.
- Within your organization — with other authorized users of your organization’s account, according to the roles and permissions your administrators set.
- Third-party data-product recipients — only the aggregated, de-identified data products described in Section 3, and only where your organization has enabled that program.
- Legal & safety — where required by law or valid legal process, or to protect rights, safety, and the integrity of the Services.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.
5. Your choices & controls
Organization administrators can control data-sharing settings — including telemetry analytics, cross-organization benchmarks, and the optional third-party data-licensing program — from the organization’s data & privacy settings in the Services. Product usage analytics can be controlled per device. You can also exercise the privacy rights described below by contacting us.
6. Your California privacy rights (CCPA/CPRA)
If you are a California resident, you have rights to know, access, correct, delete, and limit the use of your personal information, and to opt out of its “sale” or “sharing.” We do not discriminate against you for exercising these rights.
“Sale” and “sharing”
California law defines a “sale” broadly to include disclosing personal information to a third party for monetary or other valuable consideration. Where your organization enables the optional third-party data-licensing program, our licensing of aggregated, de-identified data products may be treated as a “sale” under applicable law. We do not sell or share Primary Data or personal data, and we do not share personal information for cross-context behavioral advertising. We treat validly de-identified data as outside the definition of personal information; because de-identification is fact-specific, we provide the opt-out below in all cases.
How to opt out
- Use our “Do Not Sell or Share My Personal Information” request, or your organization’s data & privacy settings in the Services;
- We honor the Global Privacy Control (GPC) signal as a valid opt-out for browser-based personal information;
- You may also submit a request to privacy@auconsole.com.
Where our activities constitute the sale of personal information about consumers with whom we do not have a direct relationship, we register as a data broker where applicable law requires and maintain the corresponding filings and deletion processes.
7. Your rights in the EEA & UK (GDPR / UK GDPR)
For Primary Data and for Secondary Data processed to deliver the Services, your organization is the controller and AuConsole is the processor, acting on its documented instructions. Producing aggregated, de-identified data products and licensing them to third parties is a separate purpose that operates only where your organization has enabled it; that election is your organization’s documented instruction, and your organization is responsible for the lawful basis and for any notices to its staff and building occupants. We release only data produced under a documented de-identification standard; data that is merely pseudonymized (for example, tokenized but otherwise intact telemetry) remains personal data and is not licensed.
Subject to applicable law, individuals may request access, rectification, erasure, restriction, portability, and objection, and may lodge a complaint with a supervisory authority. Where we transfer personal data internationally, we use appropriate safeguards such as the EU Standard Contractual Clauses and the UK IDTA/Addendum. To exercise rights, contact privacy@auconsole.com.
8. Security & retention
We use technical and organizational measures designed to protect data, including tenant isolation and access controls. No system is perfectly secure, and we cannot guarantee absolute security. We retain data for as long as needed to provide the Services and as your organization configures, and as required to meet legal, accounting, or reporting obligations.
9. Children
The Services are for business use and are not directed to children. We do not knowingly collect personal information from anyone under 16.
10. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide reasonable notice (for example, by posting the updated Policy with a new effective date or notifying you in the Services).
11. Contact
For privacy questions or to exercise your rights, contact privacy@auconsole.com. Data-protection inquiries for the EEA/UK may be directed to [DPO / EU-UK REPRESENTATIVE].