Privacy Policy
Effective August 01, 2026
1. Who we are and what our role is
Parso Assets is a maintenance and asset management system (CMMS) sold to businesses. It is operated by Parso, a company incorporated in Costa Rica.
Understanding how responsibilities are split matters, because it determines who you should ask for what:
- Your company is the data controller. It decides what gets recorded on the platform, who has access and for how long. The assets, work orders, photos and history belong to it.
- Parso is the data processor. We process that data on your company's behalf and following its instructions, in order to provide the service.
If you are an employee or contractor of a company that uses Parso Assets and you want to access, correct or delete information about your work, your first point of contact is your company's administrator. You can also write to us and we'll help route it.
2. What data we collect
2.1 Your user account
First and last name, email address, phone number (if your company enters it), role within the platform, preferred language and — where your company uses it to calculate labour costs — your hourly rate. Your account is created by your company's administrator: the mobile app does not allow sign-up.
2.2 Content you record while working
Work orders, comments, logged hours, parts consumed, meter readings, checklists, sign-off signatures, and before-and-after photos. All of it is associated with your company's account and with your user.
2.3 Technical data
IP address, device and browser type, access dates and times, and error logs. We use these to operate the service, diagnose faults and detect abuse.
3. Permissions the mobile app requests
The app only asks for a permission when you are about to use the feature that needs it, and you can decline: the rest of the app keeps working.
- Camera. To scan asset QR codes, take evidence photos on work orders, and register equipment by photographing its nameplate. When scanning a QR code the image is processed on the device and never uploaded; only the code is read.
- Photos. So you can attach an image already on your phone to a work order. We only access the images you select.
- Microphone. To record voice notes describing job progress. See section 4.
- Notifications. To alert you about assigned work orders and upcoming due dates. A device identifier (notification token) is stored against your user.
The app does not access your location, your contacts, your calendar, or the rest of your photo gallery.
4. Use of artificial intelligence
Some features use Google Gemini models. Specifically:
- Voice notes. The audio is sent to Google to be transcribed and summarised. The audio is not stored: it is processed and discarded immediately. The only thing saved on the work order is the resulting text, which you can review and correct before accepting it.
- Nameplate photos. The image is sent to Google to read make, model and serial number and pre-fill the equipment registration form.
- Documents. Manuals and certificates you upload may be processed to extract expiry dates and maintenance plans.
- Analyst. The questions you type are sent along with the results of queries scoped to your company's data.
This data is not used to train models. If your company prefers not to use AI, the feature is switched off at the account level and the whole platform continues to operate manually.
5. Who we share data with
We do not sell personal data and we do not share it with advertisers or data brokers. We do not track you across applications. We share data only with the providers we need in order to run the service:
| Provider | Purpose | What it receives |
|---|---|---|
| Heroku (Salesforce) | Application and database hosting | All service data |
| Amazon Web Services (S3) | Photo and document storage | File attachments |
| Google (Gemini) | AI features | Audio, images and text processed on the fly |
| Expo | Push notification delivery | Device token and notification content |
| Stripe | Subscription billing | Company billing details |
| Postmark | System email delivery | Email address and message content |
| Sentry | Error diagnostics | Technical logs, which may include your user identifier and the requested path |
We may also disclose information where a competent authority requires it by law.
6. Where data is stored and for how long
Data is hosted on servers located in the United States. If you access the service from another country, this involves an international transfer.
We retain data for as long as your company's account is active. When the contract ends, data is deleted within 30 days, except billing records, which we retain for the period required by accounting and tax rules.
7. Security
- All traffic is encrypted with HTTPS/TLS.
- Passwords are stored hashed, never in plain text.
- In the mobile app, session credentials are held in the system secure store (iOS Keychain / Android Keystore), and the offline work queue is protected by the phone operating system's own encryption at rest.
- Each company is isolated from every other at the data level.
- Access is recorded in an audit trail your company can review.
8. Your rights
You may request access, rectification, deletion, restriction and portability of your personal data, and object to certain processing.
To delete your user you have three routes: do it yourself in the mobile app under Profile → Delete my account, do it from your profile in the web version, or use the public account deletion page. Deleting your user permanently erases your email, name and phone number. The company's maintenance history is retained without your personal information, because it belongs to the company rather than to you.
To delete a company's entire account — with all of its assets, work orders, photos and history — the request is made by someone with the owner role from that same page. We verify the request and carry it out within 30 days.
9. Minors
Parso Assets is a workplace tool and is not directed at minors. We do not knowingly collect data from minors.
10. Changes to this policy
If we make material changes we will update the effective date in the header and notify customer companies by email before they take effect.
11. Contact
Write to [email protected] with any question about privacy or about exercising your rights.