Legal

Privacy
Policy

Your data powers your operations, not ours. This policy explains what we collect, how we use it, how we protect it, and what rights you have. No legalese, no surprises.

Information
We Collect

Effective: August 2026

Account, Contact & Scheduling Information

When you create a Merobix account, contact us, or submit a demo scheduling request, Merobix or the scheduling provider receives the information you choose to provide:

  • Name, email address, and phone number if you choose to provide one
  • Company name, job title, facility location, and project details you submit
  • Requested meeting date and time, time zone, and scheduling notes
  • Billing address and payment information (processed securely via Stripe)
  • Login credentials (passwords are hashed with PBKDF2-HMAC-SHA256 at 200,000 iterations and never stored in plaintext)

Usage Data

We automatically collect information about how you interact with the Merobix platform:

  • Pages viewed, features accessed, and session duration
  • Dashboard configurations, alert preferences, and report settings
  • IP address, browser type, and device information
  • Login timestamps, session tokens, and authentication events

Android App Device ID

For the Merobix Android app, we collect an app-generated mobile device ID used for app functionality, security, fraud prevention, and device/session management. This identifier helps maintain authorized mobile sessions, device records, security posture, and account/device deletion workflows. The Android launch does not collect Advertising ID, Android ID, IMEI, hardware serials, hardware identifiers, Firebase Cloud Messaging tokens, crash logs through Sentry, precise location, camera data, microphone data, contacts, calendar, SMS, phone state, or body-sensor data. The app also does not request notification, overlay, foreground-service/subtype, boot/background-start, storage/media, install/package-query, nearby-device, exact-alarm, or sensitive hardware-feature access for this launch.

Device & Sensor Data

When you connect field equipment to the Merobix platform, we collect operational telemetry:

  • PLC register values, sensor readings, and process measurements (pressure, temperature, flow, level, etc.)
  • Gateway connection status, signal strength, and firmware version
  • Alarm events, threshold triggers, and acknowledgment history
  • Historian data including time-series records at configured polling intervals

How We Use
Your Data

Service Delivery

We use your data to operate and deliver the Merobix SCADA platform. This includes rendering live dashboards, generating trend reports, triggering alarm notifications, and maintaining your historian archive. Without this data, the platform cannot function.

Security & Access Control

We use authentication data, IP addresses, and session information to enforce multi-factor authentication, role-based access control, brute-force lockout policies, and full audit logging. Every login, config change, and alert acknowledgment is logged to protect the integrity of your operations.

Analytics & Improvement

We use aggregated, anonymized usage data to understand how customers interact with the platform, identify performance bottlenecks, and prioritize feature development. We never use your sensor data or operational telemetry for marketing, advertising, or any purpose unrelated to your service.

Data Storage
& Security

Encryption In Transit

All data transmitted between your gateways, the Merobix API, and your browser is encrypted with TLS 1.3. No data travels in plaintext at any point in the pipeline. Gateway-to-cloud connections are outbound-only, meaning your OT network never accepts inbound connections from the internet.

Encryption At Rest

All data stored in our databases and historian archives is encrypted at rest using AES-256. Backups are encrypted with separate keys. Database credentials are rotated regularly and never stored in application code.

Customer Data Isolation

Each customer's data is stored in isolated database partitions and separate historian buckets. There are no shared data pools. One customer's API query cannot access another customer's data under any circumstances. This isolation is enforced at the database, application, and API layers.

Data
Sharing

We Do Not Sell Your Data

Merobix does not sell, rent, or trade your personal information or operational data to any third party. Your sensor data, process measurements, and operational telemetry are yours alone. We do not monetize customer data in any form.

Limited Service Provider Sharing

We share limited data with service providers that help us operate the website, communicate with visitors, schedule meetings, and deliver the platform. Each provider handles data under its own terms, privacy commitments, and our applicable account settings:

  • Stripe - payment processing. Stripe receives billing information necessary to process your subscription. We do not store full credit card numbers.
  • SendGrid - transactional email. SendGrid delivers alarm notifications, password reset emails, and account communications. Email content is transmitted securely.
  • Railway - cloud infrastructure. Our API and databases are hosted on Railway with encrypted storage and isolated deployment environments.
  • Google Analytics 4 (Google) - website analytics on our marketing site (www.merobix.com) only. GA4 loads only after you accept analytics cookies, and has no access to your SCADA dashboard or operational data.
  • Microsoft Clarity (Microsoft) - website behavior analytics and session replay on our marketing site only. Clarity records anonymized interaction data (clicks, scrolls, mouse movement, page navigation) to help us improve the site. It loads only after you accept analytics cookies, and text you type into form fields is masked from recordings. Clarity is not present in the authenticated SCADA dashboard.
  • Content delivery and edge security - our marketing site is served through content-delivery and edge infrastructure, including a visitor-security monitor that logs request metadata (IP address, approximate geographic location, and network/ISP) to detect abuse, block malicious traffic, and protect site availability. This is essential security logging and does not depend on cookie consent.
  • Site chat assistant - if you use the on-site chat, your messages, the contact details you provide, and the page context are stored so we can respond and follow up on your inquiry, and are processed by our messaging and AI providers. We ask that you not submit passwords, live telemetry, or confidential OT information in chat.
  • YouTube (Google) - embedded product and training videos. We load YouTube videos through the privacy-enhanced youtube-nocookie.com domain, and no YouTube content loads until you click to play.
  • Cal.com - demo scheduling. The scheduler loads only after you click to open it. If you load or use the scheduler, Cal.com processes the scheduling information you submit, such as your name, email address, requested time, time zone, and any company, project, or scheduling details requested by the form, together with ordinary request and device metadata. Cal.com may use cookies or similar storage under its Privacy Policy.
  • Microsoft 365 and Microsoft Teams - approved meeting invitations. If Merobix approves a scheduling request and creates a meeting through Microsoft 365 or Microsoft Teams, Microsoft receives the attendee and scheduling information needed to create and send the invitation. This policy does not state that every scheduling request is approved or that a Teams meeting is created before approval.

Legal Requirements

We may disclose information if required by law, subpoena, or court order. If this occurs, we will notify affected customers to the extent legally permitted and will challenge overbroad requests.

Data
Retention

Account Data

Your account information, user profiles, and configuration settings are retained for as long as your Merobix account is active. Upon account cancellation, we retain account data for 30 days to allow for reactivation, after which it is permanently deleted from our systems.

Sensor & Historian Data

Operational telemetry and historian records are retained according to the retention policy associated with your subscription plan. Standard plans include 90 days of historian data. Extended retention is available on higher-tier plans. Upon account closure, sensor data is purged within 30 days of the retention period expiring.

Audit Logs

Security audit logs (login events, configuration changes, access records) are retained for a minimum of 12 months for security and compliance purposes, regardless of account status.

Your
Rights

You have the following rights regarding your data held by Merobix. To exercise any of these rights, contact us at [email protected].

  • Access - request a copy of the personal data and operational data we hold about your account
  • Correction - request correction of inaccurate or incomplete personal information
  • Deletion - request deletion of your personal data, subject to legal retention requirements and active contractual obligations
  • Data Export - request an export of your historian data and account information in a machine-readable format (CSV/JSON)

We will respond to all data rights requests within 30 days. For large data exports (historian archives exceeding 1 GB), we may require up to 60 days and will keep you informed of progress.

Cookies

Session Cookies

The Merobix SCADA dashboard uses session cookies to maintain your authenticated session after login. These cookies are essential for the platform to function and are not used for tracking or advertising. Session cookies expire after 8 hours of inactivity or upon logout.

Analytics Cookies (Consent Required)

Our marketing website (www.merobix.com) can use Google Analytics 4 and Microsoft Clarity to understand visitor traffic, page views, referral sources, and how visitors interact with pages. These tools set cookies and, in Clarity's case, record anonymized session interactions (with typed form input masked).

These analytics do not load until you choose "Accept" in our cookie banner. If you decline, or if your browser sends a Global Privacy Control or Do Not Track signal, no analytics cookies are set and neither tool is loaded. You can change your choice at any time using the Cookie Settings link in the site footer. Analytics cookies are only present on the public marketing site, never within the authenticated SCADA dashboard at scada.merobix.com.

Theme Preference

We store your light/dark mode preference in browser localStorage. This is not a cookie and contains no personal information. It simply remembers your display preference between visits.

Third-Party Demo Scheduler (Loads on Request)

The Cal.com scheduler is not loaded merely because you visit the Merobix demo page. It loads only after you click to open the scheduler or when you follow the external scheduling link. Once loaded, Cal.com may use cookies or similar technologies and receives information associated with your interaction under its Privacy Policy. Merobix does not state a fixed Cal.com or Microsoft retention period here; those providers' handling and retention are governed by their policies and the applicable Merobix account settings.

Questions About
Your Privacy?

If you have questions about this privacy policy, your data, or want to exercise your rights, reach out to our team directly.