Privacy Policy
Avera Sokhtmon CRM
Contents
- Overview
- Roles of the parties
- Who can use the app
- What data is processed
- Purposes of processing
- Legal basis and client consent
- App permissions
- Data storage and isolation
- Sharing with third parties
- Security
- Data retention
- Your rights and account deletion
- App Store and Google Play disclosures
- Children, changes, contact
1. Overview
This Privacy Policy describes what data is processed by the "Avera Sokhtmon CRM" mobile application (the "App") and its backend service, for what purpose, and under what conditions. The App is a workplace tool for employees of a construction/real-estate development company: it is used to manage projects, buildings and units (apartments, parking spaces, offices), clients and deals, generate contracts and installment schedules, record payments, and track warehouse/material stock.
The data controller for the development and provision of the App is Avera ("we", "us", "the Operator"). By installing and using the App, you agree to the terms of this Policy.
2. Roles of the parties
The App is a multi-tenant B2B system: each customer company operates in an isolated database under its own account. The following division of roles applies to the data of that company's employees and clients:
- The customer company (the developer/builder using the App) acts as the data controller for its employees' and clients' data — it determines what data is entered and is responsible for the lawfulness of its collection.
- Avera acts as the data processor — providing the software and infrastructure used to store and process this data on the customer company's behalf.
3. Who can use the app
The App is intended for employees of the customer company (roles: admin, sales manager, cashier, accountant, manager). There is no public self-registration in the App — employee accounts are created by the customer company's administrator.
4. What data is processed
4.1. Employee account data
First and last name, email address (login), phone number, password (stored as a hash), role in the system, SMS sign-in verification code, phone-verification status, and a profile photo (if uploaded).
4.2. Client data entered by the customer company
The App allows employees to record data about clients (property buyers): full name, phone number, email address, passport number, lead source, deal stage, manager notes, and photos of documents (including passport/ID scans or photos), which may be processed with automatic text recognition (OCR) — the extracted text is stored alongside the image. This data belongs to the customer company and is entered by its employees; clients themselves are not users of the App.
4.3. Business and financial records
Data about projects, buildings and real-estate units, contracts and installment schedules (including the client's passport number, which is inserted into the generated contract text), payments and receipts, expenses, and warehouse material stock.
4.4. Technical and diagnostic data
When the App communicates with the server, standard technical information is automatically recorded: IP address, request date and time, device model, operating system version, and App version. This data is used to keep the service running securely and reliably.
5. Purposes of processing
- authenticating and identifying employees;
- providing the customer company with CRM/ERP functionality: managing units, clients, deals, contracts, payments, and stock;
- generating contracts and installment schedules;
- sending SMS notifications (verification codes, payment notices);
- ensuring security, preventing abuse, and diagnosing errors.
We do not use data for advertising, do not track users across other companies' apps and websites, and do not sell data to third parties.
6. Legal basis and client consent
Consent from the client (buyer) to process their personal data, including passport data and documents, is obtained by the customer company offline, at the time the deal is made — outside the App. Processing of employee data is based on the employment relationship between the employee and the customer company.
7. App permissions
| Permission | Purpose |
|---|---|
| Network access (Internet) | Syncing with the server, authentication, sending and receiving data. |
| Camera | Taking photos of units, client documents, and receipts to upload into the system. |
| Photos / media library | Selecting existing images and documents for upload. |
| Local storage | Temporary on-device caching for stable operation. |
The App does not request access to location, contacts, or the microphone.
8. Data storage and isolation
Each customer company's data is stored in a separate, isolated database on the infrastructure used by the App. Uploaded files (photos, documents, receipts) are stored on server storage or in an S3-compatible cloud object storage, depending on the deployment configuration.
9. Sharing data with third parties
We do not sell or share personal or business data with third parties for advertising purposes. Limited disclosure is made only to the following service providers, which are necessary for the App to function:
| Service provider | Data shared | Purpose |
|---|---|---|
| SMS delivery provider | Phone number, message text | Sending verification codes and payment notifications. |
| Email service (SMTP) | Email address, message text | Service notifications and data-removal requests. |
| Cloud object storage | Uploaded files (photos, documents) | Storing and serving uploaded images and documents. |
| Hosting provider | Technical request data | Hosting the backend and web version of the App. |
Disclosure may also occur where required by applicable law or requested by authorized government authorities.
10. Security
We apply the following safeguards: employee passwords are stored as a hash and never in plain text; API access is protected by a time-limited authorization token that can be revoked on sign-out; access to data is restricted by role and permission within each customer company; the connection between the mobile app and the server is encrypted (HTTPS). No method of transmitting data over networks can be guaranteed to be completely secure, so we also recommend that users protect their credentials and devices.
11. Data retention
Customer company data is retained for the duration of the agreement to use the App. Upon a deletion request, data is deleted or anonymized within 30 days, except where longer retention of contractual, accounting, or financial records is required by applicable law.
12. Your rights and account deletion
Employee accounts are created and deleted by the customer company's administrator. Any user may independently submit a request to delete their data:
- through the form at /sokhtmon/remove-account;
- by email, using the address listed in the "Contact" section below.
If you are a client (buyer) of a developer company using the App and would like information about your data or to have it deleted, please contact that company directly as the data controller — Avera, as processor, will assist it in fulfilling such a request.
13. App Store and Google Play disclosures
| Data category | Collected | Shared with third parties | Purpose |
|---|---|---|---|
| Contact info (name, email, phone) | Yes | No (except the service providers listed in section 9) | Account functionality, communication |
| User identifiers | Yes | No | Authentication |
| Financial info (payments, contracts) | Yes | No | App functionality |
| Photos / documents | Yes | Cloud storage (section 9) | App functionality |
| Diagnostics | Yes | No | Security and stability |
| Precise location | No | — | — |
| Data used for ad tracking | No | — | — |
We confirm: the App does not track users across other companies' apps and websites, does not use data for targeted advertising, and does not share data with data brokers. An account and data deletion request can be submitted at /sokhtmon/remove-account.
14. Children's privacy, changes, contact
The App is intended for business use by employees of customer companies and is not directed at individuals under 18 years of age. We do not knowingly collect data from children.
We may update this Policy from time to time. The current version is always available at this page's address, and the "last updated" date is shown at the top.
For questions about data processing and this Policy, contact:
- Operator: Avera
- Email: avera.tajikistan@gmail.com
- Jurisdiction: Republic of Tajikistan