Vatra
Privacy Policy for the Vatra apps
Effective October 9, 2026
Who we are and who is responsible for the data
Vatra is a workplace system for hospitality venues such as restaurants and hotels. It is developed and maintained by IMtech. This policy covers the mobile apps Vatra (for venue staff) and Vatra HD (for the maintenance service) and the Vatra back office in the browser. Each client company runs on its own Vatra server. Staff data belongs to that company, your employer: it decides who has access and how long data is kept. IMtech processes the data on the company's behalf so that the system works.
Data we process
- First and last name and phone number — to sign you in and to let colleagues and managers see who filed or handles a request. Required.
- Password — to sign you in; the server stores it only as a hash. Required.
- Position, venue, service and role — to show you the relevant requests and actions. Required.
- Profile photo — so colleagues can recognise you. Optional.
- Requests: text, comments, photos of the problem and of the completed work, expenses on a request — the core function of the app.
- Device identifier for notifications (a Firebase Cloud Messaging or Apple Push Notification service token) and the phone type — to send notifications about requests. Only if you allowed notifications.
- Beta feedback: your description of an idea or a bug and the screenshots you attach — to fix and improve the app. Optional.
- Server records: sign-in time, list of active sessions, request activity log — for security and request history.
What we do not collect
We do not collect location, contacts, advertising identifiers, health or payment data. The apps contain no ads and no third-party analytics. PIN, Face ID and fingerprint are checked on your phone only: the app never receives or transmits biometric data.
Phone permissions
- Camera — to photograph a problem or the completed work.
- Photos — to attach a picture from the gallery to a request or profile; the app only gets the photos you pick.
- Notifications — to tell you about changes in requests.
- Face ID or fingerprint — to open the app quickly instead of typing a password.
Each permission can be revoked in the phone settings.
Who receives the data
- Your employer — data is stored on its Vatra server and is visible to managers and colleagues according to their roles.
- Google (Firebase Cloud Messaging) and Apple (Apple Push Notification service) — only to deliver notifications to your phone: the device identifier and a short notification text.
- IMtech — beta feedback and technical support of the servers.
We do not sell data or share it for advertising.
How we protect data
The app talks to the server over an encrypted connection (HTTPS). Sign-in keys are kept in the phone's secure storage. Access to data on the server is limited by roles.
Retention
Data is kept while your account is active in the company's workspace and afterwards for as long as the employer or the law requires. After an account is deleted, personal data is erased or anonymised within 30 days; request records may stay in the venue's history without a link to you if the employer needs them for its records.
Your rights and account deletion
You can view and correct your data in the Profile section of the app, remove your profile photo, turn off notifications and end sessions on other devices. To delete your account and the data associated with it, use the account-deletion form linked below and state the app name (Vatra or Vatra HD) and the phone number of the account, or ask the manager of your venue, who closes the access and files the request. We reply within 30 days. If deletion depends on the employer, for example because it is obliged to keep records, we will tell you and pass the request on.
Children
The apps are intended for venue employees aged 18 and over. We do not knowingly collect children's data.
Changes to this policy
If this policy changes, we update the date at the top of the page and announce material changes in the app.