Documentation

Go to Portal Website

Privacy And Telemetry Controls

Privacy and telemetry controls determine what security context AppTego collects and how deployed apps refresh supported configuration. Use these controls deliberately and align them with your privacy notice, legal basis, retention policy, and customer support process.

Collect enough context to investigate security events, but avoid collecting data your team does not need.

Control Matrix

ControlPlatformsMinimum planExecutionUse when
Configuration Update FrequencyAndroid, iOSEnterpriseRuntime configurationYou need to tune how often protected apps check for configuration updates.
Store Device InformationAndroid, iOSEnterpriseTelemetry storageDevice posture and metadata should be available in AppTego logs.
Store IP AddressAndroid, iOSEnterpriseServer-side telemetry storageIP address collection is required for security analytics or compliance.
Store Location InformationAndroid, iOSEnterpriseServer-side telemetry enrichmentCountry-level location context from IP address is required and covered by your privacy policy.

Store Location Information depends on Store IP Address. AppTego derives country-level location server-side from request IP metadata; it does not use device GPS APIs or trigger mobile location permission prompts.

Privacy Review Checklist

QuestionWhy it matters
What data is collected?Security teams need enough context to investigate events without collecting unnecessary information.
Why is it collected?Each telemetry control should map to a security, compliance, fraud, or support purpose.
Who can access it?Portal roles and support processes should match your organization policy.
How long is it retained?Retention should match your contract, regulation, and operational need.
What do users see?Privacy notices and consent flows should match the enabled controls.

Rollout Guidance

  1. Review the control with your privacy, legal, and security stakeholders.
  2. Confirm tenant roles and access permissions for logs that include telemetry context.
  3. Enable the control in Development or Staging and verify log output.
  4. Update privacy notices, support scripts, and data-handling records where required.
  5. Promote to Production only after retention and deletion workflows are understood.

Documentation To Keep Internally

RecordPurpose
Enabled telemetry controlsShows what data categories your protected apps can report.
Business purposeMaps each data category to security, fraud, compliance, or support need.
Access ownersIdentifies who can view or export telemetry.
Retention processConfirms how long data is kept and how exports are handled.
Support languageHelps support teams explain privacy-sensitive behavior consistently.