OPM (Security Project Management) OPM (Security Project Management)

Public legal page

Privacy Policy — OPM (Security Project Management)

OPM (Security Project Management)

Effective date13 August 2026
Last updated13 August 2026
Androidcom.app.opm
iOScom.opm.ae

https://opm.ae · support@opm.ae

This Privacy Policy explains how OPM / Security Project Management (“we”, “the app”) collects, uses, stores, shares, and protects personal data when you use the OPM app on Android and iOS, and the related services on the official website.

By creating an account or using the app, you agree to this policy. If you do not agree, please do not use the app.

1. Who this app is for

OPM is a workplace project-management tool. Administrators, project managers, supervisors, field workers, and clients use it to manage projects, tasks, expenses, requests, invoices, payments, team chat, and field updates.

Accounts are usually created or invited by the employer. The app is not directed at children.

2. Data we collect

We collect only what is needed to run the app. Depending on your role and the features you use, this may include:

2.1 Account and profile

  • Full name
  • Email address
  • Phone number
  • Login credentials (passwords are stored hashed/encrypted on our servers; we do not keep them in plain text)
  • Role, job title, department, and account status
  • Profile photo
  • Language and app preferences
  • Organisation / project membership

2.2 Work and activity data

  • Projects, tasks, comments, statuses, and assignments
  • Expenses, receipts, categories, and related notes
  • Operational / HR requests and approvals
  • Invoices, payments, and payment-proof files (when you or your organisation upload them)
  • Reports and exports you generate
  • Favourites, home-section order, and similar settings
  • In-app activity needed for dashboards, notifications, and latest updates

2.3 Media and files

  • Photos, video, and documents attached to tasks, expenses, requests, or chat
  • Voice messages recorded in chat (microphone permission is requested only when recording)
  • Files you pick from the gallery or file picker

2.4 Location

  • Address / location text entered on a profile, project, or task (for example a city or worksite).
  • Device location (GPS) only if you grant location permission and use a feature that attaches a field update or worksite. We do not sell location data and we do not use it for advertising.

2.5 Messages (chat)

  • Chat messages, attachments, and delivery/read status for project or team conversations
  • Chat content is stored so authorised members of the same project can communicate

2.6 Device, notifications, and security

  • Push notification token (Firebase Cloud Messaging)
  • Device type (Android / iOS) and app language, so the right notification can be sent
  • Approximate device/app information needed for login, session, and support
  • Auth tokens stored securely on the device
  • Optional fingerprint / Face ID unlock on this device only (biometric data stays on your device; we do not receive fingerprint or face templates)

2.7 Sign-in providers

If you sign in with Google, Apple, email/password, OTP, or UAE Pass (when enabled), we receive the identity data the provider shares with us (typically name, email, and the provider user id).

We do not collect payment-card numbers inside the app for card processing. Any payment proof is a file you or your organisation choose to upload.

We do not sell personal data.

3. How we collect data

  • Directly from you (registration, profile, forms, uploads, chat)
  • From your organisation (invites, role, project assignment)
  • Automatically when you use the app (session, notifications, network errors needed to run the service)
  • From operating-system permissions you grant (camera, photos, microphone, notifications, location)
  • From the sign-in provider you choose

4. Why we use data

We do not use your data for third-party advertising or sell it to data brokers.

5. App permissions

The app may request:

You can refuse or withdraw a permission in system settings. Some features may then be unavailable.

6. Sharing data

We share data only as needed to operate the service:

  1. Authorised people in your organisation — members of the same project or team who need the information to do their work.
  2. Service providers who process data on our instructions, including:
    • Hosting and API on the official website
    • Google Firebase (push notifications, Firestore chat, chat media storage)
    • Google Sign-In and Sign in with Apple (if you use those methods)
    • Map/location libraries if a map or GPS feature is used
  3. Authorities when there is a valid legal request.
  4. A successor if the business is transferred, with equivalent protection.

We do not sell personal data or share it for commercial marketing outside the service.

7. Storage, protection, and retention

  • Data is stored on our servers and trusted cloud providers (including Google Firebase for chat and notifications).
  • Access tokens are kept in secure on-device storage.
  • We use appropriate technical and organisational measures to limit unauthorised access, alteration, disclosure, or loss.
  • No transmission or storage method is 100% secure.

We keep data for as long as your account and organisation need the app, and as required by law, security, or accounting. When an account is deleted or the organisation asks for removal, we delete or anonymise the data within a reasonable time, unless we must keep it by law.

8. Your rights

Under applicable law (including the UAE Personal Data Protection Law where it applies), you may request:

  • Access to your personal data
  • Correction of inaccurate data
  • Deletion of your account and related personal data
  • Restriction of, or objection to, certain processing
  • Export of a copy of your data where technically feasible
  • Withdrawal of consent for optional permissions (camera, photos, microphone, location, notifications)

You can update much of your profile inside the app. For other requests, email the support address shown on this page.

If your account was created by an employer or client, some records may be under that organisation’s control. We may need to coordinate with them before deleting work records they are legally required to keep.

9. Account deletion (Google Play and App Store requirements)

You can request deletion of your OPM account by:

  1. Account / support options in the app, if available; or
  2. Emailing support from the address registered on the account, with the subject: Delete OPM account.

We will verify your identity, then delete or anonymise personal data linked to the account, except what must be kept by law or as part of the organisation’s work records (for example an approved expense in an audit file). Messages you sent may remain visible to other members in the project record unless the organisation asks for removal.

10. Children

The app is intended for adults in a professional context. We do not knowingly collect personal data from anyone under 18. If a child has used the app, contact us so we can delete the data.

11. International data transfers

Servers and processors (including Google Firebase) may be located outside your country. When data is transferred internationally, we take steps consistent with applicable law to protect it.

12. Cookies and similar technologies

The app uses local storage and similar technologies (such as a session token, language, UI order, and notification settings) to keep you signed in and remember preferences. It is not an advertising product that relies on cookies.

13. Changes to this policy

We may update this policy when the app or the law changes. The “Last updated” date above will change. Continued use after an update is acceptance of the revised policy. We may announce material changes in the app or by email.

14. Contact

OPM — Security Project Management

For privacy and support, use the email and website shown at the top of this page.