Last updated: July 2026
Privacy Policy
Controller
Bit ON Consultores S.L. (BitON) is the controller for data collected through the CoreAsset application and this website. Tax ID: B-61680591. Registered address: Calle Mandri, 66, 08022 Barcelona, Spain. Email: info@biton.es.
Legal framework
This Privacy Policy explains how we collect and process information when you use CoreAsset, including apps downloaded from Google Play Store, App Store or other app stores. It is drafted in line with the GDPR and Spanish data protection law.
Data collected
CoreAsset may process account data such as email address, name, company or organisation, user, assigned licence and active project; service data such as projects, assets, locations, catalogues, asset photos, imports, exports, backups, reviews and operational logs; and technical data such as platform, device model, operating system, app version, technical identifiers, errors and crash reports. To control the number of active devices per licence, CoreAsset may derive and store a pseudonymised technical installation identifier (computed by hashing the device identifier).
Purposes
We process data to manage authorised users, authentication and administration; provide asset inventory, review and control services; manage projects, assets, locations, photos, imports, exports and backups; answer support or contact requests; manage the contractual or commercial relationship between BitON, client organisations and users; send technical or functional notifications where required or consented to; and maintain security, traceability and app stability.
Legal basis
The legal basis may be performance of a contract or service relationship, user consent where required, compliance with legal obligations, and the legitimate interest of BitON or the client organisation in keeping CoreAsset secure, traceable and operational.
App permissions
Internet and network state are used for authentication, password recovery, authorised synchronisation, support and technical diagnostics. Camera is used to scan QR/barcodes and take asset photos when requested by the user. Photos and files are used to select images, import templates, export Excel/CSV, share documents and save or restore local backups. CoreAsset does not request the All files access permission in versions distributed through Google Play. On Android, generated documents are saved to public locations such as Downloads through Android shared-storage APIs, photos are published to Images or shared when requested by the user, and import/restore flows use system pickers for specific files. On Android 12 or below, legacy permissions such as READ_EXTERNAL_STORAGE or WRITE_EXTERNAL_STORAGE are used only when needed for compatibility with older versions. Bluetooth is used solely to detect and connect compatible RFID readers (Zebra) when this feature is enabled by the licence; CoreAsset does not use Bluetooth to determine the user's location. Notifications, when enabled, are used for technical, functional or service notices through Firebase or another configured provider. CoreAsset does not request geolocation permissions: references to "locations" within the app refer to the physical location of inventoried assets, not the user's position.
Recipients and providers
Data may be disclosed to BitON group companies, IT service providers acting as processors, including Google/Firebase for authentication, database, storage and messaging, and Sentry or other configured providers for error diagnostics. Data may also be disclosed to public authorities, courts and tribunals where legally required.
International transfers
Some providers, such as Google/Firebase or Sentry, may process data outside the European Economic Area (in particular, in the United States). Where this occurs, BitON relies on the safeguards provided for in Articles 44 et seq. of the GDPR, such as adequacy decisions —including the EU-US Data Privacy Framework for certified providers— or standard contractual clauses approved by the European Commission.
Retention
Data is retained while the contractual or service relationship remains in place, while the account or licence is active, until deletion is requested, and for the periods necessary to comply with legal obligations or handle potential liabilities. After a deletion request, some data may remain blocked where required for legal, security or audit reasons.
User rights
You may exercise your rights of access, rectification, erasure, restriction, objection and portability, and withdraw any consent given at any time without retroactive effect, by emailing info@biton.es or by post to Calle Mandri, 66, 08022 Barcelona, Spain, with the reference "Data Protection". You may also request account and data deletion at /en/delete-account. You have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
Minors
CoreAsset is a business and professional application. Under Spanish law, processing data of minors under 14 is lawful only when consent is granted by the holder of parental responsibility or guardianship.
Security
BitON applies technical and organisational measures to protect information against unauthorised access, loss, alteration or improper disclosure. Data is transmitted encrypted via HTTPS/TLS and access to CoreAsset is restricted to users authorised by their organisation.
Cookies and local storage (website)
This website does not use cookies, tracking technologies or third-party analytics or advertising services, so no consent banner is required. It only uses the browser's local storage (localStorage) to save two technical preferences chosen by the user: the visual theme (coreasset-theme) and the language (coreasset-lang). These preferences are strictly necessary to provide the requested functionality, do not identify or track the user, and are exempt from the consent requirement under Article 22.2 of the Spanish LSSI-CE and the AEPD Guide on the use of cookies. Fonts and other resources are served from the site itself, without connections to third-party servers. If non-essential cookies or analytics tools are added in the future, prior user consent will be requested through a compliant consent manager and this policy will be updated.