Privacy Policy
Amaya PestID · Last updated 15 July 2026
This policy explains what personal data the Amaya PestID mobile app and its web console (“the Service”) collect, how that data is used, and the rights you have over it. The Service is provided by Amaya Technology (“we”, “us”).
Who is responsible for your data
Amaya PestID is a business tool used by pest-control organisations. Where the Service is used by such an organisation, that organisation is the data controller for the operational records created through it (photographs, identifications, technician activity, and any customer or property details it chooses to record), and we process that data on the organisation’s behalf under our agreement with them. We are the controller for the account and sign-in data needed to provide the Service. If your organisation provided you with access, please also refer to their own privacy notice.
What we collect
- Account information — your name and email address, used to create and secure your account and to identify who recorded each capture.
- Photographs — the images you take of pests or signs of activity, which are the core of the Service.
- Location — the GPS position of a capture, when you allow it, so a record can be tied to where it was taken. You can decline location access and still use the app.
- Voice notes — audio you optionally record against a capture, and its transcription.
- Usage and device information — basic technical data such as app version and device type, used to operate the Service and diagnose problems.
How we use it
We use this data to identify pests from your photographs, to attach a defensible record to each identification, to sync your work to the web console for review and reporting, to secure your account, and to maintain and improve the Service. We do not use your data for third-party advertising, we do not sell it, and we do not track you across other companies’ apps or websites.
Legal basis (UK GDPR)
Where we act as a controller, we process account data to perform our contract with you or your organisation, and technical data under our legitimate interest in operating a secure, reliable service. Where your organisation is the controller, it is responsible for the legal basis of the operational records it collects through the Service.
Who we share it with
We use a small number of trusted service providers to run the Service, each acting on our instructions:
- Clerk — account authentication and sign-in.
- Cloudflare R2 — secure storage of capture images.
- Neon — the database that holds capture records.
- Vercel — hosting for the API and web console.
- Google (Gemini) — cloud verification of an identification from the capture photograph.
Some of these providers are based outside the UK. Where personal data is transferred internationally, it is protected by appropriate safeguards such as the UK International Data Transfer Agreement or Standard Contractual Clauses. We share data with these providers only as needed to run the Service, and with your organisation. We may also disclose data where required by law.
How long we keep it
Capture records are retained for as long as your organisation’s account is active, or as that organisation directs, so they remain available as part of its records. Account data is kept while your account exists. When an account is closed, associated data is deleted or anonymised within a reasonable period, except where we must retain it to meet a legal obligation.
Your rights
Under UK data protection law you have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, and to data portability. Where your organisation is the controller, please direct these requests to them; we will assist them in responding. To exercise a right, or to raise a concern, contact us using the details below. You also have the right to complain to the UK Information Commissioner’s Office (ico.org.uk).
Security
Access to the Service requires authentication, data is transmitted over encrypted connections, and access to stored data is restricted. No system is completely secure, but we take reasonable technical and organisational measures to protect your data.
Children
Amaya PestID is a professional tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated through the Service.
Contact us
For any question about this policy or your data, contact us at privacy@amaya.technology.