privacy

TIGER ENGINEERING is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with and what rights you have over it. It covers our web site, our online store, our security monitoring software and its mobile application, and our investor portal and its mobile application.


1. Who We Are and How to Reach Us

TIGER ENGINEERING ("we", "us", "our") is a company based in the Republic of Bulgaria. For everything described in this Policy we are the data controller, except where this Policy says otherwise - in particular section 6, where you are the controller of your own camera recordings.
For any question about this Policy, or to exercise any of the rights in section 12, write to us at info@tgrengineering.com. For technical matters, support@tgrengineering.com.
This Policy should be read together with our Terms of Use.

2. Information You Give Us

You give us personal data when you buy from our online store, register an account to download our software, contact us, or are given access to our investor portal. Depending on what you do, this includes:

  • your first and last name, and the company name where you buy as a business;
  • your email address and telephone number;
  • your address, city, postal code and country, where we need it to deliver goods or to issue an invoice;
  • your VAT number, where you buy as a business in the EU;
  • your preferred language and display settings;
  • the content of any message you send us, and our reply.

We ask only for what we need. Where a field is optional, leaving it blank does not stop you buying or using the product.
We never receive your card number. Card payments for our software are processed by Paddle, which acts as the Merchant of Record, and card details are entered on Paddle's own checkout. They do not reach our servers, our database or the software running on your machine. What we receive back is confirmation that a transaction settled, together with the country and tax treatment that applied to it. Payments in our online store are handled by PayPal, by bank transfer or by the courier on cash on delivery, and in none of those cases do we hold your card details.

3. Information We Collect Automatically

When you visit our web site, our server records the date and time of the visit, the IP address, the address of the page you came from, the pages and files you viewed, and basic information about your browser and operating system. We use this to keep the site working, to detect and investigate abuse, and to understand in aggregate how the site is used.
When you download our software, we record the operating system you chose, your IP address and the date of the download. We also derive an approximate country from your IP address, because the trial terms, the price and the currency we must show you differ between countries.
We do not use this data to build a profile of you for advertising, and we do not make any decision about you by automated means that produces a legal effect or similarly significantly affects you.

4. Cookies and Similar Technologies

Cookies are small files stored by your browser. We use two kinds.
Essential cookies keep you signed in, remember the contents of your cart, remember your language and theme, and protect forms against abuse. Without them the site does not work, so they are set on the basis of our legitimate interest in providing the service you asked for, and they cannot be switched off from within the site.
Non-essential cookies, used to measure how the site is used, are set only if you consent. You may give or withdraw that consent at any time, and withdrawing it does not restrict your access to any part of the site.
Some cookies last only until you close your browser; others remain until they expire or you delete them. Most browsers let you see which cookies are set, refuse them, or delete them. Blocking essential cookies will stop parts of the site working.
We do not use cookies to correlate your browsing with your identity for marketing purposes, and we do not sell or share cookie data with advertising networks.

5. Accounts for Our Software

To download our security monitoring software you register an account and confirm your email address. We send a one-time link to that address; using the link both confirms the address and signs you in. We store the link's token until it is used or expires.
Each installation identifies the machine it runs on by a value derived from that machine's hardware, such as network adapter, motherboard, processor and disk identifiers, combined and stored as a one-way cryptographic hash. We cannot reconstruct the original hardware details from it. We use it to bind a licence to one machine, to deliver the right detection agents to it, and to recognise the same installation when it reconnects. Because it is linked to your account, we treat it as personal data.
Alongside it we store the technical state of your installation: which version it runs, which agents it is entitled to, when its licence starts and ends, and when it last contacted us. Our servers also keep operational logs of those contacts so that we can diagnose faults.
For orders we store what was bought, the amount and currency, the market whose price list applied, the period, whether you asked for automatic renewal, the status of the payment and its reference. We keep this because it is the record of a transaction, and tax and accounting law requires us to.

6. Camera Recordings: You Are the Controller

Our security monitoring software runs on your own equipment and processes video there. We are not the controller of your camera footage. You are. We do not decide why or how you record, we do not have routine access to what you record, and we do not stream, collect or retain it. Detection images and alarm history are stored on your machine, under your control, and it is for you to set a retention period, to answer requests from people who appear in the footage, and to meet the signage and transparency duties that come with operating cameras.
There are two narrow exceptions where an image does pass through systems we operate, and both exist only because you asked for the picture:

  • Live view and frame requests. When you open a live view or request a frame in the mobile application, your installation sends that image to our server, which holds it in memory only for as long as it takes to pass it to your phone, and then discards it. It is not written to our database and it is not archived.
  • Image notifications. If you turn on notifications that include a picture, that picture forms part of the push message and therefore passes through the notification infrastructure of Google or, on Apple devices, Apple. Turning image notifications off stops this.

Our software does not perform facial recognition or biometric identification, and we do not carry out any analysis of your footage on our side.

7. The Investor Portal

Accounts on our investor portal are created by us for people we already have an arrangement with; you cannot register yourself. For each account we hold the account name, the email address, a hashed password, your language and theme preferences, and, when you ask to reset a password, a time-limited reset token.
The portal reports on your participation, so it also holds financial information about you: amounts deposited and withdrawn, realised profit and loss, return figures, fees and a history of transactions. We hold this because we need it to perform our agreement with you and because we are required to keep proper records of it.
Market data shown in the portal describes securities, not you, and is licensed to us by a third-party data provider.

8. Mobile Applications and Push Notifications

Our mobile applications request the permissions they need to work: internet access, delivery of push notifications, background operation and, where required, a wake lock. You can change these at any time in your device settings.
To deliver a push notification we must be able to address your device, so we store a push notification token issued to your installation of the app, together with the platform it runs on, such as "android". A push token is unique to that installation and is therefore a device identifier. We use it only to send you notifications about your own system or your own account. If you turn notifications off, or the notification service tells us a token is no longer valid, we delete it.
Push messages are delivered by Google's Firebase Cloud Messaging and, on Apple devices, by Apple's notification service. Those companies handle the message in transit.
We do not collect your contacts, your location, your photo library, or any identifier used for advertising.

9. Why We Are Allowed to Use Your Data

Data protection law requires us to have a lawful basis for each use. Ours are:

  • Performance of a contract: creating and running your account, licensing the software to your device, delivering agents and updates, taking and fulfilling orders, sending notifications you enabled, operating the investor portal and providing support.
  • Legal obligation: issuing and keeping invoices, accounting and tax records, and answering lawful requests from public authorities.
  • Legitimate interests: keeping our systems secure, preventing fraud and abuse of trials, diagnosing faults, understanding in aggregate how our products are used, and contacting existing customers about products similar to those they already have. We balance these against your interests, and you may object at any time under section 12.
  • Consent: non-essential cookies, and marketing messages where you are not already our customer. You may withdraw consent at any time, and doing so does not affect what we did lawfully beforehand.

10. Who We Share It With

We do not sell your personal data, we do not rent it, and we do not share it with advertising networks.
We do share it with the service providers we need in order to operate, each of which acts on our instructions under a written contract and may use the data only for the purpose we set:

  • our hosting and infrastructure providers, who store the data on our behalf;
  • Paddle, which processes card payments for our software as Merchant of Record and issues the invoice for those transactions;
  • PayPal, where you pay that way in our online store;
  • Google, for delivery of push notifications, and Apple where the device requires it;
  • the courier that delivers your order, which receives the name, address and telephone number needed to deliver it;
  • our email delivery provider, for account and service messages;
  • our accountants and auditors, and our legal advisers where we need advice.

We may also disclose personal data where the law requires it, in response to a lawful order from a court or public authority, or where it is necessary to establish, exercise or defend a legal claim, or to protect the safety of a person. If our business or part of it is transferred to another company, personal data may pass with it, and you will be told before that happens.

11. Transfers Outside the EEA and How Long We Keep Data

We are based in the EU and store data here. Some of the providers in section 10 process data outside the European Economic Area. Where that happens, the transfer is covered either by a decision of the European Commission that the country offers adequate protection, or by the European Commission's Standard Contractual Clauses together with additional safeguards. You may ask us which applies to a particular provider.
We keep personal data only for as long as we need it:

  • Account data: while your account is open, and for 12 months after you close it, so that we can deal with anything arising afterwards.
  • Orders, invoices and accounting records: for as long as tax and accounting law requires us to, which in Bulgaria is currently up to 10 years.
  • Device and licence records: while the licence is active, and for 12 months after it ends.
  • Download records, including the IP address: 12 months.
  • Server and application logs: 12 months, unless a log is needed longer for a security investigation.
  • Support correspondence: 3 years from the last message, so that we can follow the history of an issue.
  • Push notification tokens: until notifications are switched off or the token stops being valid.
  • Live view and frame images: held in memory only for the seconds needed to pass them to your phone, then discarded.
  • Investor portal records: for the duration of your participation and for as long afterwards as financial record-keeping law requires.

When a period ends we delete the data or anonymise it so that it can no longer be linked to you.

12. Your Rights

Under the General Data Protection Regulation you have the right to:

  • be informed about how we use your data, which is what this Policy is for;
  • access your data and receive a copy of it;
  • have it corrected if it is wrong or incomplete;
  • have it erased, where we no longer need it or where you withdraw a consent we relied on;
  • restrict how we use it while a dispute about it is resolved;
  • portability - to receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible;
  • object to processing based on our legitimate interests, and to object at any time, absolutely, to direct marketing;
  • withdraw consent at any time where we relied on it.

To exercise any of these, write to info@tgrengineering.com. We will respond within one month; if a request is complex we may extend that by up to two further months and will tell you why. Exercising these rights is free, unless a request is manifestly unfounded or excessive.
We may need to confirm who you are before we act, so that we do not disclose your data to someone else. We will send a copy of your data only to the address already held on your account.
If you are unhappy with how we have handled your data, you may complain to the Bulgarian Commission for Personal Data Protection at www.cpdp.bg, or to the supervisory authority of the EU country where you live or work. We would rather you came to us first so we can put it right.

13. Security

We take appropriate technical and organisational measures to protect personal data: encrypted connections to our web site and our services, passwords stored only as salted hashes and never in readable form, access to production systems limited to the people who need it, secrets held outside the application code, and separation between the systems that hold customer records and those that serve public pages.
No system is perfectly secure, and we cannot guarantee that a transmission over the internet is free of risk. If a breach occurs that is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, and we will notify the supervisory authority as the law requires.
You also have a part in this: keep your password to yourself, do not forward the one-time sign-in links we send you, and tell us at once if you think someone else has reached your account.

14. Children

Our web site, our products and our services are intended for adults and are not directed at children. We do not knowingly collect personal data from a child. In Bulgaria a child may consent to online services from the age of 14; below that age, consent must come from the holder of parental responsibility.
If you believe a child has given us personal data, write to info@tgrengineering.com and we will delete it.

15. Correspondence With Us

We keep the email correspondence you send us and our replies, together with the personal data it contains, so that we can answer you, follow the history of an issue and defend a claim if one arises. This Policy applies to that correspondence in the same way as to everything else, including the retention period in section 11 and your rights in section 12.

16. Changes to This Policy

We may update this Policy as our products and the law change. The current version is always published here, with its version number and date at the end.
If a change materially affects how we use data we already hold about you, we will tell you by email before it takes effect, and where the law requires your consent for the new use we will ask for it rather than assume it. Continuing to use the site is not how you agree to a material change.

17. Version

This Privacy Policy is Version 3.0, in force from 26 September 2026.
Version 2.0, dated 12 July 2026, covered the web site and the online store only.