This policy explains what personal data Mtik ISP Management holds in connection with MTIK, why it is held, who can see it and how long it is kept.
1. Two groups of people
The platform touches two groups, and they are treated differently:
- Subscribers. The businesses that buy the platform, and the people at those businesses who sign in to the dashboard. For their data, we decide what is collected and why — so we are responsible for it.
- End users. People who connect to a hotspot run by a subscriber. We hold that data on the subscriber's behalf and follow their instructions with it. The subscriber is responsible for telling their own customers what they collect.
2. What we hold about subscribers
- Account details: name, email address, the role the account holds and the period it may sign in for.
- A password, stored only as a one-way hash. We never see or store the password itself and cannot recover it.
- Business details you give us for your branding: company name, logo, contact line, and what you want printed on your vouchers and login pages.
- Records of use of the dashboard: when an account signed in, the address it signed in from, and the significant changes it made. This is what lets us answer "who changed that?" after something breaks, and it is also how we detect a stolen login.
- Messages you send us, over WhatsApp or email, and what we agreed about your subscription.
3. What the platform holds about end users
When someone connects to a subscriber's hotspot, the router records the session and the dashboard reads it. That means the platform may hold:
- the hardware (MAC) address of the device and the local IP address the router gave it;
- the voucher code used, when it was first used and when it expires;
- when a session started and ended, and how long it lasted;
- how much data the session moved, up and down;
- which router and which site the session belonged to.
What is not collected. The platform does not record browsing history, the sites or apps an end user visited, the contents of anything sent or received, message contents, or location beyond which site the device connected to. Nothing is inspected or decrypted. No end-user data is sold, shared for advertising, or used to build a profile.
A device address is treated as personal data even though it is not a name, because over time it can identify a person's device. That is why it is only ever visible to the subscriber whose site it connected to.
4. Why we hold it
- To provide the service you subscribed to — creating vouchers, showing live sessions, configuring routers, producing reports.
- To keep the platform secure — spotting stolen logins, blocking abuse, and being able to reconstruct what happened after an incident.
- To bill and support you — agreeing plans, sending renewal reminders and answering questions.
- Because a law says so — some countries require operators of public networks to retain session records for a set period. Where that applies, it applies to the subscriber operating the network, and we hold the data on their behalf.
5. Who can see it
Access is scoped by design. A subscriber account sees only the sites assigned to it and only the vouchers, sessions and reports belonging to those sites. One subscriber can never see another's routers, customers or figures.
Our own staff can access platform data only where it is needed to run the service, fix a fault or answer a support request.
6. Third parties
We do not sell data and we do not use advertising or analytics trackers. There is no Google Analytics, no advertising pixel and no social media tracker anywhere on this site. A small number of third parties are nonetheless involved:
- Our hosting provider, which runs the server the platform and its database sit on.
- A public content network (jsDelivr), which serves the fonts and icons used on these public pages. Loading them means your browser's IP address and the type of browser you use are visible to that network. It is not used for anything inside the dashboard.
- WhatsApp (Meta), if you choose to contact us on the number we publish. That conversation is subject to WhatsApp's own terms as well as ours.
7. Cookies
Only two cookies are used, and both are strictly necessary:
- a session cookie, which keeps you signed in and lets the site work at all;
- a security token cookie, which stops a form on another website from being submitted as if it were you.
Neither tracks you across other websites, and no cookie is used for advertising or measurement.
8. How it is protected
- Every router reaches the platform over its own encrypted tunnel, and no router has to be exposed to the internet to be managed.
- Traffic between your browser and the platform is encrypted in transit.
- Passwords are stored only as one-way hashes.
- Repeated failed sign-ins lock an account temporarily, so a stolen email address is not enough to guess a way in.
- What each account can see and do is limited to its role and its assigned sites.
No system is perfect. If a breach affects your data we will tell you, and any regulator we are required to inform, without undue delay.
9. How long it is kept
- Account details: while the account exists, and up to twelve months after it closes in case it is reopened or a record is needed.
- Vouchers and their usage figures: while the subscription is active, because a code sold months ago may still be in a customer's pocket. Expired vouchers keep only a snapshot of what was used.
- Session records read from routers: for as long as the subscriber keeps them, or for any longer period their own law requires. A subscriber can ask us to remove them sooner.
- Sign-in and change records: kept as a security record, then removed on a rolling basis.
- Support conversations: for as long as they are useful to support you.
10. Your rights
Depending on where you live, you may be entitled to ask us for a copy of the data we hold about you, to have it corrected, to have it deleted, to restrict or object to how it is used, or to receive it in a portable form. Write to us and we will answer within a month. You can also complain to the data protection authority where you live.
If you connected to a hotspot rather than subscribing to the platform, the business that runs that hotspot is your first point of contact — they decide what is collected. Come to us if you cannot reach them, and we will help.
11. Children
The dashboard is a business tool and is not intended for children. We do not knowingly collect data from children through it. A hotspot may of course be used by a family; that is a matter for the business running it and the law where it operates.
12. Where data is held
The platform runs on servers chosen by us, and your data may be stored or processed in a country other than your own. Wherever it is held, this policy and the same protections apply to it.
13. Changes to this policy
We update this policy when the platform changes. The date at the top shows when it last changed, and material changes are announced to subscribers before they take effect.
Contact
Questions about this document, or a request about your data, go to Mtik ISP Management:
- Email: mtikwifi@gmail.com
- WhatsApp: +971569625834
- +971 56 962 5834