Privacy Policy
Last updated: December 2025
About Us
Facilio is an IoT and AI-driven property operations and maintenance/facilities management software-as-a service ("SaaS") provider. This includes SaaS applications that helps owners, operators, and facility management teams run buildings and real-estate portfolios more efficiently, sustainably, and with better visibility. Facilio can be accessed on the web or as specific apps for mobile platforms.
Facilio, Inc. including its subsidiaries and affiliates ("Facilio", "we", "us" and/or "our") has created this Privacy Policy to explain how we gather, utilize, and otherwise process information relating to an identified or identifiable individual ("Personal Data") in affiliation with our website https://facilio.com/ (the "Site"), SaaS platform and our mobile application ("User Mobile Application") (cumulatively, the "Services"), as well as the choices you have regarding that information.
Information that Facilio collects
Facilio collects Personal Data you provide when you interact with our website, marketing pages, event registrations, or online forms. For these website and marketing activities, Facilio is the data controller. For information you submit within the Facilio platform as part of a customer account, your organisation (our customer) is the data controller, and we process that data on their instructions. To access, correct, or delete your Personal Data, please email dpo@facilio.com
If you are an end customer and your request relates to a customer account, we may direct you to that organization or coordinate with them as appropriate.
Service Request
When you contact us through our website, request demo, sign up for newsletters or otherwise engage with us online, Facilio collects Personal Data you provide (such as name, email, phone, company, and job title) through web forms (e.g., Contact Us, Demo, or Newsletter sign-ups). This data is used only to deliver the requested service, respond to your request, and provide information about our products, Services, and events, customer success support.
- We do not use this data for marketing purposes or share it with third parties unless you have explicitly provided consent.
- Support interactions, including tickets, chat transcripts, or call recordings, may also be collected to resolve issues and for quality assurance.
Account Creation
When you register for an account, Facilio collects:
- Identity & contact information: full name, email address, phone number, company, job title, and address.
- Authentication details: account user ID, password hashes, and MFA tokens (if applicable).
- Usage and analytics data including diagnostics, metrics, and cookie-based information is used to monitor system performance, improve Services, to measure the effectiveness of marketing campaigns, and enhance the user experience.
This information is collected to provision and secure your account, fulfil orders, issue invoices, ensure tax compliance, and provide customer success.
Information collected from third parties
Facilio may receive information about tenants, vendors, or prospective customers from:
- Controllers (customers): who may upload personally identifiable data of their vendors, employees or their customers. Controllers are responsible for obtaining the necessary legal consent before storing such data in Facilio.
- Partners and resellers: who may share lead referrals or account information or contact details when you engage with our authorized partners or resellers.
- Payment providers: who provide payment status and fraud screening outcomes (never full card data).
- Marketing and lead generation platforms: who provide campaign metrics, only where lawful, professional contact details from events, conferences, webinars etc.,
- Public sources: such as official business registries, social media and other platforms using professional profiles.
When you enable, access, or use these third-party services, their collection, use, and sharing of your data will be governed by their own privacy policies, not ours.
Where Facilio receives Personal Data from the above mentioned third parties, those third parties are responsible for ensuring they have a lawful basis to share your data with us. This includes obtaining your consent where required by applicable law.
We rely on such third parties to confirm that:
- They have collected the data lawfully;
- They have provided you with the necessary privacy notices; and
- They have obtained your consent, where required, before sharing your data with us.
Facilio will not process such information shared by such third parties unless explicitly permitted by law, contractual requirement.
Information collected indirectly
Facilio collects limited technical data to monitor and improve Services, including:
Device and Technical data: IP address, device identifiers, browser type, operating system, time zone and other system information automatically transmitted when you use our Services.
Usage data: pages viewed, clicks, referring/exit pages, session duration.
Approximate location: derived from IP address.
UI interaction logs: user agent strings and session data, used only for monitoring and debugging.
Cookies: information collected through cookies or similar technologies are provided in our Cookie Policy
This data is used for security, troubleshooting, and service improvement, and is never sold or shared for unrelated purposes.
Purpose of Information
- To deliver the requested service
- To disseminate information about our software and Services
- To Track visitor navigation
- To schedule work orders and manage assets.
- To fulfil billing and invoicing obligations.
- To understand better how you use our Services, to track and prevent issues, and to enhance our Services
- To respond to your questions, provide support, and concerns, and ensure excellent customer service
- Contractual necessity
- To send newsletter subscriptions, event registrations, and campaign engagement is used to communicate product updates, offers, and event (where you have consented or we are permitted under soft-opt-in/legitimate interests, which you can opt out at any time.
Information to third parties
Our SaaS platform may integrate with or link to third-party services, applications, or websites to support our business operations, including:
- Service Providers: Vendors that perform Services on our behalf (e.g., cloud hosting, analytics, payment processors, customer support tools).
- Affiliates and Subsidiaries: Our group companies and offices in the USA, Dubai, Australia, UK, and India.
- Business Partners and Resellers: Authorized partners, resellers, or integration providers where necessary to deliver requested Services.
- Corporate Transactions: In connection with a merger, acquisition, restructuring, or sale of assets.
These disclosures are made to enable or enhance our Services and are subject to safeguards, including contractual commitments requiring such third parties to:
- Use the data only for the specified purpose;
- Implement appropriate security measures;
- Comply with applicable data protection laws.
Where you choose to connect our SaaS platform with third-party tools, we may share limited Personal Data (e.g., account identifiers, facility records, user preferences) necessary to enable the integration. This is done only with your knowledge and authorization.
Lawful Basis for Processing
Facilio collects and processes operational data and any other Personal Data provided by its customers and customer's customers using and accessing the SaaS Services. Such data is handled solely on behalf of its customers and in compliance with applicable data protection laws.
Facilio processes Personal Data only where there is a lawful basis to do so. These include:
- Contract – when processing is necessary to perform our obligations under a contract with you, your users, such as creating and managing accounts, providing Services, fulfilling orders, and handling billing.
- Consent – when you have explicitly agreed to processing, for example to receive marketing communications, participate in events, or allow the use of non-essential cookies. You may withdraw consent at any time.
- Legitimate Interests – when processing is necessary for our business operations and does not override your rights, such as responding to enquiries, ensuring the security of our Services, maintaining customer relationships, and improving our products.
- Legal Obligation – when processing is required to comply with applicable laws, such as tax regulations, security log retention, or regulatory reporting.
Please note, Facilio does not modify Personal Data, disclose it to third parties unless legally required or authorised by its customers, or access it except as necessary to provide the Services, resolve technical issues, or respond to support requests.
Use of cookies
Facilio website uses cookies, as do many other websites. Cookies are small text files that websites place on your browser or device when you visit them which will help website to remember you and improve your browsing experience. We use cookies and related tracking technologies on our Site for functionality, analytics/advertising purposes. The use of cookies is further described in our Cookie Policy, which forms an integral part of this Privacy Policy. You can manage choices anytime via our cookie banner. If you prefer, you can enable or disable browser cookies using your browser's or device's settings. However, please realize that eliminating or rejecting cookies may have an impact on the availability and performance of our Services.
Information Access
Facilio applies strict access controls to safeguard Personal Data in accordance with applicable data protection laws.
Internal Access: Personal Data is encrypted and accessible only to authorised personnel on a need-to-know basis for service delivery, support, or troubleshooting. All access is logged and monitored.
Customer Controls: Customers are encouraged to set and regularly update secure passwords upon account activation and to use available security features (e.g., MFA) to further protect their accounts.
No Sale of Data: Facilio does not sell, rent, or otherwise disclose customer Personal Data to unrelated third parties for marketing or other independent purposes.
International data transfers
Your Personal Data will be hosted and maintained exclusively within our designated data centres. The data itself will not be transferred outside these data centres. However, duly authorized personnel of Facilio (including technical, support, and operations teams) may remotely access such data solely for the purposes of service delivery, troubleshooting, maintenance, or operational support.
All such access is strictly role-based, logged, and subject to technical and organizational safeguards to ensure compliance with applicable data protection laws. Where cross-border remote access is involved, it will be carried out in accordance with lawful transfer mechanisms and with appropriate safeguards to protect your rights and freedoms
Retention of Information
We retain your Personal Data for as long as it's needed for the purposes outlined in this Privacy Policy and until you explicitly delete or terminate your account with us. We may keep your information for extended periods of time if authorized or needed by law. We will also retain it as necessary to comply with our legal obligations, for legal and litigation purposes, to maintain accurate financial and other records, deal with complaints, and enforce our agreements. We will securely erase or anonymise your information from our active databases once we no longer have a legitimate reason to process it. We'll also keep the data safe and isolate it from further processing until it's time to delete it.
Incident response
Facilio has a team dedicated to information security. If a user discovers a security or privacy violation, they can contact us via email at dpo@facilio.com. We will use commercially reasonable efforts to acknowledge such reporting promptly and will respond in line with the severity of the issue.
Children's Personal Information
Our Site and Services are not designed or intended for children under the legal age of majority to use. Children's personal information is never knowingly collected by us.
How Secure your information
Facilio is SOC 2 compliant, and we make every effort to keep our systems secure and protect any Personal Data we collect. We implement appropriate technical and organisational measures to protect Personal Data, including encryption in transit, access controls, role‑based access, secure development practices, monitoring/logging, employee training, vendor due diligence, and incident response. No method of transmission is 100% secure; we encourage you to use strong, unique passwords and enable MFA where available.
We may send email invitations to users to provide access to our Services. By clicking on the invitation link and completing the registration process, users verify their identity and consent to join the customer organization. This process ensures that only intended recipients gain access and helps maintain the security and integrity of our services We do not make use of government-issued identifiers for authenticating users.
Your Legal Rights
Depending on your jurisdiction, you may have rights regarding your personal data, including the right to access, update, correct, or request deletion of your information, subject to applicable legal exceptions.
Access Request: You have the right to request access to the personal data Facilio holds about you. Access requests can be submitted via the contact details provided below.
Correction Request: You have the right to request that Facilio correct or update your personal data to ensure it is accurate, complete, and up-to-date:
- Updates can often be made directly through the portal or mobile application.
- If you are unable to make changes via these tools, you can contact Facilio to have the corrections made on your behalf.
Deletion Requests: Deletion of personal data is carried out by Facilio upon request. Deletion requests will be processed by Facilio, subject to legal or contractual retention obligations.
Additional Rights: Where applicable under GDPR, India DPDP, Australia Privacy Act, UAE PDPL, or U.S. laws, you may also have rights to data portability, restriction of processing, or to object to certain types of processing.
To exercise any of your rights, please contact Facilio at:
- Email: dpo@facilio.com
- Facility Contact (for visitor-related data): the respective facility where you checked in.
Facilio will respond promptly to all requests in compliance with applicable data protection laws.
Changes to this Policy
Our company's operations may alter from time to time. As a result, Facilio may update this Privacy Policy to reflect operational, legal, or regulatory changes. changes take effect on the "Last Updated" date.
Contact Us
We value your feedback on our data protection processes and aim to resolve any and all complaints to your full satisfaction. We agree to ensure open lines of communication regarding your complaints, and that all complaints will be given an impartial internal review.
For any questions or complaints about the use or disclosure of your personal data, please contact us via Email: dpo@facilio.com
Contacting the Regulator:
If you feel that your personal data has not been handled correctly, or you are unhappy with our response to any requests you have made to us regarding the use of your personal data, you have the right to lodge a complaint with your national Data Protection Authority.
For Facilio's US Customers:
United States Addendum (including California, Colorado and other states)
This section applies to residents of US states with comprehensive privacy laws. It explains your rights and how to exercise them.
Right to know/access, correct, delete, and portability.
Right to opt out of marketing communications
Right to limit the use of sensitive personal information (CA).
Right to appeal (certain states).
How to exercise your rights: Please refer to contact us section above. We will verify your identity and respond within required timeframes.
California Notice at Collection – Categories
Facilio does not sell personal information as defined by the CCPA. The following table summarizes the categories of personal information we may collect that may be disclosed to service providers as mentioned above in this Privacy Policy. Facilio does share personal information (as defined by the CCPA) as explained in this Privacy Policy. The categories we use to describe personal information are those enumerated in the CCPA
| Category of Personal Information | Sources |
|---|---|
| Identifiers (name, email, IP, address or media handles) | You; partners |
| Commercial information as part of the contract (transaction information, billing, payment records or order history) | You |
| Internet / electronic activity information (IP address, device identifiers, cookie information, browsing information) | You |
| Geolocation (approximate, based on your IP address) | You |