Skip to content

SureMDM Privacy policy

  1. INTRODUCTION
    SureMDM by 42Gears (“SureMDM” or “we” or “our”) is a leading Mobile Device Management (MDM) solution designed to help organisations securely manage, monitor, and control their device ecosystem from a unified platform. The SureMDM solution is compatible with a wide range of platforms, including Android, iOS/iPadOS, Windows 10/11, macOS, Linux, Wear OS, VR, ChromeOS, and IoT.SureMDM enables IT administrators to deploy applications, enforce security policies, protect corporate data, and ensure regulatory compliance across both company-owned and employee-owned devices. By supporting comprehensive enterprise mobility management (EMM) and unified endpoint management (UEM) capabilities, including Mobile Application Management, Mobile Content Management, and Mobile Device Management, SureMDM offers centralised visibility and control across the device lifecycle.The following Privacy Statement (hereinafter referred to as ‘statement’) describes how SureMDM collects, uses, and discloses information and what choices you have with respect to the information. SureMDM is the controller for the personal data discussed in this Privacy Statement, except as noted in the section 3.2 below.This Statement serves as a testament to our unwavering commitment to safeguarding the rights of Data Subjects, including employees, aligning rigorously with the General Data Protection Regulation (“GDPR”), 2016.
  2. SCOPE
    This Privacy Statement applies to users (“individuals” or “you”) of the SureMDM application and prospective customers who visit the website and log/sign in to get our services. For the purposes of this Notice:

    1. A “Customer” refers to any individual who registers for or accesses SureMDM services, including trial accounts or licensed enterprise solutions or a Company that takes a subscription for their employees in which case the company assumes the role of the Administrator.
      Please note that this Privacy Statement does not apply to any services offered by 42Gears or third parties that are governed by separate privacy policies not referencing or incorporating this Statement. Likewise, it does not cover the data practices of other entities that may advertise, link to, or integrate with SureMDM. This Statement applies to personal data (including sensitive personal data) as defined under applicable laws such as the EU General Data Protection Regulation (GDPR) and India’s Digital Personal Data Protection Act (DPDPA), 2023, which is collected to deliver and support SureMDM services (collectively, “Services”). It does not apply to anonymised, de-identified, or aggregated data that cannot be reasonably used to identify an individual.
  3. ROLES AND RESPONSIBILITIES
    The roles and responsibilities concerning personal data under this Privacy Policy are defined based on the nature of data collection and the relationship between the parties involved:

    1. Sign-Up Page Data Collection: For all personal data collected directly through the sign-up or registration page of the application, SureMDM shall act as the Data Controller. In this capacity, SureMDM determines the purposes and means of processing such data and assumes full responsibility for compliance with applicable data protection laws, including the exercise of Data Subject Rights.
    2. Device/Application Data Collection: For all other personal data that is collected through the use of the application installed on user devices, whether on web, mobile, or other devices, SureMDM acts solely as a Data Processor. In these instances, the subscribing organisation (referred to as the "Admin" as defined in this policy) shall be the Data Controller, determining the purposes and means of processing the data collected through the application. SureMDM processes such data strictly on the instructions of the Admin and in accordance with the contractual agreement and applicable legal obligations.
    3. This Privacy Policy does not extend to any data stored on-premise by the Admin. In such cases, SureMDM neither accesses the data nor acts as a data processor. In capacities mentioned under clauses 3.1 and 3.2, SureMDM shall facilitate the exercise of Data Subject Rights in accordance with its role and as defined under the applicable data protection laws. SureMDM is the Data Controller, and it will directly address and respond to Data Subject Rights requests. Where it is a Data Processor, it shall refer such requests to the respective Admin (Data Controller) and support them in responding to the data subject in a timely and compliant manner.
  4. DATA PROTECTION PRINCIPLES
    The following key principles are enshrined in the applicable Laws and are fundamental to SureMDM’s Statement. In its capacity as a Data Controller, SureMDM ensures that all activities shall abide by the following principles:

    1. Processing shall be performed lawfully, fairly and in a transparent manner. 4.2 Personal Data shall be collected for specified and explicit purposes and not further processed in a manner that is incompatible with those purposes; further Processing for any other purposes is permissible if they are similar or relevant to the purposes for which such data are originally collected.
    2. Personal Data shall be adequate and limited to what is necessary in relation to the purposes for which they are processed;
    3. Personal Data shall be accurate and, where necessary, kept up to date; 4.5 Every reasonable step must be taken to ensure that Personal Data that is inaccurate is erased or rectified;
    4. Personal Data shall be kept in a manner that ensures appropriate security of the Personal Data, including protection against any infringement, breach or unauthorised or unlawful processing, using appropriate technical or organisational measures by the applicable laws in this regard;
    5. Personal Data shall not be kept after the completion of the purpose for which such data is processed, provided that such data may be further kept if its Data Subject can no longer be identifiable using the “anonymisation” technique.
  5. LEGAL BASIS FOR PROCESSING PERSONAL DATA:
    SureMDM’s legal grounds for collecting and using your personal data as described in this Privacy Statement fall into the following four categories:

    1. Performance of a Contract: SureMDM processes your personal data where it is necessary to fulfil its contractual obligations to you. This includes situations where the processing of data is essential for providing the products or services you have requested or purchased. For example, when you register for a subscription, trial, or event, we may use your personal and payment information to verify your identity, process transactions, provide access credentials, and deliver the relevant features or services under the terms of the agreement. This also includes managing user accounts, responding to service-related queries, providing technical support, and facilitating onboarding or implementation services as contractually agreed. Processing under this lawful basis ensures that SureMDM can meet its commitments and provide you with a functional and reliable service experience.
    2. Legitimate Interest: SureMDM processes certain data for the legitimate interests of the organisation, its affiliates, partners, or customers. These legitimate interests include, for example, contacting you to provide support or sending you marketing information (subject to applicable law); detecting, preventing, and investigating illegal activities and potential security issues; and maintaining and developing mobile applications. The company will rely on its legitimate interests for processing personal data only after balancing its interests and rights against the impact of the processing on individuals.
    3. Other Legal Basis: In some cases, the company may have a legal obligation to process your personal data, such as in response to a court or regulatory order. SureMDM may also need to process your personal data to protect vital interests or to exercise, establish, or defend legal claims.
  6. HOW AND WHEN DATA IS COLLECTED
    SureMDM collects device data during enrolment, configuration, routine monitoring, and ongoing management through the SureMDM platform. Data collection occurs under the following circumstances:

    1. At the Time of Device Enrolment: When a device is first enrolled into SureMDM, the platform collects basic device identifiers. This helps prevent duplicate registrations and enables compatibility checks for apps in the Enterprise Store.
    2. During Regular Monitoring and Usage: As part of routine operations, SureMDM continuously monitors battery status and data usage and other data as detailed in here: https://www.42gears.com/trust-center/privacy/data-we-collect/.
      This allows IT administrators to track charging activity and network usage, and receive alerts when values exceed or fall below configured thresholds.
    3. For Company-Owned Devices: Upon enrollment and during ongoing use, SureMDM collects detailed hardware and software.
    4. For Personally-Owned Devices (BYOD): SureMDM collects limited data only necessary for enterprise use and compliance. Data is collected primarily for asset tracking, inventory management, compliance monitoring, and security enforcement in both cases. Location data helps trace lost or stolen devices, while SIM card and hardware identifiers allow detection of tampering or unauthorised access.SureMDM sign up page asks you to provide certain personal data for direct marketing/ communication purposes. You may give your free and explicit consent or not for the collection and processing of your personal data by ticking a consent box.
  7. DATA COLLECTION
    The categories of information that SureMDM may have collected from you as a Controller or Processor to provide certain services to you are listed below:

    1. SureMDM as a Controller:
      • Name
      • Company Name
      • Country and State
      • ZIP Code
      • Phone Number
      • Mail Address
    2. SureMDM as a Processor:
      1. General Device Information (All Devices)
        • Android ID 
        • Device make and model 
        • Operating system and version 
        • Time zone 
        • IP address 
        • MAC address 
        • Mobile carrier information
      2. Company-Owned Devices
        • UDID 
        • SIM serial number 
        • IMEI / IMEI2 
        • MAC address 
        • Phone number 
        • Address 
        • Bluetooth MAC address 
        • Contact name 
        • Local IP address 
        • GPS location (longitude and latitude) 
        • Security patch date 
        • Managed apps installed by SureMDM 
        • Configuration profiles installed by SureMDM
      3. Personally Owned Devices (BYOD)
        • UDID 
        • Serial number 
        • MAC address 
        • Model, brand 
        • IMEI / IMSI 
        • Storage details 
        • Phone number 
        • Address 
        • Bluetooth MAC address 
        • Contact name 
        • Local IP address 
        • GPS location (longitude and latitude) 
        • OS version 
        • Security patch date 
        • Managed apps installed by SureMDM 
        • Configuration profiles installed by SureMDM 
  8. USE OF INFORMATION
    SureMDM processes personal and device data solely for the purposes for which it was collected or shared, and in accordance with applicable data protection laws. The information we collect may be used in the following ways:
    SureMDM processes personal and device-related information to deliver, enhance, and support its services in accordance with applicable privacy regulations. The information is used for the following purposes:

    1. Service Delivery and Support: We process personal and technical information to provide the services requested by customers. This includes enabling device management features, troubleshooting issues, and offering technical support. All such data is processed only as necessary and under the direction of the customer.
    2. Business Analytics (Usage Data): We collect system-generated usage data from the devices and services configured by our customers. This data, such as device model, network statistics, memory and storage usage, and system settings, is used for internal analytics to understand how our products are used, optimize performance, and improve service offerings. We do not identify individual end users through this data unless necessary for support and with customer consent.
    3. Location-Based Services: With the user’s explicit consent, SureMDM may collect location data to enable features such as real-time location tracking, geofencing, and location-based customisations. Location data may be collected even when the application runs in the background, provided location services are enabled. These services rely on device features like GPS, Bluetooth, and Wi-Fi, and may integrate with Google Maps APIs.
    4. Application Management: Administrators may configure SureMDM to collect information about installed applications, including version details and usage status. This enables application lifecycle management such as remote uninstallation, compliance enforcement, app analytics, and startup configurations. The collected data is securely stored and never shared with third parties.
    5. Call Log and Contact Management: With explicit user consent, SureMDM may access call logs and contact details to help administrators enforce communication policies, track usage, and manage SIM-related data. Information such as contact names, call durations, and call frequency may be processed for audit and inventory purposes.
    6. SMS Usage and Reporting: Upon user authorisation, SureMDM may collect and process SMS logs, including message content, timestamps, and contact information. This supports cellular plan management and enables administrators to monitor communication usage in a compliant and secure manner.
    7. Remote Storage and File Management: Device storage-related data is processed to support remote file uploads, downloads, and execution, ensuring seamless device management and operational continuity.All information processed by SureMDM is stored securely, used strictly for legitimate business purposes as configured by the customer, and never disclosed to third parties without consent.
  9. RIGHTS OF DATA SUBJECT
    Under applicable data protection legislation of your respective jurisdiction, you have certain rights regarding the collection and processing of your personal data, namely:

    1. A right to be informed: you have the right to be informed in a concise, transparent, intelligible and easily accessible form about the way in which your personal data is processed.
    2. A right of access: you have the right to obtain (i) confirmation as to whether personal data concerning you is processed or not and, if processed, to obtain (ii) access to such data and a copy thereof.
    3. A right to rectification: you have the right to obtain the rectification of any inaccurate personal data concerning you. You also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
    4. A right to erasure: you have the right to obtain the erasure of personal data concerning you. However, this is not an absolute right, and SureMDM may have legal or legitimate grounds for keeping such data.
    5. A right to restriction of processing: in some cases, you have the right to obtain the restriction of the processing of your personal data.
    6. A right to data portability: you have the right to receive the personal data concerning you that you have provided to SureMDM in a structured, commonly used and machine-readable format, and you have the right to transmit that data to another controller without hindrance from SureMDM. This right only applies when the processing of your personal data is based on your consent or on a contract, and such processing is carried out by automated means.
    7. A right to object to processing: you have the right to object, on grounds relating to your particular situation, at any time to the processing of personal data concerning you when such processing is based on the legitimate interest of SureMDM. SureMDM may, however, invoke compelling legitimate grounds for continued processing. When your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of such data.
      You may, in particular, exercise that right by clicking on the “unsubscribe” link provided at the bottom of any messages received.
    8. The right to Object to Automated decision-making: you can challenge decisions made solely based on automated processing without human intervention.
    9. A right to Grievance Redressal: you have the right to contact a supervisory authority to complain about SureMDM’s personal data protection practices.The rights under this section can be exercised in line with merely the role of “Data Controller” by 42Gears as detailed in section 3. To exercise these rights, you can send a request to the form available on the website, or an email to privacyinfo@42gears.com, together with a copy of your identity document.
  10. PAYMENT
    When you make a purchase on our website for the SureMDM subscription, your payment information is collected and securely processed by PayPal or Stripe, as chosen by you, which are a third-party payment processor that adheres to industry security standards. Our payment gateway does not store your card data on its servers. Our payment gateway is a Reserve Bank of India (RBI) -authorised payment aggregator.We do not store or collect your payment card details in any manner whatsoever. Your purchase transaction data is only used as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is not saved. We do not store your full credit card details on our servers. By providing your payment information, you agree to the terms of service and Privacy Statement of the payment gateway provider. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express, and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

    Stripe Privacy Statement

    PayPal Privacy Statement

  11. DATA STORAGE & RETENTION
    SureMDM maintains appropriate administrative, technical, and physical safeguards to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected and processed.
    As part of our data lifecycle management practices, SureMDM automatically deletes collected data, unless a longer retention period is required to comply with legal obligations or to establish, exercise, or defend legal claims. The retention period for different categories of data is determined in accordance with applicable legal, regulatory, and business requirements. For technical clarification regarding deletion schedules or processes, further details may be obtained from the relevant department.
  12. SHARING PERSONAL INFORMATION OF USER/S
    1. We may share information with third parties. We share information with vendors who help us manage our service process.
    2. We may share information with our business partners. This includes third parties who provide or operate services on our behalf.
    3. We may share information if we think we have to to comply with the law or to protect ourselves. We will share information to respond to a court order or summons.
    4. We may also share it if a government agency or investigatory body requests it. Or we might also share information when we are investigating potential fraud. 12.5 We will never use your personal data or information to advertise, promote, or market third-party goods or services to you.You can find a list of our processors here.
  13. ADDITIONAL DISCLOSURES
    SureMDM does not sell, trade, or rent customers' personal identification information to others. We may share generic aggregated demographic information not linked to any personal identification information regarding User/s with our subsidiaries, our business partners, trusted affiliates, and advertisers for the purpose of providing you with the relevant services and personalised experience. We will not disclose customer data unless it is required to do so to comply with the statutory law or a binding order of a governmental body or a judicial authority.
    If a governmental body issues a notice or a directive to 42Gears in relation to the services provided under SureMDM subscription to share the customer data, 42Gears will attempt to redirect the same to the Customer, which shall be at the sole discretion of such authority. Governmental and regulatory bodies need to follow the stipulated procedure to obtain valid and binding orders that shall be undisputed. We will review all orders and object to overbroad or otherwise inappropriate ones. If compelled to disclose customer data to a government body, SureMDM will give customers reasonable notice of the demand to allow the customer to seek a protective order or other appropriate remedy unless SureMDM is legally prohibited from doing so.
  14. DATA TRANSFERS
    SureMDM does not transfer customer data across jurisdictions by default. Instead, customers are provided the option to select their preferred data center region at the time of signup. All personal data is stored and processed solely within the selected region, in accordance with applicable data protection laws. Any relocation or transfer of data, if required, shall occur only upon explicit instruction or configuration by the customer.
    In case SureMDM transfers your personal data to a third party that may be domiciled abroad, and in particular outside the jurisdiction whose data privacy regulations are applicable. In such a case, SureMDM shall require them to take, in accordance with applicable legislation, all organisational and technical measures that permit ensuring an adequate level of protection of your personal data. These steps may include implementing standard contractual clauses where recognised by law, obtaining your consent, or other lawful means of transferring personal information (of which you may obtain a copy, as applicable, upon request to: privacyinfo@42gears.com).
  15. SECURITY MEASURES
    1. Confidentiality and Third-Party Processing: We place paramount importance on the security of Personal Data. Third parties entrusted with processing Personal Data do so exclusively under our documented instructions, with a binding commitment to maintain strict confidentiality and data security.
    2. Robust Encryption Protocols: Data Security and Encryption: We use strong encryption protocols, including TLS 1.2 and higher with secure ciphers, to protect data in transit, and AES-256 encryption for data at rest. Authentication is enforced using digital certificates, and all web connections are secured with HTTP Strict Transport Security (HSTS). Communications between devices and the MDM server are protected using SSL, with platform-specific secure messaging services such as Apple Push Notification Service (APNs) for iOS, Firebase Cloud Messaging (FCM) for Android, and Windows Notification Service (WNS)
  16. CHILDREN’S PERSONAL INFORMATION
    We understand the importance of protecting the privacy of minors, especially in the online environment. This software is not designed for or intentionally targeted at minors under the age of 13, and we request that minors not use this software. We do not knowingly collect data from minors on this Site. If we become aware that we have received data from a person under the age of 18, we will take reasonable steps to delete such data from our records.
    In essence, we do not intentionally store any personal information of any minor via our website, and if you become aware that someone under the age of 18 has unlawfully provided us with personal data, please reach out to us at privacyinfo@42gears.com, and we will promptly take measures to delete such information.
  17. CONTACT US
    For grievances and queries on our privacy Statement or the use of our services, you may contact us through email at privacyinfo@42gears.com.
    We welcome feedback regarding this Statement at legal@42gears.com. If at any time you believe that the Company has not adhered to this Privacy Statement, please send your feedback to us and we shall endeavour to resolve the same. You may also contact 42Gears at our mailing address provided herein:https://www.42gears.com/contact-us/
  18. CHANGES TO THIS PRIVACY STATEMENT
    This Privacy Statement may be amended or revised from time to time at the discretion of 42Gears. Changes to this Privacy Statement will be posted in the application, and links to the Privacy Statement will indicate that the statement has been changed or updated. If there is a proposal to make any material changes, 42Gears will provide notice prior to the change becoming effective. The organisation encourages you to periodically review this Privacy Statement for the latest information on its privacy practices.

Version 1.0 | Release Date: October 23, 2025