Advantx L.L.C. Privacy Policy
This is the privacy policy of Advantx L.L.C., the company. It applies to everything we do: our websites, our dealings with customers, installers, partners and job applicants, and every product and service we make — including Stratosfere, our smart-building platform (the server hardware we build, the cloud service, the apps and wall panels, and the Google Home integration). It explains what personal data we collect, what we do with it, who else sees it, how long we keep it, and how you get it deleted.
Effective 2 September 2026 · Last updated 10 September 2026
1.Who we are
Advantx L.L.C. ("Advantx", "we", "us") is a smart-building company based in Kosovo. We design and build smart-home devices and the software that runs them: server controllers installed in buildings, touch panels, mobile and web apps, an installer configuration studio, and a cloud platform for fleet management. Together these products are sold under the name Stratosfere — a product name, not a separate company. There is one legal entity behind everything described here, and it is Advantx L.L.C., which acts as the data controller for the data in this policy.
| Legal entity | Advantx L.L.C. |
| Product / service | Stratosfere — the smart-home platform operated by Advantx L.L.C. |
| Postal address | Rruga Oda, Hajvali, 10001, Kosovo |
| Privacy contact | eldionadvantx@gmail.com |
| Support | eldionadvantx@gmail.com |
Where a professional installer configures and administers a building on behalf of its owner, that installer decides what is installed and who may access it. In those cases the installer is an independent controller for the choices they make, and we process the resulting data to provide the platform to them.
2.What this policy covers
One company-wide policy. It covers our websites, our business relationships and all of our products and services — described together because data moves between them.
- Our websites — this site and any other site we operate: pages you browse, forms you submit, accounts you create and messages you send us.
- Our business relationships — data about customers, installers, distributors, suppliers and people who contact us or apply to work with us.
- The cloud platform — the portal you sign in to, where installers register servers, monitor them and store configuration backups.
- The smart-home server and panels — the devices we build that are installed in the building to control lights, blinds, heating, sensors and scenes, and the app or wall panel used to operate them.
- Voice-assistant integrations — the optional link that lets you control your home with the Google Home app and Google Assistant. See section 7.
It does not cover third-party products you may connect to your home (for example a manufacturer's own cloud), or Google's own handling of your data in the Google Home app and Assistant, which is governed by the Google Privacy Policy.
3.Data we collect
Grouped by why it exists. Nothing here is collected for advertising, profiling or resale.
| Category | What it is | Where it comes from |
|---|---|---|
| Website and enquiry data | What you type into a contact form or send to our email addresses — your name, email address, company and the content of your message — and basic technical data about your visit (see Technical logs below). | You, when you visit our websites or contact us. |
| Business contact data | Contact and billing details of customers, installers, distributors and suppliers we work with — names, work email addresses, phone numbers, company details and correspondence. | You or your company, in the course of doing business with us. |
| Account data | Name, email address, company name (optional), a salted password hash, and your role on the platform. | You, when you create an account. |
| Site and server data | A name for each server, its network address and port, an optional location (for example a city) and any notes the installer writes. | The installer, when a server is registered. |
| Home configuration | Floors, rooms, device names, device types, group addresses, scenes and automation rules — the structure of the building and what is installed in it. | The smart-home server, when a backup is created or a page is opened. |
| Device state | Whether a light is on, a blind position, a setpoint, a measured temperature or humidity, a motion or contact sensor reading, an alarm state. | The smart-home server, in real time. |
| Health and diagnostics | Whether a server is reachable, when it went online or offline, its software version and whether an update is available, plus service and error logs when you ask for them. | Automatic checks and, for logs, an explicit request. |
| Google linking data | The identifier of the server that was linked, a hash of the refresh token, and the times the link was created and last used. | The account-linking flow — see section 7. |
| Provisioning records | The serial of a server that installed itself, the IP address the installation was made from, and how many times it happened. Used to match a device to the installer who deployed it for support. | The server, during installation. |
| Billing data | Amount, currency, what it was for, status and the payment provider's reference, where a paid feature such as remote access is used. | The payment provider. We never see or store your card number. |
| Technical logs | IP address, timestamp, request path and error information, kept for security and to debug faults. | Automatically, when you use the service. |
4.Data we never collect
Stated explicitly, because for a smart home it is the more important half of the answer.
- No voice recordings. When you speak to Google Assistant, Google interprets the speech and sends us a structured command such as "turn the kitchen light on". Your audio never reaches us.
- No camera images, video or audio streams are stored or relayed by the cloud platform.
- No Google account data. Linking uses a pairing code issued by your installer, not a Google sign-in. We do not receive your Google email address, profile, contacts, calendar or any other Google service data.
- No special-category or biometric data — we do not collect health, religious, political or biometric information.
- No advertising identifiers, no third-party ad networks, no cross-site tracking and no behavioural profiling.
- No payment card details. Payments are handled entirely by the payment provider.
5.How we use data
| Purpose | What that means in practice |
|---|---|
| Running the business | Answering enquiries, preparing quotes, managing orders and supplier relationships, and keeping in touch with the customers and installers we work with. |
| Running your home | Carrying out the commands you give — from the app, a wall panel, a scene, an automation or a voice assistant — and showing you the current state of your devices. |
| Keeping servers healthy | Checking every registered server periodically, recording when it goes offline, and telling the installer so a fault is noticed before you notice it. |
| Backup and restore | Storing snapshots of a home's configuration so it can be rebuilt after a failure or a hardware replacement. |
| Updates | Comparing the version a server runs against the latest release and offering the update. Updates are applied only after someone confirms. |
| Account and access control | Signing you in, keeping your session, resetting a forgotten password, and enforcing which servers each account may reach. |
| Support | Investigating a problem you report, including reading service logs when you ask us to. |
| Security and abuse prevention | Detecting brute-force attempts, rate-limiting linking, and keeping an audit trail of security-relevant events. |
| Billing | Taking payment for optional paid features and keeping the records the law requires. |
| Legal obligations | Complying with accounting, tax and lawful requests from authorities. |
We do not use your data to train machine-learning models, and we do not make decisions with legal or similarly significant effects about you by automated means.
6.Why we are allowed to
For each purpose there is a ground that permits the processing.
- Performance of a contract — operating your account, controlling your home, backups, updates and billing.
- Legitimate interests — keeping the platform secure and available, preventing abuse, and diagnosing faults. We balance this against your interests and keep the data minimal.
- Consent — optional features you switch on yourself, above all the Google Home link. You can withdraw consent at any time by unlinking, without affecting anything you did before.
- Legal obligation — retention of financial records and responses to lawful requests.
7.Google Home integration
Optional. Nothing in this section happens unless you deliberately link your home to Google.
7.1 How linking works
- In the Google Home app you choose to add your Stratosfere home.
- Google opens a page hosted by us where you enter the pairing code your installer gave you. You do not enter a Google password, and we do not receive one.
- We verify that code directly against your own server. If it is correct we issue Google a one-time authorization code, which Google exchanges for access and refresh tokens.
- Those tokens are bound to exactly one server. Every later request from Google carries the token, so it can only ever reach the home it was issued for.
7.2 What is exchanged with Google
| Direction | Data | Why |
|---|---|---|
| To Google | The list of devices in your home — identifier, name, room, type and capabilities — and their current state, such as on/off, brightness, colour, blind position, temperature setpoint, measured temperature and sensor readings. | So the Google Home app can show your devices and Assistant can answer questions about them. |
| From Google | Commands to execute (for example "set the living-room light to 40%") and requests for the current state, each carrying the access token that names your home. | So that voice and app control work. |
| To Google, proactively | State changes as they happen, pushed to Google's Home Graph, so the app is up to date without polling your home. | Responsiveness, and so Assistant does not report stale state. |
We act as a pipe: the request is forwarded to your own server and its answer is returned to Google unchanged. We do not build a separate copy of your home for our own purposes, and device state is not retained on the platform beyond what is needed to serve the request in flight.
7.3 Limited use
7.4 How to unlink
- Open the Google Home app, select your home, and remove the Stratosfere service from linked services. Google immediately stops sending us commands.
- Our stored link record — the server identifier and refresh-token hash — is deleted when you disable the Google Home switch on the server, or on request to eldionadvantx@gmail.com.
- Data already held by Google about your devices is removed under Google's own controls in the Google Home app and your Google Account.
9.International transfers
We are established in Kosovo and the platform is operated on servers in Europe. Some providers — Google in particular — process data outside that region, including in the United States. Where we transfer personal data of people in the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses, an adequacy decision where one exists, or another lawful transfer mechanism. Encryption in transit is applied throughout. You can ask us for details of the safeguards in place.
10.How long we keep data
We keep each category only as long as it serves its purpose, then delete it.
| Data | Retention |
|---|---|
| Account data | For as long as the account exists, then deleted within 30 days of closure. |
| Server registrations and configuration | Until the server is removed from the platform, then deleted with it. |
| Configuration backups | Until you delete them, or until the server they belong to is removed. |
| Online/offline history | Rolling 12 months, so an intermittent fault can still be diagnosed. |
| Device state | Not stored on the platform beyond serving the request in flight. Any history shown to you lives on your own server. |
| Google link records | Until you unlink, then deleted. |
| Technical and security logs | Up to 12 months, then deleted or aggregated so no individual can be identified. |
| Password reset tokens | Single use, and expire shortly after being issued. |
| Billing records | As long as accounting and tax law requires, typically 7–10 years. |
11.How we protect data
- Encryption in transit. All traffic to the platform and to Google uses HTTPS/TLS. Remote access to a home runs through an authenticated encrypted tunnel rather than an open port.
- Passwords are never stored. Only a salted one-way hash is kept, so a database copy does not reveal your password.
- Tokens are stored as hashes and are bound to a single home. Authorization codes are single-use, short-lived and tied to the address that requested them.
- Strict isolation between homes. Every request from Google names exactly one server; there is no code path by which one home's credentials can reach another's devices.
- Least privilege. Accounts have a role that limits them to their own servers, and administrative actions are restricted to explicitly elevated accounts.
- Abuse controls. Failed pairing attempts are rate-limited and locked out, and secrets are compared in constant time so they cannot be guessed byte by byte.
- Local-first design. Your home keeps working, and keeps its data, when the internet is down — the cloud is for management and remote access, not a prerequisite for your lights.
No system is perfectly secure. If a breach affects your personal data we will notify the competent supervisory authority and, where the risk to you is high, notify you directly and without undue delay.
12.Your rights and choices
Whatever your jurisdiction, we apply these to everyone.
- Access — get a copy of the personal data we hold about you.
- Correction — have inaccurate or incomplete data fixed. Most of it you can edit yourself in the portal.
- Deletion — have your data erased. See section 13.
- Portability — receive your configuration in a structured, machine-readable format. A backup export already does this.
- Restriction and objection — ask us to pause processing, or object to processing based on legitimate interests.
- Withdraw consent — turn off the Google Home link, or any other optional integration, at any time.
- Complain — to your local data protection authority. We would rather you told us first so we can put it right.
Write to eldionadvantx@gmail.com from the address on your account. We answer within 30 days, free of charge. We may ask for proof of identity where a request would otherwise expose someone else's data.
13.Deleting your data
There is always a way out, and it does not require talking to a salesperson.
- Delete a backup from the backups page.
- Remove a server from the portal — its health history, backups and configuration go with it.
- Unlink Google Home from the Google Home app.
- Email eldionadvantx@gmail.com from your account address, asking for account deletion.
- We confirm, then erase your account, servers, backups and link records within 30 days.
- Only billing records the law obliges us to keep are retained, and they are not used for anything else.
14.Children
Our websites, products and services are professional tools for installers and homeowners and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact eldionadvantx@gmail.com and we will delete it. A household member of any age may of course operate the lights.
16.Changes to this policy
We update this policy when the service changes. The date at the top always shows the current version. If a change materially affects how we use your personal data we will tell you in the portal or by email before it takes effect, and where the law requires it we will ask for your consent again. Continuing to use the service after a change means you accept the updated policy.
17.Contact us
Questions about this policy, or about a request you have made, go to our privacy contact: