DPRISM Pro Privacy Notice

Effective date: 20 July 2026
Last updated: 20 July 2026

1. About this notice

This Privacy Notice explains how personal data is handled when you use the DPRISM Pro mobile application.

DPRISM Pro is developed and maintained by:

Evo-Soft (Ireland) Limited
Trading as Evo-soft Ireland Ltd.
Company registration number: 348081
4 Bruach na Laoi
Union Quay
Cork
Ireland

Email: privacy@evosoft.ie
Telephone: +353 21 435 5201

DPRISM Pro is published on Google Play through the Point It developer account. Point It acts solely as the application publisher. Point It does not receive, access, store, use or otherwise process personal data handled through DPRISM Pro.

2. Who controls your personal data?

DPRISM Pro is a business application supplied to organisations for use by their authorised employees, contractors and other personnel.

The organisation that gives you access to DPRISM Pro normally determines:

  • why your personal data is processed;
  • which information you are required to provide;
  • how DPRISM Pro is configured;
  • how long your information is retained; and
  • who may access, amend or delete your information.

That organisation is therefore normally the data controller for the operational personal data processed through DPRISM Pro.

Evo-Soft normally acts as a data processor, processing operational data on behalf of the customer organisation and according to its instructions.

Evo-Soft may act as a separate data controller for limited information that it processes for its own legitimate business purposes, including customer support, service security, licensing, contract administration and compliance with legal obligations.

Questions concerning your employment records, project records, timesheets, location records or other operational data should ordinarily be directed to the organisation that provided your DPRISM Pro account.

3. Information processed through DPRISM Pro

The information processed depends on how the customer organisation has configured DPRISM Pro and which features you use.

It may include the following categories.

Account and identity information

  • Name
  • Email address
  • Username or user identifier
  • Employee or contractor identifier
  • Organisation, department, role or team
  • Account permissions and access information

DPRISM Pro does not allow users to create their own accounts. Accounts are created and administered by the relevant customer organisation.

Project and work information

  • Projects, jobs, tasks and assignments
  • Timesheets, working times and attendance-related records
  • Work progress and status information
  • Notes, comments and other user-entered content
  • Materials, quantities, activities and operational records
  • Customer or site references
  • Photographs and other supporting evidence
  • Signatures
  • Forms, confirmations and approvals

Some information may relate to other individuals, such as colleagues, customers, site contacts or authorised signatories.

Location information

DPRISM Pro may collect approximate or precise device location when you perform a relevant action within the application.

Location is not intended to be collected continuously in the background. It may be recorded when you submit, confirm or perform an action for which the customer organisation has configured location evidence.

Location information may be associated with a timesheet, project, site visit, work record, photograph, signature or other operational transaction.

Your device operating system may ask you to grant location permission. You can manage application permissions through your device settings, although disabling a permission may prevent certain DPRISM Pro functions from operating correctly.

Device and technical information

DPRISM Pro and its supporting services may process:

  • Device or installation identifiers
  • Device model
  • Operating-system version
  • Application version
  • Language and regional settings
  • Network and connection information
  • Dates and times of application activity
  • Application interactions
  • Synchronisation status
  • Authentication and security events
  • Crash reports
  • Diagnostic information
  • Performance and reliability information

Diagnostic records are intended to support application operation, troubleshooting, security and service improvement. They should not be used to evaluate employee performance unless the customer organisation separately determines and communicates such a purpose.

4. How information is collected

Information may be:

  • supplied by the customer organisation;
  • entered directly by you;
  • generated when you perform actions in DPRISM Pro;
  • obtained from the connected Business Central environment;
  • obtained from your device with the required permission, such as location or camera access; or
  • generated automatically for security, diagnostics, synchronisation and application operation.

DPRISM Pro may support offline operation. Information entered while offline may be stored temporarily on the device until it can be synchronised with the connected services.

5. How information is used

Operational personal data may be processed to:

  • authenticate authorised users;
  • provide access to projects, jobs, tasks and work records;
  • record timesheets and work activity;
  • capture project progress and supporting evidence;
  • associate an action with a project, customer, site, date, time or location;
  • capture photographs, signatures, comments and confirmations;
  • synchronise information with the customer’s Business Central environment;
  • provide offline application functionality;
  • prevent unauthorised access;
  • protect the security and integrity of the service;
  • diagnose crashes, errors and synchronisation failures;
  • maintain and improve application reliability; and
  • provide technical support.

The customer organisation determines the purposes and lawful basis for processing its operational data.

Depending on the circumstances, the customer organisation’s lawful basis may include performance of a contract, compliance with a legal obligation, legitimate interests, or another lawful basis available under applicable data-protection law.

Where Evo-Soft processes limited information as a controller for its own purposes, it ordinarily relies on:

  • performance of a contract;
  • compliance with a legal obligation;
  • Evo-Soft’s legitimate interests in operating, securing, supporting and improving its services; or
  • consent, where consent is specifically requested and legally appropriate.

6. Automated decision-making

DPRISM Pro is not designed to make decisions producing legal or similarly significant effects about users solely through automated processing.

Customer organisations may use information recorded through DPRISM Pro as part of their own business, operational or employment processes. Questions about such use should be directed to the relevant customer organisation.

7. Where information is sent

DPRISM Pro transfers operational information through Microsoft Azure-hosted services or integrations to the Business Central environment designated by the customer organisation.

Depending on the customer’s deployment, Business Central and related databases may be hosted:

  • by Microsoft;
  • by the customer organisation;
  • by an infrastructure provider selected by the customer; or
  • within another environment approved by the customer.

Evo-Soft does not sell DPRISM Pro personal data.

Evo-Soft does not use customer operational data for advertising.

Evo-Soft does not permit Point It to access or process DPRISM Pro operational data solely by virtue of Point It publishing the application.

8. Service providers

DPRISM Pro relies on selected service providers to operate particular functions.

Microsoft

Microsoft services may be used for:

  • Microsoft Azure hosting and integration;
  • connectivity with Microsoft Dynamics 365 Business Central;
  • authentication or service security, depending on deployment;
  • application analytics, diagnostics or crash reporting; and
  • infrastructure monitoring and support.

The exact Microsoft services and hosting arrangements may differ between customer deployments.

Google Maps and Google Play services

Google Maps services may be used to provide mapping and location-related functionality.

When these services are used, Google may receive technical information such as:

  • map requests;
  • device and application information;
  • IP address;
  • approximate or precise location, where required for the requested map feature; and
  • service usage and diagnostic information.

Google Play and related Android services may also process technical information necessary to distribute, install, update and secure the application.

These providers process information under their applicable contractual terms and privacy documentation.

9. Sharing and disclosure

Personal data may be made available to:

  • authorised personnel of the customer organisation;
  • administrators appointed by the customer organisation;
  • Evo-Soft personnel who require access for authorised support, maintenance or security work;
  • Microsoft and other approved infrastructure or service providers;
  • professional advisers where reasonably necessary;
  • regulators, courts, law-enforcement authorities or other public bodies where disclosure is legally required; and
  • a successor organisation in connection with a lawful merger, acquisition, restructuring or transfer of the relevant business, subject to appropriate safeguards.

Access is limited according to the applicable role, purpose, customer instructions and contractual arrangements.

10. International transfers

The customer organisation determines the principal location of its Business Central environment and operational records.

Some service providers may process limited information outside Ireland or the European Economic Area.

Where Evo-Soft is responsible for such a transfer, it will use a lawful transfer mechanism where required, such as:

  • an adequacy decision;
  • the European Commission’s Standard Contractual Clauses;
  • supplementary technical and organisational safeguards; or
  • another transfer mechanism permitted by applicable law.

Customers should consult their own contractual documentation for deployment-specific information concerning hosting locations and international transfers.

11. Data security

DPRISM Pro uses technical and organisational safeguards intended to protect information against unauthorised or unlawful access, loss, alteration, disclosure or destruction.

These safeguards may include:

  • encryption of information in transit;
  • authenticated access;
  • role-based access controls;
  • customer-controlled user administration;
  • secure Azure integration;
  • application and service logging;
  • restricted administrative access;
  • monitoring and diagnostic controls; and
  • software maintenance and security updates.

No system can guarantee absolute security. Users should protect their device credentials, avoid sharing their account and promptly report suspected unauthorised access to their organisation.

12. Data retention

The customer organisation determines how long operational records are retained in its Business Central environment and related systems.

Retention periods may reflect:

  • employment and contractual requirements;
  • project-management requirements;
  • financial and accounting obligations;
  • health and safety requirements;
  • audit requirements;
  • legal claims;
  • regulatory obligations; and
  • the customer’s internal retention policies.

Information stored temporarily on a device may remain until it is synchronised, removed through application operation, deleted by an authorised administrator or removed when the application or its local data is cleared.

Evo-Soft retains support, diagnostic, security and service-administration information only for as long as reasonably required for the relevant purpose, contractual obligations, security investigation or legal requirements.

13. Account and data deletion

DPRISM Pro does not allow users to create or independently administer their own accounts within the application.

Accounts are created, managed and disabled by the customer organisation.

DPRISM Pro does not currently provide a self-service deletion function within the mobile application. This does not mean that operational information can never be deleted.

Authorised customer administrators can manage or delete accounts and associated records through the customer’s systems, subject to:

  • the customer’s legal obligations;
  • applicable retention requirements;
  • the integrity of financial, project or audit records;
  • the rights of other individuals; and
  • technical and contractual limitations.

To request access, correction or deletion of operational information, contact the organisation that provided your DPRISM Pro account.

Where Evo-Soft receives a request relating to data for which a customer is the controller, Evo-Soft may refer the request to that customer or assist the customer in responding in accordance with the applicable data-processing agreement.

Requests concerning personal data controlled directly by Evo-Soft may be sent to privacy@evosoft.ie.

14. Your data-protection rights

Depending on the circumstances and applicable law, you may have rights including:

  • the right to be informed about processing;
  • the right to access your personal data;
  • the right to correct inaccurate or incomplete information;
  • the right to request deletion;
  • the right to restrict processing;
  • the right to object to certain processing;
  • the right to data portability;
  • the right not to be subject to certain solely automated decisions; and
  • the right to withdraw consent where processing is based on consent.

These rights are not absolute. A request may be restricted where continued processing or retention is required by law, contract, audit obligations, legal claims, the rights of others or another valid legal basis.

For operational data processed through DPRISM Pro, exercise your rights by contacting the customer organisation that provided your account.

For information controlled directly by Evo-Soft, contact:

Email: privacy@evosoft.ie

Evo-Soft may need to verify your identity before responding to a request.

15. Complaints

You may first raise a concern with the customer organisation that provided your DPRISM Pro account or with Evo-Soft, as appropriate.

You also have the right to lodge a complaint with the data-protection supervisory authority in your country.

In Ireland, the supervisory authority is the:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28
Ireland

16. Children

DPRISM Pro is a business application intended for authorised personnel of customer organisations. It is not directed towards children and is not intended for personal or household use.

Customer organisations are responsible for ensuring that users are authorised to use the application and that any processing involving minors is lawful and appropriately safeguarded.

17. Changes to this notice

This Privacy Notice may be updated to reflect:

  • changes to DPRISM Pro;
  • changes to service providers or hosting arrangements;
  • changes in legal or regulatory requirements; or
  • changes in how personal data is processed.

The revised notice will be published on the Evo-Soft website with an updated effective date.

Material changes may also be communicated through the application, Google Play, the customer organisation or another appropriate channel.

18. Contact

For questions about operational records, user accounts, timesheets, location records or project data, contact the organisation that supplied your DPRISM Pro account.

For questions about DPRISM Pro, Evo-Soft’s processing activities or this Privacy Notice, contact:

Evo-Soft (Ireland) Limited
4 Bruach na Laoi
Union Quay
Cork
Ireland

Email: privacy@evosoft.ie
Telephone: +353 21 435 5201

Scroll to Top