Skip to content
OLTPRIME

Legal

Privacy policy

What we hold, why we hold it, and what we will never do with it. Written to be read, not to be survived.

Last updated

Who this is between

OLT PRIME is a fiber-network management service operated from Iraq. On this page, “we” means OLT PRIME, and “you” means the network operator using it.

It covers both halves of the service: this website, and the product you sign in to. If you run OLT PRIME on your own server instead of ours, read the section on self-hosting — the answer there is different, and shorter.

Two kinds of data, and they are not the same

Almost every question about privacy here has a different answer depending on which of these you mean, so it is worth separating them first.

The second kind is the larger one, and it is the one we treat most carefully: we act on it only to run the product for you.

  • Your company’s data — the account, the people you add to it, what you pay. We decide how this is handled, and this page is our commitment about it.
  • Your network’s data — your OLTs, your subscribers, their lines and their routers. This is yours. We hold it so the product can work, and we act on it on your instruction, not on our own.

What this website collects

There are no analytics scripts, no advertising pixels and no third-party trackers on this website. Nothing follows you from page to page, and no cookie is set here at all.

The only information this site collects is what you type into a form and choose to send:

Our hosting provider also keeps short-lived server logs — address, page requested, time — which exist to keep the site up and to spot abuse.

  • The contact form: your name, company, email, phone, roughly how big your network is, and your message.
  • The account request form: your company, your name, email, phone, country, fleet size, and any note you add.

What the product stores

Once you have an account, the product holds what it needs to manage a network and no more:

It also holds what your staff did: every change written to a device is recorded with who made it, when, and what the value was before and after. That record exists for you, so a change nobody remembers making can still be traced.

  • Sign-in details for your staff — name, email, role. Passwords are stored only as a one-way hash; nobody here can read them.
  • How to reach your OLTs — address and the credentials the device asks for. Credentials are encrypted before they are written to disk.
  • What we read from your devices — subscriber records, serial numbers, signal readings, alarms, faults and traffic counters.
  • Billing records — your plan, the periods you paid for, and the invoices.

What the mobile app collects

The field app is the same product in a technician's hand. It signs in to whichever server your operator runs — ours, or your own if you self-host — so everything in the two sections above applies there in exactly the same way, and reaches the same place.

Three things belong to the phone rather than the product, and none of them are collected by us:

The app carries no analytics, no advertising identifier and no crash-reporting service, and it never asks for your location or your camera.

  • Sign-in tokens are held in the phone's own secure store — the iOS keychain or the Android keystore — and are erased when you sign out.
  • If a technician turns notifications on, the app registers with the service that delivers them: a subscription id that identifies the handset, whether the phone is iOS or Android, the language the app is set to, and the device's model — or the name you have given the phone, where the model is not available. These go to your operator's server so an alert can reach the right handset.
  • The app can be locked behind Face ID or a fingerprint. That check happens entirely on the phone, and the operating system tells the app nothing except whether it passed. No biometric data is read, sent or stored — not by the app, and not by us.

Why we use it

Every use falls under one of these:

We do not sell information about you or your subscribers, and we do not hand it to anyone for advertising. It is not a side business we have, and it is not one we intend to have.

  • To run the service you asked for — reading your devices, showing you the network, applying the changes you make.
  • To keep the account secure, and to answer you when something breaks.
  • To invoice you and keep the records that go with an invoice.
  • To warn you about faults on your own network.
  • To understand how the product is used in aggregate, so we know what to build next.

Cookies

This website sets no cookies.

The product sets only what a signed-in session needs — to keep you signed in, and to protect the account against forged requests. There is no advertising or analytics cookie in either place, which is why there is no consent banner to click past.

Who else can see it

A short list, and it stays short:

Everyone on it is bound to use the data only to provide their part of the service. If a request comes from an authority, we check that it is lawful and narrow before answering, and we tell you unless we are legally barred from doing so.

  • The provider that hosts our servers.
  • The service that delivers account and system email.
  • Our bank and accountant, for the invoice records they are required to hold.
  • The service that delivers notifications to the mobile app.
  • Our own staff, only while supporting you or investigating a fault, and under confidentiality.

Where it is kept, and what changes if you self-host

For the hosted service, data sits on servers we rent and administer, protected by access control and by encryption of the sensitive columns.

If you run OLT PRIME on your own server, your network data never reaches us at all — it stays on your machine, in your building, under your backups. What we receive is the licence check-in: which licence, which version, and that the installation is alive. Nothing about your subscribers is in it.

How we protect it

The measures that matter most here:

No system is perfect, and claiming otherwise would be the least trustworthy sentence on this page. If a breach affects your data, we will tell you what happened, what it touched and what we did about it — without waiting to be asked.

  • Traffic between you and the service is encrypted in transit.
  • Device credentials are encrypted at rest, never stored as readable text.
  • Passwords are hashed, and cannot be recovered by anyone.
  • We reach your OLTs only over the connection you set up and can close.
  • Every device change is recorded against the person who made it.

How long we keep it

Not forever, and not by accident:

  • Account and network data: while the account is open, and for a short wind-down period after it closes so nothing is lost to a mistake.
  • On closure: we will export your data to you on request, and remove it within 30 days of the wind-down period ending.
  • Billing records: for as long as the law requires us to keep them, which is longer than the account itself.
  • Server logs: a short retention, measured in weeks.

What you can ask us to do

You can ask what we hold about you, ask us to correct it, ask for a copy in a usable format, or ask us to delete it. Write to us and we will answer within 30 days.

We will check who is asking first. An account with access to a live fiber network is not one where we hand over data to whoever sends a convincing email.

Your subscribers are yours

The people on your network are your customers, not ours. You decide what goes into the product about them, and you are responsible for having the right to hold it and for telling them what you hold.

If one of your subscribers contacts us directly about their data, we will not act on it. We will point them back to you, because you are the one who holds both the relationship and the record.

Not for children

This is a tool sold to network operators. It is not a consumer product, it is not directed at children, and we do not knowingly hold data about anyone under 18 except where an operator has entered it as subscriber information.

When this page changes

The date at the top of this page is the real one. Small corrections happen without ceremony.

If a change actually affects what we do with your data, we will tell you inside the product and by email at least 14 days before it takes effect, so you have time to disagree.

Contact, and which law applies

Questions about this page, or about anything we hold, go to the address on our contact page and reach a person.

This policy and the service are governed by the laws of Iraq, and any dispute that cannot be settled between us belongs to the competent courts of Iraq.