Privacy Policy
Last updated: [DATE]
This notice explains how Doorping processes personal data under the EU General Data Protection Regulation (GDPR).
Data controller
The controller is [NAME / COMPANY], [ADDRESS]. For any request: [CONTACT EMAIL].
What data we collect
Owner account: email address and password (stored encrypted by our authentication provider).
Visitor messages: name (optional), text, an optional photo and an optional voice message.
Technical data: the visitor's IP address, collected to prevent abuse and spam.
Purposes and legal basis
Running the account and providing the service (performance of a contract, Art. 6.1.b GDPR).
Delivering visitor messages to the door owner (legitimate interest in operating the service, Art. 6.1.f).
Security and abuse prevention via IP address (legitimate interest, Art. 6.1.f).
Providers and where data is processed
We use Supabase (database, authentication and file storage) and Hostinger (application hosting) as data processors, under data processing agreements (DPAs).
Some providers may process data outside the EU; where they do, appropriate GDPR safeguards apply.
How long we keep data
Read messages are deleted 1 month after they are read; unread messages are deleted 3 months after they were sent. Any attached files (photo and voice) are removed together with the message.
The visitor's IP address is deleted after 30 days. Account data is kept while the account is active.
Your rights
You can request access, rectification, erasure, restriction and portability of your data, and object to processing, by writing to [CONTACT EMAIL].
You also have the right to lodge a complaint with your data protection authority.
Cookies
We only use technical cookies needed to run the service: the login session and the language preference. We do not use profiling or third-party cookies, so no consent banner is required.