Privacy Policy

Last updated: [DATE]

This notice explains how Doorping processes personal data under the EU General Data Protection Regulation (GDPR).

Data controller

The controller is [NAME / COMPANY], [ADDRESS]. For any request: [CONTACT EMAIL].

What data we collect

Owner account: email address and password (stored encrypted by our authentication provider).

Visitor messages: name (optional), text, an optional photo and an optional voice message.

Technical data: the visitor's IP address, collected to prevent abuse and spam.

Purposes and legal basis

Running the account and providing the service (performance of a contract, Art. 6.1.b GDPR).

Delivering visitor messages to the door owner (legitimate interest in operating the service, Art. 6.1.f).

Security and abuse prevention via IP address (legitimate interest, Art. 6.1.f).

Providers and where data is processed

We use Supabase (database, authentication and file storage) and Hostinger (application hosting) as data processors, under data processing agreements (DPAs).

Some providers may process data outside the EU; where they do, appropriate GDPR safeguards apply.

How long we keep data

Read messages are deleted 1 month after they are read; unread messages are deleted 3 months after they were sent. Any attached files (photo and voice) are removed together with the message.

The visitor's IP address is deleted after 30 days. Account data is kept while the account is active.

Your rights

You can request access, rectification, erasure, restriction and portability of your data, and object to processing, by writing to [CONTACT EMAIL].

You also have the right to lodge a complaint with your data protection authority.

Cookies

We only use technical cookies needed to run the service: the login session and the language preference. We do not use profiling or third-party cookies, so no consent banner is required.