Privacy Policy
Last updated: 15 September 2026
Draft prepared on 12 September 2026 for review by counsel before publication. It describes what Vecinoti does with personal data today, as the software is built: what is collected, why, who sees it, how long it is kept and what each person can do about it.
Who is responsible
For residents, guards and administrators the community that subscribes (the "Customer") decides why and how their data is processed and is the data controller. The Provider processes that data on the Customer's behalf under a Data Processing Agreement. For visitors to the website and for people who write to us, the Provider is the controller.
What we collect
Account data: name, email address, phone number if given, language, profile photo if uploaded, and the community, building and unit a membership belongs to. Activity data: entry passes and visits, notices and reactions, service requests and their photos, reservations, conversations and messages, posts and replies in the neighbour feed, documents, votes and financial records, all as entered by users and administrators. Security data: sign-in events, multi-factor enrolment, session and device identifiers, the network address and browser of requests, and an audit trail of administrative actions. Crash reports from the applications, with the page address stripped of any query string.
Visitors
If you visit a community that uses Vecinoti, the gate records your name, your ID number and, when taken, your photo, to control access and notify the unit you are visiting. The community is responsible for that record; only its gate and its administration see it, and the ID number is shown in full only to the staff member checking it. The photo is deleted after 90 days and the visit after a year, unless the community sets a different horizon. To view or delete your data, write to that community's administration.
Why we use it
To run the service the Customer contracted: let the right people in, notify residents, resolve requests, keep the community's records and let neighbours talk to each other by name. To keep accounts and communities secure, including rate limits, lockouts and audit logs. To support administrators and answer their questions. We do not profile people, sell data or use it for advertising.
Who sees what inside a community
Neighbours see each other's name and, where shown, building and profile photo — never a unit number, phone or email. Administrators see the records of their own community, including who entered when, service requests and the finance ledger. Guards see what they need at the gate: passes, visits, packages and incidents, and residents' photos. Nobody sees another community.
Who we share it with
Sub-processors that host the platform, store uploaded files, send email and, when enabled by the Customer, provide corporate sign-in. The current list is published with the Data Processing Agreement. We disclose data when the law requires it and tell the Customer unless we are prohibited from doing so.
How long we keep it
While your membership is active and, for the community's records (dues, votes, audit trails), for as long as the community's retention policy says. The defaults, which each community can adjust and the platform enforces automatically: visitor photos 90 days; visits, used passes, packages, incidents, shift handoffs and intercom calls 1 year; messages, closed requests and resolved panic alerts 2 years; invitations 90 days; read notifications 180 days; files never attached 7 days. Contact and signup requests are kept for 1 year at platform level; crash reports for 30 days. When you delete your account, your session ends at once and the account is erased 30 days later unless you sign in and cancel. Your personal data is erased; what you shared with the community is kept without your name. Backups rotate within 30 days.
Your rights
From the application you can see and correct your profile, download a copy of everything the platform holds about you, choose which notifications you receive, and delete your account after confirming your password. You can ask the Customer, or us, to exercise access, rectification, erasure, restriction, portability or objection rights under the law that applies to you, and you can complain to your supervisory authority.
How we protect it
Encrypted connections, hashed passwords, multi-factor authentication for privileged accounts, isolation between communities enforced in every request, an allow-list of file types with content checks, credential redaction in logs, backups with regular restore drills and a published vulnerability disclosure process.
Network addresses
We keep the full network address only in sign-in records, to investigate abuse, and for as long as the community sets. Everywhere else we keep only the network (the first three groups of an IPv4 address), and on public forms and rate limits a keyed pseudonym from which the address cannot be recovered.
Where data is stored
The platform runs in a single region chosen by the Customer in the order form. Data does not leave that region except to the sub-processors listed, under the safeguards described in the Data Processing Agreement.
Children
The platform is for adults who are members of a community. Accounts are created by invitation from an administrator; we do not knowingly collect data from children.
Cookies and storage
Only what is strictly necessary, and no advertising or analytics tracker. On the site and in the application: the cookie for the language you chose (one year) and, in the web application, the session cookies that keep you signed in. The application also keeps, in your browser's local storage on your device: the session token in the native app and in the demonstration, actions waiting to be sent while you have no signal, a copy of your community's data so it opens faster, and whether you have seen the welcome. None of it leaves your device or is shared.
Changes to this Policy
We may update this Policy. Material changes are announced to the Customer's administrators before they take effect, and the current version is always published on the website.
Contact
Privacy questions go to the contact address published on the website. Counsel to add the legal entity, postal address and, where required, the data protection officer or representative.