Privacy audit
Disclaimer
Section titled “Disclaimer”This page is not a legal statement, commitment, warranty, certification, or contract. It does not amend the Privacy Policy or Terms of Service.
It is an honest attempt to map how OpenApp implements and aligns with the regulations and standards listed below. We strive to keep it accurate; errors and omissions can happen.
If something looks misaligned, inconsistent, or wrong, send feedback via the
marketing contact form:
https://openapp.house/#contact (the same
POST /api/v1/public/feedback form). Privacy-specific mail:
tomer+privacy@openapp.house.
Glossary
Section titled “Glossary”- DPA (Data Processing Agreement) — contract under the General Data Protection Regulation (GDPR) Article 28 when OpenApp processes personal data for a customer (building operator). Distinct from a Data Protection Authority (a national supervisory authority (SA)) and from the United Kingdom Data Protection Act 2018.
- GDPR — General Data Protection Regulation.
- EEA — European Economic Area.
- SA — supervisory authority.
- DPO — Data Protection Officer (GDPR Art. 37).
- DPIA — Data Protection Impact Assessment (GDPR Art. 35).
- RoPA — Record of Processing Activities (GDPR Art. 30).
- DSAR / DSR — Data Subject Access Request / data-subject rights request (GDPR Arts. 15–22).
- SCC — Standard Contractual Clauses (European Union transfer tool).
- DPF — EU–US Data Privacy Framework.
- LIA — Legitimate Interests Assessment.
- PII / personal data — GDPR Art. 4(1); personally identifiable information is the common English shorthand.
- ePrivacy — ePrivacy Directive (cookies / electronic communications).
- ToS / EULA — Terms of Service / End-User License Agreement (onboarding acceptance).
- ISO — International Organization for Standardization.
- SOC 2 — System and Organization Controls 2 (American Institute of Certified Public Accountants).
- TLS — Transport Layer Security.
- FCM / APNs — Firebase Cloud Messaging / Apple Push Notification service.
Regulations and standards catalog
Section titled “Regulations and standards catalog”For each instrument: full name, official website, applicable regions, applicable areas for OpenApp, requirements at article or theme level, and honest OpenApp status. OpenApp does not claim ISO or SOC certification. This page does not paste copyrighted control text.
Laws and regulations
Section titled “Laws and regulations”General Data Protection Regulation (EU) 2016/679
Section titled “General Data Protection Regulation (EU) 2016/679”- Official: EUR-Lex; European Commission data protection
- Regions: European Union / European Economic Area (Art. 3 also extra- territorial in some cases). OpenApp is established in the EU/EEA, so Art. 3(1) applies; an Art. 27 representative is not required.
- Areas: accounts, building directories, live intercom, invitations, audit, push, optional AI enrich, subprocessors.
- Requirements that attach: Arts. 5–7 (principles, lawfulness), 12–22 (transparency and rights), 25 (data protection by design), 28 (processor), 30 (RoPA), 32–35 (security, breach, DPIA), 37 (DPO), 44–49 (transfers).
- OpenApp status: Aligning. Privacy Policy, cookie notice, Data Processing Agreement, subprocessors, RoPA, and DPIA drafts exist in-repo. Product export/erasure and scheduled purge are implemented. A Data Protection Officer is not appointed in public copy (counsel-owned). Registered company name, address, VAT, and lead supervisory authority are not published here (counsel-owned). Not certified under Arts. 42/43.
ePrivacy Directive 2002/58/EC
Section titled “ePrivacy Directive 2002/58/EC”- Official: EUR-Lex
- Regions: EU member-state implementations.
- Areas: cookies, electronic communications, guest identifiers.
- Requirements: Art. 5(3) consent for non-necessary storage; exception for storage strictly necessary to provide a service the user requested.
- OpenApp status: Aligning. Login session and invite/portal session
cookies (
ory_kratos_session,oa_access_invite,oa_guest_idfor one hour) are treated as necessary for the requested session.oa_guest_idis not a one-year cross-invitation tracker. No marketing cookies. No consent banner while only necessary/session and first-party functional preferences remain. Cookie notice.
UK GDPR + Data Protection Act 2018
Section titled “UK GDPR + Data Protection Act 2018”- Official: ICO UK GDPR guidance; Data Protection Act 2018
- Regions: United Kingdom.
- Areas: same product if UK users or customers use OpenApp.
- Requirements: UK GDPR principles, rights, and transfers, plus the 2018 Act.
- OpenApp status: Not claimed as a full UK compliance programme. If UK users exist, EU GDPR alignment is the current mapping; UK-specific representative, ICO registration, and UK transfer tools are not asserted here.
Council of Europe Convention 108+
Section titled “Council of Europe Convention 108+”- Official: coe.int
- Regions: Convention parties.
- Areas: principle-level privacy (fairness, purpose, security).
- Requirements: modernised Convention 108 principles — not a GDPR substitute.
- OpenApp status: Principle-level map only via GDPR alignment. Not a separate Convention 108+ certification.
California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA)
Section titled “California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA)”- Official: California Attorney General
- Regions: California, United States.
- Areas: “sale”/“share” of personal information, consumer rights.
- Requirements: notices, opt-out of sale/share, deletion/access in California law.
- OpenApp status: No sale of personal data. We do not claim a full CPRA consumer-rights machinery (California-specific “Do Not Sell” and 12-month lookback workflows are not the EU product). Honest: EU GDPR rights tools are what exist today.
OECD Privacy Guidelines
Section titled “OECD Privacy Guidelines”- Official: OECD data protection
- Regions: OECD members (non-binding guidelines).
- Areas: collection limitation, purpose, security, accountability.
- Requirements: principle-level only.
- OpenApp status: Principle-level only. Not a binding audit.
Adjacent EU instruments
Section titled “Adjacent EU instruments”EU Artificial Intelligence Act (Regulation 2024/1689)
Section titled “EU Artificial Intelligence Act (Regulation 2024/1689)”- Official: EUR-Lex
- Regions: European Union.
- Areas: optional Gemini photo enrich (operator-submitted directory photos). No biometric identification, no licence-plate recognition in product.
- Requirements: transparency-type duties for limited AI uses; prohibited biometric identification is out of scope of this product.
- OpenApp status: Limited mapping. Gemini is key-gated with an in-product notice. We do not claim the whole AI Act is implemented. Adding face templates or licence-plate recognition would require a new DPIA and legal basis.
NIS2 Directive (2022/2555)
Section titled “NIS2 Directive (2022/2555)”- Official: EUR-Lex
- Regions: European Union.
- Areas: cybersecurity for essential/important entities and some suppliers.
- Requirements: risk management, incident reporting for designated entities.
- OpenApp status: Not claimed. OpenApp is not asserting that it is a designated NIS2 entity. Possible future relevance if we supply such entities.
Contracts and transfer tools
Section titled “Contracts and transfer tools”Data Processing Agreement (GDPR Art. 28)
Section titled “Data Processing Agreement (GDPR Art. 28)”- Official: GDPR on EUR-Lex (Art. 28).
- Regions: where GDPR applies.
- Areas: OpenApp as processor for building operators.
- Requirements: written contract, instructions, confidentiality, security, subprocessors, assistance, deletion/return, audit information.
- OpenApp status: Published. Data Processing Agreement. Counsel should confirm company details before a signed customer contract.
Standard Contractual Clauses
Section titled “Standard Contractual Clauses”- Official: European Commission SCCs
- Regions: transfers of personal data out of the EEA.
- Areas: extra-EEA processors OpenApp engages (Google, Apple push, and similar).
- Requirements: module-appropriate SCCs plus transfer assessment.
- OpenApp status: Disclosed as the intended tool on the subprocessor list. Signed vendor SCCs are counsel/vendor-owned and are not pasted here.
EU–US Data Privacy Framework
Section titled “EU–US Data Privacy Framework”- Official: dataprivacyframework.gov
- Regions: participating US organizations.
- Areas: per-vendor, only if that vendor is certified.
- Requirements: rely on DPF only for certified organizations.
- OpenApp status: Per-vendor, do not assume certification. Listed as an optional tool where a vendor participates. We do not claim OpenApp itself is DPF-certified.
Management / audit standards (not laws)
Section titled “Management / audit standards (not laws)”ISO/IEC 27001
Section titled “ISO/IEC 27001”- Official: ISO
- Regions: global, voluntary.
- Areas: information security management.
- Requirements (themes, not copyrighted controls): access control, cryptography, operations security.
- OpenApp status: Not certified. We run TLS, encryption at rest for primary databases and object storage, and access control. This page is not an ISO Statement of Applicability.
ISO/IEC 27701
Section titled “ISO/IEC 27701”- Official: ISO
- Regions: global, voluntary privacy information management (usually on ISO 27001).
- Areas: controller/processor roles.
- OpenApp status: Not certified. Dual-role documentation exists; this page is not a 27701 Statement of Applicability.
- Official: AICPA SOC 2
- Regions: typically US customer due diligence.
- Areas: security, availability, confidentiality trust services.
- OpenApp status: No SOC 2 report claimed.
GDPR Arts. 42/43 certification
Section titled “GDPR Arts. 42/43 certification”- Official: EDPB certification
- Regions: EU, voluntary seal from accredited bodies.
- OpenApp status: Not pursued in this delivery. There is no mandatory pre-market GDPR certification.
Implementation mapping
Section titled “Implementation mapping”Controller identity and contact
Section titled “Controller identity and contact”OpenApp is established in the EU/EEA. Privacy contact: tomer+privacy@openapp.house. You may lodge a complaint with a supervisory authority. Registered legal name, postal address, VAT, Data Protection Officer appointment, and lead supervisory authority are counsel-owned and are not invented on this page.
Dual roles
Section titled “Dual roles”- OpenApp as controller: accounts, End-User License Agreement records,
product security logs, sales/feedback (
POST /api/v1/public/feedback). - Building operator as controller / OpenApp as processor: residents, visitors, invitations, live intercom, directories, access events. Organization customers: Data Processing Agreement.
Processing inventory
Section titled “Processing inventory”| Category | What | Notes |
|---|---|---|
| Account | Name, email, phone | OpenApp controller |
| Auth | Identity-provider ids | Optional Google sign-in |
| Photos / media | Directory and invite photos | S3; Gemini only if enabled |
Guest oa_guest_id | Session ULID | 1 hour; invite/portal scoped |
| Invites | Tokens, validity, messages | Controller data |
| Access sessions | Metadata, token hashes | No server-side call recording |
| Live video/audio | WebRTC | Transmitted, not stored as a recording |
| Audit | Event type, outcome, time, ids | Names minimized after erasure |
| Push tokens | APNs / FCM / Web Push | Caller label (building / apartment) |
| Sales/feedback | Name, email, message | Legitimate interests, B2B |
| Locations | Site address | Google Maps/geocoding when used |
| PalGate Cloud | Customer-connected | palgate.com; storage location not specified by OpenApp |
| Other integrations | Customer-connected | Categories the connector needs |
Art. 9: OpenApp does not extract biometric templates and does not run licence- plate recognition. Live video is not automatically special-category data without a biometric template.
Legal bases (Art. 6)
Section titled “Legal bases (Art. 6)”See the Privacy Policy table: contract for the Service; legitimate interests for security logs and B2B contact; processor contract for building data; ePrivacy necessary storage for login/invite session cookies.
Recipients (OpenApp-operated)
Section titled “Recipients (OpenApp-operated)”- Amazon Web Services
eu-central-1(primary hosting) - Google Gemini, Maps, and OAuth when enabled
- Firebase Cloud Messaging and Apple Push Notification service
- Simple Email Service / Simple Notification Service when configured
- Customer audit webhooks (controller chooses the URL)
Interactive Connectivity Establishment (ICE) for WebRTC: no default Google STUN. ICE servers must be configured for the deployment.
PalGate Cloud (palgate.com) is customer-connected, not an OpenApp-operated store.
Full register: Subprocessors.
Retention (aligned with code)
Section titled “Retention (aligned with code)”| Store | Period |
|---|---|
| Audit hot (Postgres) | 30 days |
| Audit archive (object storage) | about 7 years (org may shorten, not exceed platform max) |
| Soft-delete hold | 60 days, then scheduled purge |
| Store catalog after delete | 365 days |
| CloudWatch operational logs | typically 14 days |
| Guest cookie | 1 hour |
| Audit export downloads | 7 days |
Cookies / ePrivacy
Section titled “Cookies / ePrivacy”Cookie notice. No marketing trackers (no gtag, Plausible, Posthog, or Sentry on marketing/docs/dashboard).
Data-subject rights
Section titled “Data-subject rights”Thirty-day SLA. Account holders: Privacy in the dashboard (export and deletion
request). Personal-workspace-only users can erase themselves in-product.
Org-attached users submit a request notified to organization admins. Visitor
and guest requests about building data go to the building controller.
Runbook: packages/legal/dsar-runbook.md.
High-risk processing and DPIA
Section titled “High-risk processing and DPIA”Virtual intercom, directories, and multi-year access logs are high-risk. A
DPIA draft lives at packages/legal/dpia.md. Counsel sign-off is still
required. RoPA: packages/legal/ropa.md.
Security and children
Section titled “Security and children”TLS in transit; encryption at rest for primary databases and object storage. Household members under 16: the organization customer is the controller. A parent or apartment administrator may store a calendar date of birth on the OpenApp user so call and portal limits can be computed at enforcement time (under 13 are not public-portal callees; 13–15 receive visitor calls only if the parent enables it). Date of birth is purpose-limited to those limits and is not used for marketing. OpenApp does not market to children. Family Link / Play Age Signals are not the source of truth for age.
Personal-data breaches
Section titled “Personal-data breaches”Processor notifies the organization customer without undue delay. Controller
72-hour supervisory notice and Art. 34 individual notice follow
packages/legal/breach-notification.md.