Skip to content
OpenAppPhysical access, simplified
Login

Privacy audit

This page is not a legal statement, commitment, warranty, certification, or contract. It does not amend the Privacy Policy or Terms of Service.

It is an honest attempt to map how OpenApp implements and aligns with the regulations and standards listed below. We strive to keep it accurate; errors and omissions can happen.

If something looks misaligned, inconsistent, or wrong, send feedback via the marketing contact form: https://openapp.house/#contact (the same POST /api/v1/public/feedback form). Privacy-specific mail: tomer+privacy@openapp.house.

  • DPA (Data Processing Agreement) — contract under the General Data Protection Regulation (GDPR) Article 28 when OpenApp processes personal data for a customer (building operator). Distinct from a Data Protection Authority (a national supervisory authority (SA)) and from the United Kingdom Data Protection Act 2018.
  • GDPR — General Data Protection Regulation.
  • EEA — European Economic Area.
  • SA — supervisory authority.
  • DPO — Data Protection Officer (GDPR Art. 37).
  • DPIA — Data Protection Impact Assessment (GDPR Art. 35).
  • RoPA — Record of Processing Activities (GDPR Art. 30).
  • DSAR / DSR — Data Subject Access Request / data-subject rights request (GDPR Arts. 15–22).
  • SCC — Standard Contractual Clauses (European Union transfer tool).
  • DPF — EU–US Data Privacy Framework.
  • LIA — Legitimate Interests Assessment.
  • PII / personal data — GDPR Art. 4(1); personally identifiable information is the common English shorthand.
  • ePrivacy — ePrivacy Directive (cookies / electronic communications).
  • ToS / EULA — Terms of Service / End-User License Agreement (onboarding acceptance).
  • ISO — International Organization for Standardization.
  • SOC 2 — System and Organization Controls 2 (American Institute of Certified Public Accountants).
  • TLS — Transport Layer Security.
  • FCM / APNs — Firebase Cloud Messaging / Apple Push Notification service.

For each instrument: full name, official website, applicable regions, applicable areas for OpenApp, requirements at article or theme level, and honest OpenApp status. OpenApp does not claim ISO or SOC certification. This page does not paste copyrighted control text.

General Data Protection Regulation (EU) 2016/679

Section titled “General Data Protection Regulation (EU) 2016/679”
  • Official: EUR-Lex; European Commission data protection
  • Regions: European Union / European Economic Area (Art. 3 also extra- territorial in some cases). OpenApp is established in the EU/EEA, so Art. 3(1) applies; an Art. 27 representative is not required.
  • Areas: accounts, building directories, live intercom, invitations, audit, push, optional AI enrich, subprocessors.
  • Requirements that attach: Arts. 5–7 (principles, lawfulness), 12–22 (transparency and rights), 25 (data protection by design), 28 (processor), 30 (RoPA), 32–35 (security, breach, DPIA), 37 (DPO), 44–49 (transfers).
  • OpenApp status: Aligning. Privacy Policy, cookie notice, Data Processing Agreement, subprocessors, RoPA, and DPIA drafts exist in-repo. Product export/erasure and scheduled purge are implemented. A Data Protection Officer is not appointed in public copy (counsel-owned). Registered company name, address, VAT, and lead supervisory authority are not published here (counsel-owned). Not certified under Arts. 42/43.
  • Official: EUR-Lex
  • Regions: EU member-state implementations.
  • Areas: cookies, electronic communications, guest identifiers.
  • Requirements: Art. 5(3) consent for non-necessary storage; exception for storage strictly necessary to provide a service the user requested.
  • OpenApp status: Aligning. Login session and invite/portal session cookies (ory_kratos_session, oa_access_invite, oa_guest_id for one hour) are treated as necessary for the requested session. oa_guest_id is not a one-year cross-invitation tracker. No marketing cookies. No consent banner while only necessary/session and first-party functional preferences remain. Cookie notice.
  • Official: ICO UK GDPR guidance; Data Protection Act 2018
  • Regions: United Kingdom.
  • Areas: same product if UK users or customers use OpenApp.
  • Requirements: UK GDPR principles, rights, and transfers, plus the 2018 Act.
  • OpenApp status: Not claimed as a full UK compliance programme. If UK users exist, EU GDPR alignment is the current mapping; UK-specific representative, ICO registration, and UK transfer tools are not asserted here.
  • Official: coe.int
  • Regions: Convention parties.
  • Areas: principle-level privacy (fairness, purpose, security).
  • Requirements: modernised Convention 108 principles — not a GDPR substitute.
  • OpenApp status: Principle-level map only via GDPR alignment. Not a separate Convention 108+ certification.

California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA)

Section titled “California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA)”
  • Official: California Attorney General
  • Regions: California, United States.
  • Areas: “sale”/“share” of personal information, consumer rights.
  • Requirements: notices, opt-out of sale/share, deletion/access in California law.
  • OpenApp status: No sale of personal data. We do not claim a full CPRA consumer-rights machinery (California-specific “Do Not Sell” and 12-month lookback workflows are not the EU product). Honest: EU GDPR rights tools are what exist today.
  • Official: OECD data protection
  • Regions: OECD members (non-binding guidelines).
  • Areas: collection limitation, purpose, security, accountability.
  • Requirements: principle-level only.
  • OpenApp status: Principle-level only. Not a binding audit.

EU Artificial Intelligence Act (Regulation 2024/1689)

Section titled “EU Artificial Intelligence Act (Regulation 2024/1689)”
  • Official: EUR-Lex
  • Regions: European Union.
  • Areas: optional Gemini photo enrich (operator-submitted directory photos). No biometric identification, no licence-plate recognition in product.
  • Requirements: transparency-type duties for limited AI uses; prohibited biometric identification is out of scope of this product.
  • OpenApp status: Limited mapping. Gemini is key-gated with an in-product notice. We do not claim the whole AI Act is implemented. Adding face templates or licence-plate recognition would require a new DPIA and legal basis.
  • Official: EUR-Lex
  • Regions: European Union.
  • Areas: cybersecurity for essential/important entities and some suppliers.
  • Requirements: risk management, incident reporting for designated entities.
  • OpenApp status: Not claimed. OpenApp is not asserting that it is a designated NIS2 entity. Possible future relevance if we supply such entities.
  • Official: GDPR on EUR-Lex (Art. 28).
  • Regions: where GDPR applies.
  • Areas: OpenApp as processor for building operators.
  • Requirements: written contract, instructions, confidentiality, security, subprocessors, assistance, deletion/return, audit information.
  • OpenApp status: Published. Data Processing Agreement. Counsel should confirm company details before a signed customer contract.
  • Official: European Commission SCCs
  • Regions: transfers of personal data out of the EEA.
  • Areas: extra-EEA processors OpenApp engages (Google, Apple push, and similar).
  • Requirements: module-appropriate SCCs plus transfer assessment.
  • OpenApp status: Disclosed as the intended tool on the subprocessor list. Signed vendor SCCs are counsel/vendor-owned and are not pasted here.
  • Official: dataprivacyframework.gov
  • Regions: participating US organizations.
  • Areas: per-vendor, only if that vendor is certified.
  • Requirements: rely on DPF only for certified organizations.
  • OpenApp status: Per-vendor, do not assume certification. Listed as an optional tool where a vendor participates. We do not claim OpenApp itself is DPF-certified.
  • Official: ISO
  • Regions: global, voluntary.
  • Areas: information security management.
  • Requirements (themes, not copyrighted controls): access control, cryptography, operations security.
  • OpenApp status: Not certified. We run TLS, encryption at rest for primary databases and object storage, and access control. This page is not an ISO Statement of Applicability.
  • Official: ISO
  • Regions: global, voluntary privacy information management (usually on ISO 27001).
  • Areas: controller/processor roles.
  • OpenApp status: Not certified. Dual-role documentation exists; this page is not a 27701 Statement of Applicability.
  • Official: AICPA SOC 2
  • Regions: typically US customer due diligence.
  • Areas: security, availability, confidentiality trust services.
  • OpenApp status: No SOC 2 report claimed.
  • Official: EDPB certification
  • Regions: EU, voluntary seal from accredited bodies.
  • OpenApp status: Not pursued in this delivery. There is no mandatory pre-market GDPR certification.

OpenApp is established in the EU/EEA. Privacy contact: tomer+privacy@openapp.house. You may lodge a complaint with a supervisory authority. Registered legal name, postal address, VAT, Data Protection Officer appointment, and lead supervisory authority are counsel-owned and are not invented on this page.

  • OpenApp as controller: accounts, End-User License Agreement records, product security logs, sales/feedback (POST /api/v1/public/feedback).
  • Building operator as controller / OpenApp as processor: residents, visitors, invitations, live intercom, directories, access events. Organization customers: Data Processing Agreement.
CategoryWhatNotes
AccountName, email, phoneOpenApp controller
AuthIdentity-provider idsOptional Google sign-in
Photos / mediaDirectory and invite photosS3; Gemini only if enabled
Guest oa_guest_idSession ULID1 hour; invite/portal scoped
InvitesTokens, validity, messagesController data
Access sessionsMetadata, token hashesNo server-side call recording
Live video/audioWebRTCTransmitted, not stored as a recording
AuditEvent type, outcome, time, idsNames minimized after erasure
Push tokensAPNs / FCM / Web PushCaller label (building / apartment)
Sales/feedbackName, email, messageLegitimate interests, B2B
LocationsSite addressGoogle Maps/geocoding when used
PalGate CloudCustomer-connectedpalgate.com; storage location not specified by OpenApp
Other integrationsCustomer-connectedCategories the connector needs

Art. 9: OpenApp does not extract biometric templates and does not run licence- plate recognition. Live video is not automatically special-category data without a biometric template.

See the Privacy Policy table: contract for the Service; legitimate interests for security logs and B2B contact; processor contract for building data; ePrivacy necessary storage for login/invite session cookies.

  • Amazon Web Services eu-central-1 (primary hosting)
  • Google Gemini, Maps, and OAuth when enabled
  • Firebase Cloud Messaging and Apple Push Notification service
  • Simple Email Service / Simple Notification Service when configured
  • Customer audit webhooks (controller chooses the URL)

Interactive Connectivity Establishment (ICE) for WebRTC: no default Google STUN. ICE servers must be configured for the deployment.

PalGate Cloud (palgate.com) is customer-connected, not an OpenApp-operated store.

Full register: Subprocessors.

StorePeriod
Audit hot (Postgres)30 days
Audit archive (object storage)about 7 years (org may shorten, not exceed platform max)
Soft-delete hold60 days, then scheduled purge
Store catalog after delete365 days
CloudWatch operational logstypically 14 days
Guest cookie1 hour
Audit export downloads7 days

Cookie notice. No marketing trackers (no gtag, Plausible, Posthog, or Sentry on marketing/docs/dashboard).

Thirty-day SLA. Account holders: Privacy in the dashboard (export and deletion request). Personal-workspace-only users can erase themselves in-product. Org-attached users submit a request notified to organization admins. Visitor and guest requests about building data go to the building controller. Runbook: packages/legal/dsar-runbook.md.

Virtual intercom, directories, and multi-year access logs are high-risk. A DPIA draft lives at packages/legal/dpia.md. Counsel sign-off is still required. RoPA: packages/legal/ropa.md.

TLS in transit; encryption at rest for primary databases and object storage. Household members under 16: the organization customer is the controller. A parent or apartment administrator may store a calendar date of birth on the OpenApp user so call and portal limits can be computed at enforcement time (under 13 are not public-portal callees; 13–15 receive visitor calls only if the parent enables it). Date of birth is purpose-limited to those limits and is not used for marketing. OpenApp does not market to children. Family Link / Play Age Signals are not the source of truth for age.

Processor notifies the organization customer without undue delay. Controller 72-hour supervisory notice and Art. 34 individual notice follow packages/legal/breach-notification.md.