Privacy Policy
This Privacy Policy explains how OpenApp ("OpenApp", "we", "us", or "our") collects, uses, and protects personal data when you use OpenApp, our physical access control platform offered as a service ("Service"). This Policy forms part of our Terms of Service.
Controller. OpenApp is established in the European Union / European Economic Area and is the controller of account, marketing, and product-security data described below. For resident, visitor, invitation, intercom, and access-event data that a building or organization customer stores in the Service, that customer is the controller and OpenApp is the processor. Organization customers should also read our Data Processing Agreement.
Privacy contact. Questions, data-subject requests, and suspected misalignment: tomer+privacy@openapp.house or the contact form. We aim to respond within one month (General Data Protection Regulation (GDPR) Art. 12(3)). You may lodge a complaint with your local supervisory authority.
A non-legal mapping of how we implement these rules is published at Privacy audit.
1. Data we collect
- Account data: name, email address, and — where you sign in with a phone number — your phone number, used to create and secure your account.
- Authentication data: identifiers from identity providers you choose (such as Google), limited to what is needed to verify your identity.
- Access and audit data: records of access events, device and entity configuration, policies, and invitations that you or your organization create.
- Directory and media: apartment or unit display names, optional photos, and similar building-directory content uploaded by operators.
- Intercom session data: call session metadata (who was called, timestamps, outcome). We do not store server-side recordings of live video or voice.
- Guest identifiers: a short-lived
oa_guest_idcookie (or equivalent header) used only to attribute actions during an invitation or portal session. See the Cookie notice. - Push tokens: device tokens so we can deliver incoming-call alerts (Apple Push Notification service, Firebase Cloud Messaging, or web push).
- Locations: site addresses you enter; we may geocode them with Google Maps.
- Technical data: IP address, browser or device information, and timestamps, used to operate and secure the Service.
- Household date of birth: a parent or apartment administrator may record a household member's calendar date of birth so the Service can apply call and portal age limits. Sign-up does not collect date of birth. We use this date only for those limits, not for marketing. The organization customer is the controller of this household data; OpenApp is the processor.
- Sales and feedback: name, email, and message if you contact us.
We do not sell personal data.
2. Legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Provide the Service, authenticate you, authorize physical access | Contract (Art. 6(1)(b)) |
| Security, abuse prevention, audit integrity | Legitimate interests (Art. 6(1)(f)) and, where applicable, legal obligation (Art. 6(1)(c)) |
| Organization-customer processing of residents and visitors | Contract with the customer; we act as processor (Art. 28) |
| Service emails (login codes, security notices) | Contract / legitimate interests |
| Sales inquiries from the contact form | Legitimate interests in responding to B2B inquiries |
| Optional AI directory enrich (Gemini) | Contract with the customer who enables it; see in-product notice |
| Cookies strictly necessary for login or an active invite session | ePrivacy necessary storage; see Cookie notice |
We do not rely on consent as the primary basis for core access-control processing. Where we ask for a checkbox (Terms and Privacy acceptance at sign-up, PalGate Cloud linking acknowledgements), that records agreement or acknowledgement, not a substitute for the bases above.
3. How we use data
We use personal data to:
- provide, maintain, and secure the Service;
- authenticate users and authorize physical access;
- produce audit logs and other features you or your organization enable;
- communicate with you about your account and the Service; and
- comply with legal obligations and enforce our Terms of Service.
4. Sign-in with Google and other providers
When you sign in with a third-party identity provider, we receive basic profile information (such as your name and email address) needed to create and authenticate your account. We do not use this information for advertising, and we request only the scopes necessary to provide the Service. Your use of the provider is also governed by that provider's privacy policy.
5. How we share data
We share data only:
- with service providers who process data on our behalf (see Subprocessors) under confidentiality and security obligations;
- with third-party integrations you or your organization explicitly connect (for example PalGate Cloud at palgate.com). Those products are governed by their own terms; OpenApp does not operate their infrastructure;
- within your organization, with administrators who manage your access;
- to customer-configured audit webhook URLs, if an organization enables them (that organization is controller of the destination); and
- when required by law or to protect the rights, safety, and security of users, the public, or OpenApp.
6. International transfers
Primary hosting for the Service is in the European Union (Amazon Web Services,
eu-central-1). Some features send data to extra-European Economic Area
recipients when enabled (Google identity, Maps, and Gemini; Apple and Google
push). Where required, we use Standard Contractual Clauses and/or the EU–US
Data Privacy Framework for participating organizations. Details:
Subprocessors.
7. Data retention
- Account data: while the account is active, then typically 60 days after soft-delete before purge.
- Audit and access records: 30 days queryable in our database; long-term archive about 7 years for security, dispute resolution, and legal claims (GDPR Art. 17(3) may apply). After erasure we keep event type, outcome, timestamp, and technical identifiers — not display names — where the archive must survive.
- Store catalog (soft-deleted products): up to 1 year so historical statements remain readable.
- Operational logs (CloudWatch): typically 14 days.
- Guest session cookie: duration of the invitation/portal session (see Cookie notice).
- Audit export downloads: 7 days.
When data is no longer needed, we delete or anonymize it.
8. Security
We apply administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, loss, or misuse, including TLS in transit and encryption at rest for primary databases and object storage. No system is completely secure. See also our breach terms.
9. Your rights
Depending on your role, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing.
- Account holders: use Privacy in the OpenApp dashboard (export and deletion request) or email tomer+privacy@openapp.house. Personal-workspace-only users can request erasure in-product. If you belong to an organization, that organization is often the controller and must approve erasure of workplace data.
- Residents, visitors, and guests: contact the building or organization that uses OpenApp (they are the controller). We will assist them as processor.
- We may need to verify your identity. We respond as required by applicable law (normally within one month).
You may object to processing based on legitimate interests. You may lodge a complaint with a supervisory authority.
We do not make solely automated decisions that produce legal or similarly significant effects (GDPR Art. 22).
10. Children's privacy
The Service is not directed at children under 13 as a primary audience. Residential buildings may include household members under 16. A parent or apartment administrator may declare that member's date of birth so OpenApp can limit visitor calls (under 13 are not rung from the public portal; 13–15 receive visitor calls only if the parent enables it). That date is purpose- limited to call and portal limits. It is not used for marketing and is not shown to other residents.
The organization customer is the controller of household member data; OpenApp is the processor. We do not knowingly collect children's data for our own marketing. If you believe a child has provided us personal data as a controller, contact us so we can delete it.
Family Link or Play Age Signals on a phone are not how OpenApp decides someone is a child. Many children have phones without those tools. Parent- declared date of birth on the OpenApp user is the source of truth.
11. Cookies
See the Cookie notice.
12. Changes to this Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date below and, where appropriate, provide additional notice.