# Privacy Policy
## 1. Controller
The controller of personal data collected through the Service is the operator
identified in the footer of the Service ("Operator"). You can reach us at the
support email shown in the Service.
## 2. What we collect
- **Account data:** name, email, password hash, preferred locale, role.
- **Organisation data:** company name, address, tax identifiers, bank details,
invoicing settings, SMTP credentials you configure.
- **Application data:** everything you enter about properties, leases, tenants,
invoices, expenses, attachments, and audit log entries.
- **Billing data:** subscription plan, billing period, and payment status. Card
details are collected and stored solely by our payment processor and never
reach the Operator's servers.
- **Technical data:** IP address, User-Agent, timestamps of logins and audit events.
## 3. Purposes and legal bases
- **Providing the Service** — Art. 6(1)(b) GDPR, performance of the contract.
- **Security, abuse prevention, audit logs** — Art. 6(1)(f), legitimate interest.
- **Billing and tax records** — Art. 6(1)(c), legal obligation.
- **Service communications** — Art. 6(1)(b) and (f).
## 4. Cookies
The Service uses only cookies that are **strictly necessary** for it to work.
They are exempt from consent under ePrivacy rules.
| Cookie | Purpose | Duration |
| --- | --- | --- |
| `sid` | Authenticated session | Session / rolling |
| `csrfToken` | Cross-site request forgery protection | Session |
The Service does **not** set any analytics, advertising, or third-party tracking
cookies. Should that change, this policy will be updated and consent requested
where required. You can delete or block cookies in your browser settings;
blocking the strictly necessary cookies will prevent the Service from working.
## 5. Retention
Application data is retained for as long as your organisation exists. After you
request deletion, data is hard-deleted following the grace period configured in
the Service. Audit logs and billing records may be retained longer where required
by law.
## 6. Recipients
We share personal data only with the categories of processors strictly necessary
to run the Service; the up-to-date list of named providers is maintained on the
**Subprocessors** page of the Service. The categories are:
- a **transactional email delivery provider** (verification, notifications,
billing emails sent by the Service);
- a **payment processor** for paid plans, which acts as an independent controller
for card data;
- a **DNS and network security provider** in front of the Service;
- an **identity provider**, only if you choose to sign in with a third-party
account (for example Google OAuth).
The application and its database are hosted on infrastructure operated directly
by the Operator in the European Union. Emails you send through your own configured
SMTP server (for example invoices to your tenants) are transmitted by your
provider and remain under your control. We do **not** sell personal data.
## 7. International transfers
Where these processors transfer data outside the EEA we rely on Standard
Contractual Clauses or other safeguards required by the GDPR.
## 8. Your rights
You have the right to access, rectify, erase, restrict, object to, and port your
personal data, and to lodge a complaint with your supervisory authority.
## 9. Contact
Requests should be sent to the support email shown in the Service. We will respond
without undue delay and in any case within one month.