Privacy Policy
This Privacy Policy explains how your personal data is handled when you use Domuno. This English version is intended for users in English-speaking countries. Each processing purpose has its own legal basis, set out below — using the Service does not itself substitute for that basis or amount to blanket consent.
1. Data We Collect
We collect only what is necessary for the Service to function: account information (name, email, language); property, unit and resident data provided by the administrator; communications content; Plus-plan billing data; technical and access data (IP address, logs, device information); anti-bot verification data, which processes the visitor's IP address during registration. We do not sell your data, and we do not profile you or take automated decisions that produce legal effects concerning you.
2. Roles: Controller and Processor
Domuno is operated by an individual developer, Newton Urbanetz, a natural person, not a company. That person is the data controller for the data of your account (registration data, communications with us) and is reachable at the contact address in Section 12; full identification details are provided on request. For the data of residents and the condominium that you manage in the Service, the condominium administrator (or the condominium itself) is the data controller and the operator of Domuno acts as data processor on documented instructions. The administrator is responsible for the lawful basis of processing resident data, for informing residents, and for handling residents' requests under applicable data protection law.
3. How We Use Data
Your data is used solely to provide and improve the Service: authenticate users, display relevant information, and send notifications. We do not use behavioural analytics tools.
4. Data Storage and Transfers
Data is stored on servers located in the European Union. Some providers needed to run the Service may process data from outside your country; where that happens, we require those providers to apply appropriate contractual safeguards. You can ask for the current list of providers and the applicable safeguards at any time, at the address in the contact section.
5. Data Sharing
We share your data only with: (a) processors necessary to run the Service — hosting, transactional email delivery and anti-bot verification, engaged as processors; (b) authorities, where required by law; (c) with your explicit consent.
6. Your Rights
Subject to the data protection law that applies to you, you generally have the right to access your data, to have it corrected, to have it erased, to receive it in a portable format, to restrict how it is processed, and to object to processing carried out on the basis of legitimate interests. We respond to requests without undue delay and in any event within one month. Erasure may be implemented by permanent deletion or irreversibly anonymising the data. Where processing rests on consent you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before the withdrawal. Write to [email protected] to exercise any of these. You may also lodge a complaint with your local data protection authority.
7. Data Retention
We keep account data while your account is active. When the account is deleted, or when you ask for deletion, the data is deleted or anonymised within 30 days. Audit logs are kept for up to 12 months for security purposes. Technical logs are kept for up to 2 months and deleted within that period. Server snapshots, when taken, may contain data until they are replaced by newer ones. Where the law requires (e.g., tax obligations) or to establish, exercise or defend legal claims, data may be kept longer. These retention periods may change without prior notice, subject to any minimum period required by law.
8. Legal Basis for Processing
We process account, property and communication data to perform our contract with you for the Service. We keep security logs on the basis of our legitimate interest in keeping the Service secure, balanced against your rights. Where the law requires us to retain particular records, the basis is compliance with a legal obligation. Providing account data is a contractual requirement: without it we cannot provide the Service. We do not carry out automated decision-making, including profiling, that produces legal effects concerning you.
9. Security and Breach Notification
We apply appropriate technical and organisational measures: TLS encryption in transit, role-based access controls and audit logging. In the event of a personal-data breach we will notify the competent authority and affected users without undue delay where required by applicable law and where the risk to them is high.
10. Cookies and Local Storage
The marketing site sets no cookies itself. The application uses only strictly necessary authentication cookies (httpOnly session) and stores, locally in your browser (localStorage) on your own device: preferences (language, theme), your selected active condominium, and a cache of your basic account data (name, email, role) used to load the interface without a fresh server request on every visit. The marketing site uses no visitor analytics and loads no third-party scripts. We do not use advertising or profiling cookies.
11. Children
You must be at least 18 to hold an account: this applies to the accountholder (administrator or registered resident). That is separate from data about children: an administrator may record, as resident data, information about a child living in a unit — in that case the administrator is responsible for the lawful basis of that processing towards the data subject or their legal guardian, as set out in Section 2. If you believe data about a child has been submitted without an adequate legal basis, contact us so it can be removed.
12. Contact
For any privacy-related inquiries, contact us at [email protected].