Privacy Policy
Your privacy matters. Here's how we handle your data.
1. Data Controller
Domera ("we", "us"), operated from the United Kingdom, is the data controller for personal data processed through the Platform. We comply with the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR). For any privacy-related questions, contact us at hello@domera.io.
2. Data We Collect
We collect the following personal data:
3. Legal Basis for Processing (GDPR Art. 6)
4. Data Sharing
We share personal data with the following processors:
We do not sell personal data. We do not share data with advertisers. All sub-processors are GDPR compliant with appropriate data processing agreements in place.
5. Within Your Building
Building managers can see apartment details, payment status, and contact information for all residents in their building. Residents can see the building directory (names, phone numbers, emails) and shared financial information (reserve balance, expenses). Votes cast are recorded with apartment identification for legal compliance.
This data sharing is necessary for the legitimate purpose of building management and is consistent with the legal obligations of co-ownership.
6. Data Retention
7. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
To exercise these rights, contact hello@domera.io. We will respond within 30 days.
8. Data Security
We use industry-standard security measures including encrypted data transmission (TLS), encrypted data at rest, row-level security policies in our database, and regular security audits. Card payment data is handled entirely by Stripe (PCI DSS Level 1 certified) and never touches our servers.
9. International Transfers
Data is primarily stored in the EU. Where data is processed outside the EU (e.g., by Vercel's global CDN), appropriate safeguards are in place including Standard Contractual Clauses (SCCs) approved by the European Commission.
10. Supervisory Authority
You have the right to lodge a complaint with your local data protection authority. For the UK, this is the Information Commissioner's Office (ICO). EU users may contact their national data protection authority — a full list is available at edpb.europa.eu.
11. Changes
We will notify you of material changes to this policy via email or in-app notification at least 30 days before they take effect.