Privacy Policy

How we collect, store and protect the data of residents and buildings.

The service provider is in the process of being registered. The company name, registered office and tax number will be published on this page as soon as registration is complete. Until then, please send any questions about data processing to ivannkpetrovic@gmail.com.

Last updated: 13 August 2026

1. Data controller

The data controller is the service provider named at the top of this page. For any question about data processing, write to ivannkpetrovic@gmail.com.

For data a building enters about its residents, the building acts as controller and the service provider as a processor acting on its instructions.

2. What data we collect

Account data: name, email address, optionally a phone number, and sign-in records.

Building data: name, address, entrance, the building's bank account, individual parts with floor areas, owners, co-owners and tenants.

Financial data: monthly charges, payments, expenses and arrears per individual part. The platform does not collect card numbers and does not receive payments.

Content entered by users: documents, notices, fault reports with photographs and chat messages.

Technical data: data needed to operate and secure the service, including error logs and, if you have enabled them, the details needed to deliver push notifications.

3. Why we process it

To perform the contract — to provide the service you asked for: keeping the building's records, calculating charges, publishing documents and notifying residents.

To meet the building's legal obligations — the Law on Residential Building Maintenance requires records of how funds are spent, reporting to owners and action on overdue receivables.

On the basis of legitimate interest — securing the service, preventing abuse and improving the platform.

On the basis of consent — for push notifications to your device and for commercial messages. Consent can be withdrawn at any time.

4. Who sees your data

One building's data is available only to members of that building. The separation is enforced at database level, row by row.

Within a building, financial records are visible to all members, because Article 21 of the Law on Residential Building Maintenance gives every owner the right to inspect how funds are spent.

Whether names are shown alongside arrears is a building setting. By default arrears are shown against the label of the individual part.

Staff of the service provider access data only where necessary for support or fault resolution, and such access is logged.

5. Processors and data transfers

To run the service we use established infrastructure providers: Supabase (database, authentication and file storage), Vercel (application hosting) and Resend (email delivery).

These processors may store data on servers in the European Union. A data processing arrangement compliant with the General Data Protection Regulation is in place with each of them.

We do not sell data and do not pass it to third parties for marketing purposes.

6. How long we keep data

Building data is kept while the service is in use, and for a further ninety days afterwards to allow export, after which it is deleted.

A building's financial records may be kept longer where accounting rules or the Law on Residential Building Maintenance require it.

Technical error and access logs are kept for no longer than twelve months.

7. Your rights

You have the right to request access to your data, its correction, deletion, restriction of processing and portability in a structured format.

You have the right to object to processing based on legitimate interest and to withdraw any consent you have given.

Send requests to ivannkpetrovic@gmail.com. We respond within thirty days at the latest.

If you believe your rights have been infringed, you may lodge a complaint with Montenegro's Agency for Personal Data Protection and Free Access to Information.

8. Cookies

We use only the cookies necessary to run the service: keeping you signed in and remembering your language. We do not use cookies for advertising or for tracking behaviour on other sites.

That is why the site has no consent pop-up — there is nothing to consent to.

9. Security

Traffic is encrypted, passwords are stored in cryptographically protected form, and access to a building's data is checked in the database itself rather than only in the application.

Documents and photographs are held in private storage and are reachable only through links with a limited lifetime.

In the event of a data breach that may put people's rights at risk, we notify the competent authority and the affected users as the regulations require.

10. Changes to this policy

We may amend this policy. Material changes are announced by email and in the application at least fifteen days in advance.

The date of the last change is shown at the top of this page.