Privacy Policy
Last updated: January 1, 2026
Rezideo is a community platform that connects residents of the same building with their property managers (syndics, agencies, property administrators). The processing of your personal data is governed by the General Data Protection Regulation (GDPR). This policy describes precisely the data we collect, the purposes for which it is used and the rights you have.
1. Data collected
We only collect data necessary for the operation of the service. Account data: email address, password (hashed with bcrypt, never stored in plain text), first name, last name, optional avatar, preferred language. Residence data: postal address, postal code, city, country, freely entered unit identifier or floor, status (resident, owner or manager). Published content: posts, comments, photos, reactions, polls and votes, incident reports, private messages between neighbors, tenant reviews (anonymized after 6 months). Level: a community score derived from your interactions, aggregated at the residence, neighborhood, city and region levels. Technical data: IP address, user-agent, login timestamps, audit logs for sensitive actions. Payment data (managers only): company name, billing address and historical invoices; no banking information is stored by Rezideo, processing is fully delegated to Stripe. Notification preferences: by category (in-app toast, web push, email).
2. Processing purposes
Your data is processed to: create and secure your account; operate your residence's community spaces (feed, messaging, events, polls, incident reporting); calculate and publish your reputation level as well as the aggregated level of your building, neighborhood, city and region; send you the notifications you have enabled (in-app, web push, email); allow managers authenticated by the community to officially communicate, share documents and manage their subscription; moderate reported content through a community voting system and, as a last resort, by our team; ensure security (rate limiting, audit logs, fraud prevention); improve the service through aggregated and anonymized statistics; comply with our legal obligations (accounting, judicial requisitions).
3. Legal basis
In accordance with Article 6 of the GDPR, we process your data on the following bases: performance of the contract (Terms of Service) for account creation, access to community spaces and sending of service notifications; legitimate interest for platform security, fraud prevention, community moderation, anonymized audience measurement and reputation level; explicit consent, revocable at any time, for non-critical email notifications (weekly digest, non-transactional communications), push notifications and non-essential cookies; legal obligation for retention of connection logs (12 months), invoicing of manager subscriptions (10 years) and response to requisitions from competent authorities.
4. Retention period
Active account: as long as you use Rezideo. Upon account deletion, your personal data is erased within 30 days, except for data retained by legal obligation. Published content: kept as long as your account is active and the residence exists; you can delete a post, comment or message at any time. Tenant reviews: automatically anonymized after 6 months (the score remains, the author is dissociated). Connection and audit logs: 12 months. Manager invoices and subscriptions: 10 years from issuance (accounting obligation). Encrypted backups: rolling 30 days. Session cookies: 15 minutes for the access token, 7 days for the refresh token.
5. Sub-processors and sharing
Your data is never sold. It is only shared with the technical sub-processors necessary for the operation of the service, all bound by a data processing agreement compliant with the GDPR: Hetzner Online GmbH (hosting of the application and the database, Nuremberg, Germany); Stripe Payments Europe Ltd (manager payment processing, Dublin, Ireland); Mailjet SAS (transactional and digest email sending, Paris, France); Cloudflare Inc. (DNS resolution and DDoS protection); public geocoding APIs queried with your residence address only (Géoplateforme IGN for France, Swisstopo for Switzerland, Photon/Komoot for international); OpenStreetMap for map tiles. Within your residence, your first name, last name, avatar, level score and content you publish are visible to other members according to the visibility setting you choose. No transfer outside the European Union takes place without standard contractual clauses or an adequacy decision.
6. Your rights
You have all the rights provided by the GDPR over your personal data: right of access and copy, right of rectification, right to erasure (« right to be forgotten »), right to restriction of processing, right to portability (structured export), right to object to processing based on legitimate interest, right to withdraw your consent at any time, right to define directives regarding the fate of your data after your death. Most of these actions are available directly from your personal space: account deletion, export, notification preference management. For any additional request, write to us at privacy@rezideo.app — we respond within a maximum of 30 days. You also have the right to lodge a complaint with the CNIL (France), the Federal Data Protection Commissioner (Switzerland) or the supervisory authority of your country of residence.
7. Cookies and authentication
Rezideo uses a minimal number of cookies, all under our sole control. Strictly necessary cookies (no consent required): access_token and refresh_token, set as httpOnly and secure on the .rezideo.app domain to ensure your authentication between the website (rezideo.app) and the app (my.rezideo.app); a language preference cookie. Audience measurement cookies (with prior consent): anonymized internal usage statistics, with no cross-referencing with a third-party identifier. No advertising cookie or social network tracker is set. You can withdraw your consent at any time from your account settings or by blocking cookies in your browser.