Privacy
Landlords save a contact email for each resident and invitation. The app shows saved addresses as read-only and lets owners select one resident per apartment for utility email. Email is not login. Invitation cancellation, expiry, reset or restore invalidation clears the pending contact. Acceptance transfers it to the resident account and clears the invitation copy. Resident deletion removes the address and clears that resident’s utility-email selection. Contact addresses are excluded from resident responses, Assistant tool data, logs and audit detail. Email utilities publishes the complete saved bill in the app, then supplies a named, protected temporary Excel file and message data to native iOS sharing for the selected authorized resident. The app removes its temporary file after sharing or account clear; after a process interruption, at the next launch. It does not cache product snapshots on disk. The landlord selects Gmail or another compatible app, checks the fields and sends from that app’s chosen account. Manual entry can be needed. Cancelling the email app leaves the bill published; share completion never proves email delivery or changes payment status. Gabor Villa does not access the email password or send automatically. The chosen app and provider process the message and attachment under their own rules. Their copies are outside Gabor Villa and are not removed when app access ends.
Temporary manual utility reviews can retain actual cumulative Start and End observations and their dates as immutable bill evidence for a closed partial period. The landlord and authorized residents share one corrected bill. Original calendar meter records stay intact. This does not extend access or create a separate resident debt.
Gabor Villa processes the data required to operate the building and provide apartment access: account and apartment assignment, resident display names, passkey public keys, device-integrity data, access start and end dates, and security-audit records. A resident transmits their date of birth only when verifying an invitation. The server never stores the raw date: while an invitation is pending, it stores only a domain-separated HMAC-SHA256 verifier keyed by the production invitation secret and used solely to confirm the invited person. The verifier is erased when the invitation is used, cancelled, expires, is reset, or is invalidated by restore.
Operational data includes room temperature, humidity, dew point and temperature history, temperature setpoints, blind positions, weather data, cumulative meter readings, and security and technical-alarm state and history. The server uses authoritative readings and configuration to calculate costs; the app does not recalculate money locally.
Financial data includes effective-dated utility and electricity tariffs, Internet charges, rent, Common costs, garage and storage charges, permanent active transfer destinations and their currencies, closed statements, landlord utility approvals bound to the exact calculation fingerprint, correction revisions, payment submissions, verification or rejection decisions, and payment-status history. Landlord-only financial data also includes HUF Lift schedules and owner-only operating-cost comparisons. These schedules and reports do not create resident charges, statements or payments and do not contact the building controller (PLC). Until approval, a resident sees Utilities as Missing without utility values or payment details; Rent & Charges remains independent. Transfer details are displayed for manual copying only; Gabor Villa does not initiate a bank transfer or receive online-banking credentials. The landlord and internal audit retain utility corrections, reconciliations and calculation provenance, but residents do not receive that history. Approved utility values are locked against later utility-affecting changes.
If notifications are enabled, the server stores the APNs device token, its installation binding and selected notification language only while that installation is registered. Push text is generic and localization-key based; its custom data contains only the event type and the relevant apartment, statement or payment identifiers—never a name, date of birth, IBAN, amount, meter value, banking credential or passkey. An invalid-token response from APNs removes the registration and queued delivery; resident revocation and account or building deletion remove associated registrations as well.
More than one resident may have active access to an apartment, but each resident account belongs to one apartment. Access is enforced only within its configured validity period and is revoked automatically after it ends. Personal apartment and room names are private to that resident. Removing one resident does not remove another resident or the apartment’s financial history. Meter readings, statement revisions and payment history remain as apartment records after resident turnover; the former resident’s personal link is removed.
The optional experimental Assistant is for landlords on iOS 27 or later and is off by default. It is a read-only text chat in English and German. It uses a dedicated help database; the public manual remains the complete fallback. Authorized tools can read selected apartment status, diagnostics, alarms, access counts or dates, stored statement details, rates, and payment state. Financial requests cover at most twelve closed months. Tool results omit resident names, full bank details, internal identifiers, revisions, provenance, and credentials before model processing. The Assistant cannot change accounts, controls, financial settings, statements, or payments. It cannot read audit records or use a billing read that creates a statement.
For model-generated answers, the Assistant first uses Apple Private Cloud Compute when available. Clarification questions and resident-count-only answers use native app logic. Their questions and access data are not sent to a language model. Attention summaries and month comparisons also use native app logic without a language model. Native questions and answers are excluded from later model context. Source links open app-controlled screens or verified manual topics without submitting changes. The question and the required redacted, read-only villa data can be processed by Apple Private Cloud Compute. This requires a network connection and has a daily user limit. For documented availability, network, quota, timeout, rate-limit, or language failures, the app can use the on-device Apple model. Refusals and safety failures do not trigger that fallback. Gabor Villa does not persist conversation text. The Assistant does not use microphone input, audio recording, or spoken output.
Biometric data never leaves the device. Gabor Villa does not sell data or use advertising trackers. Live-data deletion follows the in-app account and building-erasure rules. A manually created SQLite backup on the same Railway volume may retain data removed later until that backup is deleted or replaced; production has no provider-managed or off-volume backup. Normal backend audit records have a rolling 180-day retention window. Sensitive landlord financial and administrative changes record the responsible account, action and UTC time with compact safe values or revision references, never raw requests, names, secrets or bank details. Personal audit links and metadata are anonymized when required. Anonymized records expire at 90 days from their original creation, not from deletion. Expired records are removed at startup and daily; deletion immediately removes related records already past 90 days. The app and Assistant do not provide an audit-history viewer.
Contact: support@altotech.eu.