Privacy policy
How HAUS handles personal data: for the companies that use it, for the owners and residents of the units it covers, and for anyone signed in at a gate.
Last updated 29 July 2026
1.Who we are, and who decides what
HAUS is property and building-access software operated by [TODO: registered company name], [TODO: registered office address] (registration [TODO: company registration number]). This policy is written against the Data Protection Act, 2019 (Kenya).
Two different relationships run through this product, and almost every question about your data depends on which one you are in.
- For the people who sign in (owners, managers and security staff with an account) we are the data controller. We decide what a login holds and how it is secured.
- For everything a customer puts into the system (the unit register, residents’ contact details, tenancy and rent records, and the visitor log) the management company or property owner using HAUS is the data controller and we are their data processor. They decide who is registered at their gate and what is asked for; we hold it for them and act on their instructions.
If you are a visitor or a resident and want your details corrected or removed, the fastest route is the management company that runs your building. They can act immediately. You can also write to us at [TODO: privacy@example.com] and we will pass the request to them and help them carry it out.
2.What we hold
| Category | What it is | Where it comes from |
|---|---|---|
| Account holders | Name, email address, role, the buildings or properties assigned to you, and a one-way hash of your password. Never the password itself. | Entered at registration, or by an owner on your account. |
| Units and residents | House number, unit details, and the name, email, phone, identity document type and number, and postal address of each unit's owner and lessee. | Entered by the management company from its unit schedule. |
| Visitors | Name, email, phone, nationality, identity document type and number, a photograph of that document, vehicle registration, who they are visiting, the unit, arrival and departure times, any curfew, and the note a guard writes. Each adult arriving together is recorded individually. Where a unit was already at its maximum and a manager admitted somebody anyway, the reason they gave and their name are recorded on the visit and kept with it. If a stay is extended, the date it replaced and who agreed to it are kept alongside the new one. | Taken at the gate at the moment of arrival, from the person and their document. |
| House-rule acknowledgements | Which pages were opened and when, how long each was on screen, the language chosen, the time of acceptance, and the IP address and browser the acceptance came from. | Recorded as the visitor reads the rules through the link emailed to them. |
| Access passes | For visitors whose stay warrants one: a card holding their name, the unit, the dates of the stay and a short reference, reached by a private link. No identity photograph is ever on it. Saving it to Apple Wallet or Google Wallet copies those same details onto your phone. Extending a stay moves the pass's expiry with it, and you are emailed when that happens. A pass can also be issued to somebody for the role they hold rather than for one visit: an owner, a tenant, a cleaner, a contractor or a member of the building's staff. Those hold the same details plus the email address and phone number the building was given for them, a note the building keeps for its own records, and the dates the pass runs between, which have no expiry at all for an owner or a host. The building can print any pass as a card to be worn, which carries the name, the role, the reference and the code and never a photograph. | Created from the visit above when the house rules are accepted, or issued by the building to a named person. |
| Tenancies and money | Leases, rent charges and payments, bills, staff records and wage payments for the customer's own portfolio. | Entered by the customer. |
| Operational records | A log of emails the system has sent, smart-lock events where a building has connected locks, and short-stay calendar availability imported from listing sites. | Generated by the system, or fetched from the services in section 6. |
3.Why we hold it
Under section 30 of the Data Protection Act, 2019 (Kenya) personal data needs a lawful basis. Ours are:
- Performance of a contract (running the account of the customer who signed up, and holding the records they put into it.
- Legitimate interests of the building is knowing who is inside it. A residential block records arrivals so that a resident, an owner and, if it comes to it, the police can establish who was on the premises and when. The interest is the safety of the people living there; the balancing act is why the identity photograph has a short life (section 5) and why children are counted but never photographed (section 11).
- Compliance with a legal obligation applies where a building is required by law, by its lease or by a regulator to keep an access register.
- Consent: where a customer asks for something optional, such as connecting a smart lock or a listing calendar.
We do not sell personal data, we do not share it for advertising, and we do not use it to train anyone’s models. See section 7.
4.What a visitor is told at the gate
The management company operating the gate is responsible for telling people what is being recorded before it is recorded. In practice, a notice at the barrier and the guard saying so. The system supports this by emailing every visitor with an address the building’s house rules to read and accept, and that email is also where a link to this policy belongs.
If you were signed in and shown nothing, that is a failure by the building rather than a feature of the software, and it is worth raising with them or with us.
5.Identity photographs
A photograph of an identity document is the most sensitive thing this system holds, and it is treated differently from everything else in it.
- It is discarded 7 days after the visit is closed at the gate. An automated sweep runs every night and deletes the image from the record. The written details (that a document of that type and number was seen, and when) remain, because that is the register. Where a visit is never signed out at the gate, the photograph stays until it is; a building that leaves visits open is holding documents it said it would discard, and closing them is the fix.
- It is never included in an export. The access log can be downloaded as a spreadsheet by a manager or an owner. It carries names, document numbers and times; it never carries images, and it states for each person whether a photograph is still held.
- It is never listed, only fetched. Images are excluded from every list and search in the product. Viewing one is a separate, individually authorised request that is checked against the viewer’s account and their assigned buildings, and is marked so that no browser stores a copy.
- Every adult in a group is recorded individually. Where two or more adults arrive together, each is named against their own document rather than being counted under someone else’s. Children are counted and never photographed.
6.Who else processes it
We use the following processors. Each holds data only to provide the service described, under contract, and none of them is permitted to use it for their own purposes.
| Service | What it does | What reaches it |
|---|---|---|
| MongoDB Atlas | The database. | Everything in section 2, encrypted at rest. |
| Vercel | Application hosting. | Requests in transit, and the technical logs a web host keeps. |
| Apple Wallet / Google Wallet | Only if you choose to add your access pass to your phone's wallet. | The details printed on the pass (your name, the unit, the dates) pass through Apple or Google to reach your phone. Nothing is sent unless you tap the button. |
| Mailchimp Transactional (Mandrill), with Postmark as fallback | Sends the house-rules invitation, the notice to a unit owner that a visitor has arrived, and the account's reminders. | Recipient name and address, and the contents of that message. |
| Anthropic (Claude) | Reads an uploaded house-rules document and rewrites it in plain language; translates it into a visitor's language; and, at the gate, transcribes a photographed identity document into the check-in form so a guard does not have to type it. | The house-rules document, and, for the transcription only, the photograph of the identity document. See section 7. |
| Tuya | Smart-lock events, where a building has connected locks. | Lock and door identifiers and event times. |
| Listing sites (Airbnb and similar), by calendar link | Imports which dates a short-stay unit is already booked. | Nothing personal leaves; only dates are read in. |
7.Automated processing and AI
Three features send data to Anthropic’s Claude API: simplifying a house-rules document, translating it, and transcribing a photographed identity document at check-in. Anthropic processes that data to return a result and does not use API inputs or outputs to train its models.
None of it decides anything. A transcription is a draft of a form. The guard checks it against the document in their hand and what they confirm is what is stored, because at a barrier the person holding the passport is the authority, not the model. A simplified or translated set of house rules is a reading aid; the uploaded document remains the rules. Nothing in this product produces a decision with legal effect on you by automated means within the meaning of section 35 of the Data Protection Act, 2019 (Kenya).
Where the transcription service is unavailable, check-in continues with the guard typing the details in. It is never a condition of being admitted.
8.Transfers outside Kenya
The processors in section 6 operate infrastructure outside Kenya, so personal data is transferred out of the country. Under sections 48 and 49 of the Data Protection Act, 2019 (Kenya) we rely on the transfer being necessary for the performance of the contract with the customer, together with the contractual safeguards each processor is bound by.
A customer with a requirement to keep data in a particular jurisdiction should raise it before signing up, not after. It is a hosting decision and cannot be made per record.
9.How long things are kept
| What | Kept for | Then |
|---|---|---|
| Identity photographs | 7 days after check-out | Deleted automatically. The visit record remains, marked to show the photograph was taken and has since been discarded. |
| The visitor register (names, documents, times, notes) | As long as the building needs it, decided by the management company as controller | Deleted on their instruction, or when their account is closed. |
| House-rule acknowledgements | Kept with the visit they belong to | They are the evidence that a person was shown the rules and accepted them, and outliving the photograph is the point of them. |
| Access passes | Kept with the visit they belong to, or until the building withdraws them | The pass stops admitting anyone the moment the visit is closed, the stay ends, the dates run out, or the building withdraws it. A pass issued for a role ends only when its dates run out or somebody withdraws it, which the building can do at any time and which takes effect immediately, including for a card already printed. It shows its own status rather than being deleted, and a withdrawal is kept with the reason given and who gave it. A copy saved to a phone wallet is yours to delete. |
| Unit, tenancy and financial records | For the life of the account, and any period the customer must keep them for tax or audit | Deleted with the account. |
| Account logins | Until the account is closed or the login removed | Deleted. |
| Backups | Up to 30 days after deletion | Overwritten on the ordinary backup cycle. |
10.Security
- Traffic is served over TLS, and passwords are stored only as bcrypt hashes.
- Every account is isolated from every other. Two management companies on the same installation cannot see any trace of each other.
- Inside one account, access is limited twice over: by the buildings a person is assigned, and by what their role is allowed to do. Security staff can register arrivals and sign people out, and cannot read the account's finances, change its settings, or download the register. A gate phone is shared, and it is treated as shared.
- Identity photographs are excluded from every list query and served only from a single authorised endpoint, uncacheable, one image per request.
- Requests for records outside your reach answer as though the record does not exist, so the system cannot be used to confirm that a guessed unit or building is real.
No system is beyond compromise. If a breach occurs that is likely to result in real risk, we will notify the Office of the Data Protection Commissioner (ODPC) within 72 hours of becoming aware of it, notify affected customers without undue delay, and support them in notifying the people affected.
11.Children
The product is not for use by children and no account may be created by one. Children arriving as part of a group are counted so that a unit’s occupancy is accurate, and are deliberately never photographed and never asked for a document. Holding an image of a child’s papers on a shared front-desk phone is a risk a building gains nothing from.
12.Cookies
One cookie: a signed session token, set when you sign in and cleared when you sign out. It is strictly necessary. Without it there is no way to stay signed in. Your light or dark theme preference is kept in your own browser and never sent to us.
There are no analytics, advertising or third-party tracking cookies anywhere in this product.
13.Your rights
Under the Data Protection Act, 2019 (Kenya) you have the right to be told how your data is used, to a copy of it, to have it corrected where it is inaccurate or misleading, to have it deleted where there is no lawful reason to keep it, to object to processing, and to be given it in a portable form.
To exercise any of them, contact the management company for the building concerned. They are the controller and can act on the record directly. If you cannot reach them, or you are asking about your own login, write to [TODO: privacy@example.com]. We will respond within 30 days.
You may also complain to the Office of the Data Protection Commissioner (ODPC) (https://www.odpc.go.ke). Our registration is [TODO: ODPC registration number, or 'registration pending'].
One limit worth stating plainly: a building’s access register is a safety record, and a request to erase the fact of a visit will usually be refused for as long as the building has a legitimate reason to keep it. That is not a refusal to engage. The reason will be given, and the identity photograph goes on its own schedule regardless.
14.Changes to this policy
Material changes will be notified to account holders by email before they take effect, and the date at the top of this page will change. Continuing to use HAUS after that date means the revised policy applies.
15.Contact
[TODO: registered company name]
[TODO: registered office address]
[TODO: privacy@example.com]
See also our terms of use.