Privacy Policy — Plazio
Effective date: 12 June 2026
This Privacy Policy explains how personal data is processed in connection with Plazio — a software service for residential complex management, comprising a mobile application for residents (the "App", app.plazio) and a web panel for management staff (the "Panel"), available at https://plazio.app (together, the "Service").
The Service is operated by the Plazio service operator ("we", "us", "Plazio"). Plazio is currently operated by a private individual; the operator's full legal identity and contact details are disclosed on legitimate request — for example, to data subjects exercising their rights or to competent authorities — via the contact below.
Contact for any privacy question or request: [email protected].
1. Who controls your data
Plazio is a multi-tenant platform used by property management companies and building managers (each a "Management Company") to manage their residential complexes and communicate with residents.
- Resident community data (resident name, phone, e-mail, apartment/block, dues status and history, building documents and photos, announcements, tasks) is controlled by the Management Company that operates your residential complex. Plazio acts as a data processor on its behalf, under a data processing agreement. For requests about this data, contact your Management Company; you may also write to us and we will forward or assist.
- Management staff accounts (the Panel users) are controlled by Plazio. We are the controller for these accounts.
- App technical data strictly needed to run and secure the App (push notification token, device identifier, platform, sign-in/security logs) is controlled by Plazio to the extent necessary to operate the App.
Where this Policy says "we process", read it together with the roles above.
2. What data we process
Residents (App):
- Identity & contact: name, phone number, e-mail (optional), preferred language, resident role (owner/tenant), apartment and block.
- Access: multi-use invite code, invitation and last-login timestamps.
- Device & notifications: push notification token (Expo), device identifier, OS platform (iOS/Android), last-seen time.
- Community content you submit or that concerns you: dues (aidat) status, amounts, payment reference, manager notes; task comments/photos where applicable; read-receipts for announcements.
Management staff (Panel):
- E-mail, password (stored only as a secure hash), name, phone, language, role, complex assignment, password-reset token, account timestamps.
Uploaded content (by managers):
- Building photos, PDF documents, complex payment details (e.g. IBAN), administration contacts, and bank statement files (CSV/Excel) uploaded to reconcile dues. These files may contain payer references and amounts.
We do NOT collect: resident payment card data or online-payment credentials. The App does not connect to your bank and does not read your accounts; the dues feature only lets you copy a payment reference and open your own banking app.
3. Why we process it (purposes and legal bases)
| Purpose | Legal basis (GDPR / KVKK / 152-FZ) |
|---|---|
| Provide the Service: accounts, login, showing your apartment, dues, announcements, documents | Performance of a contract; for resident data — processing necessary to deliver the Management Company's service |
| Send push and e-mail notifications (announcements, dues reminders, invites, password reset) | Performance of contract / legitimate interest; consent for push where required by the OS |
| Translate announcement text across languages | Legitimate interest in a multilingual service |
| Security, fraud and abuse prevention, rate-limiting, logs | Legitimate interest; legal obligation |
| Comply with legal obligations and respond to lawful requests | Legal obligation |
For EU/EEA users, bases are GDPR Art. 6(1)(a) consent, (b) contract, (c) legal obligation, (f) legitimate interests. For users in Türkiye, bases are KVKK Art. 5 (contractual necessity, legitimate interest, legal obligation, and explicit consent where applicable). For data of Russian citizens, processing is based on consent and contract under Federal Law No. 152-FZ.
4. Who we share data with (sub-processors and recipients)
We do not sell personal data. We share it only with service providers that help us run the Service, and only as needed:
| Recipient | Purpose | Data shared |
|---|---|---|
| Expo (Expo Push Notification Service) | Deliver push notifications | Push token, notification content |
| Google Firebase Cloud Messaging (FCM) | Push delivery on Android | Push token, notification payload |
| Apple Push Notification service (APNs) | Push delivery on iOS | Push token, notification payload |
| DeepL SE (Germany) | Machine translation of announcement text | Announcement text |
| Resend | Sending transactional e-mail | E-mail address, message content |
| Hetzner (Germany) | Hosting database and files | All stored data, as host |
We may also disclose data to competent authorities where required by law, and to a successor in the event of a reorganisation, subject to this Policy.
5. International data transfers
Our servers are located in Germany, and some sub-processors (Expo, Google, Apple, DeepL) process data in other countries, including the EU and the United States. This means your data may be transferred across borders, including outside Türkiye, the EU/EEA and the Russian Federation.
Such transfers are carried out on the basis of your explicit consent and/or because the transfer is necessary to perform the contract with you or the Management Company, and — for EU/EEA personal data — under appropriate safeguards such as Standard Contractual Clauses where applicable.
6. Retention
We keep personal data while the related account is active and the Management Company uses the Service, and afterwards only as long as needed for the purposes above or as required by law (e.g. accounting, dispute resolution). When data is no longer needed, we delete or anonymise it. See Data Deletion for how to request earlier deletion.
7. Your rights
Depending on where you live, you have rights to: access your data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and to withdraw consent at any time (without affecting prior processing). Users in Türkiye have the rights set out in KVKK Art. 11; users in the EU/EEA have the rights under GDPR Arts. 15–22; users in Russia have the rights under 152-FZ.
To exercise rights, contact [email protected] or, for resident community data, your Management Company. We respond within the period required by applicable law. You also have the right to lodge a complaint with your data protection authority (in Türkiye: KVKK / Kişisel Verileri Koruma Kurumu; in the EU: your local DPA; in Russia: Roskomnadzor).
8. Security
We apply technical and organisational measures including: encryption in transit (TLS); passwords stored only as salted hashes; token-based authentication (JWT) and signed, time-limited links for file downloads; strict tenant isolation so data of different complexes is not mixed; access controls by role; rate-limiting and brute-force protection on login; and files never served directly by the web server. No system is perfectly secure, but we work to protect your data.
9. Children
The Service is intended for adults (apartment owners, tenants and management staff) and is not directed at children under 16. Management Companies must not register minors as users. If you believe a child's data was provided, contact us and we will remove it.
10. Changes
We may update this Policy. We will post the new version at this URL and update the effective date; for material changes we will provide reasonable notice in the App or Panel.
11. Contact
Plazio — [email protected]