Privacy Policy
Last updated: April 2026
1. Who we are
Aedile Table B ("we", "us", "our") is a communal fee management platform for apartment buildings. We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable local data protection laws.
2. Data we collect
We collect and process the following personal data:
- Account information: Full name, email address, phone number, preferred language
- Building data: Property addresses, unit areas, ownership/tenancy records
- Financial data: Communal fee charges, payment records, bank IBAN (for payment instructions only)
- Communications: Messages sent through the in-app messaging system
- Uploaded documents: Building insurance, contracts, verification documents
- Usage data: Login timestamps, actions performed (via audit log)
3. Legal basis for processing
We process your data under the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR) — to provide the communal fee management service
- Legal obligation (Art. 6(1)(c) GDPR) — to comply with financial record-keeping requirements
- Legitimate interest (Art. 6(1)(f) GDPR) — for platform security, fraud prevention, and service improvement
- Consent (Art. 6(1)(a) GDPR) — for optional email notifications and analytics cookies
4. How we use your data
- Calculate and distribute communal fee shares based on property areas
- Generate PDF statements and financial reports
- Send transactional emails (charge notifications, payment reminders, account verification)
- Provide in-app messaging between building members and committees
- Maintain an audit trail of financial actions for accountability
5. Data sharing
We share personal data only with:
- Building committees: Committee members see owner/renter data for units in their building
- Service providers: Only if you submit a quote or are assigned to a job
- Infrastructure providers: Vercel (hosting), Resend (email delivery), Vercel Blob (file storage) — all GDPR-compliant, with data processing agreements in place
We do not sell your personal data to any third party.
6. Data retention
- Account data: Retained while your account is active, plus 6 months after deletion request
- Financial records: Retained for 7 years as required by EU financial regulations
- Audit logs: Retained for 3 years
- Messages: Retained while the related building account is active
7. Your rights
Under GDPR, you have the right to:
- Access your personal data — use the data export feature at
/api/me/export - Rectification — update your profile information at any time
- Erasure — request account deletion by contacting us
- Portability — download your data in JSON format via the export feature
- Object — opt out of non-essential communications
- Restrict processing — contact us to limit how we use your data
8. Cookies
We use the following cookies:
- Essential: Session authentication cookie (required for the platform to function)
- Analytics: Only with your consent — used to understand how the platform is used
You can manage cookie preferences via the banner shown on your first visit.
9. Security
We protect your data with encryption in transit (TLS), hashed passwords (bcrypt), role-based access controls, rate limiting, and comprehensive audit logging.
10. Contact
For privacy-related inquiries or to exercise your rights, contact us at: privacy@aedile.io