Privacy Policy and Data Protection
Last updated: 12 August 2026
1. Who we are
Porter's Desk is a concierge desk management tool provided to residential buildings. Each building has its own private account and only its authorised staff can access its data.
2. What data we process
To run a building's concierge desk we process the following personal data:
- Resident names and flat or apartment numbers.
- Resident email addresses, where provided.
- Parcel records: courier, item description, dates, and who collected the parcel.
- Key movement records: who signed keys in or out, and when.
- Handwritten signatures captured on the signing pad when collecting parcels or signing keys in and out.
- Housekeeper names and schedules.
- Building staff and concierge names.
- Building contact details, such as contact name, email, phone, and address, provided by the building.
3. Why we process it
We process this data to provide the concierge desk service to the building. This is done on the basis of our legitimate interests and the performance of our service contract with the building. Where resident notification emails about parcels are sent, they are sent on behalf of the building to keep residents informed.
4. Data controller and processor
The building or property management company is the data controller for its residents' personal data. Porter's Desk acts as a data processor, handling that data on the building's instructions and only for the purpose of providing the service.
5. Data separation between buildings
Each building's data is fully isolated from every other building. This separation is enforced at the database level, so one building cannot access another building's residents, parcels, keys, signatures, or staff records.
6. Where data is stored
Data is hosted using Supabase Postgres infrastructure. Transactional emails are sent via Resend. We use reputable third-party processors and do not sell or share personal data for marketing purposes.
7. Retention
Records such as parcels, keys, and signatures are retained while the building uses the service and for a reasonable period afterwards to allow for queries and audit. A building can request deletion of its data, and data is removed when a building account is closed.
8. Resident rights
Residents can exercise their data rights, including access, correction, and erasure, by contacting their building. As data controller, the building will action the request and Porter's Desk will assist as processor.
9. Security
Access is controlled per building and data is transmitted over HTTPS. Signatures and records are only visible to that building's authorised staff. API keys and other secrets are stored securely server-side and are not exposed in the application code.
10. Contact
For privacy questions, please contact Mlaye915@gmail.com.