Porter’s Desk

Privacy Policy and Data Protection

Last updated: 12 August 2026

1. Who we are

Porter's Desk is a concierge desk management tool provided to residential buildings. Each building has its own private account and only its authorised staff can access its data.

2. What data we process

To run a building's concierge desk we process the following personal data:

  • Resident names and flat or apartment numbers.
  • Resident email addresses, where provided.
  • Parcel records: courier, item description, dates, and who collected the parcel.
  • Key movement records: who signed keys in or out, and when.
  • Handwritten signatures captured on the signing pad when collecting parcels or signing keys in and out.
  • Housekeeper names and schedules.
  • Building staff and concierge names.
  • Building contact details, such as contact name, email, phone, and address, provided by the building.

3. Why we process it

We process this data to provide the concierge desk service to the building. This is done on the basis of our legitimate interests and the performance of our service contract with the building. Where resident notification emails about parcels are sent, they are sent on behalf of the building to keep residents informed.

4. Data controller and processor

The building or property management company is the data controller for its residents' personal data. Porter's Desk acts as a data processor, handling that data on the building's instructions and only for the purpose of providing the service.

5. Data separation between buildings

Each building's data is fully isolated from every other building. This separation is enforced at the database level, so one building cannot access another building's residents, parcels, keys, signatures, or staff records.

6. Where data is stored

Data is hosted using Supabase Postgres infrastructure. Transactional emails are sent via Resend. We use reputable third-party processors and do not sell or share personal data for marketing purposes.

7. Retention

Records such as parcels, keys, and signatures are retained while the building uses the service and for a reasonable period afterwards to allow for queries and audit. A building can request deletion of its data, and data is removed when a building account is closed.

8. Resident rights

Residents can exercise their data rights, including access, correction, and erasure, by contacting their building. As data controller, the building will action the request and Porter's Desk will assist as processor.

9. Security

Access is controlled per building and data is transmitted over HTTPS. Signatures and records are only visible to that building's authorised staff. API keys and other secrets are stored securely server-side and are not exposed in the application code.

10. Contact

For privacy questions, please contact Mlaye915@gmail.com.