Privacy

Privacy Policy

How 2doors collects, uses and protects your personal data, and how you can exercise your rights under the GDPR.

Last updated:

This Privacy Policy explains how 2doors (“2doors”, “we”) processes personal data when you visit our website, create an account, use our property-management application, or interact with us in other ways. It applies alongside our Terms of Service.

We follow the EU General Data Protection Regulation (Regulation 2016/679, “GDPR”) and Czech Act No. 110/2019 Coll. on Personal Data Processing.

#1. Who is the controller

2doors is the controller of the personal data described in this Policy for our own users (landlords, property managers and tenants using their portal). For the personal data landlords upload about their tenants, guarantors or contractors, the landlord is the controller and 2doors acts as a processor under a data processing agreement.

For privacy matters, contact us at [email protected].

#2. What data we collect

We collect the following categories of data:

  • Account data — name, email, phone number, password hash, role, language and timezone.
  • Property and lease data — property details, unit information, lease terms, rent amount, deposits, expenses.
  • Tenant records — names, contact details, tenancy dates and communications. Landlords upload this data as controllers.
  • Financial data — invoices, payment records, transaction identifiers. Card and bank details are handled by our payment processor and are not stored on 2doors servers.
  • Communications — support tickets, in-app messages, email correspondence and their metadata.
  • Technical data — IP address, device and browser information, log data, cookies and similar identifiers, product usage events.
  • AI interaction data — prompts and responses when you use AI features, so we can deliver, monitor and improve those features.

#3. How and why we use your data

We use personal data for the following purposes:

  • To create and administer your Account and provide the Service (GDPR Art. 6(1)(b) — performance of a contract).
  • To take payments, issue invoices and prevent fraud (Art. 6(1)(b) and 6(1)(f) — legitimate interest in preventing fraud).
  • To keep records required by tax, accounting and other laws (Art. 6(1)(c) — legal obligation).
  • To secure the Service, investigate abuse and enforce our Terms (Art. 6(1)(f)).
  • To improve the Service, including anonymised analytics, feature research and model quality checks (Art. 6(1)(f), with the ability to object).
  • To send transactional messages about your Account (Art. 6(1)(b)) and, with your consent or where permitted by law, product news and marketing (Art. 6(1)(a) / 6(1)(f)).

#4. AI processing

When you use AI features, the prompts you submit and the relevant records may be sent to large language model providers acting as our processors under contractual safeguards. We do not permit them to use your data to train their public models. AI outputs may contain errors and should not be treated as legal, tax or financial advice.

We do not make decisions that produce legal or similarly significant effects about you solely by automated means.

#5. Who we share data with

We share personal data with the following categories of recipients, all of whom act as processors under contractual protections unless noted:

  • Cloud infrastructure and hosting — for storage, compute and backup.
  • Payment processors — for rent collection and subscription billing.
  • AI model providers — for AI features you use.
  • Email, SMS and notification providers — for transactional messages.
  • Analytics and error monitoring — to keep the Service reliable.
  • Professional advisers — auditors, lawyers or accountants under duties of confidentiality.
  • Authorities — tax authorities, courts or regulators, where required by law or to protect our rights.
  • Successors — if 2doors is involved in a merger, acquisition or asset sale, subject to this Policy.

#6. International data transfers

Where personal data is transferred outside the European Economic Area, we rely on adequacy decisions of the European Commission or on the EU Standard Contractual Clauses together with supplementary safeguards where appropriate.

#7. How long we keep data

We keep personal data only as long as necessary for the purposes described in this Policy:

  • Account and profile data — for the life of your Account, then up to 90 days after closure.
  • Property, lease and tenant records — controlled by the landlord; deleted when they delete them, subject to legal retention.
  • Invoicing, accounting and tax records — up to 10 years to satisfy Czech tax and accounting law.
  • Support communications — up to 3 years from resolution.
  • Security logs — typically 12 months.

#8. Your rights

You have the right to (a) access your data, (b) correct inaccurate data, (c) request erasure, (d) restrict or object to processing, (e) receive your data in a portable format, (f) withdraw consent where processing is based on consent, and (g) lodge a complaint with a supervisory authority.

To exercise your rights, email [email protected]. In the Czech Republic, the supervisory authority is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz). If your data was uploaded by a landlord, please contact them first — they are the controller of that data.

#9. Cookies and similar technologies

We use cookies and similar technologies for three purposes: strictly necessary (to sign you in and keep the Service secure), preferences (to remember your language and theme), and analytics (aggregated usage data to improve the product). Non-essential cookies are only set with your consent, and you can withdraw consent at any time from the cookie settings.

#10. Security

We apply industry-standard technical and organisational measures, including encryption in transit, encryption of backups, access controls, audit logging, hardened infrastructure and regular reviews. No system is perfectly secure; if we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and, where required, the supervisory authority.

#11. Children

The Service is not directed at children under 18 and we do not knowingly collect data from them. If you believe a child has provided us with personal data, please contact us so we can delete it.

#12. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will notify you in the Service or by email at least 14 days before they take effect.

Contact us

For questions about privacy, or to exercise your GDPR rights, email [email protected].

This Policy is provided for transparency. It complements — and is not a substitute for — the notices, consents and data processing agreements you may receive when using specific features.