Alzette One
Alzette One app privacy
Last updated: 27 September 2026
What data the app uses, why, who we share it with and how to exercise your rights.
Alzette One help · [email protected] · [email protected]
Alzette sàrl, 3, Côte d’Eich, L-1450 Luxembourg, RCS Luxembourg B308795, the property manager (syndic) of your building, is the controller for data processed in the Alzette One app (iOS and Android).
For any question about your data: [email protected]. The alzette.lu website has its own privacy policy.
The app has no advertising, no analytics and no tracking across apps or websites, and we do not sell your data. Depending on your role, it uses:
- Identity and contact: name, email, phone, language.
- Your link to the building: building, unit and role (owner, resident, owners’ council).
- Sign-in: one-time sign-in codes, sessions per device (model, dates of use), IP address.
- Building records: documents, meeting notices, proxies, statements and balances.
- Your requests: descriptions, messages, photos and attached files.
- Tenants: if you declare a tenant, their name, contact details and lease dates.
- Signatures: the device’s public key, the signed text, the signature, date and IP address.
- Notifications: notification token, language and app version.
- Giving you access to your building and securing your account: performance of the service (Art. 6(1)(b) GDPR) and our legitimate interest in security (Art. 6(1)(f)).
- Managing the co-ownership (documents, general meetings, accounts): the management mandate and legal obligations (Art. 6(1)(b) and 6(1)(c)).
- Handling and answering your requests: performance of the service and our legitimate interest in maintaining the building.
- Keeping proof of a signature or an electronic meeting notice: legal obligations and our legitimate interest in establishing proof.
- Lease analysis: your consent (Art. 6(1)(a)), which you can withdraw at any time.
When you sign a proxy, revoke one or agree to electronic meeting notices, your phone checks your face or fingerprint. That check stays on the device: we receive no biometric data.
The signing key is created in the phone’s secure chip and never leaves it. We receive the public key and the signature, which lets anyone verify the act. This proof is not deleted on request while it may be needed to establish an act of the co-ownership.
Lease analysis: if you tap “Analyze lease” and agree, the lease text is read on your phone and then sent to OpenAI to prefill the form. Without that action, nothing is sent. Always check the result; you can enter everything by hand.
Replies to your requests: for each request, OpenAI prepares a draft reply for the Alzette team from your name, the building and the text of the conversation. Attachments are not sent. A team member reads, edits and decides; no decision is made automatically.
A notification contains only a generic sentence, such as “A reply to your request is available.” The details stay in the app. You can turn notifications off in your phone’s settings.
Photos taken in the app are saved again without their metadata, including location. Files you pick from your documents are sent as they are. Every file is scanned for malware before it is accepted.
- The Alzette team, as far as they need it to manage your building.
- Other residents do not see your requests. Co-ownership documents are shared with the people entitled to them.
- Contractors working in the building receive what the job requires (description, access, contact).
- Our service providers, acting on our instructions: Hetzner (hosting), Cloudflare (file storage, email delivery, network), Open-Xchange (email), Twilio (SMS), Apple and Google (notifications), OpenAI (the features in section 5).
- Authorities, lawyers, bailiffs or insurers, only when the law or a case requires it.
Cloudflare, Twilio, Apple, Google and OpenAI are US companies and may access data from the United States. These transfers rely on the EU–US Data Privacy Framework or on the European Commission’s standard contractual clauses. You can ask for a copy at [email protected].
- Account: as long as you have access to a building. A session expires after 30 days without use, and after 90 days at most.
- Accounting records and statements: 10 years, as required by law.
- Co-ownership documents, minutes and proof of signatures or meeting notices: as long as they serve management or proof.
- Requests and messages: for the life of the case, then as long as a warranty, insurance claim or dispute requires.
- Backups: deleted on rotation, after about 6 months at most.
In the app: Account, then “Request account deletion”. You can also write to [email protected].
We check your identity before handling the request; your access stays active during the review, and you follow the answer in the app. Records the law requires us to keep, such as accounting documents and signature proof, are retained; we tell you which ones.
You can ask to access, correct, erase, restrict or port your data, object to processing based on our legitimate interest, and withdraw your consent. Write to [email protected]; we reply within one month.
You can also complain to Luxembourg’s data protection authority, the CNPD, 15, Boulevard du Jazz, L-4370 Belvaux, cnpd.public.lu.
We update this page when the app or our providers change. If something important changes, we tell you in the app.
