Privacy Policy
DoorLink ("we", "us", "our") is a real-time video communication platform for visitor management and household connectivity, operated by DigitalAlerts B.V., registered in the Netherlands.
This Privacy Policy describes how we collect, use, store, and protect your personal information when you use the DoorLink mobile application ("App"), the DoorLink visitor web application, and related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information as described in this policy.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (required for authentication)
- Password (stored as a cryptographic hash, never in plaintext)
- Display name
- Phone number (optional)
- Profile photo (optional)
1.2 Device Information
To deliver push notifications and enable core functionality, we collect:
- Push notification tokens issued by your device platform's push notification service, including VoIP call tokens
- Device type, platform (iOS or Android), and operating system version
- Device identifiers used solely for push notification delivery
1.3 NFC and BLE Device Data
If you register hardware devices with your household:
- NFC tag unique identifiers (UID) and read counters
- BLE beacon identifiers (UUID, major, minor)
These identifiers are used solely to associate physical devices with your household for visitor verification.
1.4 Call and Communication Data
- Call initiation and completion timestamps
- Call duration and status (answered, rejected, missed, timed out)
- Visitor names (provided by the visitor)
- Text messages left by visitors
- Audio and video messages (when the feature is used)
1.5 Technical and Usage Data
- IP address (used for rate limiting, security, and abuse prevention)
- API request metadata (route, method, timestamp) for audit logging
- Authentication session data (token issuance and expiry)
1.6 Visitor Data
Visitors who use the web application to initiate calls are not required to create an account. We collect only the name they voluntarily provide and their IP address for rate limiting. Visitor video and audio streams are transmitted in real time and are not recorded or stored by DoorLink.
2. How We Use Your Information
We use the information we collect exclusively to provide and improve the Service:
- Authenticate your identity and maintain your session
- Deliver push notifications for incoming visitor calls
- Enable real-time video and audio communication between visitors and household members
- Display call history and visitor messages
- Register and verify NFC tags and BLE beacons
- Manage household memberships and settings
- Send transactional emails (account verification, password reset)
- Prevent abuse, enforce rate limits, and maintain security
Legal Basis for Processing
Under the GDPR, we rely on the following grounds:
- Performance of a contract (Art. 6(1)(b)) — creating and authenticating your account, connecting calls between visitors and household members, delivering the notifications that make those calls reach you, managing household memberships, and storing visitor messages. Without this processing we cannot provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — keeping the Service secure and available: rate limiting, abuse prevention, security audit logging, and diagnosing crashes in the app. Our interest is in operating a reliable and secure service; we have weighed this against your rights and limit the data used to what those purposes require.
- Consent (Art. 6(1)(a)) — access to your camera and microphone, and the optional details you choose to add such as a phone number or profile photo. You can withdraw consent at any time, in your device settings or by removing the detail.
- Legal obligation (Art. 6(1)(c)) — where we must retain certain records to comply with the law.
We do NOT use your data for: advertising, ad targeting, selling to third parties, behavioral profiling, cross-app tracking, or any purpose unrelated to the Service.
3. Third-Party Services
We keep the number of third parties involved in the Service to a minimum. The real-time video and audio at the heart of DoorLink is carried by our own servers, which we operate ourselves in the European Union — no outside company receives your calls, your call media, or the metadata describing them.
For the functions we cannot perform on our own infrastructure, we rely on the following categories of processors. We share only the data each function actually requires, and only for that function:
| Service | Purpose | Data Shared |
|---|---|---|
| Push notification services of the iOS and Android platforms | Delivering incoming-call and visitor alerts to your device, including VoIP calls | Device push tokens and the contents of the notification |
| Transactional email provider (European Union) | Sending account verification and password reset emails | Email address, email content |
| Mobile error and crash diagnostics provider (European Union) | Diagnosing crashes and errors in the mobile app | Error messages and stack traces, device model, operating system and app version, and the device IP address. Account identifiers, authentication tokens and household identifiers are removed before transmission. |
| Cloud infrastructure provider (European Union, Amsterdam) | Hosting our servers, database, and media storage | Acts as a hosting processor for the data described in this policy; does not use it for any purpose of its own |
We do not share your personal data with any other third parties, data brokers, or advertisers. If you need the identity of a specific processor — for example to exercise your rights or to complete your own compliance review — contact us at privacy@doorlink.io and we will tell you.
4. Data Storage and Security
- All data is transmitted over encrypted connections (HTTPS/TLS)
- Passwords are cryptographically hashed using bcrypt before storage
- Authentication tokens are stored as SHA-256 hashes in the database
- Access tokens expire after 1 hour; refresh tokens expire after 7 days
- Visitor session tokens expire after 5 minutes
- Mobile app authentication tokens are stored in encrypted storage on the device
- Database connections use SSL/TLS encryption with certificate verification
- NFC verification uses AES-128 encryption and AES-CMAC authentication
- The API enforces rate limiting to prevent brute-force attacks
- Infrastructure is protected by firewall rules and key-only administrative access; password-based remote login is disabled
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Retained while your account is active |
| Call history | 90 days |
| Visitor messages (text, audio, video) | 90 days |
| Push notification tokens | Deactivated on logout; removed after 90 days of inactivity |
| Audit and security logs | 90 days |
| Video and audio streams | Not stored — transmitted in real time only |
These periods are enforced automatically. A job on our servers runs daily and permanently deletes every record past its retention period — call history, visitor sessions and messages, notification records, NFC tap events, audit logs, and push notification tokens that have gone unused. The audio and video files that visitor messages point at are stored in a bucket whose own 90-day expiry rule removes them on the same schedule, so the record and the file it refers to disappear together.
When you delete your account, we permanently remove your personal data in accordance with Section 7.
6. Camera and Microphone Usage
DoorLink requests access to your device's camera and microphone solely for the purpose of real-time video and audio calls with visitors. These permissions are requested at the time of use and can be revoked at any time through your device's system settings.
Video and audio streams are carried in real time over encrypted WebRTC connections, relayed only by our own media servers in the European Union, and are not recorded, stored, or analyzed by DoorLink.
7. Your Rights
Under applicable data protection laws (including the GDPR), you have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Correct any inaccurate or incomplete personal data
- Erasure — Delete your account and all associated personal data
- Data Portability — Request your data in a structured, machine-readable format
- Restriction — Restrict the processing of your personal data in certain circumstances
- Objection — Object to the processing of your personal data
- Withdraw Consent — Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at privacy@doorlink.io. We will respond within 30 days.
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with a supervisory authority — in our case the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl), or the authority in the EU country where you live.
Account Deletion
You can delete your account directly from within the DoorLink mobile app. Open Settings — the same screen where you log out — and tap Delete Account. You will be asked to confirm with your account password, after which we revoke all active sessions, deactivate your household memberships, delete your registered device credentials, and remove your personal data — your name, phone number, profile photo, password, and your email address, which is replaced with a non-identifying placeholder. What remains is an anonymous record that an account was closed and when. This action cannot be undone.
Alternatively, you can request deletion of your account at any time by emailing privacy@doorlink.io from the email address associated with your account, using the subject line "Account Deletion Request". To protect your account, we may ask you to verify your identity before we process the request.
Once your request is verified, we permanently delete your account and associated personal data, revoke all active sessions, and deactivate your household memberships. We complete deletion requests within 30 days. This action cannot be undone. Certain records may be retained where required for legal, security, or audit purposes — these follow the same 90-day limit set out in Section 5, Data Retention.
8. International Data Transfers
Our servers, our database, and our media storage are located in the European Union (Amsterdam, Netherlands). If you access the Service from outside the EU, your data may be transferred to and processed in the EU.
One function necessarily reaches beyond the EEA: to make your phone ring, a push notification must pass through the push notification service of your device's platform, and the providers of those platforms are established outside the EEA. Those transfers are limited to your device push token and the contents of the notification, and rely on the safeguards permitted under Chapter V of the GDPR — an adequacy decision, or the European Commission's Standard Contractual Clauses. We ensure that all transfers comply with applicable data protection laws, including the GDPR.
9. Children's Privacy
DoorLink is not intended for use by children under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that information promptly.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify you through the App or via email for significant changes
- Provide a summary of key changes
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: privacy@doorlink.io
- General Support: support@doorlink.io
- Company: DigitalAlerts B.V., The Netherlands