Privacy Policy
Last updated: July 2026
Siedla ("we", "us", "our") is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the Austrian Data Protection Act (DSG). This policy explains what data we collect, on what legal basis, how long we keep it, and the rights you have over it.
1. Data Controller
The data controller within the meaning of Art. 4(7) GDPR for the operation of the Siedla platform (accounts, sign-in, platform security) is the operator of Siedla; contact details are provided in the “Contact & Complaints” section below and in the imprint linked from the site footer. Where a community or its property management enters or imports data about residents, owners or units (for example unit registers, land-register extracts or imported correspondence), that community or property management is responsible for this data under data protection law and Siedla processes it on their behalf.
2. Data We Collect
- Account data: Email address (required for sign-in via magic link or one-time login code), first name, last name, phone number (optional; verified via SMS code if provided), display preferences (locale, theme), and notification preferences.
- Community data: Community memberships, unit/apartment information, member role (homeowner, tenant, property manager), and — where a community uses the cost features — bank account details (IBAN and account holder) entered for refunds and payments.
- Data entered by communities: Property managers and community admins may enter or import data about owners, tenants, and units — for example from land-register extracts or correspondence — including data about persons who do not have a Siedla account. The community or property management entering this data is responsible for its lawfulness; Siedla processes it on their behalf.
- Content data: Conversations and comments you create, proposals you author, votes you cast, announcements you publish, contact messages you send, documents you upload, and meeting participation records.
- Technical data: IP address, browser user agent, session tokens, request timestamps, and requested URLs. These are processed for security, abuse prevention, rate limiting, and request routing; IP address, user agent, and the requested URL also appear in our infrastructure provider's (Cloudflare) request logs, which are retained for a limited period and not used for tracking. Some URLs embed access tokens - for example calendar-subscription feeds and invitation links - which therefore also appear in these logs. No tracking cookies or analytics scripts are used.
- File uploads: Images (JPEG, PNG, GIF, WebP) and PDF documents, stored in Cloudflare R2. Size limits depend on the feature: 5 MB per image attachment and up to 50 MB per document.
3. Purpose & Legal Basis
- Contract performance (Art. 6(1)(b) GDPR): Providing the community platform, including sign-in, membership management, conversations, proposals, voting, announcements, contact messaging, meetings, cost management, documents, and maintenance features.
- Legitimate interest (Art. 6(1)(f) GDPR): Security and abuse-prevention logging by our infrastructure provider (Cloudflare), rate limiting to prevent abuse, audit trail for community governance transparency.
- Consent (Art. 6(1)(a) GDPR): Optional features you actively enable — for example connecting a Gmail account for the email import, adding an optional phone number, or enabling SMS and push notifications. You may withdraw consent at any time with effect for the future (for example by disconnecting the integration or disabling the notification channel) without affecting the lawfulness of processing carried out before the withdrawal.
- Legal obligation (Art. 6(1)(c) GDPR): Retention of records where Austrian or EU law requires it, and handling of data subject requests.
4. Data Retention
Your account data is retained for as long as your account is active. When you delete your account, your data enters a 30-day grace period during which you may cancel the deletion. After 30 days, your personal data is permanently deleted or anonymized. Activity log entries are retained for community governance and audit purposes; personal identifiers are removed once the account is deleted. Session data expires automatically. Data exports you request are available for download for 7 days and then deleted. Content you contributed to a community (such as conversations, comments, and votes) remains visible to that community after account deletion in anonymized form, attributed to a neutral placeholder instead of your name, because it forms part of the community's decision record. Where Austrian or EU law requires longer retention (for example, records that form part of a community resolution), the underlying record is kept in anonymized form for the duration of that statutory obligation.
5. Third-Party Processors
- Cloudflare, Inc. (Workers, D1, R2, Queues, Vectorize, Workers AI, Access, Email Service): Infrastructure hosting, database, file storage, background processing, network security, and transactional email delivery (magic links, notifications). The AI search, content translation, and meeting-protocol drafting features run on AI models hosted within Cloudflare's infrastructure — content processed by these features does not leave Cloudflare. Data processing agreement in place.
- Anthropic PBC (Claude API): AI-assisted processing for the optional land registry (Grundbuch) extraction feature and for the email-import feature used by property managers, including text recognition on photographed documents. Only the content actively submitted to these features is forwarded to the API. Per Anthropic's commercial terms, data submitted via the API is not used to train Anthropic's models. Data processing agreement in place.
- Google Ireland Limited (Gmail OAuth): When a property manager actively connects their Gmail account to use the email-import feature, Google authenticates the user and grants the platform read-only access to the connected mailbox. No other user data is shared with Google, and the connection can be revoked at any time from the user's Google account.
- SMS gateway (GatewayAPI ApS, Denmark — EU-hosted): Delivery of one-time phone verification codes, SMS invitations, and opt-in SMS notifications. The gateway receives the recipient's phone number and the message text. SMS is only sent to numbers in the EU and Switzerland.
- Apple Inc. (Apple Push Notification service): If you use the iOS app and enable push notifications, the notification content (title and short text) is routed through Apple's push service to your device.
- OpenStreetMap Foundation (Nominatim): When a community or property address is entered or imported, the street, postal code, and city are sent to the Nominatim geocoding service to validate and standardize the address. No account data is transmitted.
- We do not use any advertising networks, analytics services, or social media trackers.
6. International Data Transfers
We prefer processors that store and process data in the EU/EEA. Where a processor is established in the United States (Cloudflare, Anthropic, Apple), transfers are based on the European Commission's adequacy decision for the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), with supplementary measures where required.
7. Your Rights (GDPR)
- Right of access: You can export all your personal data from your account settings at any time.
- Right of rectification: You can update your profile information (name, phone, email visibility) in your profile settings.
- Right to erasure: You can delete your account from your account settings. After a 30-day grace period, all personal data is permanently removed.
- Right to restriction of processing: Contact us to request restriction of processing of your data.
- Right to data portability: The data export feature provides your data in a structured, machine-readable JSON format.
- Right to object: You may object to processing based on legitimate interest. Contact us to exercise this right.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time with effect for the future — for example by disconnecting an integration or disabling a notification channel.
8. Cookies
- Session cookie (better-auth.session_token): Strictly necessary for authentication. Cannot be disabled.
- Locale cookie: Stores your language preference. Strictly necessary for delivering content in your chosen language.
- Theme cookie: Stores your display theme preference (light/dark/system). Strictly necessary for rendering the interface correctly.
- All cookies are strictly necessary for the service to function. No tracking, analytics, or advertising cookies are used. No consent banner is required.
9. No Automated Decision-Making
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR). AI-assisted features (search, translation, document extraction, protocol drafting) only prepare content — decisions are always made by people.
10. Security Measures
All data is transmitted over HTTPS/TLS. Authentication uses magic links and short-lived one-time login codes (no passwords are stored). The platform is protected by Cloudflare's network security (WAF, rate limiting) and, where enabled, Cloudflare Access (Zero Trust). Request-level security telemetry, including IP addresses, is handled by our infrastructure provider (Cloudflare). Session tokens expire automatically.
11. Contact & Complaints
For questions about your data or to exercise your rights, contact us at contact@siedla.com. The full controller details are listed in the site imprint. Requests are answered within one month, in line with Art. 12(3) GDPR. You also have the right to lodge a complaint with a data protection supervisory authority - for users resident in Austria this is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40-42, 1030 Wien, dsb@dsb.gv.at.