Privacy Policy
How Daniel Group handles personal data collected through this website.
DGIConnect — Privacy Policy
Operated by Daniel Group. Last updated: 21 August 2026.
This Privacy Policy explains how Daniel Group (“we”, “us”) collects, uses, stores and shares information when you use the DGIConnect mobile application and related backend services (the “Service”). DGIConnect is a professional property-management platform intended for business use by property managers, building managers, branch managers, owners, residents, technicians and contractors. It is not directed to children.
1. Who we are & contact
Data controller: Daniel Group (product: DGIConnect). For any privacy request or question, contact support@dgiconnect.com. When you use the Service under an organization (your employer or property-management company), that organization is also a controller of the records created within its workspace.
2. Information we collect
Account & authentication
- Email address, first and last name, and (optional) profile photo/avatar.
- Password — stored only as a salted one-way hash (bcrypt); we never store your password in readable form.
- If you enable two-factor authentication (2FA): a time-based one-time-password secret (stored encrypted) and one-time recovery codes (stored hashed).
- Your assigned role and permissions, and the organization/company/branch you belong to.
Security & session information
- IP address, device browser/operating-system information (user-agent), and sign-in timestamps, recorded for active sessions, trusted devices and security audit logs.
- Authentication tokens are stored on your device in the platform’s secure storage (Android Keystore / iOS Keychain).
Profile & contact details
- Phone number and emergency-contact details, where you or your organization provide them (for example, for residents and owners).
Property-management records (entered by organization users)
- Organizations, companies, branches, buildings and apartments/units, including postal addresses and building coordinates.
- Owner records: name, company name, email, phone, tax number, address and emergency contacts.
- Resident records: name, email, phone, occupation and, where recorded by the organization, nationality and identity/passport number.
- Contractor records: name, company, phone, email and notes.
- Leases and related dates and amounts.
Financial records
- Invoices, expenses, balances and payment records (amount, method, free-text reference, date). Payments are recorded manually/offline.
- We do not collect or store payment-card numbers, card security codes, or bank-account credentials, and the app does not integrate a live payment processor. You may upload a proof-of-payment file (e.g., a bank-transfer receipt), which may itself contain financial details you choose to include.
Maintenance data
- Work-order titles and descriptions, comments/messages, status history, and before/after photos and attachments related to maintenance in a unit or building.
Documents, files & photos
- Files you upload — for example lease agreements, insurance, invoices, permits, certificates, legal documents and photos — together with their filename, type and size. These files may contain personal information about residents, owners or others.
- Camera and photo-library access is used only when you add a maintenance photo, upload a document/payment proof, or set a profile photo. Images are uploaded to our Service for that purpose.
Notifications
- If you enable push notifications, we collect a push notification token and your platform (Android/iOS) so we can deliver notifications about your work.
What we do NOT collect
- We do not collect precise or approximate device location.
- We do not use advertising identifiers and there is no advertising in the app.
- We do not use third-party analytics, tracking or crash-reporting SDKs (e.g., Google Analytics/Firebase, Sentry, Mixpanel, Meta SDK).
3. How we use information
- To provide and operate the property-management Service and its features.
- To authenticate you and keep accounts and data secure (including 2FA and security audit logs).
- To deliver notifications you have enabled.
- To maintain financial, maintenance and document records on behalf of your organization.
- To provide customer support and to comply with legal obligations.
4. Service providers & data sharing
We do not sell your personal data. We share data only within your organization’s workspace (access is isolated per organization and controlled by role) and with the service providers we use to run the Service:
| Provider | Purpose | Data involved |
|---|---|---|
| Hetzner (hosting, Germany/EU) | Hosts our application, database and uploaded files | All Service data described above |
| Expo Push Service (Expo, via Google FCM on Android) | Delivers push notifications | Push token, platform, and notification title/body |
| Email delivery (SMTP relay) | Sends transactional email (invitations, password resets, notices) | Recipient name, email and message content |
| Google Play / Apple / Expo (EAS) | App build and distribution | App package only (not your account data) |
| Apple Maps / Google Maps | Only when you tap “Directions”, to open an address in your maps app | The property address you selected |
5. International processing
Our servers and stored data are located in the European Union (Germany). Some providers, such as the push-notification and email-delivery services, may process limited data (such as a push token or email content) in other locations. Where required, we rely on appropriate safeguards for such transfers.
6. Security
- All communication between the app and our servers uses encrypted connections (HTTPS/TLS).
- Passwords are stored only as salted hashes (bcrypt), never in plaintext; 2FA secrets are stored encrypted.
- Access is controlled by role-based permissions and strict per-organization isolation; security-relevant actions are recorded in audit logs.
- Uploaded files are served only to authenticated, authorized users and are not publicly accessible.
We apply reasonable technical and organizational measures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Data retention & deletion
- Delete your account in the app: open Settings → Delete account. This deactivates your login, anonymizes your login email, ends your sessions, and removes your push-notification tokens.
- Records you created within an organization’s workspace (for example property, resident, owner, lease, financial, maintenance and document records) are controlled by that organization and may be retained by it for its own legal and operational purposes after your login is deleted. To request deletion of those records, contact your organization administrator or support@dgiconnect.com.
- Organization administrators can deactivate or remove user accounts within their organization.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete or export your personal data, and to object to or restrict certain processing. Where the EU General Data Protection Regulation (GDPR) applies, these rights apply to you. To make a request, contact support@dgiconnect.com; if your data was entered under an organization’s workspace, we may direct your request to that organization as the controller.
9. Children
DGIConnect is a professional tool intended for users aged 18 and over and is not directed to children. We do not knowingly collect personal data from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notice within the Service.
11. Contact
Questions or requests: support@dgiconnect.com — Daniel Group / DGIConnect.