Privacy Policy
HouseControl.at is a Software-as-a-Service platform for digital property management. This privacy policy explains what personal data is processed when visiting, registering for, and using the platform. It applies to the website, the web app, and connected mobile use.
As of: August 2026
1. Controller
Ing. Stephan Rudolf Landsteiner, Online-Agentur Landsteiner
Operator of HouseControl.at
Address: Schopperweg 29, 6321 Angath, Österreich
E-mail: stephan@landsteiner.info
Phone: +43 660 5646705
2. Roles in data protection
For data collected by property management companies, owners, tenants, or service providers in a building context, the respective property management company or customer is regularly responsible for the legality of the processing. HouseControl.at technically processes this data as a platform operator within the scope of providing the software.
For its own website, billing, support, security, and administration processes, HouseControl.at processes data as the controller.
3. Processed data
Depending on usage, the following data may be processed in particular:
- Account data: Name, email address, password hash, language, role, user ID, MFA status.
- Building and administrative data: Properties, floors, units, assignments, invitations, and roles.
- Communication data: messages, comments, support requests, email notifications, and attachments.
- Functional data: Surveys, votes, signatures of official votes, calendar appointments, documents, house rules, operating costs, and orders.
- Payment and subscription data: Stripe customer number, subscription status, plan, number of units, payment and invoice status.
- Technical data: IP address, browser data, session/cookie data, log data, security events, and audit logs.
- Test mode data (historical): the time-limited test mode was discontinued in August 2026. Content created in it no longer exists. What remains is the record of the terms accepted: time of activation, time of expiry and the confirmed version of the terms. IP address and browser identifier are removed 90 days after the test session ended.
- Support and administration context: support tickets, attachments, processing status, technical context data, active building/unit assignment, and identification of developer simulations.
- Affiliate/Referral data: Partner code, time of call, linked registration, subscription conversion, and hashed IP/browser identifiers for abuse checking.
4. Purposes and legal bases
- Provision of the platform and user accounts: Contract fulfillment or pre-contractual measures.
- Building, role, and communication functions: Contract fulfillment and legitimate interest in secure digital administration.
- Payment processing, invoices, and accounting: Contract fulfillment and legal obligations.
- Security, abuse protection, MFA, audit logs, and error analysis: legitimate interest and legal obligations.
- Notifications, support, and service communication: Contract fulfillment and legitimate interest.
- Optional features such as Google Login, push notifications, or AI/translation functions: depending on configuration, consent, contract fulfillment, or legitimate interest.
- Affiliate/Referral Tracking: Consent for persistent partner cookies; session assignment upon registration during the same visit for contract fulfillment or pre-contractual assignment.
5. Cookies and local storage
The platform uses technically necessary cookies for login, session, security, and cookie settings. Optional analysis or marketing cookies are only used if activated and legally permissible. Browsers can block cookies; technically necessary functions may be restricted as a result.
If a user accesses HouseControl.at via a partner or referral code, a referral cookie may be set after consenting to the “Marketing” category. This cookie contains no payment data, but rather a partner assignment, and serves to trace a later registration or subscription conversion back to a partner. IP address and browser identifier are not stored in clear text but are hashed for this purpose. Without marketing consent, the assignment remains limited to the current visit.
6. Payment processing with Stripe
Payments, subscriptions, and the customer portal are handled via Stripe. Payment, customer, invoice, and transaction data are transmitted to or processed by Stripe. HouseControl.at does not store full credit card data. Changes to subscriptions are synchronized within the platform via signed Stripe webhooks.
Further information: stripe.com/at/privacy
7. Google Login, Push and optional external services
If Google Login is used, HouseControl.at processes the profile data transmitted by Google, in particular email address, name, and Google ID, for login and account linking.
For push notifications, push tokens and technical device identifiers may be processed. If Firebase Cloud Messaging or similar services are activated, data may be transmitted to the respective provider.
The platform uses AI in three places: for the text improvement of entries, for the automatic translation of content between the residents' languages, and for the initial handling of support requests. For all three, the content submitted is transmitted to Google Cloud — text improvement and support AI via Vertex AI, translation and language detection via Cloud Translation.
These calls go to the EU endpoints of these services. For this configuration Google guarantees that data at rest and processing by the service take place within the selected EU region, and that content is not used to train AI models. For the project we use, the exception to prompt logging is additionally confirmed: requests and responses are not stored even if abuse is suspected.
This guarantee governs where processing takes place — not from where access is possible: Google support and technical staff may also access from outside the EU in the event of a fault or maintenance. Resource identifiers and the service's operational and billing data are not covered by the guarantee. The precise scope is described at AI & data protection .
AI features are only executed after the AI privacy notice has been confirmed; without that confirmation no transmission takes place. Automatic translation is switched off by default. Such features should only be used for content whose transmission is legally permissible.
We use AI technology to optimise support and to handle requests as quickly as possible. In doing so, entire cases are not transmitted, but exclusively individually approved fields (data minimisation pursuant to Art. 5(1)(c) GDPR). The aim is efficient initial handling; where necessary, the case is passed on to a member of staff. Support without AI assistance is available at any time via the support form. Statutory contact details can be found in the Legal notice.
To protect public forms from automated abuse, Cloudflare Turnstile may be used. Cloudflare processes technical information about the request to distinguish between legitimate use and bot access.
8. Hosting, logs and backups
The platform is operated on servers within the deployed hosting infrastructure. Server and application logs may contain IP address, timestamp, accessed URL, technical errors, and security-relevant events. Logs serve security, error analysis, and operational stability.
Backups are created to restore the service and deleted according to a defined retention concept. Data deleted in regular systems may technically remain in backups until the backup retention period expires.
A backup kept only on the same server would be lost together with it. Backups are therefore additionally stored with a second provider. They are encrypted on the server itself, that is, before they leave it; the provider of that storage has no access to the contents. Backups are kept for 14 days on the server and for 30 days in the second location. The companies involved are listed among the sub-processors in the data processing agreement.
9. Access by support
To handle support requests and faults, the provider may sign in to your account and see and operate the application as you see it. Such access is possible only for authorised staff of the provider with two-factor confirmation, requires a stated reason, ends automatically after 30 minutes and is fully logged: start, end, reason and every change made in the process are attributed to the member of staff acting, not to your account. The logs can be viewed in the audit log.
10. Recipients and processors
Personal data may be transferred to technical service providers as far as this is necessary for operation, security, payment, communication, or support. This may include, in particular, hosting providers, mail providers, Stripe, Google, Cloudflare, push services, monitoring/error analysis services, and translation or AI services.
Where necessary, agreements according to Art. 28 GDPR are concluded with processors. For transfers to third countries, appropriate safeguards such as adequacy decisions or standard contractual clauses are taken into account.
11. Storage duration
Data is stored only for as long as it is required for the stated purposes or for as long as statutory retention obligations apply. Contract, payment and accounting data may be stored longer in line with statutory periods. No content from the discontinued test mode remains; what is kept is the record of the terms accepted, from which IP address and browser identifier are removed 90 days after the test session ended.
Support tickets (text history and attachments within the platform) are generally deleted after 24 months upon completion (storage limitation according to Art. 5 para. 1 lit. e GDPR). There is no blanket legal retention period solely for support chats; tax and accounting-relevant documents (e.g., invoices) are stored separately via billing (Stripe) in accordance with the deadlines under BAO/UGB. Email replies to the inbound address are removed from the inbox after processing — the adopted text remains saved in the ticket.
12. Data subject rights
Affected persons have rights under the GDPR to information, rectification, erasure, restriction of processing, data portability, objection, and withdrawal of granted consents. Inquiries can be sent to stephan@landsteiner.info be directed.
13. Right to lodge a complaint
Affected persons can complain to a data protection supervisory authority. In Austria, this is the Austrian Data Protection Authority: www.dsb.gv.at.
14. Amendments
This Privacy Policy may be adapted if functions, service providers, legal bases, or technical processes change.