Who processes your data
The controller for Douvo is [LEGAL OR TRADING NAME], [STREET AND NUMBER, POSTCODE, CITY, GREECE], VAT [GREEK VAT NUMBER], company registry [COMPANY REGISTRY NUMBER] — referred to below as “we” or “Douvo”.
For anything to do with personal data, write to app.douvo@gmail.com. We answer within one month at the latest.
We have not appointed a Data Protection Officer: the GDPR does not require one for a business of this size and activity. Requests go to the address above and we handle them ourselves.
What this policy covers
- The Douvo app for iPhone and Android.
- The douvo.app website, including the waiting-list form.
- The public project links (the client portal) that you send to your own clients.
It does not cover third-party services you may reach through Douvo — your phone's maps or dialler, for instance. Their own policies apply there.
Two roles: your data and your clients' data
This distinction is the most important thing in the document, because it decides who any given request should go to.
For your own account data — email, name, business, settings — we are the controller.
For everything you enter in the app about your clients — names, phone numbers, addresses, floors, doorbells, notes, photos, amounts — you are the controller. We are the processor and act only on your instructions.
- You make sure you have a lawful basis for holding those details, usually performance of your contract with the client.
- You tell your clients that you keep their details in a digital tool.
- You answer them if they ask for access or deletion. The app gives you the buttons to do it.
- We do not touch that data for our own purposes. We do not read it either, unless you ask us for help with a specific problem and give us access.
If you are a client of a tradesperson and want to know or delete what they hold about you, contact them — it is their decision. If you don't know who to ask, write to us and we will pass the request on.
What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email, hashed password, full name, profile picture, trade, notification settings | From you at sign-up; or from Apple/Google if you sign in that way (email and name only) |
| Business and crew | Company name, VAT number, logo, trade, members and roles, the email addresses you invite | From you |
| Work content | Clients (name, phone, address, floor, doorbell, notes), jobs, appointments, projects and phases, materials, prices, expenses, payments and instalments | From you and from your crew members |
| Photos | Job and project photos, with the date taken and any caption | From your device — only the ones you pick or shoot inside the app |
| Notifications | Your device's push token and the profile's notifications switch | From your device, once you grant permission |
| Technical logs | IP address, request time, device or browser type — in our infrastructure providers' logs, for security and debugging | Automatically, with every request |
| Waiting list | Your email, the language of the page, the time you signed up and a one-way hash (HMAC) of your IP — never the IP itself | From the form on douvo.app |
What we don't do
- We use no analytics, tracking pixels or advertising SDKs. Not in the app, not on the website. We do not know which screens you open.
- We do not sell, rent or trade data with anyone.
- We do not read your contacts, your messages or your photo library. Only the photo you choose is uploaded.
- We do not collect your location. The “Map” button simply opens your maps app with the address you typed; we never read GPS.
- We do not use your data to train artificial-intelligence models.
- We make no automated decisions about you and build no profiles (GDPR art. 22).
Permissions the app asks for
| Permission | When it is asked | What it does |
|---|---|---|
| Camera | The first time you take a photo on a job or project | The photo goes into your project |
| Photo library | The first time you pick an existing photo | Only the photo you selected is uploaded, at a reduced size |
| Notifications | The first time a reminder or an assignment needs to reach you | Reminders before appointments and “a job was assigned to you” |
Every permission can be withdrawn in your device settings. The app keeps working — it just loses that one piece.
Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Creating your account and running the app | Performance of a contract (§1b) |
| Storing and syncing your data across devices and crew members | Performance of a contract (§1b) |
| Security, abuse prevention, rate limits and keeping bots off the form | Legitimate interests (§1f) — keeping the service standing and clean |
| Push notifications for appointments and assignments | Consent through the device permission (§1a), within the contract (§1b) |
| Sending an invitation email to someone you want in your crew | Legitimate interests (§1f) — you explicitly asked us to send it |
| The “it's out” email to people on the waiting list | Consent (§1a), withdrawable at any time |
| Support and answering your requests | Performance of a contract (§1b) and legal obligation (§1c) |
| Meeting tax and other statutory obligations | Legal obligation (§1c) |
Who else sees data
We give data to no one for their own purposes. We do use infrastructure providers that process it on our behalf, under a data-processing agreement:
| Provider | What it does | Where |
|---|---|---|
| Supabase (Supabase Inc., USA) | Database, user authentication, photo storage | AWS servers in Frankfurt (EU) and London (UK) |
| Vercel (Vercel Inc., USA) | Hosting and delivery of douvo.app and the waiting list | Global delivery network, processing in the EU and the USA |
| Expo (650 Industries, Inc., USA) | Relays push notifications to your device | USA |
| Apple (APNs) and Google (FCM) | Deliver the notification to the iPhone or Android handset | USA and EU |
| Apple and Google | Sign-in with an Apple or Google account, app distribution through the stores | USA and EU |
Beyond those, we may have to disclose data where a law, a court order or a competent authority requires it, or to establish and defend legal claims.
Transfers outside the European Economic Area
Your data is stored on servers inside the EU (Frankfurt) and in the United Kingdom (London). The UK is covered by a European Commission adequacy decision, so a transfer there is treated like a transfer within the EU.
Some of the providers above are US companies whose staff may access data for maintenance and support. Those transfers rely on the European Commission's Standard Contractual Clauses and/or the EU–U.S. Data Privacy Framework, depending on what each provider certifies.
The text of a push notification — the job title and the client's name, for example — travels through Expo's, Apple's and Google's networks to reach the handset. Don't put anything in a job title that you would not want to travel that way.
The public project link
When you turn sharing on for a project, Douvo mints a link with a random, unguessable token, and you hand it to your client.
- The page shows progress, phases, visits and photos for that one project.
- Financial figures appear only if you switch them on — and never your expenses or your margin.
- The pages are marked noindex and excluded in robots.txt, so they stay out of search engines.
- Photos are served through signed links that expire within an hour.
- The moment you stop sharing, the link stops working and shows an error page.
Anyone holding the link can see it — there is no password. Send it only to the person who needs it, and stop sharing once the project is done.
How long we keep it
| Data | Retention |
|---|---|
| Account and work content | For as long as your account exists |
| After you delete your account | Deleted within 30 days; backups roll over and clear within a further 30 days |
| Business data with several members | Stays with the business when a member leaves — it belongs to the business, not the individual |
| Waiting-list email | Until the launch email is sent, and at most 24 months; immediately if you ask us to remove it |
| Temporary rate-limit records (hashed IP) | One hour, then deleted automatically |
| Providers' technical logs | Per their own policies, typically up to 30 days |
| Records with tax or accounting significance | For as long as the law requires |
How we protect it
- Encryption in transit (TLS) and encryption at rest by the provider.
- Row Level Security in the database: each row is reachable only by the user or the business it belongs to, regardless of what the app asks for.
- Project photos sit in private storage and are served only through signed, short-lived links.
- Roles: an employee sees the jobs assigned to them, not prices, profit or statistics.
- Administrative keys live on the server only and never reach a browser or a handset.
- The waiting list stores a hash of your IP rather than the address — enough to block abuse, useless as an identifier.
Your profile picture is stored in public storage under a random filename, so anyone with the exact link can view it. Don't use an image you would mind being reachable that way.
No service is perfectly secure. If a breach affects you, we will notify the supervisory authority within 72 hours and you without undue delay, as the GDPR requires.
Minors
Douvo is built for working professionals. It is not intended for anyone under 18 and we do not knowingly collect their data. If we find that we have, we delete the account.
Your rights
The GDPR gives you the following, and we honour them without conditions:
- Access — find out what we hold and get a copy.
- Rectification — correct anything wrong or incomplete.
- Erasure — ask for your data to be deleted.
- Restriction — freeze processing while a disagreement is resolved.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interests.
- Withdrawal of consent — at any time, without affecting what came before.
Most of these you can exercise yourself inside the app: edit your profile, delete clients, jobs and photos, stop sharing, delete your account. For the rest, email app.douvo@gmail.com.
We answer within one month. Complex requests may take two months longer, and we will tell you if that happens. There is no charge unless a request is manifestly unfounded or excessive.
If you think we handled you badly, you can complain to the Hellenic Data Protection Authority: 1-3 Kifissias Avenue, 115 23 Athens, Greece, +30 210 6475600, contact@dpa.gr, www.dpa.gr.
Changes to this policy
We may update it when something changes in the app or among our providers. The date at the top always marks the current version.
If a change is material — a new category of data, or a new purpose — we will tell you in the app or by email at least 30 days before it takes effect.
Contact
[LEGAL OR TRADING NAME], [STREET AND NUMBER, POSTCODE, CITY, GREECE]. Data-protection email: app.douvo@gmail.com.
Write to us in Greek or in English. No formal request template is needed — one clear sentence about what you want is enough.