Back to home

Privacy policy

Last updated: [DATE]

1. What this policy covers

Colloport provides a platform for remotely monitoring and operating gates, barriers and garage doors. We do not sell that platform directly to the user of a gate, but to installation companies and suppliers, who offer it to their own customers under their own name or under the Colloport name.

That distinction decides who is responsible for what, which is why it comes first.

We are the controller for the data of the companies we have a contract with ourselves: their contact people, their billing, their questions to our support team, and the people who approach us through our website. This policy covers that data, and you can come to us about it.

We are not the controller for the data stored in the platform: the users, the operation of gates, the notes. That data is there on the instructions of the installation company that is your customer relationship. That company decides what happens with it and how long it is kept; we carry out what it instructs us to do. If you want to know what has been recorded about you, or want it deleted, contact that company. We help them with that, but we are not allowed to hand over or erase that data on our own initiative.

What we do as a processor is set out in a data processing agreement with that company.

2. Who we are

Colloport B.V.
Laan van Selis 3
5283 PG Boxtel, the Netherlands
Chamber of Commerce (KvK) 42069663

Privacy questions: [email protected]

We do not have a data protection officer. For an organization of our size and nature that is not required. Your question reaches two people, so a holiday never costs a response deadline.

3. What data we process as controller

WhatWhat forLegal basis
Name, role, email address and phone number of contact people at our customers and prospectsMaintaining contact, sending quotes, performing the agreementPerformance of the agreement, and our legitimate interest in approaching business relations
Company and invoicing detailsBilling and administrationPerformance of the agreement, and the statutory retention duty
The content of your questions to our support teamAnswering your question and solving the problemPerformance of the agreement
Name, email address and message from the contact form on our website, with the IP address and browser data it was sent withAnswering your message, and preventing abuse of the formOur legitimate interest in answering messages and protecting the form
Our own staff's account data in the platformAdministration and supportPerformance of the agreement

We do not buy address lists and we do not enrich your data with data from third parties.

4. What we don't do

  • We do not sell data to third parties, and we do not share anything for advertising purposes.
  • We do not use advertising cookies or advertising identifiers, and we do not track you across other websites. On our own website we do measure visitor numbers, but only if you give consent for that; see chapter 9.
  • We do not build profiles and we do not make decisions about people based on automated processing.
  • We do not use your data to train artificial intelligence models, and we have required the providers of the models we use not to do so either. This is technically enforced on every request, not merely agreed contractually.

5. How long we keep it

WhatHow long
Invoices and the related administrationSeven years, statutory retention duty
Customer contact detailsSeven years after the end of the customer relationship, matching the administration they belong to
Prospect contact detailsTwo years after the last contact
Messages to our support teamTwo years after resolution
Messages via the contact formOne year after resolution
Visitor statistics for our websiteFourteen months, and only if you gave consent for that

The retention periods for data in the platform are not decided by Colloport but by the installation company responsible for it.

When we delete something, we do so on the systems in active use. Our backups are not searched for that purpose; they expire on their own schedule and until then exist only to restore something that was lost.

6. Who we share data with

We use suppliers who process data as part of their work. A data processing agreement is in place with every supplier, and they may use the data only for the work we instruct them to do.

SupplierWhat forWhere
Hetzner OnlineThe servers the platform runs onGermany and Finland
NeonThe database with configuration and account dataGermany (Frankfurt)
Backblaze B2Backup storageThe Netherlands (Amsterdam)
CloudflareShielding and delivering internet trafficGlobal network
ResendSending email, including login codes and invitationsIreland
ExpoPassing push notifications to Apple and GoogleUnited States
Apple and GoogleDelivering a push notification to your deviceWorldwide
Grafana LabsSystem logs and metrics for our own infrastructure. These contain no names, email addresses or message content, but do contain an IP address truncated to 24 bits and the internal identifiers of a user and an environmentGermany
SentryRecording errors in the console and the mobile app, with the identifier of the user and the IP address the error occurred fromGermany
OpenRouterPassing a question to the assistant feature on to a language modelUnited States, and the provider behind a given question differs per model
GoogleVisitor statistics for our website, only after your consentIreland and the United States

The last row concerns only our website, not the platform. If you visit the website without giving consent, nothing from Google is loaded; see the cookie policy.

We keep the full list of what each supplier processes internally, and we notify a change at least thirty days in advance to customers with a data processing agreement.

We also provide data where the law requires us to, for example to a regulator or under a court order.

7. Processing outside Europe

The platform itself and the data in it stay within the European Economic Area: the servers in Germany and Finland, the database in Germany, the backups in the Netherlands, email sending in Ireland and error logging in Germany.

There are four parts where data can leave Europe.

Delivering push notifications. To get a notification on your phone, your device token and the content of the notification go through Apple or Google.

Shielding internet traffic. Traffic to our website and our console runs over a global network, which sees your IP address in the process.

The assistant feature. The question you ask and its context are passed to a language model. We enforce on every request that the data is not retained and not used to train models. Where the computation physically happens is not always known to us: for many models, only the country the provider is registered in is public, not where its servers are. We would rather say that plainly than give a guarantee we cannot keep. For a model we cannot confirm is processed within Europe, we also only use it once the administrator of the relevant environment has explicitly consented to that.

The visitor statistics for our website, and only if you have given consent for that.

For all these transfers we use the standard contractual clauses set by the European Commission.

8. How we secure it

  • Logging in works with a one-time code by email. We do not store passwords.
  • All connections are encrypted, and devices in the field identify themselves with a certificate stored in a secure chip that the certificate can never leave.
  • Data and backups are stored encrypted.
  • Access within the platform is scoped per role and per location; what someone may do must have been explicitly granted.
  • Actions by users and administrators are logged, so it can be reconstructed afterwards who did what.
  • Our system logs contain no names, email addresses, passwords, codes or message content. An IP address is truncated to its network portion before storage, so it no longer points to one connection; what remains are internal identifiers that let us trace a request.

9. Cookies

In the console and the mobile app we use only storage needed to make the service work: remembering that you are logged in, which environment you had selected and how you had arranged your screen. That needs no consent, and there is accordingly no cookie notice. It contains no analytics cookies, no advertising cookies and no third-party cookies.

On our website we do ask for consent. There we use Google Analytics to see how many people visit the site and which pages they read. That only happens if you give consent for it; as long as you do not, nothing from Google is loaded. We use advertising cookies nowhere.

The full overview is in the cookie policy.

10. Your rights

You can ask us for access to your data, for correction of inaccurate data, for erasure, for restriction of processing, and to receive your data in a common format. Where we process data based on a legitimate interest, you can object to that.

Send your request to [email protected]. We respond within one month. If we need more time, we let you know within that month.

If your request concerns data in the platform, we refer you to the company responsible for it. We will tell you who that is.

If you are not satisfied with how we handle your request, you can lodge a complaint with the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl.

11. Changes

We update this policy whenever the service or the regulations give reason to. For a material change we let you know by email or through a notice in the platform. The date at the top shows when the policy was last changed.