Privacy policy
Last updated: [DATE]
1. What this policy covers
Colloport provides a platform for remotely monitoring and operating gates, barriers and garage doors. We do not sell that platform directly to the user of a gate, but to installation companies and suppliers, who offer it to their own customers under their own name or under the Colloport name.
That distinction decides who is responsible for what, which is why it comes first.
We are the controller for the data of the companies we have a contract with ourselves: their contact people, their billing, their questions to our support team, and the people who approach us through our website. This policy covers that data, and you can come to us about it.
We are not the controller for the data stored in the platform: the users, the operation of gates, the notes. That data is there on the instructions of the installation company that is your customer relationship. That company decides what happens with it and how long it is kept; we carry out what it instructs us to do. If you want to know what has been recorded about you, or want it deleted, contact that company. We help them with that, but we are not allowed to hand over or erase that data on our own initiative.
What we do as a processor is set out in a data processing agreement with that company.
2. Who we are
Colloport B.V.
Laan van Selis 3
5283 PG Boxtel, the Netherlands
Chamber of Commerce (KvK) 42069663
Privacy questions: [email protected]
We do not have a data protection officer. For an organization of our size and nature that is not required. Your question reaches two people, so a holiday never costs a response deadline.
3. What data we process as controller
| What | What for | Legal basis |
|---|---|---|
| Name, role, email address and phone number of contact people at our customers and prospects | Maintaining contact, sending quotes, performing the agreement | Performance of the agreement, and our legitimate interest in approaching business relations |
| Company and invoicing details | Billing and administration | Performance of the agreement, and the statutory retention duty |
| The content of your questions to our support team | Answering your question and solving the problem | Performance of the agreement |
| Name, email address and message from the contact form on our website, with the IP address and browser data it was sent with | Answering your message, and preventing abuse of the form | Our legitimate interest in answering messages and protecting the form |
| Our own staff's account data in the platform | Administration and support | Performance of the agreement |
We do not buy address lists and we do not enrich your data with data from third parties.
4. What we don't do
- We do not sell data to third parties, and we do not share anything for advertising purposes.
- We do not use advertising cookies or advertising identifiers, and we do not track you across other websites. On our own website we do measure visitor numbers, but only if you give consent for that; see chapter 9.
- We do not build profiles and we do not make decisions about people based on automated processing.
- We do not use your data to train artificial intelligence models, and we have required the providers of the models we use not to do so either. This is technically enforced on every request, not merely agreed contractually.
5. How long we keep it
| What | How long |
|---|---|
| Invoices and the related administration | Seven years, statutory retention duty |
| Customer contact details | Seven years after the end of the customer relationship, matching the administration they belong to |
| Prospect contact details | Two years after the last contact |
| Messages to our support team | Two years after resolution |
| Messages via the contact form | One year after resolution |
| Visitor statistics for our website | Fourteen months, and only if you gave consent for that |
The retention periods for data in the platform are not decided by Colloport but by the installation company responsible for it.
When we delete something, we do so on the systems in active use. Our backups are not searched for that purpose; they expire on their own schedule and until then exist only to restore something that was lost.
6. Who we share data with
We use suppliers who process data as part of their work. A data processing agreement is in place with every supplier, and they may use the data only for the work we instruct them to do.
| Supplier | What for | Where |
|---|---|---|
| Hetzner Online | The servers the platform runs on | Germany and Finland |
| Neon | The database with configuration and account data | Germany (Frankfurt) |
| Backblaze B2 | Backup storage | The Netherlands (Amsterdam) |
| Cloudflare | Shielding and delivering internet traffic | Global network |
| Resend | Sending email, including login codes and invitations | Ireland |
| Expo | Passing push notifications to Apple and Google | United States |
| Apple and Google | Delivering a push notification to your device | Worldwide |
| Grafana Labs | System logs and metrics for our own infrastructure. These contain no names, email addresses or message content, but do contain an IP address truncated to 24 bits and the internal identifiers of a user and an environment | Germany |
| Sentry | Recording errors in the console and the mobile app, with the identifier of the user and the IP address the error occurred from | Germany |
| OpenRouter | Passing a question to the assistant feature on to a language model | United States, and the provider behind a given question differs per model |
| Visitor statistics for our website, only after your consent | Ireland and the United States |
The last row concerns only our website, not the platform. If you visit the website without giving consent, nothing from Google is loaded; see the cookie policy.
We keep the full list of what each supplier processes internally, and we notify a change at least thirty days in advance to customers with a data processing agreement.
We also provide data where the law requires us to, for example to a regulator or under a court order.
7. Processing outside Europe
The platform itself and the data in it stay within the European Economic Area: the servers in Germany and Finland, the database in Germany, the backups in the Netherlands, email sending in Ireland and error logging in Germany.
There are four parts where data can leave Europe.
Delivering push notifications. To get a notification on your phone, your device token and the content of the notification go through Apple or Google.
Shielding internet traffic. Traffic to our website and our console runs over a global network, which sees your IP address in the process.
The assistant feature. The question you ask and its context are passed to a language model. We enforce on every request that the data is not retained and not used to train models. Where the computation physically happens is not always known to us: for many models, only the country the provider is registered in is public, not where its servers are. We would rather say that plainly than give a guarantee we cannot keep. For a model we cannot confirm is processed within Europe, we also only use it once the administrator of the relevant environment has explicitly consented to that.
The visitor statistics for our website, and only if you have given consent for that.
For all these transfers we use the standard contractual clauses set by the European Commission.
8. How we secure it
- Logging in works with a one-time code by email. We do not store passwords.
- All connections are encrypted, and devices in the field identify themselves with a certificate stored in a secure chip that the certificate can never leave.
- Data and backups are stored encrypted.
- Access within the platform is scoped per role and per location; what someone may do must have been explicitly granted.
- Actions by users and administrators are logged, so it can be reconstructed afterwards who did what.
- Our system logs contain no names, email addresses, passwords, codes or message content. An IP address is truncated to its network portion before storage, so it no longer points to one connection; what remains are internal identifiers that let us trace a request.
9. Cookies
In the console and the mobile app we use only storage needed to make the service work: remembering that you are logged in, which environment you had selected and how you had arranged your screen. That needs no consent, and there is accordingly no cookie notice. It contains no analytics cookies, no advertising cookies and no third-party cookies.
On our website we do ask for consent. There we use Google Analytics to see how many people visit the site and which pages they read. That only happens if you give consent for it; as long as you do not, nothing from Google is loaded. We use advertising cookies nowhere.
The full overview is in the cookie policy.
10. Your rights
You can ask us for access to your data, for correction of inaccurate data, for erasure, for restriction of processing, and to receive your data in a common format. Where we process data based on a legitimate interest, you can object to that.
Send your request to [email protected]. We respond within one month. If we need more time, we let you know within that month.
If your request concerns data in the platform, we refer you to the company responsible for it. We will tell you who that is.
If you are not satisfied with how we handle your request, you can lodge a complaint with the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl.
11. Changes
We update this policy whenever the service or the regulations give reason to. For a material change we let you know by email or through a notice in the platform. The date at the top shows when the policy was last changed.