1. Who we are
NidoKey is operated by Logic Edge SL, a company registered in Spain ("we", "us"). We are the data controller for the personal data described in this policy. For anything related to privacy, write to our contact address.
2. What this policy covers
This policy applies to the NidoKey app for iOS and Android, the NidoKey device installed next to the intercom of your building or home, the NidoKey websites (including nidokey.com and the pages that open NidoKey links) and the online service that connects them.
It does not cover services run by others, such as the App Store, Google Play, your phone’s operating system or your internet provider, which have their own privacy notices.
3. Data we process
Depending on how you use NidoKey, we process the following data:
- Key holder details: your name, email address and phone number, which we record when we prepare your virtual key, and the invitation we send you.
- Key and pairing data: identifiers of your key, of the app installation and of the NidoKey device, the public part of your key (never the private part), the platform (iOS or Android), the doors your key opens, the key status and when it was last used.
- Door openings: for each opening, the door, the time, the result and the cryptographic signatures and one-time values needed to verify it and prevent replays.
- Doorbell rings: the time of the ring, the device and the doors it concerns. Camera images taken when someone rings are encrypted on the NidoKey device for the phones paired with it; our servers only relay them in encrypted form and delete them within two minutes. We cannot see them.
- Notification tokens: the push token of your phone, stored encrypted, so we can tell you when someone rings.
- Device data: the status, firmware version, connectivity and last contact of the NidoKey device, and security and error events it reports.
- Technical data: IP addresses and request data used to protect the service against abuse (for example rate limits that expire within minutes) and standard logs kept by our hosting provider.
- Support messages: what you send us when you write to us, and our replies.
Some data stays only on your phone and never reaches us: your activity history, decrypted doorbell images, NFC tag and widget settings, your language choice and, if you choose to remember it, the Wi-Fi password you used to set up the device. Wi-Fi details travel from your phone to the NidoKey device over an encrypted Bluetooth connection; we do not receive them.
We never receive your fingerprint, face or screen lock: confirmation is handled by your phone’s operating system, which only tells the app whether it succeeded.
4. Permissions on your phone
- Bluetooth: to pair your phone with the NidoKey device, update it and set up its Wi-Fi.
- Location: Android and iOS require it to search for nearby Bluetooth devices. NidoKey uses it only for that search; your location is not stored or sent to us. On Android, if this permission has already been granted, the app may also read your approximate last known position, on the phone only, to draw the time-of-day sky.
- Notifications: to tell you when someone rings and how a door opening went.
- Face ID, Touch ID, fingerprint or screen lock: to confirm that it is you before a door opens or a key is used.
- NFC: to open doors from the NFC tags you link in the app.
You can turn these permissions off in your phone settings at any time; the features that depend on them will then stop working.
5. Why we use your data and on what legal basis
- To provide the service you asked for: issuing and managing your key, pairing doors, opening them, delivering doorbell rings and updating the device (performance of our contract with you).
- To keep the service and your doors secure: verifying every opening, preventing replays and abuse, detecting faults and investigating incidents (our legitimate interest in protecting you, other residents and the service, and legal obligations on security).
- To answer your messages and give support (performance of the contract and our legitimate interest).
- To comply with the law and to establish, exercise or defend legal claims (legal obligation and legitimate interest).
We do not use your data for advertising, profiling or automated decisions with legal or similarly significant effects, and we do not sell it.
6. Who we share data with
We share personal data only with providers that help us run the service, under contracts that oblige them to protect it and to use it only on our instructions:
- Cloudflare, Inc.: hosting of our servers, databases, storage, websites and network protection.
- Google (Firebase Cloud Messaging): delivery of notifications to Android phones.
- Apple (Apple Push Notification service): delivery of notifications to iPhones.
We may also disclose data when the law requires it, to protect people’s safety or our rights, or as part of a merger or sale of the business, always subject to this policy. The App Store and Google Play process data under their own terms when you download the app.
7. International transfers
Our providers may process data outside the European Economic Area, for example in the United States. When they do, we rely on the safeguards provided by data protection law, such as the European Commission’s adequacy decisions (including the EU-US Data Privacy Framework) or standard contractual clauses.
8. How long we keep data
- Key holder details: while you have an active key or a contract with us, and afterwards only as long as needed for legal obligations or claims. When a key is deleted, we keep only a one-way fingerprint of it to stop it from ever being used again.
- Door openings and other activity: up to 90 days; denied attempts and errors up to 180 days, for security.
- Doorbell rings: 30 days. Encrypted doorbell images: deleted from our servers within two minutes.
- Notification tokens: deleted 30 days after they are disabled, and after 180 days without use.
- Abuse-prevention data such as IP-based rate limits: minutes.
- Support messages: as long as needed to handle your request and any related obligation.
Data stored only on your phone stays under your control: the activity history is kept for up to 90 days, you can delete it in the app at any time, and uninstalling the app removes it.
9. Your rights
You can ask us for access to your personal data, to correct or delete it, to restrict or object to its processing and to receive it in a portable format. Write to our contact address; we may need to confirm your identity before acting, and we will answer within one month.
If you are not satisfied with our answer, you can complain to a data protection authority, such as the Spanish Agencia Española de Protección de Datos (www.aepd.es) or the authority where you live.
10. Security
Security is the core of NidoKey. Your key is created in your phone’s secure hardware and never leaves it. Every door opening needs three independent proofs to match: a signature from your phone, a code that only your phone and your NidoKey device share, and a signature from our service. A compromised server alone cannot open your door. Connections are encrypted, Bluetooth sessions are authenticated, and the device only installs firmware signed by us.
No system is perfectly secure. If you lose your phone, tell us at our contact address so that we can disable your key. If you believe you have found a security issue, please report it to the same address.
11. Children
NidoKey is not directed at children. A key for a minor under 14 is only issued at the request of a parent or legal guardian, who provides the necessary details and is responsible for its use.
12. Our websites
Our websites do not use cookies, analytics or third-party content. They only store your language choice in your browser so that the page opens in that language next time.
13. Changes to this policy
We may update this policy when the service or the law changes. We will change the date at the top and, for important changes, tell you in the app or by email.
14. Contact
Logic Edge SL · our contact address