This Privacy Policy explains how personal data is processed when you use IRES AI (the "Service"), a community-management platform for residential estates. It is issued in accordance with Regulation (EU) 2016/679 (the "GDPR") and the Cyprus Law 125(I)/2018 implementing the GDPR.
1. Data controller
The controller responsible for the processing of your personal data is:
John Peters, private individual, Nicosia, Cyprus
Email: privacy@iresai.app [TBD]
The Service is operated as a personal, non-commercial project. No Data Protection Officer has been appointed as neither Article 37(1) GDPR trigger applies; you may nonetheless contact us for any privacy-related matter at the address above.
2. Categories of personal data processed
Depending on how you use the Service, we process the following categories of personal data:
- Account data: email address, display name, hashed password (or OAuth identifier when signing in with Google), preferred language.
- Community data: the community and unit you are associated with, your role (Chair, Treasurer, Secretary, Flat Owner, Committee, Management), messages you send, requests, votes you cast, expense receipts, photos, meeting attendance and other content you actively upload.
- Financial data: fee payments, expense records, bank-statement lines you upload for reconciliation. This data is retained for statutory bookkeeping periods (see §6).
- AI-assistant interactions: prompts you send to the built-in AI assistant and its responses. These are stored in your chat threads so you can revisit them, and processed through our AI gateway to generate replies.
- Voice input: when you use the voice-input button, the audio is transmitted to a speech-to-text endpoint, converted to text and immediately discarded; only the resulting text is stored in the corresponding chat message.
- Technical data: IP address, browser user-agent, device type, session identifiers, timestamps of security-relevant actions (audit log).
We do not knowingly collect special categories of personal data (Art. 9 GDPR). Please do not upload health data, political opinions or similarly sensitive content into free-text fields.
3. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Providing the account, community workspace and core features | (b) performance of the contract with you |
| Storing financial records, receipts and audit logs | (c) legal obligation (bookkeeping and tax laws) |
| Security, abuse prevention, error diagnostics | (f) our legitimate interest in a safe and reliable service |
| Generating AI-assisted drafts, summaries and translations | (b) performance of the contract |
| Sending transactional emails (verification, notifications) | (b) / (f) |
| Optional analytics or marketing (currently not enabled) | (a) your explicit consent, revocable at any time |
4. Recipients and processors
We use the following processors (Art. 28 GDPR) to run the Service. Each has been bound by a data-processing agreement:
- Cloudflare, Inc. — edge hosting, DNS, TLS termination. Data may be processed at the nearest edge location worldwide.
- Supabase, Inc. — managed PostgreSQL database, authentication, file storage. Data is stored in the EU region [region — TBD, typically Frankfurt].
- Lovable AI Gateway — inference layer that forwards AI prompts to the underlying large-language-model providers. Prompts and responses are processed to generate the reply and logged for debugging; they are not used to train third-party models.
- Google LLC — only if you sign in via Google OAuth; Google receives the fact that you authenticated.
5. International transfers
Some processors are established outside the European Economic Area (in particular the United States). Where personal data is transferred, we rely on the European Commission's Standard Contractual Clauses (SCCs, 2021/914) and, where applicable, the EU–US Data Privacy Framework. You may request a copy of the safeguards in place from the contact address in §1.
6. Retention
- Account and community data: for as long as your account exists; deleted within 30 days after account closure, unless retention is required by law.
- Financial records and invoices: 7 years (Cypriot bookkeeping requirements).
- Audit-log entries: up to 7 years for security and compliance evidence.
- AI chat threads: until you delete them or your account is closed.
- Voice recordings: not retained; discarded immediately after transcription.
- Web-server logs (IP, user-agent): typically 30 days.
7. Your rights
Under the GDPR you have the right to:
- request access to your personal data (Art. 15);
- request rectification (Art. 16) or erasure (Art. 17);
- request restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw any consent you have given, at any time, with effect for the future.
To exercise these rights, contact us at privacy@iresai.app. You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus or any other competent supervisory authority in the EU.
8. Automated decision-making
The Service uses AI to generate drafts and suggestions. These outputs are advisory only; a human user (typically the Chair, Secretary or Treasurer) always confirms before any action is taken. No solely-automated decisions with legal or similarly significant effect within the meaning of Art. 22 GDPR are made.
9. Aggregated and anonymised statistics
We may transform personal data processed through the Service into anonymous, aggregated statistics about community operations, cost structures, governance patterns and building management in Cyprus and the wider European Union. These statistics — and, where appropriate, anonymised row-level datasets — may be published, shared or licensed for a fee to third parties, in particular public authorities, academic and research institutions, and commercial partners.
The step that transforms personal data into anonymous data is itself a processing activity and is carried out on the basis of our legitimate interest pursuant to Art. 6(1)(f) GDPR (research, product improvement and enabling evidence-based policy in the residential-property sector). Once data is anonymised in line with EDPB Opinion 05/2014, it no longer constitutes personal data and falls outside the scope of the GDPR.
Our anonymisation standard includes, at minimum: application of minimum aggregation thresholds (no output derived from fewer than a defined minimum number of records), suppression of rare attributes, removal of free-text fields and identifiers, and a prohibition on releasing combinations of attributes that could reasonably re-identify a household, a specific community or an individual. No personal data is transferred to the recipients.
We do not offer a product-level opt-out toggle for this processing. Your statutory right under Art. 21 GDPR to object to processing based on legitimate interests remains available and can be exercised on a case-by-case basis by writing to privacy@iresai.app.
10. Cookies
See our separate Cookie Policy.
11. Security
We implement appropriate technical and organisational measures including TLS in transit, encryption at rest via our hosting providers, row-level security in the database, hashed passwords, role-based access control and audit logging.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced in the application or via email. The "Last updated" date at the top of this page always reflects the latest version.
