Privacy Policy

Last updated: August 26, 2026

DoorLink is a brand operated by IBALTON S.A.S. (CUIT 30-71750823-4), based in the City of Buenos Aires, Argentina ("DoorLink," "we," "us"). This policy explains what data we collect through our website, the DoorLink mobile app, and the intercom modules installed in your building, and how we use, store, and protect it.

1. What data we collect

Account and building

When you create an account in the app (verified through Firebase Authentication) we store your name and email address, your assigned unit and building, your role (admin, technician, or resident), and, if a unit admin sets it up, your door-access permissions and schedule. We also record whether you've marked yourself as "away," and since when, to decide how to route calls.

Notifications

We store your device's push-notification token (FCM on Android; FCM/APNs/VoIP on iOS) so we can alert you when someone rings the intercom. We don't use these tokens for anything else.

Camera and microphone

During a video call, the app and the intercom module access your camera and microphone to stream live audio and video between the visitor and you, over a LiveKit server we run ourselves (not a third-party provider). That stream is live only — we never record or store call audio or video, anywhere in the system.

Visitor snapshot

When someone presses the intercom button, the module captures a single photo of the visitor and uploads it to our server so we can show it to you in the call notification. That photo is kept for 7 days and then automatically deleted. Viewing a call's photo requires a link signed specifically for that call; inside our staff dashboard, only the admin role can view it.

Device data (intercom module)

If you have a device-management role, we store technical data about the module installed in your building: MAC address, status, configuration, telemetry (temperature, CPU/memory usage, tamper-sensor state), and operating logs. Logs and telemetry are kept for 30 days. The module does not collect or transmit GPS location.

Website contact form

If you write to us through the site, we store the name, email, and message you enter (and, if submitted from the pricing calculator, your selected features) to answer your inquiry and put together a quote.

Diagnostic data

We may collect anonymous technical information about your device (app version, OS version, device model) to diagnose bugs and improve app stability. This information never includes your name, email, or any account identifier.

2. How we use your data

3. Who we share data with

We don't sell your personal data or share it for advertising purposes. We use the following outside providers, solely to run the service:

Video calls and remote support access to modules run on infrastructure we operate ourselves (self-hosted LiveKit and Headscale) — they never pass through third-party servers. We don't use third-party analytics, advertising, or tracking tools, on the website or in the app.

If we ever add a new integration that involves sharing personal data with a third party, we'll let you know and, where required, ask for your consent.

4. How long we keep your data

5. How we protect your information

Traffic between the app, website, modules, and our servers is encrypted (HTTPS/TLS; call audio and video use WebRTC encryption between participants). Module credentials are stored hashed, never in plain text, and are never exposed in any API response. Access to resident-identifying data (like a call's photo or a unit's member list) is role-restricted within our team. No system is 100% secure; we do our best to protect your information, but using the service means accepting that reasonable risk.

6. Your rights

You can ask us at any time to:

To exercise these rights, email us at [email protected]. We'll review and act on your request manually within a reasonable time.

7. Minors

The app and website may be used by people 18 or older, or by minors under the supervision of an adult responsible for the account.

8. International transfers

Some of our providers (Google Firebase, Apple) may process data on servers located outside Argentina. These providers maintain their own security and data-protection standards.

9. Changes to this policy

We may update this policy from time to time. Changes are posted on this page along with the "last updated" date, and take effect once published.

10. Contact

IBALTON S.A.S. — CUIT 30-71750823-4
City of Buenos Aires, Argentina
Email: [email protected]
Phone/WhatsApp: +54 11 3465-2325