Privacy Policy
Effective 2026-__-__
This policy explains what personal data Open House collects, why, who can see it, and how long we keep it. It reflects what the system actually stores.
1. What we collect
Account data: name, email address, phone number, password (stored hashed, never in readable form), preferred language, and — if you connect Telegram — your Telegram account identifier and username.
Tenant records: legal name (in up to four scripts), display name, nationality, phone, email, occupation, employer, and notes recorded by your property manager.
Identity documents: for tenants, the document type, the document number (stored encrypted), and an image of the document. Access is restricted and, by default, granted only temporarily.
Landlord and owner records: legal name, nationality, contact details, entity type (individual or company), and — where local practice separates them — the registered title holder and the person authorised to sign.
Sale transaction parties: name, company name, passport number, nationality, contact details, and any power-of-attorney document.
Agent records: profile, phone, Telegram username, service areas, languages, verification level, and reputation indicators.
Referrer records: name, phone, and payout account details used to record referral rewards.
Property and tenancy records: leases, charges, payments, receipts, settlements, expenses, and property tax status by unit and year.
Viewing evidence: GPS check-in coordinates, timestamps, entry and exit photographs, one-time codes, and a snapshot of the consent text you agreed to at the time.
Uploaded files and voice messages, including transcripts produced from them.
Technical data: IP address and timestamps for sign-in sessions and password resets, and an audit trail of administrative actions.
2. Why we use it
To operate tenancies and sales: to produce contracts, invoices, receipts, and settlements, and to keep an accurate financial record.
To route enquiries and viewings between the right people, and to attribute referrals and commissions.
To establish accountability for property access — viewing evidence exists so that it is clear who entered a property, when, and with whose consent.
To verify identity where a transaction or a management mandate requires it.
To send operational notifications, such as payment reminders and expiry notices.
To detect misuse and to keep an audit trail.
3. Automated processing
Uploaded documents and voice messages are sent to third-party AI providers for reading, transcription, or translation. Untrusted text is isolated before processing so that it cannot issue instructions to the system.
Automated output never authorises a financial action on its own. A person confirms before anything is written to a ledger, confirmed, or sent.
4. Who can see your data
Data is separated by organisation. Staff of one company cannot see another company's records; this is enforced at the database level as well as in the application.
Within an organisation, visibility depends on role. Assistants see contact fields masked. Counterparty agents see masked contact details until a reveal is requested and approved, and approvals expire.
Landlords see records for their own units. Tenants see their own tenancy. Buyers see their own purchase.
We share data with service providers who host the system, store files, send messages, and provide AI processing. We do not sell personal data.
We disclose data to authorities only where legally required.
5. International transfer
The service is hosted outside Cambodia, and AI and messaging providers may process data in other countries. By using the service you accept that your data is processed abroad.
6. How long we keep it
Financial and audit records are retained for the period set by your organisation's policy — seven years by default — because they are business records and may be needed to resolve a dispute.
Viewing evidence and identity documents are kept for as long as needed for the transaction and any dispute period, then removed.
Backups are taken daily and rotated; deleted data may persist in backups until they age out.
7. Your choices
You can ask to see the personal data we hold about you, to correct it, or to have it deleted where we are not required to keep it.
You can turn off non-essential notifications. Operational messages about your tenancy or transaction cannot be turned off while it is active.
To make a request, contact your property manager, who can escalate it to us.
8. Security
Passwords are hashed. Identity document numbers are encrypted. Access is restricted by role and by organisation. Administrative access to sensitive fields is logged.
No system is perfectly secure. If a breach affects your data, we will tell you.