Security & Privacy

Art.1

Security

Openr strives to be as transparent as possible. This document provides insight into the security aspects that have been carefully considered in the development of Openr’s products. Openr is a secure and personal intercom and access control system that enables access and management within the office environment. Both Openr’s hardware and software are developed with great care and always comply with the most up-to-date security protocols. This document provides a clear overview of the security measures based on the theme: Account and Access.

Art. 2

Account

Authentication
Authentication uses HTTPS and personal account credentials as the authentication and access mechanism. Passwords are never stored.

Personal Data
Openr registers the following personal data: first and last name, email address, and phone number. These details are never shared with third parties or stored elsewhere in any form. The data is visible only to the individual user, the Openr administrator, and the administrator of the specific project (building). The user always retains ownership of their data and has the ability to delete or modify it. This also means the data is deleted when the project contract expires.

Passwords
User-specific, case-sensitive passwords used to access the Openr account are not visible to Openr or the project administrator. Passwords are encrypted using modern algorithms that comply with the latest industry standards. The password remains the property of the respective individual or company at all times.

Units / Tenants
At the tenant level (units), within the Openr admin environment, tenant/company names and corresponding phone numbers (including an optional backup number) are stored. This data belongs to the tenant(s) and can be modified or deleted at any time. The data is also removed when the project contract ends.

Art.3

Access

Access includes not only the operation and security surrounding access control but also usage data and company information that may be displayed on the intercom or in the admin dashboard.

Access Token
Communication between the user’s (mobile) network and the Openr server is encrypted (AES256) and results in a specific token that can only be used by the requesting user.

Admin / Management
Access to the admin environment (openr.nl/admin) is protected by authentication using HTTPS and personal account credentials. Passwords are never stored.

Activity
User activity involving Openr products is not stored and is only visible for 30 days to users with a manager/admin profile or higher.

Art.4

Third Parties

Privacy and Security Policies of Openr Suppliers

  • Web hosting: Google Cloud Platform

  • Server: Container-Optimized OS (Linux)

Art.5

Privacy Policy

Openr B.V.
Openr B.V., located at Bos en Lommerplein 270-300, 1055RW Amsterdam, is responsible for the processing of personal data as stated in this privacy statement.

Contact Information
www.openr.nl
Bos en Lommerplein 270-300
1055RW Amsterdam
+31 (0)85 1301 799

Data Protection Officer: Jop Japenga

Personal Data We Process

Openr B.V. processes your personal data because you use our services and/or because you have provided this data to us. At the bottom of this document, you will find an overview of the personal data we process, along with an explanation of:

  • what we do with it (processing),

  • why we do it (purpose),

  • on what legal basis (lawful grounds),

  • what categories of data we store,

  • with whom we may share it (third parties),

  • and how long we keep it (retention period).

These terms apply to all the aforementioned data processing activities.

Special and/or Sensitive Personal Data

Our website and/or service does not intend to collect data from visitors under the age of 16, unless they have parental or guardian consent. However, we cannot verify the age of our visitors. We encourage parents to be involved in their children’s online activities to prevent data from being collected without parental consent. If you believe we have collected personal information about a minor without proper consent, please contact us at service@openr.nl and we will delete the information.

Purposes and Legal Grounds for Processing Personal Data

Openr B.V. processes your personal data for the following purposes:

  • Processing payments

  • Sending newsletters and/or marketing materials

  • Contacting you via phone or email when necessary to provide our services

  • Informing you about changes to our products and services

  • Enabling account creation

  • Delivering goods and services to you

  • Analyzing your behavior on the website to improve it and tailor content and offerings to your preferences

  • Meeting legal obligations, such as tax filing requirements

Sharing Personal Data with Third Parties

Openr B.V. does not sell your data to third parties and only shares it when necessary for executing our agreement with you or to comply with a legal obligation. We sign a data processing agreement with companies that process data on our behalf to ensure the same level of security and confidentiality. Openr B.V. remains responsible for these processing activities.

Automated Decision-Making

Openr B.V. does not make decisions based on automated processing that could have significant consequences for individuals. This refers to decisions made by computer programs or systems without human intervention.

Cookies and Similar Technologies

Openr B.V. uses functional, analytical, and tracking cookies. A cookie is a small text file stored in your browser upon first visit to our website. Openr B.V. uses cookies for the proper functioning of the site and to remember user preferences. They also help us optimize the site and tailor content and advertisements.

You were informed about these cookies during your first visit and asked for your consent.

You can opt out of cookies by configuring your browser to not store them, and you can delete all previously stored information via your browser settings. For more info:
https://veiliginternetten.nl/themes/situatie/cookies-wat-zijn-het-en-wat-doe-ik-ermee/

Cookies from third parties (e.g., advertisers or social media platforms) may also be placed.

Viewing, Modifying or Deleting Data

You have the right to access, correct, or delete your personal data. You also have the right to withdraw your consent or object to the processing of your data by Openr B.V. Additionally, you can request the transfer of your data to yourself or another organization.

Requests can be sent to service@openr.nl. To verify your identity, please attach a copy of your ID with your request. Redact your photo, MRZ (machine-readable zone), passport number, and citizen service number (BSN) to protect your privacy. We will respond as soon as possible, but within 4 weeks.

You may also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons

Door opening and intercom usage logs are kept for no longer than 30 days and are automatically deleted thereafter.

How We Secure Your Data

Openr B.V. takes your data security seriously and implements appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure, and unauthorized modifications. If you believe your data is not properly secured or suspect misuse, please contact our customer service.

We have taken the following security measures:

  • Security software such as antivirus and firewalls

  • TLS (formerly SSL): We send your data over a secure internet connection (visible by the “https” and padlock icon)

  • DKIM, SPF, and DMARC to prevent phishing or spoofing in emails

  • HTTPS for authentication and access to personal accounts

  • AES256 encryption for securing the database storing personal data

  • Modern encryption algorithms that comply with current industry standards