1. Who we are
Domakin (“the platform”) is a service for administering residential rentals: leases, manual tracking of rent payments, expenses, deposits, manager commission, indicative tax estimates, reminders, and meter readings. The platform is used by property owners, managers, and tenants and is self-hosted on servers in the European Union. Domakin does not process payments — rent is marked as paid manually.
2. Roles under the GDPR
- Processor: for tenant personal data and lease data that owners and managers enter into the platform, Domakin acts as a processor. The controller of that data is the respective landlord (the property owner), who determines the purposes and means of the processing.
- Controller: for user account data (email address, name, settings, sessions, security records) the platform operator is the controller.
3. What data we process
- Account data — email address, name, language and notification settings, session and device data.
- Tenant identity data — names, phone, email, ЕГН (Bulgarian personal identification number), ID document number, and scanned copies of ID documents. ЕГН, document numbers, and scans are stored with field/object-level encryption; access to them is audit logged.
- Financial records — rent months and payments (marked manually), expenses, commission statements, owner–manager cash ledger entries, deposits.
- Photos — meter photos and task photos.
- Notification data — device push subscriptions and delivery records for notifications (push and email).
4. Lawful bases
| Processing | Lawful basis |
|---|---|
| Leases, rent months and payment tracking; tenant ID document data | Performance of a contract (Art. 6(1)(b) GDPR) |
| Uploading scanned ID documents | Explicit consent, recorded at the moment of upload (Art. 6(1)(a)) |
| Retention of financial records for accounting and tax purposes | Legal obligation (Art. 6(1)(c)) |
| Security audit logs and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
5. Retention periods
Retention windows are platform configuration; the values below are the defaults. Automated purges are performed by a system job and are audit logged.
| Data | Retention |
|---|---|
| Financial records (rent months, expenses, commission, cash ledger, deposits) | 10 years after account deletion, counted from the year of each record; kept anonymized until then, hard-deleted afterwards |
| Other lease documents (contract, handover protocol) | 5 years after the lease ends |
| Scanned ID documents | 1 year after the lease ends, or immediately upon an erasure request — whichever comes first |
| Meter and task photos | 3 years after submission; numeric readings remain with the property history |
| Notification delivery records | 12 months |
| Audit log | 5 years; entries recording administrative access — 10 years |
6. Your rights and how to exercise them
You have the rights of access, rectification, erasure, restriction of processing, data portability, and objection, as well as the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP).
- Data export (portability): from Settings → Account (
/settings/account) you can download a full export of your data as a ZIP archive of structured files and attached documents. - Account deletion: from the same screen. Deletion follows the retention periods in section 5; an export is offered first.
- Tenants: your profile data in a landlord’s portfolio is managed by that landlord as controller — to have your profile erased, contact your landlord or manager. Erasure is refused while the profile is linked to an active lease (contract necessity).
7. Where your data is stored
All data, including backups, is stored on servers in the EU/EEA. We do not transfer personal data to third countries and we do not sell personal data.
8. Security
- Encryption in transit (TLS) and at rest.
- Additional field/object-level encryption for ЕГН, document numbers, and document scans.
- Sensitive actions (access to personal data, exports, permission changes) are recorded in an audit log.
9. Changes to this policy
We will notify you through the platform of any material changes. The current version is always available on this page.
10. Contact
Questions and requests regarding this policy can be addressed to the platform operator at no-reply@myhub.io.