Melduno
Melduno

Privacy policy

Information about the processing of personal data on the Melduno websites and in the closed beta.

Last updated: 6 August 2026

Closed beta

Melduno is not yet offered publicly as a paid service. Features and providers may change during testing. Beta participants will be informed of material changes.

Data controller

Data controller
Mateusz Paradiuk — owner and operator of Melduno
Controller address
The full service address will be published before the public launch.
Privacy contact
beta@melduno.com

1. Scope and allocation of responsibility

This policy covers melduno.pl, melduno.de and melduno.com and the closed beta application at beta.melduno.de.

The Melduno operator is responsible for the website, beta accounts, security, direct support, billing and platform development. Where a property owner, manager or service company enters data about its tenants, customers or employees and determines the purpose of that use, that organisation may be a separate controller. Melduno then handles the data only as required to provide the service. A processing agreement under Article 28 GDPR will be made available before public B2B production use.

2. Categories of data

  • technical data: IP address, request time, requested address, browser and device information, and data needed for abuse prevention and fault diagnosis;
  • account and security data: name, email, role, organisation, invitation status, sign-in history, encrypted or hashed credentials, 2FA settings and sessions;
  • property and report data: property and address, unit, issue description, category and urgency, appointments, status, reporter contact details, contractor, photos and messages;
  • Melduno Match and the company directory: profiles, trades, service area, contact details, listings and responses; some public company profiles may originate from Overture Maps;
  • Melduno Business: customer and employee data, work plans, job addresses, calendar, time records, reports, photos, defects, customer signature and the email address used for the report copy;
  • support and beta data: request content, contact email, optional phone number, response history, feedback, rating and the page concerned;
  • payment data where used: order, customer name, email, amount, currency, method, status and transaction identifier. Melduno does not store full card numbers or CVC codes.

3. Purposes and legal bases

  • providing accounts, reports, jobs, bookings and Business features — Article 6(1)(b) GDPR or delivery of the service for the user's organisation;
  • security, abuse prevention, operational records, development and stability — Article 6(1)(f) GDPR; the legitimate interest is a secure and reliable platform;
  • accounting, billing and legal obligations — Article 6(1)(c) GDPR;
  • optional WhatsApp or Telegram notifications and other clearly optional features — Article 6(1)(a) GDPR; consent may be withdrawn for the future;
  • pre-contract enquiries and general contact — Article 6(1)(b) or (f) GDPR, depending on the request.

4. Recipients and service providers

Data is available only to people and organisations that need it for the relevant case and to technical providers to the extent required.

  • Contabo — VPS hosting and backups in a European data centre;
  • OVHcloud / Zimbra — email delivery and receipt;
  • OpenStreetMap Nominatim — converting country, postcode and city into coordinates for local company searches;
  • Overture Maps Foundation — a source of public directory data, not a recipient of report data;
  • Mollie or Stripe — only when a payment handled by that provider is started;
  • Meta (WhatsApp Business Platform) or Telegram Bot API — only after the channel is enabled; only short notices and a protected link are sent, not full chat content, photos or reports;
  • OpenAI — only when AI support is enabled and the approved knowledge base is insufficient; the current question and limited recent conversation may be sent. Passwords, 2FA codes, card details and unnecessary sensitive information must not be entered;
  • the property manager, owner, service company, assigned employee or customer — only as authorised and for the relevant report or job.

5. Transfers outside the EEA

Melduno's primary infrastructure is in Europe. Optional providers such as OpenAI, Meta, Telegram or Stripe may process data outside the European Economic Area. Those features are used only when configured. Any transfer is based on an appropriate Chapter V GDPR mechanism, particularly an adequacy decision or the EU Standard Contractual Clauses. The controller can confirm the providers currently active on request.

6. Retention

  • sign-in sessions expire after 7 days, activation links after 24 hours and password reset links after 30 minutes;
  • technical request limits are cleaned regularly, while security logs are kept only for as long as needed to detect abuse, investigate an incident or defend claims;
  • messages with a selected lifetime are deleted after 24 hours, 7 days or 30 days; messages without an expiry remain part of the case history;
  • accounts, reports, photos, job documentation and Business data are kept during the test or service and then until the matter is closed, the account is deleted or the applicable claims period ends;
  • accounting and transaction evidence is retained for statutory tax and commercial record-keeping periods;
  • backups rotate and are normally deleted after 14 days. Deleted data may remain in a protected backup until then and is restored only for disaster recovery.

7. Cookies and device storage

Melduno does not currently use advertising or third-party analytics cookies. It uses the technically necessary protected melduno_session cookie and local preferences for language, market, text size, font mode and the most recent company-search area. These are used only for sign-in and features expressly requested by the user. Any future non-essential tools will be enabled only after the required consent.

8. Data from public sources

Public company profiles may come from the Overture Maps Foundation. Where available, this includes the name, activity, address or area, coordinates, website, telephone number and source metadata. The basis is the legitimate interest in an up-to-date service directory under Article 6(1)(f) GDPR. Profiles are marked as public and unverified. A person or company may request correction, labelling or removal through the privacy contact.

9. Individual rights

Subject to the GDPR, individuals may request access, rectification, erasure, restriction, portability, object to legitimate-interest processing and withdraw consent for the future. Requests can be sent to the privacy contact. A complaint may also be made to the supervisory authority for the individual's residence, workplace or the alleged infringement. The German state authority responsible for the operator will be determined by the service address published before launch.

10. Required data and automated decisions

Fields marked as required are needed for the account or selected process. Without them that feature may not work. Phone numbers, messenger connections and some profile details are optional.

Rules-based initial assessment and AI support are assistive only. They do not produce legal effects or make binding decisions based solely on automated processing. Uncertain or sensitive support questions are referred to a person.

11. Security and changes

Measures include TLS transport encryption, role-based access, password and token hashing, 2FA for privileged accounts, request limits and rotating backups. The current beta chat is stored on the server and visible to authorised case participants; it is not yet protected by full end-to-end encryption.

This policy may change as Melduno develops or the law changes. The current version will remain available at this address and beta participants will be informed of material changes.

Legal notice
© 2026 Melduno. All rights reserved.Back to the home page