‹ Back to home

Privacy Policy

Last updated:

This Privacy Policy explains how we process your personal data when you use the EZYsmart website or contact us. We process data in accordance with the General Data Protection Regulation (GDPR) and Estonian law.

1. Data controller

The data controller is Innovate Invest OÜ (registry code 14504365), Asuvere tee 7, Tihemetsa alevik, Saarde vald, Pärnumaa 86201, Eesti. For data-protection matters, email support@ezysmart.cc or call +372 52 888 46.

2. What data we collect

We collect only the data needed to provide the service and respond to enquiries:

  • Contact details you provide in the quote or contact form: name, email address, areas of interest and the content of your message.
  • The content of your communication if you email or call us.
  • Technical data generated when you visit the website: IP address, device and browser type, pages visited and approximate country. We use these for security, statistics and to keep the site working.

3. The EZYsmart app (smart-lock and management app)

When you use the EZYsmart app (Android, iOS or desktop), we additionally process the following data needed for the app to work:

  • Account data: email address (required), and name and phone number (optional) — to create your account, sign you in and contact you. We never store your password itself, only an encrypted (bcrypt) hash of it.
  • Push notification identifier: to deliver critical notifications (such as a low-water-level or booking reminder) we store your device’s Firebase Cloud Messaging (FCM) registration token. FCM is provided by Google.
  • Activity log: door open/lock events (device, action, method) as a security audit trail. The log contains no location and no message content.
  • Error and performance data: to keep the app stable we collect crash and performance reports through the processor Sentry.

Location — used on your device only. If you enable auto-open, the app uses your precise (GPS) and approximate (WiFi network name) location solely on your device to detect whether you are inside a configured geofence or connected to a configured WiFi network. Location is matched on-device and then discarded; geofence settings are stored only in your device’s local storage. We do not transmit or store your location on our servers, and the door audit log records only the method, never coordinates.

Deleting your account or data: email support@ezysmart.cc. The account is soft-deleted (marked as deleted); before deletion we verify that no device would stop working for other users as a result. The push-notification token can be removed at any time. All app data is encrypted in transit (HTTPS/TLS). We do not sell app data or share it for advertising, and the app contains no advertising identifiers.

4. Purposes and legal bases

  • Responding to enquiries and preparing quotes — taking steps at your request and our legitimate interest (GDPR Art. 6(1)(b) and (f)).
  • Preparing and performing a contract — contract (Art. 6(1)(b)).
  • Website security, error detection and statistics — legitimate interest (Art. 6(1)(f)).
  • Analytics and non-essential cookies — your consent (Art. 6(1)(a)), which you can withdraw at any time.
  • Meeting legal obligations such as accounting — legal obligation (Art. 6(1)(c)).

5. Cookies and analytics

We use cookies necessary for the site to work (such as your chosen language) and Google Analytics to measure visit statistics. Statistics help us improve the site. You can manage or block cookies in your browser settings; disabling essential cookies may limit how the site works.

6. Who we share data with

We do not sell your data. We share it only with trusted service providers (processors) who process it on our instructions:

  • website hosting and infrastructure (e.g. Vercel);
  • email delivery (e.g. Resend);
  • visit statistics (Google Analytics);
  • app push-notification delivery (Google Firebase Cloud Messaging);
  • app error and performance diagnostics (Sentry);
  • managing customer communication in our own system.

We may also disclose data to authorities where required by law.

7. Transfers outside the European Economic Area

Some service providers may process data outside the European Economic Area. In that case we ensure protection through appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, in line with the GDPR.

8. How long we keep data

We keep personal data only as long as needed for the purpose: enquiry and customer data for the duration of our business relationship and a reasonable period afterwards, and accounting records for the period required by law (generally 7 years). After that we delete or anonymise the data.

9. Your rights

You have the following rights regarding your personal data:

  • to access the data we process about you and receive a copy;
  • to have inaccurate data corrected or completed;
  • to have data erased or processing restricted in the cases provided by law;
  • to object to processing based on legitimate interest;
  • to receive your data in a portable format;
  • to withdraw any consent at any time, without affecting the lawfulness of prior processing.

To exercise these rights, email support@ezysmart.cc. We respond within one month at the latest.

10. Data security

We apply reasonable technical and organisational measures to protect data against loss, misuse and unauthorised access, including encrypted connections (HTTPS) and restricted access to data.

11. Complaints

If you believe your data is being processed in breach of your rights, please contact us first. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Tatari 39, Tallinn, aki.ee).

12. Changes

We may update this Privacy Policy from time to time. The version published on the website applies, and the revision date is shown at the top of the page.