Privacy policy
How ResidenceSafe collects, uses, and protects your personal data in compliance with Andorran and European data protection standards.
Contents
- Data Controller
- Scope and Application
- Data We Collect
- Legal Bases for Processing
- Purposes of Processing
- Location Data and Biometric Data
- In-App Purchases and Payment Data
- Third-Party Services
- Data Retention
- International Data Transfers
- Your Rights
- Children and Minors
- Cookies and Tracking
- Security Measures
- Data Breach Notification
- Changes to This Policy
- Contact
1. Data controller
The data controller responsible for your personal data is:
RJ Digital HUB SLU (commercial brand: Undercoverlab, also stylized UndercoverLab / Ulab)
C/ de la Sardana 3, altell escala B
AD500 Andorra la Vella
Principality of Andorra
NRT (Tax Registration Number): L-713047-Z
Phone: +376 861 092
DPO: dpo@residencesafe.com
Support: hello@residencesafe.com
General: hello@residencesafe.com
2. Scope and application
This Privacy Policy applies to the ResidenceSafe mobile application (iOS and Android), the website residencesafe.com, and any related services (collectively, the "Service"). It governs how we collect, use, store, and protect your personal data.
This policy is drafted in compliance with:
- Andorran Qualified Law 29/2021 on the protection of personal data (LQPD), effective May 17, 2022, which replaced Law 15/2003 and aligns with the EU General Data Protection Regulation (GDPR).
- Regulation (EU) 2016/679 (GDPR), applicable due to Andorra's EU adequacy decision.
- Apple App Store Guidelines (Section 5.1, Privacy) and Apple's App Privacy requirements for apps distributed via the App Store.
- Google Play Developer Program Policies on user data and privacy.
3. Data we collect
We collect the following categories of personal data:
3.1 data you provide directly
| Data type | Examples |
|---|---|
| Account information | Email address, display name, password (hashed) |
| Profile data | Nationality, country of residence |
| Support communications | Messages, attachments sent to our support channels |
3.2 data collected automatically
| Data type | Examples |
|---|---|
| Precise location data | GPS coordinates at the time of each check-in |
| Device information | Device model, OS version, unique device identifiers |
| Usage data | Check-in frequency, feature usage, session duration |
| Biometric verification data | Facial recognition data used locally to verify identity during check-in (processed on-device only, never transmitted to our servers) |
| Network information | IP address, Wi-Fi network identifiers (for location corroboration) |
3.3 data from third parties
| Source | Data type |
|---|---|
| Apple / Google (in-app purchases) | Purchase receipt, subscription status, transaction ID. We do not receive your payment card details. |
| Authentication providers | If you use social login (Apple Sign In, Google Sign In): email, name, unique identifier |
4. Legal bases for processing
Under Article 6 of the LQPD 29/2021 and Article 6 GDPR, we process your data on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service (check-ins, reports) | Performance of contract (Art. 6.1.b) |
| Processing payments via Apple/Google | Performance of contract (Art. 6.1.b) |
| Location verification and certification | Explicit consent (Art. 6.1.a) |
| Biometric processing (facial recognition) | Explicit consent (Art. 6.1.a / Art. 9.2.a) |
| Fraud prevention and security | Legitimate interest (Art. 6.1.f) |
| Legal compliance (tax records, audit) | Legal obligation (Art. 6.1.c) |
| Marketing communications | Explicit consent (Art. 6.1.a), revocable at any time |
| Analytics and service improvement | Legitimate interest (Art. 6.1.f) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.
5. Purposes of processing
We process your personal data for the following specific purposes:
- To create and manage your account and authenticate your identity.
- To perform location check-ins and generate certified proof-of-presence records.
- To produce eIDAS-aligned reports (PDF, CSV) documenting your residency history.
- To manage subscriptions (Free, Premium, PRO) and process in-app purchases through Apple App Store and Google Play.
- To provide multi-country monitoring and 183-day residency tracking.
- To issue blockchain immutability certificates (PRO plan).
- To respond to support inquiries and resolve technical issues.
- To send transactional communications (payment confirmations, subscription changes).
- To send marketing communications (only with your explicit consent).
- To detect and prevent fraud, misuse, or unauthorized access.
- To comply with applicable laws, regulations, and legal proceedings.
- To improve the Service through aggregated, anonymized analytics.
6. Location data and biometric data
ResidenceSafe is a location-verification service. The collection of precise location data is essential to its core functionality.
6.1 location data
We collect GPS coordinates each time you perform a check-in. This data is used to generate certified proof of your physical presence at a specific location and time. Location data is collected only during active check-ins. We do not track your location in the background or continuously.
You may revoke location permissions at any time through your device settings, though this will prevent the core check-in functionality from working.
6.2 biometric data
Residence Safe processes biometric data in two distinct contexts that you should understand separately:
(a) Device-level biometrics for app access. If you enable biometric unlock for the Residence Safe app, your device uses Apple Face ID / Touch ID or Google BiometricPrompt to authenticate you. Biometric templates created for this purpose are managed entirely by your operating system, never leave your device, and are not accessible to Residence Safe or to any third party.
(b) Identity verification (KYC) at registration and selected check-ins. To deliver verifiable proof of presence at eIDAS HIGH assurance level, Residence Safe integrates the verification platform operated by Didit (see Section 8). During an identity verification flow, the Didit SDK captures, on your device, an image or short video of your face for liveness analysis and an image of your identity document. These media files and associated technical signals (device telemetry, liveness vectors, document OCR/MRZ data) are transmitted to Didit's verification infrastructure for processing. Didit acts as our Data Processor under Article 28 GDPR for these operations. The legal basis is your explicit consent under Article 9.2.a GDPR. You may withdraw this consent at any time by contacting dpo@residencesafe.com, but doing so will limit your access to certified check-in functionality, which depends on verified identity.
Biometric data processed by Didit is retained according to Didit's documented retention policy and our configured retention settings, and is deleted, anonymised or securely destroyed once the verification purpose has been fulfilled and any applicable legal retention period has expired.
7. In-App purchases and payment data
ResidenceSafe offers subscription plans (Premium and PRO) through in-app purchases managed by Apple App Store and Google Play Store.
- We do not collect, process, or store your credit card, debit card, or bank account information. All payment processing is handled directly by Apple and Google.
- We receive from Apple/Google: purchase receipt data, subscription status, transaction identifiers, and your country or region of residence (for tax purposes, including Andorran IGI at 4.5%).
- Apple creates a Subscriber ID unique to you and our developer account. This ID is used for subscription management and is not linked to your Apple ID.
- Refund and cancellation requests for in-app purchases must be directed to Apple or Google, as they are the merchants of record.
For details on how Apple processes your payment data, see Apple's App Store & Privacy. For Google, see Google's Privacy Policy.
8. Third-Party services
We share personal data with the following categories of third parties, all of which provide equivalent data protection as required by the LQPD 29/2021:
| Service | Purpose | Data shared |
|---|---|---|
| Apple Inc. / Google LLC | Payment processing, app distribution | Purchase receipts, subscription status |
| Didit (Didit Identity Spain SL + Didit Identity, Inc.) | Identity verification, liveness detection, document authentication, AML screening, and fraud prevention at eIDAS HIGH assurance level prior to issuing certified check-ins. | Selfie image and short video for liveness, identity document image, document metadata (OCR/MRZ), liveness and anti-spoof signals, device and network telemetry (including IP address), and verification outputs. |
| Cloud hosting provider | Data storage and processing | Encrypted account and check-in data |
| Blockchain network (PRO plan) | Immutability certification | Anonymized check-in hash (no personal data) |
| Analytics provider | Aggregated usage statistics | Anonymized usage data, device type, OS version |
| Email service provider | Transactional and marketing emails | Email address, name |
About Didit (identity verification provider). "Didit" refers to Didit Identity Spain SL (CIF B22929327, Calle Napoles 227, P. 1, 08013 Barcelona, Spain) and its US affiliate Didit Identity, Inc. (1111B S Governors Ave STE 34855, Dover, DE 19904, USA). Didit acts as our Data Processor under Article 28 GDPR for identity verification, liveness detection, document authentication, AML screening and fraud prevention, and as Independent Controller for limited purposes including audit logging and legal claims. Data may be transferred from the European Economic Area to the United States; such transfers are protected by Standard Contractual Clauses under Article 46 GDPR. Didit holds ISO 27001 certification and iBeta Level 1 certification for presentation attack detection. For full details, see Didit's Verification Privacy Notice and Privacy Policy. Didit's Data Protection Officer: dpo@didit.me.
We do not sell your personal data to any third party. We do not share your personal data with third-party AI services without your explicit consent, in accordance with Apple's App Review Guidelines (Section 5.1.1).
9. Data retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law:
| Data category | Retention period |
|---|---|
| Account data | Duration of your account + 30 days after deletion request |
| Check-in and location records | Duration of your account + 5 years (legal documentation purposes) |
| Payment/transaction records | 7 years (Andorran tax and accounting obligations) |
| Support communications | 2 years after resolution |
| Marketing consent records | Duration of consent + 3 years |
| Anonymized analytics | Indefinitely (no personal data) |
When the retention period expires, data is securely deleted or irreversibly anonymized.
10. International data transfers
Your data is primarily stored and processed within the European Economic Area (EEA) and Andorra. Andorra benefits from an EU adequacy decision, meaning personal data can flow freely between the EU/EEA and Andorra.
Where data is transferred to countries outside the EEA that do not benefit from an adequacy decision (e.g., to Apple Inc. or Google LLC in the United States), we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- The recipient's participation in recognized certification mechanisms.
You may request information about the specific safeguards applied to your data by contacting us at dpo@residencesafe.com.
11. Your rights
Under the LQPD 29/2021 and the GDPR, you have the following rights regarding your personal data:
- Right of access: Obtain confirmation of whether your data is being processed and access a copy of it.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request deletion of your data when it is no longer necessary for the purposes for which it was collected, or when you withdraw consent.
- Right to restriction of processing: Request that we limit the processing of your data under certain circumstances.
- Right to data portability: Receive your data in a structured, commonly used, and machine-readable format (JSON, CSV).
- Right to object: Object to processing based on legitimate interests, including profiling.
- Right to withdraw consent: Withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at dpo@residencesafe.com. We will respond within 30 calendar days as required by law.
Account deletion: You may delete your account directly within the app (Settings > Delete Account). In compliance with Apple's App Store Guideline 5.1.1(v), account deletion is available as a self-service feature. Upon deletion, your data will be erased within 30 days, except where retention is required by law (see Section 9).
Right to lodge a complaint: You have the right to file a complaint with the Andorran Data Protection Agency (APDA):
Agencia Andorrana de Proteccio de Dades (APDA)
C/ Prat de la Creu 59-65, Edifici Montclar, planta 3
AD500 Andorra la Vella
Website: www.apda.ad
12. Children and minors
ResidenceSafe is not intended for individuals under the age of 16. We do not knowingly collect personal data from minors under 16 years of age.
In accordance with the LQPD 29/2021, processing of personal data of minors under 16 requires the consent of a legal representative. If we become aware that we have collected data from a minor without proper authorization, we will delete it promptly.
If you believe a minor has provided us with personal data, please contact us at dpo@residencesafe.com.
13. Cookies and tracking technologies
The ResidenceSafe website (residencesafe.com) uses cookies and similar technologies. The mobile application does not use cookies.
Types of cookies used on the website:
| Type | Purpose | Duration |
|---|---|---|
| Essential / Technical | Session management, security, CSRF protection | Session |
| Analytics | Anonymized usage statistics to improve the website | Up to 13 months |
| Preferences | Remember language and display preferences | 12 months |
Non-essential cookies are only activated after you provide consent through our cookie banner, in accordance with the APDA's cookie guidelines and Consent Mode v2.
14. Security measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Hashed and salted password storage.
- Role-based access control for internal systems.
- Regular security audits and vulnerability assessments.
- On-device biometric processing (no server-side biometric storage).
- Blockchain-based tamper-proof records for PRO plan users.
15. Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Andorran Data Protection Agency (APDA) within 72 hours of becoming aware of the breach, as required by Article 33 of the LQPD 29/2021.
Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, providing clear information about the nature of the breach, the likely consequences, and the measures taken or proposed.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Service. When we make material changes:
- We will update the "Last updated" date at the top of this page.
- We will notify you via email or in-app notification at least 30 days before the changes take effect.
- Where required by law, we will obtain your renewed consent before applying changes that affect the legal bases of processing.
17. Contact
For any questions, concerns, or requests related to this Privacy Policy or the processing of your personal data, contact us at:
RJ Digital HUB SLU, Data Protection
Email: dpo@residencesafe.com
Phone: +376 861 092
Address: C/ de la Sardana 3, altell escala B, AD500 Andorra la Vella, Andorra
We will respond to all data protection requests within 30 calendar days.