Last updated: 21 May 2026
1. Who operates this website
This website is operated by DoorWay. Until a company is formally registered, the service may be operated by an individual acting as the data controller for enquiries submitted through this website.
Controller contact: add your legal name, country, business address if applicable, and contact email before publishing final production copy.
2. What personal data we collect
When you contact us or request a demo, we may collect your name, email address, company or building details, country, number of sites or doors, message content, IP address, user agent, submission time, and security information needed to prevent spam or abuse.
If you later become a customer or pilot user, additional service data may be processed inside the DoorWay application, such as users, tenants, access cards, access policies, audit logs, and door event logs. That processing should be covered by a separate customer agreement or data processing agreement when the service is used for real buildings.
3. Why we use the data
- To respond to demo requests and messages.
- To discuss installation, support, pilot projects, or commercial terms.
- To protect the website from spam, abuse, and security incidents.
- To keep records needed for legal, tax, accounting, or dispute purposes if a business relationship starts.
4. Legal bases under GDPR
We rely on legitimate interests to respond to business enquiries and protect the website, contract steps when you ask about a service or pilot, consent where you specifically opt in to optional communications, and legal obligation where records must be kept under applicable law.
5. Cookies
This website currently uses only necessary first-party session cookies for security, CSRF protection, form handling, and rate limiting. These cookies are required for the website to work and do not require separate consent.
We do not currently use Google Analytics, advertising pixels, profiling cookies, or third-party tracking cookies on the public website. If optional analytics or marketing cookies are added later, the website should ask for consent before setting them and provide an easy way to refuse or withdraw consent.
6. Sharing and processors
We may use hosting, email, database, security, backup, and infrastructure providers to operate the website and respond to enquiries. They process data only as needed to provide those services. We do not sell personal data.
7. International transfers
Some providers may process data outside the European Economic Area. Where this happens, appropriate safeguards should be used, such as adequacy decisions, Standard Contractual Clauses, or equivalent lawful transfer mechanisms.
8. Retention
Contact enquiries are kept only for as long as needed to respond, follow up, and maintain reasonable business records. Security logs may be kept for a limited period to protect the website. Customer operational data, if any, should follow the retention settings and agreement for the relevant building or customer.
9. Your rights
If you are in the European Economic Area, you may have the right to request access, correction, deletion, restriction, portability, objection, and withdrawal of consent where processing is based on consent. You may also lodge a complaint with your local data protection authority.
10. Changes
We may update this policy when the service, legal requirements, or processing activities change. The updated date above shows the latest version.