At a glance
- You are the controller for what your desk records. Lobbero is the processor, and acts only on your documented instructions.
- No AI training on your data, ours or a vendor's. Contractual, not a setting.
- Breach notice to you within 48 hours, so you can meet your own 72-hour deadline under Article 33.
- Service data is hosted in the the European Union. Transfers out rely on Standard Contractual Clauses.
- On termination we delete or return everything within 90 days and give you a written removal record certifying it.
- An ID document photographed at the desk is never stored — the name is read and the image is discarded.
01 Parties & precedence
This Data Processing Agreement ("DPA") is between the Lobbero customer identified in the account ("Controller", "you") and Moxelle, Inc., a Delaware corporation, of 651 North Broad Street, Suite 206, Middletown, DE 19709, United States ("Processor", "Lobbero", "we").
It forms part of, and is incorporated into, the Terms of Service. Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails. Where a signed order form conflicts with this DPA on the same subject, the order form prevails.
In this DPA, "GDPR" means Regulation (EU) 2016/679 and, where it applies, the UK GDPR as retained in UK law. "Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Supervisory Authority" have the meanings the GDPR gives them. "Customer Personal Data" means Personal Data we process on your behalf under the Terms, described in Annex I.
02 Roles
You are the Controller — we are the Processor
For the operational records a building keeps in Lobbero — residents, visitors and guests, parcels, incidents, the daily log, shift handovers — you decide why the data exists and for how long, and we process it for you. Residents and visitors should bring a privacy request to you first; we help you answer it.
Where Lobbero is itself the Controller
For a smaller, separate set of data we decide the purposes and are the Controller: the account details of the people who administer Lobbero, billing information, our security and support records, and visitors to lobbero.com. That processing is governed by our Privacy Policy, not by this DPA.
We are not a joint controller with you, and neither of us is the other's agent.
03 Processing on your instructions
We process Customer Personal Data only to provide, secure and support the service, and only on your documented instructions. The Terms, this DPA, your configuration of the product, and the requests you make through it are those instructions in full.
We will not:
- process Customer Personal Data for our own purposes, including marketing or profiling;
- use it to train or fine-tune any machine learning or AI model, ours or a sub-processor's;
- sell it, or share it for cross-context behavioural advertising;
- combine it with another customer's data.
We may produce aggregated, de-identified statistics that cannot be attributed to you, a building or an individual, and use those to run and improve the service.
If we believe an instruction of yours would breach data-protection law, we will tell you and may pause that processing until it is resolved. If we are compelled by law to disclose Customer Personal Data, we will tell you first unless the law forbids it, and will disclose only what is legally required.
04 Personnel & confidentiality
Access to Customer Personal Data is limited to the people who need it to run or support the service, each under a duty of confidentiality that survives their engagement.
Support access to a customer's account is time-limited and audited: a grant stops working the moment it expires — not at the next sweep — and a record of it remains in the audit trail. Lobbero staff working in the internal admin console hold a separate, short-lived elevation that is logged in the same way.
05 Security measures
We implement and maintain the technical and organisational measures in Annex II, which are appropriate to the risk, taking account of the state of the art and the nature of the data a front desk records.
We may change a measure, but not in a way that materially reduces the overall level of security. Our Security & Trust page describes the same measures in narrative form, including the ones that are not in place yet.
06 Sub-processors
You give general authorisation for us to engage sub-processors. The current list is Annex III.
Before adding or replacing one we will give you at least 30 days' notice by email to your account owners and by updating Annex III. If you reasonably object on data-protection grounds within that period, we will work with you to find an alternative; if there is none, you may terminate the affected part of the service and we will refund the unused part of any prepaid period for it.
Each sub-processor is engaged under a written contract imposing obligations no less protective than this DPA, and we remain responsible to you for its performance.
07 Data subject rights
You can answer most requests yourself, from inside the product. Account → Privacy requests lets an owner find a person across visits, activities, parcels, resident records and staff accounts — including people who never had an account — and then export or erase what was found.
Two things about erasure that are worth knowing:
- It reaches the copies. Erasing a person also clears their name from earlier versions of an entry, the search index, handover name maps, AI summaries for that building, notifications that quoted the name, and invitations. A name inside a free-text note is redacted word by word; the rest of the note stays, because the note is also the building's record of an event.
- A shared record survives. Where a visit involved several people, erasing one removes that person and leaves the building's record of the visit intact.
Each request is recorded in the audit trail without the name in it. If a Data Subject comes to us directly, we will not respond on your behalf: we will tell them to contact you, and tell you, unless the law requires otherwise. Where you need help we cannot give through the product, we will provide reasonable assistance.
08 Personal data breach
We will notify you of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it — deliberately inside your own 72-hour Article 33 deadline, so that the time is yours rather than ours.
The notice will describe, as far as we know it at the time:
- what happened and when we became aware;
- the categories and approximate number of records affected;
- the likely consequences;
- what we have done to contain it and what we will do next;
- a contact point for follow-up.
We will update you as the picture changes, and will not delay a first notice to make it complete. We will not notify a Supervisory Authority or any Data Subject on your behalf unless you ask us to or the law requires us to; notifying regulators and individuals is the Controller's decision.
09 Assistance & impact assessments
We will give you the information you reasonably need to carry out a Data Protection Impact Assessment or to consult a Supervisory Authority about the processing described in Annex I — including the measures in Annex II, the sub-processor list, retention behaviour, and how the AI features work.
10 Return & deletion
You can export your records at any time during the subscription, in PDF and CSV, without asking us.
On termination we delete or return all Customer Personal Data within 90 days. Removal is verified: the process checks that no rows remain anywhere, including file storage and backups as they roll off, and reverses itself rather than leaving a partial deletion. It then produces a written removal record — your certificate, listing what was removed and when.
We keep data beyond that only where the law requires it (for example tax records of what you paid), and only that limited record. Backups are retained for a short, defined period and expire on their own cycle; a deletion request is not defeated by a backup, it is completed when the last copy of that cycle expires.
11 Audits & information
On reasonable written request, and no more than once a year unless a Supervisory Authority requires otherwise or there has been a Breach, we will provide the information you need to verify our compliance with this DPA: written answers to a security questionnaire, the measures in Annex II evidenced, and the sub-processor contracts' data-protection terms.
Where that is genuinely not enough for your regulator, we will cooperate with an audit on agreed scope, timing and confidentiality terms, during business hours, without disrupting the service or exposing another customer's data. You bear the cost of an audit you commission, unless it finds a material breach of this DPA.
The Processor will state its current certification and assurance status, and complete the Controller’s security questionnaire, on request; see Security & Trust. The Processor will not imply a certification it does not hold.
12 International transfers
Customer Personal Data is stored in the European Union.
Some sub-processors in Annex III are US-based, so a transfer out of the EEA or the UK can occur. Where it does, it is covered by the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum where the UK GDPR applies, or by an adequacy decision where one covers the recipient. Module Two (controller to processor) applies between you and us; Module Three (processor to processor) between us and our sub-processors.
Where the SCCs require a choice: the governing law and forum are those stated in the Terms; Clause 9 option 2 (general written authorisation, 30 days' notice) applies to sub-processors; the Annexes of the SCCs are Annexes I to III of this DPA. You can request a copy of the safeguards for a specific transfer at hello@lobbero.com.
13 AI processing
On plans including Lobbero IQ, log text is sent to our AI sub-processor at the moment a question is asked or a summary generated, and a photographed document or parcel label is sent at the moment it is scanned. That processing is:
- subject to a data-processing agreement with the provider including SCCs and an explicit no-training commitment;
- decision-support only. It produces no automated decision about a person within the meaning of Article 22, and no profiling for a purpose other than describing your own records;
- traceable — every answer cites the entries it came from, so you can verify it against the log.
For an ID document, the name is extracted and the image is discarded; it is never written to storage. A parcel tracking number is stored masked.
14 US state privacy laws
Where the CCPA/CPRA or a comparable US state law applies, you are the business and Lobbero is a service provider (or processor, in states using that term). We process Personal Information only to provide the service under the Terms, and we do not sell it or share it for cross-context behavioural advertising as those laws define those words. The obligations in this DPA apply to that Personal Information as they do to Personal Data, including the deletion and assistance provisions.
15 Liability & term
This DPA starts when the Terms do, and lasts as long as we process Customer Personal Data — the deletion obligation in §10 survives termination.
Each party's liability under this DPA is subject to the limitation of liability in the Terms, except where data-protection law makes such a limit unenforceable, in which case the law governs.
If a provision of this DPA is unenforceable, the rest stands. If the SCCs or the law change such that a term here no longer provides a valid transfer mechanism, we will agree a replacement in good faith.
A1 Annex I — the processing
| Subject matter | Providing the Lobbero front-desk service: recording and retrieving visitor, resident, parcel, incident and daily-log entries, notifying residents, generating reports and shift handovers, and — on plans that include it — AI summaries and plain-language search over those entries. |
| Duration | The term of the Terms, plus the deletion window in §10. |
| Nature & purpose | Collection, recording, organisation, storage, retrieval, consultation, use, disclosure to the Controller's own personnel, restriction, erasure and destruction — for the purpose of running a staffed residential front desk. |
| Categories of Data Subject | Building staff and concierges; property managers, owners and board members; residents and occupants; visitors, guests, contractors, vendors and delivery drivers; parcel recipients; and prospective residents. |
| Types of Personal Data | Name; work or personal email; telephone number; unit and building; role and access grants; occupancy status; visit type, times, who was visited, approval and parking details; free-text notes authored by staff; parcel carrier, masked tracking number, recipient and collection proof (signature or photograph); incident category, notes and derived severity; authored-by attribution on every entry; authentication data (hashed password, two-step secret, hashed recovery codes, device and session records including IP address and user agent); and the name read from an identity document. |
| Special categories | None intended, and none required. The product asks for no special-category data and the Terms prohibit recording it. An incident note could incidentally capture health-related detail; the Controller is asked to record only what is necessary, and erasure redacts a name inside a note. Identity-document images are not stored at all. |
| Frequency | Continuous, for as long as the desk is in use. |
| Retention | Per record type, configurable with a 30-day floor. Defaults: visitor log 12 months; activities and incidents 24 months; parcels 6 months after pickup; emergency visits 24 months; notifications 6 months; payment webhook payloads 90 days; sign-in and device records 30 days after expiry. A parcel still on the shelf is never removed. Periods can be changed only by the database owner, not by the application. |
| Controller contact | The account owner(s) named in the Lobbero account. |
| Processor contact | hello@lobbero.com — Moxelle, Inc., a Delaware corporation |
A2 Annex II — technical & organisational measures
These are the measures actually in place, not a list of intentions. Where a control is planned rather than done, it is named as such at the end.
| Area | Measure |
|---|---|
| Tenant isolation | Each organisation’s data is isolated at the database level, not by application filtering alone. Nothing crosses a building boundary. |
| Access control | Role-based and least-privilege, granted per building and per role and resolved on every request. Only an owner can grant administrative control. A grant with an end date stops working when it expires. |
| Authentication | Passwords stored hashed with a current, deliberately slow password-hashing function. Two-step sign-in available on every account, with recovery codes. Sign-in, reset and the second step are rate-limited, and repeated failures lock an account temporarily. |
| Sessions | Short-lived and renewed in the background; reuse of a retired credential ends every session on the account. Users can list and revoke their own devices. Cross-site request forgery protection on every state-changing request. |
| Encryption in transit | Modern, industry-standard protocols, with obsolete versions refused. The application-to-database connection is encrypted and pinned. |
| Encryption at rest | Personal identifiers (names, email addresses, telephone numbers) held as ciphertext under a strong authenticated cipher, with keys kept separately from the data. A failed encryption refuses the write rather than storing plaintext. |
| Data minimisation | Identity-document images are read and discarded, never stored. Parcel tracking numbers are stored masked. Email addresses are masked in application logs. |
| Audit trail | Append-only: the application can add audit records but cannot alter or delete them. Deletions are themselves audited, without personal data in the audit entry. |
| Erasure completeness | Removing a record removes its earlier versions and search-index entries. Erasing a person reaches versions, indexes, derived summaries, notifications and invitations. |
| Retention | Per-record-type periods with a floor, configurable by the Controller and changeable only with elevated database rights. Every copy of a record goes with it. |
| Hosting | A major cloud provider, with service data hosted in the European Union. Application and database are separated. |
| Resilience | Backups taken regularly, verified by restore, and retained for a defined period. |
| Secure development | Code review and automated checks before release. Releases are blocked while a critical dependency advisory is open. Database changes are rehearsed against a restored copy of production. |
| Web hardening | Transport security, framing, content-type, referrer and permissions policies on both the application and the website, plus a published vulnerability contact. Fonts are self-hosted; there is no analytics, advertising or error-tracking third party in either. |
| Our own access | Support access is time-limited and audited. The internal console is read-only and cannot change a Controller’s records. |
| Incident response | A documented procedure to identify, contain and investigate security events, with the 48-hour notification commitment in §8. |
| Contract-end removal | A verified removal process that confirms no rows remain, reverses itself on a partial result, and issues a written removal record. |
Specifics, on request
This Annex describes the measures by category rather than publishing a configuration inventory: algorithm choices, version numbers, thresholds and infrastructure detail are useful to an attacker and are not needed to assess the posture. The Processor will share that detail, complete a security questionnaire, and state its current certification and assurance status, on request under NDA — see Security & Trust.
A3 Annex III — sub-processors
The current list. We give at least 30 days' notice before adding or replacing an entry (§6).
| Sub-processor | Purpose | Data it receives | Location |
|---|---|---|---|
| Amazon Web Services | Hosting, database, file storage, backups | All Customer Personal Data | European Union |
| Google (Gemini API) | Lobbero IQ; reading ID and parcel photographs | Log text at query time; the photograph at scan time. Not used for training | US / EU — SCCs |
| Google (Maps & Places) | Address and city lookup, maps | The address being searched | US / EU — SCCs |
| Stripe | Payments and subscription billing | Billing contact, plan and unit count. Card details go to Stripe directly and are never stored by Lobbero | US / EU — SCCs |
| SendGrid (Twilio) | Email — invitations, notifications, password resets | Name, email address, message content | US — SCCs |
| Browser push services (Google, Apple, Mozilla) | Push notifications, if a user enables them | An encrypted payload and a device token | US / EU |
| Vercel | Hosting of lobbero.com | None — the marketing site holds no Customer Personal Data and sets no cookies | Global edge |
There is no analytics, advertising or error-tracking sub-processor in either the product or the website.
Need this signed?
We will sign this DPA as a standalone document, and answer a security questionnaire alongside it.