At a glance
- Your building is the data controller for the residents, visitors and parcels it logs. Lobbero is the processor — we handle that data on your building's instructions, under a Data Processing Agreement.
- We do not sell or share your personal information, and we do not use customer data to train AI models.
- When we scan an ID, we read the name and then discard the image — "extract-and-discard." We keep only what the front desk actually needs.
- You can ask to access, correct, export or delete your data. Residents and visitors direct those requests to their building; we help the building fulfil them.
- Each building's data is isolated from every other building's. See our Security page for how.
01 Who we are & our role
Moxelle, Inc., a Delaware corporation ("Lobbero", "we", "us"), provides Lobbero, a concierge and front-desk platform for residential buildings. Our registered office is 651 North Broad Street, Suite 206, Middletown, DE 19709, United States. You can reach our data-protection point of contact at hello@lobbero.com.
Data-protection law distinguishes the controller (who decides why data is collected) from the processor (who handles it on the controller's behalf). Lobbero plays both roles, depending on the data:
When your building is the controller — Lobbero is the processor
For the operational data a building records in Lobbero — residents, visitors, parcels, incidents and the daily log — the building (or its management company) decides why the data exists and is the controller. Lobbero processes it strictly on the building's documented instructions under a Data Processing Agreement (GDPR Article 28). If you are a resident or visitor, your building is your first point of contact for privacy requests.
When Lobbero is the controller
For a smaller set of data we decide the purposes ourselves and are the controller: the account details of the people who administer Lobbero (owners, managers, concierges), billing information, website visitors, product analytics, and our own security and support records.
If your organisation is in California or another US state with a privacy law, the equivalent terms are business (controller) and service provider (processor). Lobbero acts as a service provider for your building's operational data and processes it only to provide the service.
02 The data we handle
Lobbero is deliberately data-minimal — the front desk records what it needs to run the building and little else. The table below is the working inventory; a building's own configuration may narrow it further.
| Data we handle | What it includes | Lawful basis (GDPR) | Typical retention |
|---|---|---|---|
| Account & staff | Name, work email, phone, role, hashed password, sign-in and device/session records, and the log entries a staff member authors | Contract | Life of the account, then 90 days after the contract ends |
| Resident roster | Name, email, unit and building, occupancy status | Contract / Legitimate interest | While resident, then removed with the building 90 days after the contract ends |
| Visitor log | Name, visitor type (guest, vendor, delivery, prospect, resident entry, emergency), unit visited, who they are seeing, arrival & departure time, approval, parking, free-text notes | Legitimate interest / Legal obligation | 12 months |
| ID scans | Identity document photographed at check-in — the name is extracted and the image is discarded | Legitimate interest / Consent | Image: not stored. Name: with the visitor log |
| Parcels | Carrier, tracking number (stored masked), recipient name, unit, shelf location, and who collected it | Legitimate interest | 6 months after pickup |
| Incidents & daily log | Category, notes, and a derived severity (OK / follow-up / incident) | Legitimate interest | 24 months |
| Billing | Plan, unit count, billing contact; card details are handled by our payment processor and not stored by Lobbero | Contract / Legal obligation | As required by tax law, typically six to seven years |
| Website & cookies | No analytics, no advertising and no error-tracking of any kind. lobbero.com sets no cookies at all; the app sets four, and all four exist only to keep you signed in | Strictly necessary | Session — see the Cookie Policy |
We aim to avoid special-category data (health, and similar sensitive categories under GDPR Article 9). Incident notes could occasionally capture health-related detail; we ask buildings to record only what is necessary, and the extract-and-discard approach keeps identity documents out of storage.
03 Why we can process it
Under the GDPR we must have a lawful basis for each purpose (Article 6). We rely on:
- Performance of a contract (Art. 6(1)(b)) — to give account holders the service they signed up for, and to bill for it.
- Legitimate interests (Art. 6(1)(f)) — for the building's genuine interest in security and access control (the reason a lobby keeps a visitor log at all), for keeping parcels accountable, and for securing and improving the product. Where we rely on this basis we have carried out, and can provide, a Legitimate Interests Assessment that weighs it against people's rights.
- Legal obligation (Art. 6(1)(c)) — where local law requires visitor or guest registration, and for tax and accounting on billing.
- Consent (Art. 6(1)(a)) — for non-essential cookies and any marketing. You can withdraw consent at any time.
04 People who never signed up
Most software only holds data about people who chose to use it. Lobbero is different: a visitor is logged simply by arriving at a building. That makes them a third-party data subject, and the law gives them specific protections.
- We collect the minimum needed to record the visit — and no more than the building configures.
- The image of any ID document is discarded after the name is read; it is never retained.
- Visitor records are kept only for a defined period (12 months) and then purged.
- A visitor can exercise their rights — including asking what was recorded, or asking for it to be deleted — by contacting the building, or us at hello@lobbero.com. Because a visit is a shared record, we can remove an individual without destroying the building's overall log.
Emergency (911 / 112) entries
Records tagged as an emergency response may be retained differently where safety or legal obligations require it. Where that applies, it is set out in the building's Data Processing Agreement.
05 Lobbero IQ & artificial intelligence
Lobbero IQ reads a building's own log to write shift handovers and answer plain-language questions ("how many deliveries had no ID last month?"). Our commitments:
- We do not train AI models on your data. Customer data is never used to train or fine-tune models — ours or a vendor's. This is written into our sub-processor agreements.
- Scoped to the building. Lobbero IQ can only reach data within the scope the asker already has access to; it never crosses building boundaries.
- Traceable, not oracular. Every answer cites the log entries behind it, and states when the entries searched contain nothing — it does not invent facts.
- Human in the loop. Lobbero IQ is decision-support. It does not make automated decisions that produce legal or similarly significant effects about a person (GDPR Article 22); a member of staff always acts on the information.
Lobbero IQ is delivered using a third-party large-language-model provider, Google (Gemini API), under a data-processing agreement that includes Standard Contractual Clauses and a no-training commitment. See the sub-processor list.
07 International transfers
Lobbero serves buildings in the EU and the US, so data may move across borders. Where personal data leaves the EEA or the UK, we protect it with an approved transfer mechanism — the European Commission's Standard Contractual Clauses (and the UK Addendum), or reliance on an adequacy decision. Where our AI or other vendors are US-based, their data-processing agreements include SCCs. You can request a copy of the safeguards for a specific transfer at hello@lobbero.com.
Data residency
Service data is hosted in the European Union. The application and the database run on separated infrastructure within the same private network, and backups are taken regularly and retained for a defined period. We share our hosting and disaster-recovery specifics with customers on request — see Security & Trust.
08 How long we keep it
We keep personal data only as long as it serves the purpose it was collected for, then delete or anonymise it. Default periods are in the data table above; buildings can tighten them in their configuration. When a customer's contract ends, we delete or return their data within 90 days and can certify that we have done so, except where the law requires us to keep a limited record for longer.
09 Your rights (GDPR / UK GDPR)
If you are in the EEA or the UK, you have the following rights. For a building's operational data, exercise them with the building (the controller); Lobbero, as processor, will support the request. For data where Lobbero is the controller, contact us directly.
We respond within one month (extendable by two further months for complex requests, as the GDPR allows). You can also complain to the supervisory authority of the EU member state where you live or work, or to the UK Information Commissioner's Office — though we would appreciate the chance to resolve it first. Lobbero has no single lead supervisory authority: the one-stop-shop in Article 56 applies to controllers established in the Union, and Moxelle, Inc. is established in the United States, so every national authority is competent for complaints from its own residents.
10 Your US privacy rights
If you are a California resident, the CCPA (as amended by the CPRA) gives you the rights below; residents of Virginia, Colorado, Connecticut, Utah, Texas and other states with comprehensive privacy laws have comparable rights.
We do not sell your personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law. For a building's operational data, Lobbero acts as a service provider and uses the data only to provide the service. To make a request, contact hello@lobbero.com; you may use an authorised agent, and we will verify your identity before acting. We respond within 45 days (extendable once where permitted).
11 How we protect it
Security is covered in full on our Security & Trust page. In summary: each building's data is isolated; access is role-based and least-privilege; data is encrypted in transit and at rest; identity documents are extract-and-discard; and we keep an audit trail of activity. If a personal-data breach occurs, we notify the relevant supervisory authority within 72 hours where the GDPR requires it (Article 33), notify affected customers without undue delay, and comply with applicable US state breach-notification laws.
12 Children
Lobbero is a workplace tool for building staff and is not directed at children. We do not knowingly collect data from children through our accounts. A building's log may incidentally record that a visitor was a minor; buildings should record only what is necessary and handle such data with care.
13 Changes to this policy
We may update this policy as the product and the law evolve. We will post the new version here with a fresh "last updated" date and, for material changes, notify account holders directly. The date at the top always reflects the current version.
14 Contact us
For any privacy question or to exercise a right:
- Data-protection point of contact — hello@lobbero.com
- Post — 651 North Broad Street, Suite 206, Middletown, DE 19709, United States
- EU representative (GDPR Art. 27) — to be appointed
- UK representative (UK GDPR Art. 27) — to be appointed
Residents and visitors: your building is your first point of contact, and we will support it in answering you.