Version: 1.2 Effective Date: 2026-09-12
This Privacy Policy explains how SILAS Smart Doorlock ("SILAS," "we," "us") collects, uses, shares, and protects your personal data when you use:
This policy applies to all users of the Services — Organisation Owners, Tenants/Members, and Platform Administrators. It should be read together with our Terms of Service, which govern your use of the Platform.
For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is:
DSFABW LIMITED
Unit 5 The Ivories, 6 Northampton Street, London N1 2HY, United Kingdom
Contact: admin@dsfabw.com
| Category | Examples |
|---|---|
| Account information | Email address, phone number, username, password hash (we never store your password in plain text) |
| Organisation information | Organisation name, property names (floors, rooms), lock names |
| Billing information | Subscription plan choice, payment method type — but not your full payment card or bank account number (see §6: Data Sharing — GoCardless, Apple) |
| Communications | Enquiries, support requests, Enterprise plan enquiry details you submit to us |
| Category | Examples |
|---|---|
| Device and lock data | Lock ID, lock status, lock operation events (unlock, lock, configuration changes), device command logs |
| Access control data | Passwords created for locks (stored encrypted), Bluetooth unlock authorisations (time-limited), permission assignments |
| Activity logs | Timestamps and metadata for: user login, lock operations, member invitations, permission changes, password creation/viewing, subscription changes, organisation administrative actions |
| Device and network information | IP address, device type, operating system version, App version, browser type (Web console) |
The App may request the following device permissions. In all cases, processing happens on your device only — we do not upload, store, or share camera feeds, photos, or QR code images.
We process your personal data for the following purposes:
| Purpose | Description | Legal Basis (UK GDPR) |
|---|---|---|
| Service delivery | Operating the smart lock platform: managing accounts, processing unlock commands, managing passwords and permissions, sending notifications. | Contract performance (Art. 6(1)(b)) |
| Billing and payments | Managing subscriptions, processing payments via GoCardless (Direct Debit) and Apple (in-app purchases on iOS), enforcing grace periods, handling plan changes. | Contract performance (Art. 6(1)(b)) |
| Security and fraud prevention | Monitoring for unauthorised access, detecting and preventing fraudulent activity, enforcing rate limits, protecting the integrity of the Platform. | Legitimate interests (Art. 6(1)(f)) — protecting our users and Platform |
| Audit and compliance | Maintaining records of high-risk operations (remote unlock, password viewing, member removal, organisation deletion) for security auditing and regulatory compliance. | Legal obligation (Art. 6(1)(c)) and legitimate interests |
| Platform administration | Enabling Platform Administrators to perform cross-organisational oversight, support, and emergency actions, with mandatory reason recording and audit logging. | Legitimate interests (Art. 6(1)(f)) |
| Support | Responding to your enquiries and support requests. | Contract performance (Art. 6(1)(b)) |
| Service improvement | Analysing aggregated, anonymised usage patterns to improve the Platform. | Legitimate interests (Art. 6(1)(f)) |
| Marketing (if applicable) | Sending you information about new features or plans — only if you have given explicit consent. | Consent (Art. 6(1)(a)) — you may withdraw at any time |
We process personal data only where we have a valid legal basis under UK GDPR:
We share data only with providers necessary to operate the Services. All providers are contractually bound to process your data solely on our instructions and in compliance with applicable data protection law.
| Provider | Data shared | Purpose |
|---|---|---|
| GoCardless | Organisation identifier, subscription plan, payment amount, mandate reference | Processing direct debit payments. We do not send your full payment instrument data to GoCardless — they collect and store it directly. |
| Apple | Apple ID, product identifier, transaction identifier, subscription status. We never receive your payment card or bank details for these purchases. | Processing in-app purchases and subscriptions on iOS, and reporting their status to us (App Store Server Notifications). Apple is the merchant of record for these transactions. See Apple's Privacy Policy. |
| SMS provider | Phone number, verification codes, notification content | Delivering SMS verification codes and service notifications. |
| Email provider | Email address, verification codes, notification content | Delivering email verification codes and service notifications. |
We may disclose personal data if required to do so by law, regulation, court order, or a valid request from a law enforcement or regulatory authority. We will notify you of such disclosure where permitted by law.
If SILAS or its assets are acquired by or merged with another entity, your data may be transferred as part of that transaction. You will be notified of any such change in ownership or control.
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
We retain your personal data for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
| Data category | Retention period |
|---|---|
| Account data | For the lifetime of your Account. Upon Account deletion, account data is removed or anonymised within a reasonable period, except as below. |
| Audit logs | Retained for the period required by applicable law and our legitimate business needs for security auditing, compliance, and dispute resolution — typically up to 6 years after the associated event. |
| Payment and subscription records | Retained for the period required by applicable tax, accounting, and financial regulations — typically 6 years from the end of the relevant financial year. |
| Access credentials (passwords, Bluetooth authorisations) | Removed asynchronously upon Organisation deletion, subscription expiry, or member removal, as appropriate. |
| Verification codes (SMS / email) | Deleted immediately after successful verification or upon expiry (whichever occurs first). |
When data is no longer needed, we securely delete or anonymise it.
You have the following rights regarding your personal data:
| Right | What it means |
|---|---|
| Right of access (Art. 15) | You may request a copy of the personal data we hold about you. |
| Right to rectification (Art. 16) | You may request that we correct inaccurate or incomplete data. |
| Right to erasure (Art. 17) | You may request that we delete your personal data in certain circumstances ("right to be forgotten"). Note that this right is not absolute — we may need to retain certain data for legal, regulatory, or audit purposes. |
| Right to restrict processing (Art. 18) | You may request that we limit how we process your data in certain circumstances. |
| Right to data portability (Art. 20) | You may request a copy of your data in a structured, machine-readable format for transfer to another service. |
| Right to object (Art. 21) | You may object to processing based on legitimate interests, including profiling (we do not profile). |
| Rights relating to automated decision-making (Art. 22) | You have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you. SILAS does not make any automated decisions with legal or similarly significant effects — all consequential actions (subscription status changes, permission revocations, etc.) are rule-based and reviewable by a human. |
To exercise any of these rights, contact us at admin@dsfabw.com. We will respond within one month (extendable by up to two additional months for complex requests, in which case we will notify you). We may ask you to verify your identity before processing your request.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at www.ico.org.uk if you believe our processing of your data violates UK GDPR.
We implement and maintain appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. These measures include:
| Measure | Description |
|---|---|
| Encryption in transit | All communications between the App, Web console, and our servers are encrypted using TLS (HTTPS). |
| Encryption at rest | Sensitive data (passwords, access credentials, authentication tokens) is stored in encrypted form. Passwords are one-way hashed — we cannot recover your plain-text password. |
| Access control | Access to personal data is restricted to authorised personnel and systems on a need-to-know basis. Multi-factor authentication and role-based access control are enforced for administrative access. |
| Audit logging | High-risk operations are logged with timestamp, user identity, and operation details, enabling security monitoring and forensic investigation. |
| Authentication | Stateless JWT-based authentication with token expiry and refresh mechanisms. |
| Rate limiting | Login, verification code, and other sensitive endpoints are rate-limited to prevent brute-force and enumeration attacks. |
While we take these measures seriously, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
Our servers are located in United Kingdom (GB). If we transfer your personal data outside the UK, we ensure that appropriate safeguards are in place, such as:
The Services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data without parental consent, please contact us and we will take steps to delete it.
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the App and/or Web console before the changes take effect. The updated policy will indicate a new version number and effective date at the top of this document.
If the changes materially affect how we use your data, we will ask you to re-confirm your agreement.
We encourage you to review this policy periodically. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.
For questions about this Privacy Policy, to exercise your data protection rights, or to raise a concern about our data practices:
This Privacy Policy was last updated on 2026-09-12. Version 1.2.