Back to Resivana

This document is maintained in English only. The English version is the binding one.

Resivana Privacy Policy

Version 1.0 — 2 August 2026

Applies to: Resivana web application, Resivana mobile application, and the Resivana marketing site


1. Who this policy is about

Resivana is property-management software. A landlord, property manager, or real-estate firm (the client, sometimes called the account owner) signs up for Resivana and uses it to manage their buildings, units, tenants, and rent. This policy explains how Resivana handles personal data for:

  • Client staff — the owners, managers, accountants, and collectors who log in to run the account.
  • Tenants and occupants — the people who rent from a client and use the mobile app to view charges, submit payment evidence, and communicate with their landlord.
  • Visitors to the Resivana marketing site.

It does not cover how a client uses or shares data outside Resivana (for example, printing a report and emailing it to a third party) — that is the client's own responsibility, described further in terms-of-service.md.

2. The white-label relationship: who is the data controller

Resivana is white-label: every client gets a branded portal (their own subdomain, logo, and colours) that their tenants and staff see as the client's own product. This shapes how data protection responsibility is split:

  • For tenant and occupant data (names, contact details, contracts, charges, payment evidence, and similar records the client enters or their tenants submit), the client is the data controller — they decide what is collected and why, and they are the party a tenant should generally contact about their data. Resivana acts as the data processor / service provider, handling that data only to provide the software and only on the client's instructions.
  • For client staff account data (the login credentials, roles, and activity of the owners, managers, accountants, and collectors who use Resivana) and for marketing site visitors, Resivana is the data controller.
  • For subscription billing data (the client's own billing contact and payment method used to pay Resivana), Resivana is the data controller, acting through its payment processor.

Clients are responsible for having a lawful basis to collect and process their tenants' data (including any tenancy-law notices or consent required in their jurisdiction) and for responding to their tenants' data-protection requests, with Resivana providing the tools and cooperation described in Section 10 to help them do so.

Where Resivana acts as a processor for a client, we commit to:

  • Process that data only to provide and support the service, and on the client's instructions — never for our own purposes and never to sell or to serve advertising.
  • Limit access to the staff who need it, under confidentiality obligations, with support access audited and time-limited.
  • Use only the sub-processors listed in Section 7, under contracts that restrict their use of the data.
  • Help the client respond to a tenant's or staff member's data-protection request.
  • Notify the client without undue delay after we become aware of a personal data breach affecting their account's data, with what we know at the time and what we are doing about it.
  • Return or delete the data on the client's instruction when the relationship ends, subject to Section 9.

3. Resivana does not process or hold rent money

Resivana records rent. It does not move it.

Rent, deposits, and every other amount owed under a tenancy pass directly between the tenant and the client — or a collector the client authorises — by bank transfer, cash, cheque, or whatever method they arrange. Resivana is never in the payment path, never holds those funds, and has no ability to charge, debit, or pay a tenant.

For your data, this means:

  • Resivana stores records about payments: an amount, a date, a method, a reference number, an allocation to a charge, and any evidence image uploaded to support the claim.
  • Resivana does not collect or store tenant card numbers, bank account credentials, wallet logins, or any other payment instrument — it never asks for them, and has no use for them.
  • The only card details anywhere in the Resivana relationship are the client's own, used to pay the Resivana subscription. Those are handled by our payment gateway (Section 7); Resivana does not store full card numbers.

If Resivana ever adds the ability to collect rent through the platform, that will be a separate service and this policy will be updated before it ships.

4. What we collect, and why

4.1 Account and staff data (client owners, managers, accountants, collectors)

DataWhy we collect it
Name, email, phone, password (stored hashed)Create and secure a login
Role and permission scopeControl what the person can see and do
Login sessions and refresh tokens (stored hashed)Keep users signed in; let users and administrators revoke sessions
Actions taken in the app (audit trail)Accountability for financial and record changes — approvals, edits, deletions
Language preferenceShow the interface in the language the user picked

4.2 Tenant and occupant data

DataWhy we collect it
Legal/display name, phone, email, address, nationality, preferred languageIdentify the tenant and communicate with them
Company and registration details (commercial tenants)Represent commercial tenancies accurately
Emergency contacts, authorised occupants, guarantorsRepresent who else is party to or connected with a tenancy
Tenancy contract terms (rent, dates, deposit, charges, renewal/termination status)Administer the lease
Contract registration details where the market requires them (for example an Ejari or Tawtheeq number and expiry)Track legal registration and expiry alerts in markets that require it
Notes, maintenance requests, and communication historyRun the day-to-day management of the tenancy

4.3 Payment evidence

Tenants and authorised collectors upload evidence to show a charge has been paid: transfer screenshots, deposit slips, cheque images, signed receipts or acknowledgements, and cash-collection photographs, together with the claimed amount, date, reference, and notes. This is reviewed and approved (or rejected) by the client's staff before it counts toward a paid charge.

Location and device time are not captured at launch. If that capability is added, it will be off by default and captured only where the client has enabled it and disclosed it to the uploader.

4.4 Legal-document acceptance records

When someone accepts a version of this policy, the terms of service, or a tenant-facing notice, we record who accepted it, which document and version, the UTC time, the IP address and browser or app used, and the account it relates to. These records are the evidence of what was agreed and when. They are immutable, and they are kept even after an account closes — see Section 9.

4.5 Identity documents (later phase — not collected at launch)

Once enabled, identity documents (for example a passport, Emirates ID, or similar) and their expiry dates may be stored against a tenant record. These will carry stricter access permissions than other tenant data and will be excluded from bulk exports. This policy will be updated with the specifics before that capability ships.

4.6 Device push tokens

When a user signs in to the Resivana mobile app and allows notifications, the app registers a device push token so reminders and alerts can reach that device. The token identifies a device for delivering notifications; it is not used for advertising or tracking. It is removed when the user signs out of the app, and dropped automatically once our push provider reports the app is no longer installed on that device.

4.7 Cookies, refresh tokens, and similar technologies

  • Refresh tokens keep a user signed in between sessions. They are stored securely on the device and only ever stored hashed in our database — the readable token never touches our database. They can be revoked by the user or an administrator at any time.
  • Web session/authentication cookies keep a signed-in user logged in on the web app. We do not use third-party advertising or cross-site tracking cookies.
  • The marketing site may use strictly-necessary cookies. If analytics are ever added, we will ask for consent first where the law requires it, and update this policy before doing so.
  • No analytics, crash-reporting, advertising, or tracking SDK is currently integrated in the web app, the mobile app, or the API. If one is added, this policy and our app store listings are updated before that version ships.

5. How we use data

Data described above is used to:

  • Provide the core product: buildings, units, tenants, contracts, charges, payments, cash handovers, deposits, expenses, documents, maintenance, and reporting.
  • Send reminders and alerts (rent due, contract expiry, document expiry) by email and push notification.
  • Operate the white-label experience (branded subdomain, logo, sign-in) for each client.
  • Secure accounts, investigate misuse, and maintain an audit trail of financial and record changes.
  • Bill the client for their subscription.
  • Provide customer support, with access to a client's data limited to what support needs, time-limited, and logged.

We do not sell personal data, and we do not use tenant or client data to serve third-party advertising.

6. Storage and security posture

This describes the practices we follow. It is a description of what we do, not a guarantee of any particular outcome, and we hold no third-party security certification — see Section 13.

  • Data is encrypted in transit (TLS) and at rest using our hosting provider's managed encryption.
  • Passwords are stored hashed using our framework's maintained secure defaults; refresh tokens and password-reset tokens are stored hashed, never in readable form.
  • Every query for account data is filtered by the authenticated account before any record is looked up, so one client's account cannot reach another's.
  • Uploaded files (payment evidence, documents, branding assets) are served through signed, short-lived URLs rather than public links, stored under randomised keys, and checked against an allowed list of file types and sizes.
  • Location metadata (such as GPS coordinates embedded in a photo) is stripped from uploaded images unless there is a disclosed business reason to keep it.
  • Identity documents, once collected, will carry distinct, stricter permissions and be excluded from bulk or broad exports.
  • Secrets and credentials are kept in our hosting provider's secret manager, never in source code.
  • Application logs are designed to exclude passwords, tokens, document contents, identity numbers, and full financial evidence.
  • Backups are encrypted, and restore procedures are documented and tested.
  • If we become aware of a personal data breach, we will notify affected clients without undue delay, and any regulator or individual the law requires us to notify.

No system is completely secure. We cannot guarantee the absolute security of information transmitted to or stored by Resivana, and users are responsible for keeping their own credentials and devices secure.

7. Who we share data with (sub-processors)

We use a small number of service providers ("sub-processors") to operate Resivana. Each only receives the data it needs to perform its function, under a contract that restricts its use of that data.

CategoryPurposeData involved
Cloud hosting and databaseRuns the application and stores dataAll account data described in Section 4
Object storageStores uploaded files (evidence, documents, branding assets)Payment evidence, documents, branding assets, and identity documents once that capability ships
Transactional emailSends account, reminder, and receipt emailsName, email address, message content
Subscription paymentsCharges the client's card for their Resivana subscriptionClient billing contact and payment details, handled by the gateway; Resivana does not store full card numbers
Push notificationsDelivers mobile reminders and alertsDevice push token

The current provider for each category is available on request from support@resivana.com. Our launch subscription-billing gateway is SafePay; push notifications are delivered through Google Firebase Cloud Messaging.

Changes to this list. We will update this section before a new sub-processor category goes live in production. Where we add or replace a sub-processor that handles client or tenant data, we will give clients at least 30 days' notice by in-app announcement or email — except where a change has to be made sooner for security or service continuity, in which case we will tell clients as soon as we can. Clients who object to a new sub-processor may cancel their subscription before the change takes effect.

We may also disclose data where the law requires it, to respond to a lawful request from a competent authority, to establish or defend legal claims, or to protect the safety of a person. Where we may lawfully do so, we will tell the affected client first.

If Resivana is involved in a merger, acquisition, or sale of assets, account data may transfer to the acquirer. We will give notice before that happens, and the data stays subject to a policy at least as protective as this one.

8. International data transfers

Resivana runs on managed cloud infrastructure and uses the sub-processors listed in Section 7. Depending on the provider and region, some data may be stored, processed, or accessed outside the country where a client or their tenants are located. In particular:

  • Our launch subscription-billing gateway settles in Pakistan, so a client's own billing contact and payment details are processed there.
  • Resivana staff may access an account from outside the United Arab Emirates for support, under the audited, time-limited access described in Section 5.

We select providers that commit contractually to protecting the data they handle. Once the hosting region for client and tenant data is fixed, we will state it in this section. If a launch market requires a specific transfer mechanism or in-country storage for a category of data, we will put that in place before offering the service there.

9. Retention and deletion

  • We retain data for as long as the client's account is active, plus any additional period required by law or agreed in the client's contract with Resivana.
  • A lapsed or expired trial does not delete data. A lapsed subscription makes the account read-only — nothing is deleted — and paying again restores full access immediately.
  • After an account is terminated or closed, the client can ask us for a copy of their data for 30 days. After that period we may delete it, subject to the exceptions below.
  • Clients can request export or deletion of their account's data at any time. Tenants and staff should raise these requests with their client — the data controller for their data, see Section 2 — who can raise them with Resivana support.
  • What survives a deletion request: acceptance records for legal documents (Section 4.4), financial and audit records we are required to keep by law, and aggregated statistics that cannot identify any person.
  • We have not yet published fixed retention periods for individual record types — for example how long payment evidence or a tenant record is kept after a tenancy ends. Until we do, we keep that data for as long as the account exists and delete it on request, subject to the exceptions above. Configurable retention periods and self-serve account export and deletion tooling are being added, and this section will be updated when they are.

10. Your rights

Depending on your jurisdiction and your relationship to a Resivana account, you may have rights to access, correct, export, restrict, or object to the processing of your personal data, to request its deletion, to withdraw a consent you gave, and to complain to your data protection authority.

  • If you are a client's tenant, occupant, or staff member: please contact your landlord, property manager, or firm directly — they control your data and can action most requests, with Resivana's support where needed. If you contact us instead, we will pass your request to them and help them answer it.
  • If you are a client (account owner) or a marketing site visitor: contact us using the details in Section 15.

We aim to respond within 30 days, and will tell you if we need longer and why. We may need to verify your identity before acting on a request, and some rights are subject to conditions and exceptions under the law that applies to you.

11. Children's data

Resivana is a business tool and is not directed at children. We do not knowingly collect personal data from children. Tenancy records may reference minors as occupants (for example, a tenant's dependents) as entered by the client for legitimate tenancy-management purposes; this is the client's data-entry decision as data controller.

12. Mobile app data disclosures (Apple App Store / Google Play)

This section maps our data handling to the categories Apple's App Privacy details and Google Play's Data safety form ask about, and reflects what the mobile app collects as of this version.

CategoryCollected?Notes
Contact info (name, email, phone, address)YesClient staff accounts and tenant records
Financial infoYes — records onlyPayment evidence images, claimed amounts, and charge/ledger records. No tenant payment instrument is collected; Resivana does not process rent (Section 3). Subscription card details go directly to our payment gateway
Identifiers (user ID, session identifiers)YesAccount and session identifiers; device push token from the mobile app
Photos and mediaYesPayment evidence photos, uploaded documents, branding logos — uploaded by the user, when the user chooses to
Files and documentsYesTenancy documents and evidence a user uploads
User content (notes, messages)YesInternal notes, maintenance requests, communication history
App activity / in-app actionsYesAudit trail of financial and record changes, for accountability
LocationNoNot collected at launch. The app requests no location permission. If evidence-location capture is added, it will be off by default and disclosed first (Section 4.3)
Contacts (device address book)No
CalendarNo
Health and fitnessNo
AudioNo
Browsing or search historyNo
Diagnostics, crash data, analyticsNoNo analytics or crash-reporting SDK is integrated. If one is added, this table and the store listing are updated before that build ships
Data used for third-party advertisingNo
Data used to track you across apps or sites owned by othersNo
Data linked to your identityYesMost data above is linked to a named account or tenant record
Data encrypted in transitYesTLS
Users can request data deletionYesClients at support@resivana.com; tenants and staff through their landlord, manager, or firm (Sections 9 and 10)

This table is re-checked against the live App Store Connect and Google Play Console questionnaires before each submission — the platforms change their categories periodically, and a feature that ships between submissions can change the answers.

13. Legal framework and compliance posture

Resivana's primary launch market is the United Arab Emirates, with Pakistan second. This policy is written to align with the UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its executive regulations.

To be clear about what that means:

  • We do not hold any privacy or security certification (for example ISO 27001 or SOC 2), and we do not claim certified compliance with any scheme. Section 6 describes practices we follow, not audited guarantees.
  • Clients established in the DIFC or ADGM free zones may be subject to the DIFC Data Protection Law or the ADGM Data Protection Regulations instead of, or alongside, federal PDPL. If that applies to you, tell us at support@resivana.com so we can agree what your account needs.
  • Contract-registration data (Ejari in Dubai, Tawtheeq in Abu Dhabi) is entered and controlled by the client; Resivana stores the fields and drives the expiry alerts, and does not register anything on the client's behalf.
  • Before we open a new market, we review what that market requires for tenancy records, identity data, consent, data residency, messaging, and retention, and update this policy for it.

Nothing in this policy is legal advice, and it does not decide the obligations a client has to its own tenants under its own law.

14. Changes to this policy

This policy is a versioned document. When we publish a new version, we update the version number and date at the top and keep the previous version available on request.

Material changes affecting client accounts are communicated through the in-app announcement mechanism or by email before they take effect. Where a change materially affects how we handle personal data, users are asked to review and accept the new version at their next sign-in, and we record that acceptance as described in Section 4.4.

15. Who we are and how to contact us

  • Operator and data controller (for client staff account data, the marketing site, and Resivana's own billing data): Resivana. Registered entity name, address, and trade-licence details will be published here once finalised.
  • Privacy questions and requests: support@resivana.com.
  • We have not appointed a separate data protection officer. Privacy requests go to the address above and are handled by the Resivana team.