Privacy policy
This policy covers Kommonz at kommonz.com and app.kommonz.com, our iOS and Android apps, and the account, booking, membership and support services we provide.
Who is responsible for your data
Kommonz is operated by LaserFocused OÜ, an Estonian company, registry code 17118792, at Telliskivi tn 49, 10611 Tallinn, Estonia. Contact us at justin@kommonz.com.
We act as a data controller for website enquiries, our relationship with account holders and customers, and the security and operation of our platform. Your coworking-space operator normally controls the membership, booking, billing, community and access records it manages through Kommonz. We process those records on its instructions. The operator's privacy notice also applies. Contact your space for decisions about its services; contact us if you need help identifying the responsible operator.
Information we handle
- Account and profile: email address, account identifiers, password hash when you use a password, and any name, job title, biography or profile image you or your operator provide. Google and Apple sign-in supply an account identifier and email address; Apple may supply a private relay address. We securely store provider credentials needed to manage the sign-in connection and revoke it when required. We also hold your organization, membership, role and access associations.
- Bookings and purchases: room and desk reservations, booking titles, dates and times, guest details, event registrations, orders, memberships, credit balances, invoices, payment status and related correspondence.
- Payments: Stripe processes payment details through its payment screens. We receive transaction references, payment status and the billing or limited payment-method information needed to manage purchases. Billing details can include a name, address or company information. Our servers do not receive your full card number or security code.
- Community and support: posts, comments, messages sent through supported web features, content reports, blocking preferences, community-terms acceptance, account deletion requests, and information you send to support or enter in our demo form. Community contributions and the profile information shown with them are visible to the relevant space's members. Only post information you are comfortable sharing with that audience.
- Door access: where your space enables supported hardware, access rights and credentials, the door or reader used, the time and result of an attempt, Bluetooth signal readings, and app/device diagnostics. These records can indicate your presence at a particular space.
- Technical and usage information: IP addresses, device and browser details, app versions, generated identifiers, page or screen interactions, crash reports, performance measurements and security logs. Our analytics includes approximate country and city information derived from IP addresses.
Information comes from you, your device, your space operator, other users who book or invite you, and connected providers. You can browse public information without an account. Account and transaction details are needed for the corresponding member or paid features; profile enrichment and community contributions are optional.
Why we use it
- Provide the service: create and secure accounts, manage memberships, show availability, fulfil bookings and purchases, calculate credits, process payments, deliver service emails and provide support. Where we are the controller, this is necessary to perform our contract with you or take steps you request before a contract.
- Operate and improve Kommonz: diagnose failures, understand feature use, prevent fraud and misuse, and maintain reliable services. We rely on our legitimate interests where permitted, balanced against your rights, and consent where the law requires it.
- Meet legal obligations: keep required accounting records, respond to lawful requests and handle legal claims. We use legal obligation or legitimate interests, as applicable.
- Optional device features: use permissions you choose to grant for supported doors, nearby-perk reminders and notifications. You can revoke permissions in device settings. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.
Space operators determine the legal bases for the records we process on their behalf. We do not sell personal data or use it for cross-app advertising. We do not use automated decision-making that produces legal or similarly significant effects about you.
Location, Bluetooth and notifications
On iOS, optional nearby-perk reminders use location, including background location when you enable that feature. The reminder logic evaluates your location on your device; that feature does not upload your GPS coordinates to Kommonz. It can continue checking proximity while the app is closed. This is separate from access records that identify a known door and from approximate location derived by analytics providers. The current Android app displays perks without background location or nearby-perk reminders.
Supported door unlocking uses Bluetooth to find a nearby reader. Older Android versions may also require location permission for Bluetooth scanning. On iOS, notification permission allows local reminders. Denying an optional permission disables the related feature; you can still use other features that do not depend on it.
Analytics and device storage
We use PostHog for product analytics and Sentry for errors and performance diagnostics, configured with their EU services. Our marketing site uses analytics in memory without analytics cookies or persistent analytics storage, and respects the browser's Do Not Track signal. It stores no preferences on your device and does not record sessions.
The web app uses storage for authentication and preferences and associates analytics with account and organization identifiers. On the production app, sampled web session replay helps us diagnose problems; text and input fields are masked. Web analytics respects Do Not Track. Our native apps send lifecycle and diagnostic events in release builds, use generated analytics identifiers, and do not record screenshots or session replays. The native apps currently have no analytics opt-out setting. You can contact us to exercise applicable privacy rights.
Clearing browser or app data removes local information but does not delete your server-side account or business records. Signing out and uninstalling are also separate from account deletion.
Who receives information
We share information as needed with your space operator and its authorized staff, other users when you contribute to a shared feature, and service providers supporting Kommonz:
- Hetzner Online GmbH hosts our application servers, database, uploaded files and on-server backups in Germany, so it holds all the data processed in Kommonz.
- Cloudflare provides DNS, encrypted connections and the network in front of every Kommonz host, so all traffic passes through it. It also hosts this website and stores our off-site backups in the EU. Backups are encrypted before upload, and Cloudflare holds no key.
- Stripe processes payments and the subscription fees spaces pay us. It receives names, email addresses, billing details and transaction data. Card details go only to Stripe or, at a card terminal, to the space's terminal provider.
- Resend and connected email providers send service email, such as sign-in links, invitations, receipts, invoices, reminders and email campaigns. They receive the recipient's name and email address and the message content.
- OpenAI Ireland Ltd. powers AI features: plain-language explanations of payment-reconciliation items for spaces that connect a workspace-management system (the invoice and payment involved and that customer's other open invoices: customer and payer names, invoice numbers, amounts, statuses, dates, the receiving account name and payment references; we send no email addresses); the campaign drafting assistant in Mailing when staff use it (the staff request, the draft, the space's name, address, sender name, sign-off and campaign styling, its published events and perks, and the previous campaign, but not the member list or recipients); and our support assistant, which receives a staff member's question and the space data that staff member allows it to access. OpenAI Ireland passes this data to its US affiliate under standard contractual clauses, and to its sub-processors under standard contractual clauses or an adequacy decision, so it may be processed in the United States. OpenAI does not use it to train its models.
- Anthropic drafts email replies when staff use our reply-drafting tool on a mailbox the space has connected. It receives the incoming email (sender name and address, subject and text), the space's name, the reference documents the space uploaded and the mailbox's sender name and address, and may process them in the United States and other countries.
- Google Workspace hosts our company mailboxes, which receive privacy requests, security reports and demo requests, including the names, email addresses and message content you send us.
- Google Calendar, when a space turns on room-calendar sync, receives the booking title, time and guest name of room bookings.
- Apple and Google push notification services, which our support desk uses to notify our support staff. They receive the staff device's push token and internal conversation identifiers, and Apple also receives a fixed alert text. No names or message content are sent.
- PostHog for product analytics and Sentry for error and performance diagnostics, both in their EU services.
- OpenStreetMap map tiles on the public space directory load directly in your browser, which shares your IP address with the OpenStreetMap Foundation.
A demo request is delivered to our company inbox; it does not subscribe you to a marketing list.
If your operator enables an integration, relevant customer, invoice, booking, event or access information may be exchanged with its accounting, calendar, event or door-access provider. The operator decides which integrations it uses. Integrations a space connects itself, for example Mailchimp or Xero, run under that space's own contract with the provider, and we pass them only the information needed for the task the space turns on. We may also disclose information to comply with law, protect rights and security, or in a business transfer subject to applicable safeguards.
Storage, transfers and security
Our core application database is hosted in the EU. Some providers use global networks or process information outside the European Economic Area. Where required, transfers rely on an applicable adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses. For example, our AI features use OpenAI Ireland Ltd., which passes data to its US affiliate under standard contractual clauses, and to its sub-processors under standard contractual clauses or an adequacy decision, so that data may be processed in the United States. Contact us for information about safeguards relevant to your data.
We use encrypted connections, password hashing, access controls and organization-based permissions to protect information. Access is limited according to the task and role. No service can guarantee absolute security. Our security page describes these measures and how to report a security issue.
How long we keep information
We retain account and service records while needed to provide the service and for the purposes described here. Retention depends on the record, the operator's instructions and applicable law. Our scheduled retention process removes the following records automatically:
- door-access event history after 90 days;
- door-access configuration history (changes to a space's door setup) after 13 months;
- email campaign recipient addresses 90 days after the campaign is sent;
- email delivery events after 30 days;
- the recipient address and content of automated space emails (receipts, booking, event and invitation emails) 30 days after they are sent;
- the sign-in and connected-app access tokens of ended sessions 30 days after they end (the record that you approved a connected app is kept);
- workspace invitations 90 days after they expire or are used;
- billing-contact invitations 90 days after they expire, and billing-contact access 90 days after it is revoked;
- mailing-list confirmation and preference links 7 days after they expire or are used;
- for completed account deletion requests, the contact email after 30 days and the request record after 12 months;
- unsent reply drafts, whether suggested by AI or written by staff, 90 days after they were last edited.
Accounting documents may need to be kept for seven years under Estonian law, or another period required of the responsible operator.
Web session recordings expire after 30 days. Analytics event history is held for product analysis and troubleshooting and expires after 12 months. Contact us for requests concerning information that can be associated with you.
We may retain limited information after account closure for unpaid transactions, fraud prevention, disputes or legal obligations. Backup copies on our server expire through backup rotation and are not immediately rewritten when a live record is removed; monthly copies there can remain for up to six months. Off-site backup copies follow the same 7 daily, 4 weekly and 6 monthly rotation through a scheduled job. Backup copies made before 21 September 2026, and copies made during our September 2026 system migration, are kept outside rotation until they are retired. Restored data remains subject to applicable deletion requests. We do not promise the same deletion deadline for every record or an operator's independent systems.
Your choices and rights
Depending on applicable law, you can request access, correction, erasure, restriction or portability of your personal data, object to processing based on legitimate interests, and withdraw consent. Email justin@kommonz.com. We may need to verify your identity. Where your operator controls the data, we will help direct the request to it. We respond within the time limits required by law, normally one month under the GDPR; if a permitted extension is needed, we will explain it.
To request deletion of your Kommonz account and associated personal data, follow our account deletion instructions. You can also complain to the Estonian Data Protection Inspectorate or your local supervisory authority.
Children and changes to this policy
Kommonz is intended for professional workspace use and is not directed at children. If you believe a child has provided personal data without appropriate authorization, contact us.
We update this policy when our practices change. The date above identifies the current version. We will provide additional notice of material changes where required by law.