Privacy
What we collect, and what we do with it.
In effect 22 August 2026 · Premise, Beirut, Lebanon
1. Two different situations
Premise is software that building operators run for their buildings. That means personal data reaches us two different ways, and our responsibilities are not the same in each. Mixing them up is how privacy policies become useless, so they are separated here.
- You contacted us through this website. We decide what to do with what you sent. We are responsible for it.
- You are a tenant, resident or member of staff using the Premise app. Your building operator decides what goes in and who sees it. We hold and protect it on their instruction. In data-protection language they are the controller and we are the processor — practically, if you want your data in the app changed or removed, you ask them first, and they can instruct us.
2. If you use this website
The demo form
When you ask for a demo you give us, and we receive:
| What | Why |
|---|---|
| Your name | To reply to a person rather than an address. |
| Company or building | To understand what you manage before the call. |
| Email address | To reply. This is the only field we reply to. |
| Phone or WhatsApp (optional) | Only if you would rather we called or messaged. |
| How many buildings | To know whether Premise fits before we take your time. |
| Your message (optional) | Whatever you choose to tell us. |
| Country of your connection | Added automatically by our host. Used to prioritise replies in our own time zone. |
That form sends one email to hello@premisepm.com and nothing else. It does not create an account, does not add you to a mailing list, and does not start an automated sequence. We reply, or we do not, and that is the end of it.
Analytics
We use Cloudflare Web Analytics to count page views. It sets no cookies, does not fingerprint your browser and does not follow you to other websites. We see totals — how many people opened a page — not individuals.
3. If you use the Premise app
Your building operator is responsible for this data. We hold it for them. What exists depends on what your building uses, and typically includes:
- Your account — name, email address, and a password we never store in readable form. Preferred language.
- Where you belong — the building, and the company or unit you are attached to, plus your role: tenant, resident, reception, valet, manager.
- What you do in the app — maintenance requests you report and any photos on them, rooms you book, visitors you invite, parcels logged for you, valet requests, survey answers, notices you post.
- Money — invoices issued to your company, payments recorded against them, receipts, and your share of any split building cost.
- Documents — leases, insurance certificates and house rules your building shares with you or with your company.
- Technical records — timestamps and identifiers needed to make the audit trail meaningful. A request having a time and an owner is the point of the product.
Who can see it
Separation between buildings, and between tenant companies inside one building, is enforced in the database itself rather than by hiding buttons in the interface, and an automated isolation test runs before every release. In practice:
- A tenant sees their own things, and what their company shares with them.
- A tenant of one company never sees another company's requests, invoices or documents.
- Someone in one building never sees anything from another building.
- Managers and staff of your building see what their role requires — a maintenance request has to reach whoever fixes it.
What we never do with it
- We do not sell it, and we do not share it with advertisers.
- We do not use one building operator's data to serve another.
- We do not use it to train machine-learning models.
- We do not read your content except when we have to fix a fault you or your operator reported, and only as far as that fault requires.
4. Who else touches the data
Running software means using other companies' infrastructure. These are all of them. Each is bound to us by its own terms and processes data on our instruction:
| Who | What for |
|---|---|
| Supabase | The database, sign-in, and stored files (documents, photos on requests). |
| Vercel | Runs the app itself. |
| Cloudflare | Serves this website, protects both from attack, and counts page views. |
| Resend | Sends email — sign-in links, password resets, notifications, and the demo form on this site. |
These providers operate infrastructure outside Lebanon, so data is stored and processed abroad. If where your data physically sits matters to your organisation, raise it with us before the pilot and we will tell you exactly where it is.
5. How long we keep it
| What | How long |
|---|---|
| Demo enquiries | Up to 24 months from your last contact, then deleted. Sooner if you ask. |
| App data | For as long as your building operator uses Premise. Records with an accounting purpose — invoices, receipts — are kept as long as their law requires. |
| Your account after you leave a building | Deactivated when your operator removes you. Deleted on request from you or from them. |
| If a building operator stops using Premise | They can export everything. We delete their data within 90 days of the account closing unless they ask us to hold it longer. |
6. Your rights, and how to use them
Under Lebanese Law No. 81 of 2018 on Electronic Transactions and Personal Data, and as a matter of how we would want to be treated, you can:
- Ask what we hold about you, and get a copy.
- Have anything wrong corrected.
- Ask for it to be deleted.
- Object to a particular use, or withdraw a consent you gave.
Write to hello@premisepm.com. We answer within 30 days. If your request is about data inside the app, we will tell your building operator, because it is theirs to decide — and we will say so plainly rather than going quiet.
7. Cookies
This website sets no cookies at all. The app sets only what signing in requires: a cookie that keeps you signed in, and a short-lived one that protects the sign-in itself. There is no advertising cookie, no analytics cookie and no third-party cookie anywhere in either. Clearing them signs you out; nothing else breaks.
8. Security
- Everything travels over HTTPS. The site is served with a strict content policy and HSTS.
- Passwords are hashed, never stored in a form anyone can read, and checked against known-breached password lists at sign-up.
- Separation between buildings and companies is enforced by database row-level security, not by the interface.
- No security is absolute. If a breach affects you we will tell you and your operator directly, and we will tell you what we know rather than what sounds reassuring.
9. Changes, and how to reach us
If this notice changes in a way that affects you, we will say so in the app and update the date at the top. We will not quietly widen what we do with your data and leave you to notice.
Questions, requests, or a complaint about how we have handled something: hello@premisepm.com.