VerwaltKlarVerwaltKlar

Security & privacy

Security starts with clear data flows and human responsibility.

VerwaltKlar documents which data is processed for a maintenance case, which services are involved, and where people review or approve. Locations, retention and providers are stated service by service rather than hidden behind a blanket promise.

Public overview

Clear roles. Bounded data flows. Human approvals.

This page describes verifiable product boundaries. It is neither a certification nor a complete disclosure of internal security mechanisms.

Review status: 2 August 2026

At a glance

The essential trust boundaries.

Access and sharing follow role and case context. AI prepares information; commissioning and required approvals remain with responsible people.

  • 01

    Commissioning stays human

    VerwaltKlar prepares the case and suggestions. The property manager selects and commissions the trade business.

  • 02

    Access follows role and case

    Tenant, role and case context limit which data property managers, tenants, owners and trade businesses can see.

  • 03

    Transparent AI and provider use

    We state tasks, data types and locations service by service and label planned building blocks as planned.

Bounded data flow

From reporting channel to human decision.

The public view shows responsibility and data hand-offs, not a reconstructable internal topology.

  1. 01

    Capture the report

    Telegram is the currently verified reporting channel. Text, optional photos and availability details are connected with the relevant tenancy and property context.

  2. 02

    Prepare text in a structured form

    Required report text and bounded case context support the dialogue and structuring. Photos remain case evidence in the current workflow.

  3. 03

    Review the case professionally

    The property manager sees the structured details, can edit them and reviews recommendations and required approvals.

  4. 04

    Share for the specific case

    A selected trade business receives only the case data intended for acceptance and delivery. A person commissions the work.

AI and model use

Which content is processed for which task.

For the guided dialogue, required report text and bounded case context are processed with Gemini on Vertex AI. The issue description and relevant lease clause are used to assemble liability information; extracted text is processed for document reading. Ticket photos are currently case evidence and are not described as AI image analysis. Google states that it does not use customer data to train or fine-tune models without prior permission or instruction.

This describes the current division of tasks. It is not a promise that AI output is complete or professionally correct.

Google's information on training and data retention

Services & regions

No blanket Europe promise.

The core product services for runtime, case data and customer files are currently configured in Belgium; Document AI uses the EU configuration and Cloud Translation uses its EU endpoint configuration. Firebase states that Authentication is processed in the United States, Cloud Logging storage is currently global, and reporting channels and other providers follow their own terms. We therefore make no blanket Europe promise.

Retention & data exit

Export followed by deletion is defined before pilot data is used.

Before real pilot data is processed, retention, export and subsequent deletion are defined for each data class and service. We publish no general deletion period until that procedure has passed technical and legal review.

Verified today

  • Individual technical retention rules already exist, but do not yet form an approved overall schedule.
  • A general public deletion period would therefore be misleading today.

Before real pilot data

  • Define data classes, systems, periods and owners
  • Practically test the export format and subsequent deletion
  • Document exceptions for backups and legal obligations
  • Minimise logging and complete technical and legal review

Procurement readiness

What must be completed publicly before the pilot—and what belongs in private review.

The public overview deliberately stays limited to commitments, responsibility boundaries and service-specific facts.

Verified today

  • Role- and case-scoped access controls
  • Server-checked consequential actions
  • Human commissioning and required approvals
  • Current AI tasks and boundaries

Before pilot

  • Consolidated provider and subprocessor register
  • Customer DPA and ownership of privacy requests
  • Retention, export and deletion procedure
  • Incident route and WhatsApp sign-off

On request

  • Private technical evidence matched to reviewer role and purpose
  • Detailed review of contracts and provider terms
  • Security and privacy discussion for a bounded pilot

Discuss privacy and security questions.

For a specific pilot, we jointly map data types, involved services and evidence—through the public overview or, where necessary, in a protected exchange.