Welcome to Xheris

Please select your preferred language

Privacy Policy | Xheris - Property Management Platform
GDPR Compliant

Privacy Policy

Your privacy matters to us. Learn how we collect, use, and protect your personal data in full transparency.

Last updated: November 9, 2025
1

Introduction

Welcome to Xheris, operated by Xheris OÜ, a company registered in Estonia (hereinafter "Xheris," "we," "our," or "us").

This Privacy Policy describes how we collect, process, use, store, share, and protect your information when you use our websites, mobile applications, platforms, services, and tools (collectively, the "Services").

Our Commitment

We are committed to protecting your privacy, but by using Xheris you acknowledge that we must collect and process certain personal and business data in order to provide our Services.

We comply with the General Data Protection Regulation (EU 2016/679 - GDPR) and other relevant international and national privacy laws.

2

Scope

This Privacy Policy applies to all users of Xheris, including but not limited to:

  • Tenants and property owners
  • Property managers and syndics
  • Contractors and subcontractors
  • Material and service suppliers
  • Visitors to our website
3

Data Controller

The data controller responsible for your information is:

Xheris OÜ

Registered office: Harju maakond, Tallinn, Kesklinna linnaosa, Tornimäe tn 5, 10145

Email: privacy@xheris.com

We may also act as data processor on behalf of property managers, suppliers, or contractors, depending on the services they use.

4

Information We Collect

We collect several types of information in order to provide, improve, and secure our Services:

A. Information You Provide

  • Identity data (name, surname, company, job title)
  • Contact data (email, phone, address)
  • Account data (login credentials, language preferences)
  • Property-related data (addresses, energy certificates, floor numbers, maintenance records)
  • Uploaded files (photos, videos, documents, invoices)
  • Payment information (bank details, Stripe or PayPal IDs)
  • Communication data (messages, feedback, support tickets)

B. Information Collected Automatically

  • Device and browser data (IP address, device type, OS, browser type, geolocation)
  • Usage data (logins, clicks, features used, time spent)
  • Cookies and tracking technologies
  • Geolocation data (when enabled)
5

Third-Party Integration

We may collect information from third-party sources to enhance our Services:

  • Contractors, suppliers, and managers integrated into the platform
  • Payment providers (Stripe, PayPal, banks)
  • CRM systems (Salesforce) and compliance systems (Peppol, VAT databases)
6

How We Use Your Data

We use your personal data for the following purposes:

  • To create and manage your account
  • To provide our Services (reporting issues, managing repairs, invoicing, supplier marketplace)
  • To communicate with you (notifications, support, contract updates)
  • To process and track payments securely
  • To comply with legal and tax obligations (Peppol e-invoicing, AML checks)
  • To improve user experience (UX/UI optimizations, personalization)
  • To provide analytics and reporting to managers, suppliers, and contractors
  • To ensure platform security and prevent fraud
  • For research and development, including testing AI-based features
  • For marketing and promotional communications (with consent)
Legal Basis

We process your personal data under GDPR based on:

  • Contractual necessity – to provide you with our Services
  • Legal obligations – accounting, invoicing, tax, anti-fraud, AML
  • Legitimate interests – improving our Services, ensuring security
  • Consent – for marketing and optional features
7

Sharing and Disclosure

We may share your information with:

  • Other users of the platform (tenants, contractors, suppliers, managers) when necessary for services
  • Service providers (hosting providers, email services, payment processors, IT support)
  • Affiliated companies within Orivian Group Inc.
  • Authorities and regulators where legally required
  • Potential investors or buyers in case of merger, acquisition, or restructuring
Important Note

We do not sell your personal data.

8

Data Retention

We retain personal data only as long as necessary:

  • User accounts: while active + 3 years after closure
  • Financial and billing data: 7 years (legal requirement)
  • Technical logs: 12 months (security)
  • Cookies: 12 months or until cleared by user
9

Your Rights

Under GDPR, you have the following rights:

  • Access to your data
  • Rectification of inaccurate data
  • Deletion ("right to be forgotten")
  • Restriction of processing
  • Data portability
  • Objection to processing
How to Exercise Your Rights

Requests should be sent to privacy@xheris.com. We will respond within 30 days.

10

Cookies and Tracking

Xheris uses cookies and similar technologies for:

  • Authentication and session management
  • Analytics (Google Analytics, internal tools)
  • Personalization
  • Advertising (only if you consent)

You can disable cookies in your browser, but some features may not work.

11

International Transfers

We may transfer data outside the EU/EEA (e.g., to hosting providers, support teams).

Safeguards: Standard Contractual Clauses (SCCs), adequacy decisions, or equivalent protections.

12

Security

We implement industry-standard security measures:

  • SSL/TLS encryption
  • Encrypted databases
  • Access controls
  • Regular security audits and penetration testing
13

Use of Third Parties

Our platform integrates with:

  • Stripe, PayPal – for payments
  • Google Maps API – for geolocation and mapping
  • Bitrix24 CRM – for workflow automation
  • AWS or DigitalOcean – for hosting
14

Profiling & AI

We may use automated systems, including AI, to:

  • Match contractors with jobs
  • Suggest suppliers and products
  • Predict maintenance needs
15

Marketing

We may send you marketing emails if you consent. You can unsubscribe at any time.

16

Children's Privacy

Our Services are not directed to children under 16. We do not knowingly collect their data.

17

Changes to Policy

We may update this Privacy Policy. Updates will be posted on our website and, when necessary, notified by email.

18

Contact

Have Questions About Your Privacy?

We're here to help. Contact our privacy team for any inquiries or to exercise your rights.

Xheris OÜ
privacy@xheris.com
Tornimäe tn 5, 10145 Tallinn, Estonia
Contact Privacy Team