Privacy Notice
Last updated · 23 August 2026
Buzz-In is a QR-code video intercom. When you scan the code at a building’s entrance, you can place a live video call to a resident, who can speak with you and release the door remotely. This notice explains what personal data is involved when you use a Buzz-In door, and your rights over it.
Who is responsible for your data
The building operator (the manager or company that runs the building you are visiting) is the data controller for visitor data at their door, and decides how long it is kept and who can see it. Buzz-In provides the technology and processes that data on the operator’s behalf (a data processor). For questions you can contact us here, and we will pass on requests to the relevant building operator where needed.
What we collect, and why
- A photo at the door. When you place a call, your device may capture a single still image from the front camera so the resident can see who is calling and so the building keeps a security record of the visit. This only happens if you allow your browser’s camera prompt — you can decline.
- Approximate location. If the building enables it, we check your device location to confirm you are actually at the building before connecting the call. These coordinates are used only for that check at the moment you call and are not stored. You can decline the location prompt (the call may then be unavailable).
- Network information. Your IP address is recorded with the call to keep the service secure and prevent abuse.
- Call details. The apartment you called, the date and time, whether the call was answered or missed, and whether the door was released.
- Live video and audio. During a call your video and audio are streamed to the resident through our video provider (Daily.co). Buzz-In does not record or store the call itself.
Legal basis
Under UK GDPR we rely on legitimate interests — operating a secure door-entry system and keeping a record of who has called — and, for access to your camera and location, on your consent, which you give through your browser’s permission prompts and can withhold.
How long it is kept
Visitor photos and call logs are retained by the building operator for as long as they reasonably need them for security and access records, after which they are deleted. If you would like to know the specific retention period for a particular building, contact us and we will help you reach the operator.
Who can see it
Visit records and photos are visible to the residents and managers of the building you called. We use trusted service providers to run the service — Daily.co (live video), Supabase (database and photo storage) and Vercel (hosting). We do not sell your personal data or use it for advertising.
Cookies and local storage
We use no advertising, tracking or third-party analytics cookies, so there is nothing for you to consent to and you will not see a cookie banner. The only thing we store on your device is a sign-in session, and only after you log in — a cookie for administrators, browser local storage for the manager and installer portals. It keeps you signed in, and is cleared when you sign out or when it expires. A visitor who scans a door QR code is given no cookie at all.
We do count page views on our public pages, to see which ones are read. That count records only the page address — no cookie, no identifier, no IP address, nothing that could identify you. Our web fonts are served from our own servers, so loading a page tells no third party that you were here.
Your rights
You have the right to ask for a copy of your data, to have it corrected or deleted, and to object to or restrict its use. To exercise any of these, contact us here. You do not have to use that form — a request made to us any other way counts just the same, and we will not ask you to resubmit it. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk.
Contact
Questions about this notice? Contact us here.