Privacy policy.
Short version: we collect as little as possible, keep it in the EU, never sell it, and tell you exactly what we have.
Effective date: Cerloq One v1.0 launch (summer 2026) · Last updated: 24 May 2026
Who we are
Cerloq B.V., registered at the Kamer van Koophandel under KvK number TBD, with registered office at TBD, Amsterdam, The Netherlands. Reachable at privacy@cerloq.com.
What we collect from the device
Cerloq One devices publish only the following to our cloud:
- Indoor temperature and humidity readings (every 5 min)
- Property-state changes and avoided-runtime savings intervals (occupancy is computed on-device and used there for automation and aggregate savings — never exposed as a live presence feed)
- AC control events: which preset was sent and when (no payload data; we do not measure total AC consumption unless you fit the optional clamp add-on)
- Alert events: antitheft (plus smoke-relay once that roadmap feature ships)
- Device health: firmware version, free memory, uptime
What we do not collect: audio, video, raw radar data, live guest presence, or anything that personally identifies guests. There is no microphone or camera in the device.
What we collect from you (account holder)
- Email address (for login + critical alerts)
- Property name + address (for property + analytics context)
- Optional: iCal URL(s) of your bookings, if you opt into the roadmap turnover features (we read; never write)
- AC capacity in kW (one-time, for ROI calculation)
- Optional: electricity-bill amount + month, for ROI model calibration
What we never do
- Sell your data to anyone — ever.
- Share your data with advertisers, brokers, or third-party trackers.
- Store data outside the EU. Our backend runs in Google Cloud's
europe-west4region (Netherlands). - Record audio — there is no microphone in the device.
- Use cameras. We use 24 GHz radar for occupancy — it detects motion without imaging, and the verdict never leaves the device as a live feed.
Cookies + analytics
This marketing site uses no third-party trackers, no Google Analytics, no Facebook Pixel, no advertising cookies. Authenticated app sessions use a single first-party cookie to keep you logged in.
Your rights under GDPR
You can:
- Access all data we hold about you. Email privacy@cerloq.com.
- Export all your device telemetry as JSON, anytime, via the app or API.
- Delete your account + all associated data. Permanent, no waiting periods.
- Correct any data that's wrong.
- Lodge a complaint with the Autoriteit Persoonsgegevens (Dutch DPA).
Data retention
Active accounts: telemetry retained for 30 days (Starter), 12 months (Pro), or 36 months (Property Manager). Account deletion is immediate and permanent. We do not keep "deleted" backups beyond the operational backup window (7 days) required for disaster recovery.
Subprocessors
We use the following EU-based subprocessors:
- Google Cloud Platform — backend hosting,
europe-west4. - Neon — Postgres database, EU region.
- HiveMQ Cloud — MQTT broker for device communication, EU cluster.
- Cloudflare R2 — firmware binary storage (encrypted in transit).
- Stripe — payments (EU-licensed, GDPR-compliant).
Changes to this policy
If we change anything material, we'll email you and give 30 days' notice. The "Last updated" date at the top of this page is authoritative.
Contact
Privacy questions: privacy@cerloq.com
General contact: hello@cerloq.com