Privacy Policy
Draft — 9 August 2026
This policy is under legal review; the final version will replace it.
Key is a gate-access service for gated communities, operated by Zorviancode, an Egyptian company, through its app studio Kode Solutions. Its registration details will be added here once issued. This policy explains what we hold about you and why.
In most cases your compound’s management decides how your data is used and we act on their instructions. Where we decide — keeping the service secure and working — we are responsible ourselves. The PDPL Notice sets out that split.
What we collect
We do not collect your location, we do not track you across other websites, and we do not sell data to anyone.
- Your account: your name in English and Arabic as you enter them, your phone number, your email address, and your language and notification preferences.
- Your residency: the compound and unit your community’s management links you to, your role, and when your access is due for renewal. You do not set these — your management does.
- People you invite: when you issue a visitor pass, the name and phone number you type for that visitor.
- Gate activity: each time a pass is scanned we record which pass, which gate, the result, the time, and the guard on duty. For some passes a guard may also record a vehicle plate or take a photograph at the gate.
- Your device: if you turn notifications on, the technical address your device needs to receive them, and the browser or device type.
- Faults: if the app fails, technical diagnostics that help us fix it.
Why we use it
To verify who may enter the compound; to show a guard enough to make a decision at the gate; to keep an accurate record of entries for the community’s security; to tell you about your passes and your access; to keep the service secure and working; and to comply with the law.
When someone else’s data is in our system
If you invite a visitor, you are giving us their name and phone number. Please only invite people who would expect you to. We use it solely to let them through your gate, and we say so on the pass page they open.
Who can see what
- Your compound’s guards see a pass and its verdict at the gate, and their own scans.
- Your compound’s management sees the entry log, residents and passes for that compound.
- Other compounds see nothing. Communities are separated in the database itself, not merely hidden in the interface.
- We access a community’s data only to operate and support the service, and every such action by our staff is logged.
Who we rely on
A managed database and sign-in provider (data stored in Frankfurt, Germany), a web hosting and content delivery provider, an error monitoring provider, and the push notification services operated by Google and Apple. An email provider and a messaging provider for one-time sign-in codes are being added. Each may use the data only to provide their service to us.
Where your data is kept
Today, in the European Union (Frankfurt, Germany). We intend to move primary storage to Egypt. [The lawful basis for storage outside Egypt is under legal review.]
How long we keep it
[Retention periods are under legal review.] An entry record is a security audit trail, so there is a real tension between erasing a departed resident’s data and keeping a truthful record of who passed a gate. Our intention is to keep the record while removing the personal details no longer needed to identify it.
Your rights
You may ask to see the data we hold about you, correct it, delete it, restrict or object to its use, or receive a copy. You may withdraw consent for notifications at any time in Settings.
Some data cannot be deleted while you are a resident with gate access, and some entry records must be kept for the community’s security — we will say so clearly whenever that applies. To exercise a right, contact us at privacy@kode-solutions.com. If we cannot resolve your concern, you may complain to the Egyptian Personal Data Protection Centre.
Children
Key is intended for adults. [Accounts for teenagers are planned and under legal review.]
Security
Communities are separated by the database itself. Passes are cryptographically signed, so a pass cannot be forged or altered. Connections are encrypted. Our own staff access is logged.
Changes
We will post any change here and, if it materially affects you, tell you in the app.