Privacy notice
What data One-Home uses, why it is used and how its local design aims to limit unnecessary cloud processing.
1. Who processes your data?
This privacy notice applies to one-home.online, the Customer Portal and the One-Home Cloud services offered through this environment. One-Home is currently an early access product. Before a paid commercial launch, this page will publish the full name of the legal operator, its registered address, registration number and a direct privacy contact.
For personal data that remains exclusively within your local One-Home Core, the owner/administrator of that installation generally determines how the data is used. As soon as data is sent to One-Home Cloud, this notice applies to that cloud processing.
2. Our approach to privacy
One-Home is designed around a local-first principle. This means that device controls, home logic, automations and, where possible, sensitive home data can remain local. Cloud services are used for features where being online adds real value, such as account management, licences, update checks, optional backups and support.
3. What data may we process?
Depending on the features you use, the following categories may be processed:
- Account data: name, email address, account ID, verification status and security settings such as 2FA status.
- Home and installation data: home name, installation ID, hostname/platform, software version, update channel, last-seen time and technical health/status information.
- Licence and subscription data: plan, status, term, installation entitlements and administrative references.
- Contact and lead data: name, email address, type of enquiry and the text you enter in the contact form.
- Support data: data needed to handle a support request and, only with your consent, limited diagnostics from your installation.
- Backup metadata: installation ID, filename, size, timestamp and integrity information. The contents of a cloud backup are intended to be encrypted locally before upload.
- Security and log data: IP address, timestamps, session and audit information, error messages and information needed to investigate misuse, faults or security incidents.
- Payment information: when payments are enabled, a payment provider may process the payment. One-Home would then not need to store all card or bank details itself, but may process transaction, status and invoice references.
One-Home Cloud is not intended as the default storage location for camera footage, continuous sensor history or the full contents of your home database.
4. Why do we process data?
We process personal data only for clearly defined purposes. The main purposes are:
- creating, securing and managing a One-Home account;
- securely linking your local installation to your account and home;
- managing licences, releases, downloads and update channels;
- making optional cloud backups available;
- handling support questions, demo requests and partner enquiries;
- preventing and investigating fraud, misuse, account takeovers and technical attacks;
- improving the reliability and security of One-Home;
- complying with legal record-keeping, tax or security obligations where applicable.
5. Legal bases
Under the GDPR, every processing activity must have a valid legal basis. Depending on the circumstances, One-Home may rely on:
- Performance of a contract where processing is necessary to provide a requested service, account feature or cloud feature.
- Legitimate interest for proportionate security, fraud prevention, necessary technical logging and improvements to reliability, taking users' interests into account.
- Consent where a feature specifically requires it, such as certain optional communications or expressly authorised temporary support access.
- Legal obligation where data must be retained or disclosed under applicable law.
Where consent is the legal basis, you may withdraw that consent for future processing. Withdrawal does not automatically make previous lawful processing unlawful.
This website and demo: your chosen website theme and your choices in the interactive demo home are stored locally in this browser. This website's code does not load advertising or analytics scripts. You can remove local preferences through the site data settings in your browser.
6. Cookies, sessions and local storage
The Customer Portal needs technical session mechanisms to keep you signed in and secure. These strictly necessary cookies or similar technologies are intended for authentication, session security and protection against misuse. The current public website code does not contain advertising profiles or external marketing trackers.
If One-Home later adds analytics, marketing cookies or other non-essential tracking, the website and this notice will be updated and prior consent will be requested where required by law.
7. Local One-Home Core
An important design principle is that the home remains usable without a continuous cloud connection. Primary device controls, automations and the local database should therefore be able to remain on the local Core. Which One-Links need external internet access varies by brand and service.
The owner of a local installation is responsible for the users they grant access to, the One-Links they choose and the security of their own network and the host on which One-Home runs.
8. Cloud backups
When you enable cloud backups, the design aims to encrypt the backup locally before it is uploaded. The recovery key must be stored securely. If a key is kept exclusively locally by the user, losing that key may mean an encrypted backup can no longer be decrypted.
Backups are an additional recovery measure and are not a substitute for your own tested backup strategy.
9. Support and temporary diagnostics
One-Home is designed around explicit consent for support access. Where remote diagnostics are used, access should be limited, time-bound and logged. Standard diagnostics should not contain passwords, private keys or camera footage.
Do not send passwords, recovery keys, private keys or other secrets through forms or support tickets. If such information is genuinely needed for an investigation, a suitable secure channel must first be agreed upon.
10. Service providers and international transfers
One-Home may use specialist service providers for hosting, email, payments or other operational functions. Where such a party processes personal data on behalf of One-Home, appropriate data protection arrangements must be made.
If personal data is processed outside the European Economic Area, there must be a valid legal basis for the transfer and appropriate safeguards, such as an adequacy decision or applicable contractual safeguards. The final list of production data processors and locations will be published or made available on request before the commercial launch.
11. Retention periods
Personal data is retained no longer than necessary for the purpose for which it was collected, taking account of security, support, evidential and legal obligations. As One-Home is still in early access, production retention periods have not yet been published as fixed commercial commitments.
Before the commercial launch, a formal retention schedule will be established for, among other things, accounts, leads/contact requests, audit and security logs, support cases, backups and financial records. Where users can delete data themselves, technical removal from backup cycles may take place some time later.
12. How do we secure data?
One-Home uses a combination of technical and organisational measures. The current architecture provides for measures including secure sessions, CSRF protection, cryptographic device identity, anti-replay measures for device requests, signed licence/release data and locally encrypted backups.
No system can guarantee absolute security. One-Home therefore also publishes a Coordinated Vulnerability Disclosure policy and aims to include independent security testing in its release criteria before commercial production.
13. Your privacy rights
Under the GDPR, depending on the circumstances, you may have rights such as access, rectification, erasure, restriction, objection and data portability. You also have the right to receive information about the processing of your personal data.
You can initiate a request through the Customer Portal or the contact form on the website. We may request additional information to verify your identity before releasing or changing account or personal data.
If you believe that a privacy request has not been handled properly, you may lodge a complaint with the Dutch Data Protection Authority or another competent supervisory authority.
14. Children and special category data
One-Home is a home platform and is not intended as a standalone online service for children. Administrators must manage account access within a household carefully. Do not use One-Home to deliberately store special category personal data or unnecessary sensitive information in free-text fields without an appropriate legal basis.
15. Automated decision-making
One-Home is not intended to make decisions about individuals that have legal or similarly significant effects based on fully automated profiling. Home automations are home logic configured by users and are not the same as profiling for commercial decision-making.
16. Changes and contact
This privacy notice may be updated when the product, cloud architecture or legislation changes. Material changes will be published with a new version date.
Privacy contact during early access: use the contact form at one-home.online or submit a support request while signed in to My One-Home, and put “PRIVACY” at the top. Before the commercial launch, also publish a direct privacy email address and the full details of the legal operator.
Living Intelligence
One-Home Living Intelligence is not an always-listening voice assistant. The local Home Graph, contextual analyses and basic diagnostics are designed to run on One-Home Core. Intelligent features do not control devices freely and autonomously: existing permissions, safety rules and explicitly configured flows remain authoritative.