PRIVACY STATEMENT
for the dormakaba skyra Service (B2B SaaS Services)
Version: 06/2026
1. SCOPE AND SUBJECT MATTER OF THIS PRIVACY STATEMENT
1.1. General. This Privacy Statement applies to a dormakaba solution which consists of or combines the following types of components (including their related documentation and updates):
(i) a web portal or cloud service which is accessible – directly or indirectly – via a web browser (“Web Portal”), and/or
(ii) a mobile application (“Mobile App”).
1.2. Specific. The dormakaba skyra Service is a cloud-based access control service that enables operators (e.g. facility managers, system administrators and dispatchers) in critical infrastructure such as water supply, power distribution or telecom tower sites to plan, commission, operate, maintain and remotely monitor Site access authorizations and manage access thereto. The skyra Cloud Service and the skyra Mobile App, including their related documentation and updates, are components of the skyra Service and are individually and collectively also referred to herein as the “Service”.
1.3. dormakaba Switzerland Ltd, Mühlebühlstrasse 23, 8620 Wetzikon, Switzerland (“dormakaba”, “we” or “us”) is the operator of the Services. dormakaba or one of its affiliated companies provides the Services to its business customers (each a “Customer”). A Customer may grant natural persons access to use the Services.
1.4. This Privacy Statement informs natural persons who use the Service (“you”) about the types of personal data we collect from you in connection with the provision of the Services, the purposes for which this data is processed, and the rights you have in relation to the processing of your data.
1.5. Country-specific information may apply to you in addition to, instead of, or differently from the privacy information contained herein. Such country-specific information, if available, is set out in Section 11 – Country-Specific Information, or in a country-specific addendum or country-specific privacy statement for the skyra Service.
2. CONTROLLER, CONTACT INFORMATION, DATA PROTECTION REPRESENTATIVE
2.1. dormakaba Switzerland Ltd, Mühlebühlstrasse 23, 8620 Wetzikon, Switzerland, is the operator of the Services. We are the controller for the processing of personal data described in the following sections:
2.2. In addition, we process certain personal data on behalf of the Customer. The Customer may be your employer, the owner of the customer account, an account manager, property manager, administrator, or another company or person. Please note that, when we process personal data on behalf of the Customer, we are not the controller for that processing of personal data. For your convenience, we inform you about personal data that we may process on behalf of the Customer in the following section:
For further information, please contact the controller for the respective processing.
2.3. The Service provides functions that enable the Customer to enter personal data of third parties into the Service. We collect and process data concerning these third parties that is provided to us through the Service (e.g. [email address, name, mobile telephone number, additional information in a free-text field]), as well as related statistical data (e.g. type of mobile device, operating system version)]. The Customer is responsible for compliance with the applicable legal data protection obligations.
2.4. dormakaba Data Protection Representative.
a) General (for all countries): You can contact our Global Data Protection Officer at data.protection@dormakaba.comdata.protection@dormakaba.com
b) Specific (European Union): We have appointed dormakaba Deutschland GmbH, DORMA Platz 1, 58256 Ennepetal, Germany, data.protection@dormakaba.com (“EU Representative”) as our representative in the European Union within the meaning of Article 27 GDPR.data.protection@dormakaba.com
3. OUR PRINCIPLES FOR DATA PROCESSING
We process personal data in accordance with the applicable data protection laws and regulations as amended from time to time (“Applicable Data Protection Law”).
4. DATA COLLECTED, PURPOSES OF PROCESSING AND LEGAL BASES
4.1. Registration for the Mobile App (if available and applicable to you). When you register for the Service, you must enter your contact details, such as your first name, last name and email address, and set a password. To continue with the registration, you may need to use the service of the relevant provider of customer identity management services; your registration data will be shared with this provider of customer identity management services, if one is used. We process your registration data and related statistical data concerning the IP address (e.g. type of mobile device, operating system version), as well as corresponding consent management data (e.g. which provisions you accepted and when), in order to provide the Service offered and/or perform a contract with you. We may also process your contact details to provide you with information about the Service (e.g. release notes).
4.2. If you contact us by email, your email address, including the information you provide, will be stored for the purpose of processing your request and in case of follow-up questions. If the contact request concerns the clarification of problems with the Service or the provision of other services as part of the customer support we provide, the legal basis for processing your personal data is the performance of our contractual obligation.
5. USE OF ANALYTICS TOOLS; COOKIES
5.1. Analytics tools. We use the following analytics tools:
(a) [Google Analytics for Firebase and Firebase Crashlytics (“Google Analytics Tools”) from Google Ireland Ltd], [to analyse user behaviour and prepare reports on the stability of and improvements to the Services]
(b) Android Advertising ID (AAID), to analyse user behaviour and prepare reports on the stability of and improvements to the Services.
(c) Identifier for Advertisers (IDFA) on iOS, to analyse user behaviour and prepare reports on the stability of and improvements to the Services.
5.2. Cookies. We use strictly necessary cookies that are essential for the functioning of the Service. You cannot deactivate these cookies, but you can use your browser settings to block such cookies. In this case, the Service may not function in whole or in part. In some cases, we may use additional cookies. In such cases, we process your personal data on the basis of your consent by accepting the cookie notice displayed when you first use the Service.
6. PERSONAL DATA WE PROCESS ON BEHALF OF OUR CUSTOMERS
We process certain personal data on behalf of our Customer. For your convenience, we would like to inform you which personal data we may process on behalf of our Customer. Please note that we are not the controller for the processing of personal data listed in this Section 6 – Personal Data We Process on Behalf of Our Customer. For further information, please contact the controller for the respective processing.
6.1. Registration for the skyra Cloud Service (if applicable to you). We have received your contact details (email address) from the company (or another authorised user of the Service) that has designated you as an authorised user of the Service in order to send you an invitation link to the Service. When you register for the Service, you must complete the authorisation procedure and set a password.
6.2. Requests/questions via the Service. We process the data you provide via the Service in order to provide you with requested information or answer questions submitted. We process the information you enter into the Service exclusively on behalf of the Customer.
6.3. Solution-specific data management. Management of authorised users and access authorizations. The Customer or users authorised directly or indirectly by the Customer (each an “Authorised User”) manages within the Service (i) its Authorised Users and (iii) the access authorizations of individual Authorised Users to individual Access Points at individual Sites.
6.4. Access Log Data. The Customer and certain persons authorised by it have the technical ability to view information within the Service about which Access Point was used with which Key Medium and at what time, as follows:

7. RECIPIENTS; LOCATION OF DATA PROCESSING
We may disclose your personal data to processors engaged by us, including:
The Applicable Data Protection Law may contain restrictions on the transfer of personal data to third countries or other jurisdictions. If we transfer your personal data to a third country or another jurisdiction, we must comply with the Applicable Data Protection Law and implement data-transfer mechanisms and safeguards (guarantees) in accordance with that Applicable Data Protection Law, if and to the extent required for such cross-border transfer. If your personal data is processed in a country or jurisdiction other than the country or jurisdiction in which you reside, that data may subsequently be subject to the laws of that other country or jurisdiction, including any laws that permit or require disclosure of the information to the government, governmental authorities, courts and law enforcement authorities in that country or jurisdiction.
With regard to the transfer of personal data from the EU to Switzerland, the European Commission has determined that Switzerland provides an adequate level of data protection. A copy of the documentation concerning the measures we have taken is available from us upon request.
8. RETENTION PERIOD AND DELETION
We store your personal data in accordance with the Applicable Data Protection Law, when and for as long as this is necessary for the processing purposes set out in this Privacy Statement. We then delete your personal data in accordance with our retention and deletion policies or take measures to properly anonymise the data. An exception applies where we are legally required to retain your personal data for longer (e.g. for tax, accounting and auditing purposes). We retain data sent to us by email until the purpose for storing the data no longer applies (e.g. once your request has been processed).
9. YOUR RIGHTS
As a data subject, you have rights vis-à-vis the controller responsible for the data processing (see Section 2 – Controller, Contact Information, Data Protection Representative). If we are the controller for the data processing, depending on the country or jurisdiction in which you reside, you have the following rights in relation to your personal data vis-à-vis us or our respective Data Protection Representative by sending an email to our responsible Data Protection Representative (see Section 2.4 – dormakaba Data Protection Representative).
9.1. You may withdraw your consent to our processing of your personal data at any time. As a result, we may no longer process your personal data in the future on the basis of your consent. The withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
9.2. You may request information about the personal data concerning you that we process. In particular, you may request information about the purposes of processing, the types of personal data, the categories of recipients to whom your data has been or will be disclosed, the envisaged retention period, the existence of a right to rectification, erasure, restriction of processing or objection, the existence of a right to lodge a complaint, the source of your data if it was not collected directly from you, and the existence of automated decision-making, including profiling, and, where applicable, meaningful information about the details of such processing.
9.3. If and to the extent that, in the course of using the Service, you can enter, access, rectify or delete your personal data, you are responsible for rectifying, accessing or deleting your data in or from the Service. In all other cases, the following applies:
(a) You may request the immediate rectification of inaccurate personal data or completion of your personal data stored by us, and you also have the right, taking into account the purposes of processing, to request the completion of incomplete personal data, including by means of providing a supplementary statement.
(b) You may request the deletion of your personal data stored by us, unless processing is necessary for exercising the right to freedom of expression and information, compliance with a legal obligation, reasons of public interest, or the establishment, exercise or defence of legal claims, whereby the right to deletion may be restricted by national law.
(c) You may request restriction of the processing of your personal data if you dispute the accuracy of the data, the processing is unlawful but you oppose its deletion, we no longer need the data but you require it for the establishment, exercise or defence of legal claims, or you have objected to the processing.
(d) You have the right to receive the personal data that you have provided to us in a structured, commonly used and machine-readable format and to transmit this data to another controller (“right to data portability”).
9.4. You may lodge a complaint with a supervisory authority. As a rule, you may contact the supervisory authority at your habitual residence, place of work or the registered office of our EU Representative. If your personal data is processed on the basis of legitimate interests, you also have the right to object to the processing of your personal data where there are grounds relating to your particular situation.
Where personal data is processed for the purposes of direct marketing, you have the right to object at any time to the processing of your personal data for such marketing purposes; this also applies to profiling to the extent that it is related to such direct marketing.
10. CHANGES TO THIS PRIVACY STATEMENT
We may change this Privacy Statement from time to time for any reason. We will inform you of changes by publishing the new Privacy Statement in the application and changing the “Last updated” date. You should review this Privacy Statement regularly for any changes. In the event of material changes, we may also notify you by email or other appropriate means.
11. COUNTRY-SPECIFIC INFORMATION
[n/a]