Version 1.0 · Effective 12 July 2026 · Reviewed annually
Eignasaga maintains the maintenance history of properties and processes user data as well as data from public registries. This page describes how we protect it: how users are authenticated, who can see what, how every lookup is logged, and how we respond when something goes wrong.
Users authenticate with Icelandic electronic ID (Auðkenni). Every action in the system is therefore traceable to a real, verified individual identified by their national ID number.
Every user, staff member and system component gets only the access its role requires.
| Role | Access |
|---|---|
| Owner | Full access to their own properties: documents, costs, photos, work history. |
| Delegate | Access to a specific property under a formally registered grant tied to a national ID, with a defined scope (full or view-only). Revocable at any time. |
| Contractor | Sees and verifies the jobs they are registered for; sees no other property data. |
| General user | Sees only the limited public view of properties the owner has chosen to open: no documents, no photos, no itemised costs. |
| Administrator | Administrative access. Every admin view of another person’s property and every admin action is recorded in the audit log. |
Every lookup in external registries (e.g. the property registry), every property view and every admin action is recorded in an immutable audit log: who did what, when, for what purpose and from which IP address.
The system runs on certified subprocessors, with data processing agreements (DPAs) in place with all of them.
| Provider | Role | Certification | Data location |
|---|---|---|---|
| Vercel | Hosting and file storage | SOC 2, ISO 27001 | Global CDN (EEA/US) |
| Neon | PostgreSQL database | SOC 2 | AWS eu-west-2 (London) |
| Resend | Email delivery | SOC 2 | US/EU |
| Taktikal | Electronic ID and signatures | Per agreement | Iceland/EEA |
Data is kept for as long as it is needed for the purpose it was collected for, or as long as law or contracts require. After that it is deleted.
| Data category | Retention |
|---|---|
| Audit log | At least 7 years, append-only, regardless of account deletion |
| User accounts and property data | Until the user deletes them or requests deletion |
| Data from public registries | Per the data-sharing agreement with the registry authority; redistribution prohibited |
| Sessions | Until expiry |
| Rate-limit records | 24 hours |
| Security incident register | At least 7 years |
A formal incident response plan covers every event that threatens the confidentiality, integrity or availability of data. Incidents are classified by severity with defined response times: severe incidents within 1 hour, significant within 24 hours, minor within 5 business days.
Personal data is processed in line with Icelandic Act No. 90/2018 and the GDPR: purpose limitation, minimisation, security and accountability. Your rights (access, rectification, erasure, portability) and our processing are described in the privacy policy.
If you believe you have found a security vulnerability in Eignasaga, please report it privately to eignasaga@eignasaga.is rather than disclosing it publicly. Include steps to reproduce and the affected part of the system. We acknowledge reports within two business days and keep you informed until the issue is resolved.