Repute is owned and operated by Kythera Technologies FZCO, Dubai, United Arab Emirates.
Information We Handle
Depending on how Repute is used, we may handle:
- Visitor names, document type and document number
- Building-specific visitor fields configured by the customer, such as vehicle number, parking bay or access category
- Optional visitor mobile country code and national number
- Submitted identification-document images when enabled by the building's visitor form
- Building, unit, destination and purpose-of-visit information
- Arrival, checkout, checkout actor and checkout feedback
- Organization, building and unit information
- Staff names, Repute-generated internal .rep login identifiers, roles, account status and building assignments. The .rep identifiers are non-deliverable account usernames, not personal email addresses
- Activity, audit, export, certificate and billing event records
- Session, device, diagnostics and technical information
- Support communications
- Billing contacts, invoices and subscription metadata
Building management organizations configure each building's visitor form from Repute's standard fields and up to 10 typed custom fields. Visitor name and identity document are always required; organizations decide whether the remaining permitted standard fields are hidden, optional or required and remain responsible for collecting only information needed for a lawful operational purpose. Custom values are always encrypted before database storage; customers cannot disable that protection.
How Information Is Used
Information may be used to:
- Register and check out visitors
- Create, manage, search and export visitor records
- Manage buildings, units, users and permissions
- Provide dashboards and activity records
- Manage subscriptions and payments
- Provide onboarding and customer support
- Maintain auditability, troubleshoot issues and secure the service
- Protect the platform against unauthorized access, misuse and fraud
- Meet applicable legal and regulatory requirements
Repute does not sell visitor information, use visitor records for third-party advertising or share visitor-log data for cross-app tracking.
Building Management Responsibilities
The building management organization using Repute is responsible for deciding why visitor information is collected and how it is used. Customers must collect only the information needed for their operations, provide any required notice to visitors, limit access to authorized users, keep records accurate, protect shared devices and exported records, and use Repute in accordance with applicable law.
Questions about a specific visitor record should normally be directed to the relevant building management organization. Repute may support the organization where required.
Identification Scanning
On supported mobile devices, capturing the front of an Emirates ID through Scan ID or the manual-entry form performs optical character recognition (OCR) on the device before submission to assist with visitor registration. Users must review and correct the extracted name and document number before saving. The compressed front image is added to the draft even if OCR cannot read the details; the guard may remove it before saving or use manual entry without an image.
Repute Desk uses Google ML Kit for this on-device text recognition. Google states that the OCR image, recognized text and OCR result are not sent to Google by the on-device SDK. The bundled SDK does automatically collect limited device and application information, a per-installation identifier, performance measurements, API configuration, feature event types and error codes for diagnostics and usage analytics. Repute does not use that telemetry for advertising or cross-app tracking.
Separately, the production app sends Repute limited technical error reports while a staff account is authenticated. A report contains only the error type, event category, fatal status, platform and app version; it excludes error messages, stack traces, visitor information, credentials, cookies, screenshots and document images. Repute uses these reports for app functionality, troubleshooting and reliability, and conservatively treats them as linked to the authenticated staff account.
Service Providers
Repute uses trusted service providers for hosting, deployment, database storage, private object storage, authentication and session infrastructure, email, payment processing, mobile build tooling, monitoring and support. These providers may process limited information as needed to deliver their services and are expected to protect that information consistently with their role and obligations.
Vercel provides cookie-free, aggregated Web Analytics and performance measurements for Repute's website and management portal. Repute removes URL query strings, fragments and UUID path segments before browser telemetry is sent, does not configure advertising or cross-site tracking, and does not send visitor-record contents as analytics events.
Payment card details are handled by Stripe. Repute stores billing and subscription state needed to operate the product, not card details.
International Processing
Repute and its service providers may process information in the United Arab Emirates and other countries where they operate. Laws in those countries may differ. Where applicable, Repute uses contractual, access-control and security measures appropriate to the provider's role, while customers remain responsible for assessing any transfer requirements that apply to their use of Repute.
Data Retention
Repute's current platform storage limit for visitor records and attached identification images is 60 months. Authorized organization users may search, view and export visitor records from the previous 12 months for every active building. Some billing, audit, security or legal records follow their own applicable retention requirements. Customers should export required records before their dashboard visibility period or the fixed platform storage period expires.
Security
Repute uses technical and organizational measures designed to protect customer and visitor information, including role-based access, application-layer authenticated encryption for sensitive visitor-log fields, private handling for submitted identification images, session revocation, audit trails, least-privileged runtime database access and PII-safe telemetry redaction. Repute Desk clears temporary document-photo drafts from memory and cache when they are submitted or removed, when the app leaves the foreground, on explicit sign-out and whenever the signed-in account changes; stale crash-recovery files are also swept on startup.
Customers are also responsible for protecting their accounts, devices, networks, visitor notices and downloaded records.
Your Information
Individuals may have rights regarding their personal information under applicable law. For visitor records, requests should normally be made to the building management organization that collected the information. Repute may assist the organization where reasonably required.
Repute Desk does not offer public or self-service account creation. Staff accounts are provisioned and controlled by the relevant customer organization. Staff seeking account termination or deletion should contact their organization administrator, or contact hello@repute.ae so the request can be routed to the responsible organization. Requests are handled subject to applicable customer instructions, agreements, legal obligations and retention requirements.
Children's Information
Repute is a business service and is not directed to children for their own use. A customer should collect information about a minor visitor only where necessary and authorized for its building operations and after assessing any notice, consent or other requirements that apply.
Essential Cookies
Repute uses essential cookies and similar technologies required for secure login, account sessions and core website functionality.
Updates and Contact
We may update this Privacy Notice when our services, practices or legal requirements change. The latest version will be published on this page with the revised date.
For privacy questions relating to Repute, contact hello@repute.ae.