Privacy Policy
Version 3.0
1. Controller and Data Protection Officer
The controller responsible for the processing of your personal data within the meaning of the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), and other applicable data protection legislation is:
Ilya Baskakov (Operating as: Eigentum²) Von-Müller-Straße 15a 82467 Garmisch-Partenkirchen, Germany
VAT ID (USt-IdNr.): DE356119638
Email: support@dein-eigentum.de Phone: +49 176 26554582
If you have any questions regarding the processing of your personal data or wish to exercise your data subject rights, please contact us at: support@dein-eigentum.de
Data Protection Officer: A Data Protection Officer has not been appointed, as the conditions under § 38 BDSG (fewer than 20 persons regularly engaged in automated processing of personal data) are not met. For all data protection inquiries, please contact us at the email address above.
2. Scope of This Privacy Policy
This Privacy Policy explains how Eigentum² ("we," "us," "our") collects, processes, stores, and protects your personal data when you:
- Visit our website(s) and web application;
- Create an account and use our property management platform;
- Communicate with us via email, contact forms, or other channels.
This Privacy Policy applies to all users of our platform, including property owners, landlords, property managers, tenants (where data is provided by a landlord user), and visitors to our website.
Where we process personal data on behalf of our users (e.g., tenant data entered by a landlord), we act as a data processor under Article 28 GDPR. In such cases, the user who enters the data is the data controller, and a separate Data Processing Agreement (DPA) governs that relationship. This Privacy Policy covers processing activities where we act as the data controller.
3. Categories of Personal Data We Collect
3.1 Account and Authentication Data
When you create an account, we collect:
- Email address
- First name and last name
- Password (stored only in hashed form; we never store plaintext passwords)
- Phone number (optional)
- Profile image (optional)
- Preferred language and currency settings
If you enable two-factor authentication, we additionally store the shared secret used to generate your confirmation codes and a set of single-use backup codes. Both are stored encrypted with a key held by our application and never in plain text. Encryption rather than one-way hashing is unavoidable here: the server has to be able to compute the code your authenticator app is currently showing in order to check the one you type, and a backup code has to be checkable against the set we issued to you.
If your account is suspended for a breach of our Terms of Service, we store the fact of the suspension, the reason, and the date on which it ends.
If you sign up or log in via Google OAuth, we receive the following data from Google:
- Email address
- Given name and family name
- Profile picture URL
- Email verification status
We also store OAuth tokens (access token, refresh token, ID token) to maintain your authenticated session with Google. These tokens are stored securely and are not shared with any third party.
3.2 Session and Device Data
Each time you log in, we create a session record containing:
- Session token (unique identifier)
- IP address
- User agent string (browser type, operating system, device information)
- Session creation, update, and expiration timestamps
This data is necessary for maintaining your authenticated session and for security purposes (e.g., detecting unauthorized access).
3.3 Contact and Tenant Data
If you use our platform to manage properties and tenants, you may enter the following data about your contacts (tenants, guarantors, property managers, etc.):
- Salutation, first name, last name
- Date of birth and nationality
- Company name and VAT number
- Full postal address (street, city, postal code, country)
- Contact methods (email, phone, mobile, fax) with verification status
- Banking details (IBAN, BIC, bank name)
- Emergency contact information (name, relationship, phone number)
- Preferred language and contact method
- Identity verification status
- Internal notes and metadata
- Contact acquisition source
Important: When you enter personal data of third parties (such as tenants), you are the data controller for that data under GDPR. You are responsible for ensuring that you have a valid legal basis (e.g., the tenancy agreement) for entering and processing that data on our platform. We process this data on your behalf as your data processor, governed by our Data Processing Agreement.
3.4 Property Data
We collect and store detailed information about properties you manage:
- Property title and description
- Full address (street, city, postal code, country, state/region, district)
- GPS coordinates (latitude, longitude — optional)
- Property type (house, apartment, land, commercial, multi-family, mixed-use)
- Year built, building condition, quality, and renovation history
- Area measurements and room counts
- Purchase details (price, date, currency)
- Land and building values for depreciation
- Energy efficiency data and certificates
- Legal attributes (monument protection, flood risk, contamination status, easements, zoning, tenure type)
- Distance metrics (to public transport, city center, schools, shopping)
- Market indicators and investment scores
- Custom fields and metadata
3.5 Financial Data
Our platform processes the following financial information:
Payments and Rent:
- Payment amounts (expected, paid, balance)
- Payment method (bank transfer, direct debit, cash, card, platform payout, cheque)
- Bank reference, sender name, and sender IBAN
- Card details (last 4 digits, brand, and expiry month/year only — synchronised from Stripe to power renewal and card-expiry reminders; we never store full card numbers or security codes)
- Due dates, receipt dates, and clearing dates
- Payment status and reminder history
Security Deposits:
- Deposit amounts and holding type
- Bank account details for deposit accounts
- Interest tracking
- Return calculations and deduction records
Loans and Mortgages:
- Lender information (name, type, reference number)
- Loan principal, interest rates, and terms
- Repayment schedules and payment history
- German-specific features (Zinsbindung, Sondertilgung)
- Borrower and guarantor information
Subscription Billing (via Stripe):
- Stripe customer ID
- Subscription and product identifiers
- Payment method identifier (last 4 digits only)
- Subscription status, start date, and renewal dates
- Billing email address
3.6 Lease Contract Data
- Contract number and type
- Letting mode and contract form
- Duration, start and end dates, notice period
- Rent model (fixed, stepped, indexed, turnover-based)
- Rent components (base rent, operating cost prepayments, utilities, surcharges)
- Contractual area (square metres) and room count
- Special terms (furnished, pets, subletting, smoking, commercial use)
- Fixed-term justification details (in compliance with § 575 BGB)
- Guarantor associations
3.7 Ownership Transfer Data
If you use our ownership transfer feature, we process:
- Transfer type (sale, gift, divorce settlement), status, and phase
- Agreed price, asking price, and assessed values
- Participant information: the role in the transfer (initiator or receiver), the linked user account or contact record, the organisation name and professional licence number where a participant acts in a professional capacity (for example a notary or an agent), the invitation email address, and the granular permissions you set for that participant
- Invitation details: invite token, short code, and the timestamps at which the invitation was sent, opened, accepted, declined or expired
- Free-text notes recorded on a participant or on a step of the transfer
- Transfer documents you or a participant upload. Depending on the type of transfer these may include notarial deeds, land registry extracts, cadastral maps, energy certificates, identity documents, powers of attorney, tax clearance certificates, proofs of payment, mortgage clearance letters, settlement statements, building inspection reports, divorce decrees, and — where a transfer follows a death — death certificates, certificates of inheritance, wills, probate orders and agreements among heirs. We do not read these documents; their content is determined entirely by what you upload, and some of them may contain special categories of personal data (Section 4.5)
- Fee and tax calculations
- Key dates and milestones
- An event history of the transfer: the type of event, a human-readable description, the name and role of the person who caused it, the step or participant it relates to, and the state before and after the change
The transfer event history contains no IP address and no user agent.
3.8 Property Valuation and AI-Processed Data
We offer two AI-assisted features: property valuation, and the reading of loan and financing documents you select. Both run only when you start them. Our AI Transparency Notice sets out, field by field, exactly what is transmitted in each case, which provider performs it, and what comes back; the summary here does not replace it.
Property valuation. When you request a valuation, we transmit the property record we hold — including the full address and coordinates, the property's characteristics, legal and register attributes, purchase data, earlier valuations, listing activity, the rent of an active lease broken down by component, cost items, your free-text entries about the property, and the web addresses of up to twenty photographs — to our AI provider, which returns an estimated value with a range, a confidence score, the methodology and reasoning, a market assessment, limitations and the comparables relied upon. The internet-search steps within that process receive only the country, city, district, property type, an approximate size and the room count; the street, house number, postcode and coordinates are never part of a search query. No tenant, contact, guarantor, loan, mortgage or account data, and no data identifying you or your organisation, is transmitted for a valuation.
A valuation can also be requested once during sign-up, in the free valuation offered by the onboarding wizard, before an account has been confirmed. In that case the record transmitted consists only of what you entered in the wizard.
Reading loan and financing documents. When you select loan documents and start the reading, those documents are transmitted in full and unaltered to our AI provider, which returns the figures printed in them. We do not store the result of the reading; the values are placed in the loan form for you to check, correct and save. Section 8 of the AI Transparency Notice explains what this means for the content of those documents and why the selection is yours.
What we retain of an AI request. For a valuation we store the result (the estimated value and range, the confidence score, the model version, and the analysis) against your property, marked as AI-generated, together with a cryptographic hash (SHA-256) of the prompt used for deduplication. The hash cannot be reversed into the prompt, and we do not store the prompt itself. For the reading of documents we store nothing of the request or the result.
Market research cache. The market figures and comparable listings that the search steps retrieve from public sources are cached under the country, city, district and property type they relate to, so that a later valuation in the same area does not repeat the search. That cache holds published market data and public listing entries. It is not linked to you, your account or your property.
No training. Neither we nor our AI providers use your data to train, fine-tune or improve any model. Your data is processed solely to produce the output you requested.
3.9 Documents and Files
- Property documents and files (filename, MIME type, file size, category, storage path)
- Property images (filename, MIME type, file size, category, storage path)
- Folder structures for document organisation
- Upload and update timestamps with user attribution
3.10 Property Sharing Data
When you share property information with others:
- Recipient email address
- Optional message/note to the recipient
- Expiration date for the share link
- Selection of shared folders and files
- View timestamp (when the recipient accessed the shared content)
3.11 Organisation and Membership Data
- Organisation name and slug
- Subscription tier and billing information
- Billing address (street, city, postal code, country, company name)
- Tax ID (for business customers)
- Member roles and permissions
- Invitation details (email, token, status, timestamps)
- Storage quota and usage
3.12 Legal Document Acceptance Records
When you accept legal documents (e.g., this Privacy Policy, Terms of Service):
- User ID and document version accepted
- Timestamp of acceptance
- IP address at the time of acceptance
- User agent at the time of acceptance
This data is collected to maintain a legally required audit trail of your consent and acceptance.
3.13 Change Histories and Records of Consent
We keep a change history for the two areas where a later dispute about what changed and when is realistic:
- Loans: for every change to a loan we record the loan concerned, the user who made the change, the time, the kind of change (creation, update, deletion, restoration, closure), the field affected, and the value before and after.
- Ownership transfers: the event history described in Section 3.7.
Neither of these records an IP address or a user agent.
Separately, and for the purpose of being able to demonstrate a decision you made, we record the IP address and browser user agent at the moment of the decision itself in the following four cases only:
- when you accept a version of a legal document (Section 3.12);
- when you make a cookie decision (Section 5.5), where the IP address is shortened before it is stored;
- when you give a consent in the billing process;
- when you change the tax identification number held for your organisation.
Outside these cases, and outside the session records described in Section 3.2 and the server log files described in Section 3.14, we do not record your IP address against your actions in the platform.
3.14 Automatically Collected Technical Data (Server Log Files)
When you access our website or application, our servers automatically collect:
- IP address
- Date and time of access
- HTTP request method and URL requested
- HTTP status code and response size
- Referrer URL (the page you came from)
- User agent string (browser, operating system, device)
When a request fails, our servers additionally write error and diagnostic entries to these same log files — typically an error message, a stack trace, and the operation concerned. That output is produced on our servers; no data is collected from your browser for it and no third-party error-monitoring or crash-reporting service is involved.
This data is processed on the basis of our legitimate interest in ensuring the security, stability, and optimal performance of our services (Article 6(1)(f) GDPR). These log files are held by our hosting provider (Section 6.1), which retains them for a short period and then deletes them automatically. That period never exceeds 30 days, and in the ordinary configuration of the platform it is considerably shorter. We do not copy these logs into any separate long-term store, and no third-party error-monitoring, crash-reporting or log-analysis service receives them.
3.15 Notification Data
When we generate a notification or reminder for you, we store:
- The type of event and how urgent it is
- A reference to the record it relates to (for example a property, a contract, or an invoice)
- The message text and the values inserted into it (for example a property name or a date)
- The delivery status per channel (in-app, email) and whether and when you saw or opened it
Notification data is derived from data already held for the purposes described in this policy; generating it does not involve collecting any additional data about you.
3.16 Marketing and Advertising Data
If — and only if — you have consented to marketing cookies (Section 5.3), we process the following data on our public marketing pages and on our checkout page in order to measure and target our own advertising on Facebook and Instagram:
- Pixel and browser identifiers (the
_fbpcookie) - Click identifiers (the
_fbccookie and thefbclidparameter contained in the address when you reach our website from a Meta advertisement) - IP address and user agent string
- The address (URL) of the marketing page you are visiting and the address of the page you came from
- Event names. The complete vocabulary we use is:
PageView,ViewContent,AddToCart,InitiateCheckout,AddPaymentInfo,Purchase,Subscribe,StartTrial,Lead,Contact,CompleteRegistration, and the custom eventsDocsArticleViewed,OnboardingStarted,OnboardingStepCompleted,OnboardingAddressEntered,ValuationCompleted,OnboardingCompletedandCapacityRequested - Event parameters, drawn from a closed list: the subscription price and its currency, the plan identifier, the content type, name and category, the number of items, the registration status (which funnel produced the account), the property type category ("apartment" or "house") when a property type is chosen at the start of the onboarding wizard, and — for a completed step of that wizard — the identifier of the step and its position in the sequence.
OnboardingAddressEnteredreports that an address was entered and validated, and carries no parameter at all: not one character of the address is transmitted - Contact details used solely for matching: email address, first name, last name, phone number, country, and an internal user identifier. These values are irreversibly hashed (SHA-256) before they leave the browser or our server; we never transmit them in plain text. On the browser side the hashing is performed by Meta's own pixel script before the value is sent, which is the only method Meta supports; on the server side we hash them ourselves before the request is made
This data is collected by the Meta Pixel in your browser and, for a subset of events, transmitted in parallel from our servers to Meta via the Meta Conversions API, with a shared event identifier so that a single event is not counted twice. For a purchase, the page address reported to Meta is a fixed, identifier-free checkout address rather than the address of the page the purchase was actually made on, so that no organisation identifier reaches Meta. For the collection of this data and its transmission to Meta, we and Meta Platforms Ireland Limited are joint controllers (Section 6.7). The data is transferred to the United States (Section 7.5).
What is never transmitted to Meta. None of the content you store in the platform is transmitted. In particular, the following are never sent, in any form and under any parameter:
- Property data of any kind — address, street, city, postcode, coordinates, size, condition, year built, or any other property attribute
- Property valuations, estimated values, purchase prices, portfolio values, rents, security deposits, loan and mortgage amounts, or any other financial data
- Documents, images, file names, or folder structures
- Contact, tenant, guarantor, and lease data
- Organisation names or identifiers, and property, lease, sharing, or transfer identifiers
- The subject of a consultation enquiry (life event) or its free-text message
- Any data from the authenticated application. The Meta Pixel is loaded exclusively on our public marketing pages (home page, pricing, consulting, documentation, legal pages, onboarding, sign-up) and on the checkout page. It is never loaded on any page of the application in which you manage your properties, nor on any page whose address contains an identifier or a token.
If you refuse consent or withdraw it, none of this data is collected and nothing is transmitted to Meta. We do not queue or store events for later transmission.
4. Purposes and Legal Bases of Processing
We only process your personal data where we have a valid legal basis under Article 6(1) GDPR. Below, we set out each purpose of processing together with the applicable legal basis.
4.1 Provision of Our Services (Contract Performance)
Legal basis: Article 6(1)(b) GDPR — processing is necessary for the performance of a contract or for pre-contractual measures.
We process your data to:
- Create and manage your user account
- Provide our property management platform and all its features
- Process rent payments, deposit management, and cost settlements
- Manage lease contracts and tenant relationships
- Generate an AI-assisted property valuation when you request one, and read the loan documents you select when you start that reading (Section 3.8)
- Enable property sharing with third parties you designate
- Process ownership transfers
- Manage your subscription and billing
- Provide customer support
- Send you service messages about your own records and account, including status updates and automated reminders about dates and deadlines arising from the data you enter
Service messages are part of the service you contracted for and contain no advertising. In-app notifications cannot be switched off while your account is active. For most notification categories you can decide in your notification settings whether we additionally send the message by email; messages that are required by law, or necessary for the security of your account or for billing, are always sent by email as well. Advertising emails are sent only with your consent (Section 4.4), which you may withdraw at any time.
4.2 Compliance with Legal Obligations
Legal basis: Article 6(1)(c) GDPR — processing is necessary for compliance with a legal obligation.
We are subject to various legal retention and documentation obligations, including under the German Commercial Code (HGB § 257) and the German Fiscal Code (AO § 147). We process and retain data to:
- Maintain accounting and tax records (retention: 10 years per AO § 147)
- Retain commercial correspondence and business letters (retention: 6 years per HGB § 257)
- Comply with anti-money laundering regulations where applicable
- Respond to lawful requests from public authorities
- Maintain audit trails for legal document acceptance (GDPR accountability)
- Document every cookie decision — consent as well as refusal — so that we can demonstrate it (Article 7(1) and Article 5(2) GDPR; see Section 5.5)
4.3 Legitimate Interests
Legal basis: Article 6(1)(f) GDPR — processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights of the data subject.
We rely on legitimate interests for the following processing activities:
| Processing Activity | Legitimate Interest Pursued |
|---|---|
| Server log file analysis | Ensuring IT security, detecting and preventing attacks, maintaining system stability |
| Change history for loans and for ownership transfers (Section 3.13) | Being able to establish what was changed, by whom and when, in the two areas where a later dispute is realistic |
| Session management (IP, user agent) | Account security, detection of unauthorised access |
| Error and diagnostic entries written to our own server-side logs (Section 3.14) — for example an error message, a stack trace, and the operation that failed. We use no third-party error-monitoring or crash-reporting service; no cookies are involved, nothing is read from your device, and nothing is collected from your browser for this purpose. These entries sit in our server log files and are retained for the same period (Section 8). | Detecting and resolving faults and keeping the service reliable |
| Aggregated statistics computed from our own server log files (Section 3.14) — for example the number of requests, error rates, and response times. No cookies are used for this, nothing is read from or stored on your device, and no analytics provider is involved. | Understanding the load on our systems and improving the reliability and performance of our services |
| Service and security notices | Informing users of material changes to the platform or to these documents, and alerting them to security-relevant events on their account |
| Assertion and defence of legal claims | Protecting our rights and interests |
You have the right to object to processing based on legitimate interests at any time (see Section 10.7).
4.4 Consent
Legal basis: Article 6(1)(a) GDPR — the data subject has given consent.
We process data based on your consent for:
- Non-essential cookies and tracking technologies (§ 25(1) TDDDG)
- Optional sharing of property data with third parties you designate
We do not currently operate a newsletter and send no advertising emails. Should we introduce them, we would obtain your prior consent, and you would be able to withdraw it at any time through an unsubscribe link in every such message.
You may withdraw your consent at any time with effect for the future, without affecting the lawfulness of processing carried out prior to the withdrawal. To withdraw consent, please contact us at support@dein-eigentum.de or use the relevant opt-out mechanism (e.g., cookie settings, unsubscribe link).
4.5 Processing of Special Categories of Data
We do not intentionally collect or process special categories of personal data as defined in Article 9(1) GDPR (e.g., racial or ethnic origin, political opinions, religious beliefs, health data, biometric data). If such data is incidentally included in free-text fields (e.g., notes), the processing is based on Article 9(2)(a) GDPR (explicit consent) or Article 9(2)(f) GDPR (establishment, exercise, or defence of legal claims).
5. Cookies and Similar Technologies
5.1 Legal Framework
The use of cookies and similar technologies is governed by § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) and the GDPR.
5.2 Strictly Necessary Cookies
Certain cookies are strictly necessary for the operation of our website and platform. These are placed without your consent in accordance with § 25(2) No. 2 TDDDG, as they are essential for providing the service you have explicitly requested.
| Category | Purpose | Duration |
|---|---|---|
| Authentication and session | Maintaining your authenticated session and your two-factor status | 30 seconds to 30 days |
| Language and interface state | Remembering your selected language and your interface preferences | Up to 1 year |
| Cookie consent | Storing your cookie decision | 6 months |
| Payment (Stripe) | Fraud prevention on pages where payment details are entered | 30 minutes to 1 year |
| Working data in your browser | Holding form drafts and file-access credentials while you work | Up to 7 days |
A complete list, naming every individual entry with its provider, purpose, storage mechanism and duration, is set out in our Cookie Policy at https://dein-eigentum.de/legal/cookies.
5.3 Marketing Cookies and the Meta Pixel
We use the Meta Pixel and the Meta Conversions API of Meta Platforms Ireland Limited to measure the effectiveness of our advertising on Facebook and Instagram and to show relevant ads to visitors of our website. The cookies used for this purpose (_fbp, _fbc) are marketing cookies within the meaning of § 25(1) TDDDG.
These cookies are set, and the Meta Pixel is loaded, only after you have given your prior consent (Article 6(1)(a) GDPR in conjunction with § 25(1) TDDDG). Until you consent, no script is loaded from Meta and no connection to Meta is established from your browser. We do not rely on legitimate interests for this processing.
The pixel runs exclusively on our public marketing pages and on the checkout page. It is never active inside the authenticated application in which you manage your properties, and no property, valuation, financial, document, contact, or tenant data is transmitted to Meta.
We do not currently use analytics cookies. Should we introduce them, they too would be set only with your prior consent.
Other content your browser loads from third parties. For completeness, and because it is the question a cookie banner is usually asked to answer, the following is the full list of third-party hosts your browser contacts while using the platform. None of them stores anything on your device or reads anything from it for us, so none requires consent under § 25 TDDDG; each transmits your IP address and browser user agent to the host concerned as an unavoidable part of retrieving the content, on the basis of Article 6(1)(b) and (f) GDPR.
- Our file storage (Google Cloud Storage / Firebase). Property images and document previews are fetched by your browser directly from the storage host, so that large files do not pass through our servers twice. The file-access credential your browser uses for this is obtained from Google's authentication endpoints.
- Profile pictures from Google. If you signed in with Google, your profile picture is displayed from the address Google supplied, so your browser fetches it from Google.
- Stripe. On the pages where you enter payment details, Stripe's payment form is embedded and Stripe sets the two fraud-prevention cookies listed in Section 5.2. That form also causes a font stylesheet to be fetched from Google Fonts so that the payment fields match the rest of the page.
- The Google map on a shared-property page (Section 6.2).
Our own web fonts are served from our own domain, not from Google Fonts. Apart from the Meta Pixel described in this Section, which runs only with your consent, our pages load no advertising, analytics, tracking or social-media scripts of any kind.
The data processed in this context is set out in Section 3.16, the joint controllership with Meta in Section 6.7, and the transfer to the United States in Section 7.5. A full list of the individual cookies, with provider, purpose, type, and duration, is set out in our Cookie Policy at https://dein-eigentum.de/legal/cookies.
5.4 Managing Your Cookie Preferences
You can manage your cookie decision at any time via our cookie consent banner or by clicking the "Cookie Settings" link in the footer of our website. The banner offers exactly two categories: strictly necessary cookies, which are always active because the platform cannot be operated without them, and marketing cookies, which you can accept or refuse. Refusing is offered with the same prominence as accepting, and withdrawal is as easy as consenting.
Withdrawing your consent to marketing cookies takes effect immediately: the Meta Pixel is no longer executed, the _fbp and _fbc cookies are deleted from your device, and no further data is transmitted to Meta. Refusing or withdrawing consent has no effect on your ability to use the platform; we do not operate a cookie wall and no feature is withheld from you.
Your decision is stored for 6 months; afterwards we ask you again, so that your consent is always current rather than assumed. Six months is our own choice, not a period prescribed by law: neither the GDPR nor the German supervisory authorities set a maximum, and we have taken the shorter of the intervals in circulation — the six months recommended as best practice by the French supervisory authority (CNIL) — rather than the longer ones. It is at the same time deliberately longer than the 90-day lifetime of the _fbp and _fbc cookies, so that those cookies can never outlive the consent that permits them.
Independently of that interval, we ask you again whenever what you consented to changes. Under the guidance of the German supervisory authorities, a bundled consent does not extend to a purpose or a recipient that was not part of it, so introducing a new advertising partner or a new purpose invalidates the earlier decision and we obtain a new one.
You can also configure your browser to block or delete cookies, though this may affect the functionality of our platform.
5.5 Documentation of Your Consent (Proof of Consent)
Article 7(1) GDPR requires us to be able to demonstrate that consent was given. We therefore document every cookie decision — whether you accept or refuse, and whether or not you have an account with us. Visitors without an account are documented in exactly the same way as registered users; no account is created for this purpose and none is required.
The record consists of the categories you accepted or refused, the date and time of your decision, the version of our Cookie Policy in force at that time, the internal version of the consent banner under which you decided, the language in which the banner was displayed to you, a pseudonymous consent ID, and your abbreviated IP address together with your browser's user agent.
If you were already signed in when you made your decision, the record additionally refers to your user account. This reference exists only in that case: for anyone who is not signed in — whether or not they have an account with us — it is absent, and no account is created or assigned in order to add one. Whether it is present makes no difference to whether and how your decision is documented.
Legal basis for the documentation itself. We process this documentation in order to comply with a legal obligation, Article 6(1)(c) GDPR. The obligation follows from Article 7(1) GDPR, which requires us to be able to demonstrate consent, and from the accountability principle in Article 5(2) GDPR. This processing cannot be based on consent itself, because we also document refusals, where no consent exists. The same legal basis therefore covers keeping a record that you refused and that your refusal was honoured.
Pseudonymous consent ID. When you make a decision, a random identifier is generated and stored on your device alongside that decision. It allows us to link a later withdrawal to the consent originally given, without identifying you. It is not derived from any data about you, carries no meaning outside our consent records, and is never transmitted to Meta or to any other third party. It is not permanent: it is stored for six months, like your decision itself, and when we ask you for your decision again a new identifier is issued.
Abbreviated IP address. The IP address in the consent record is shortened before it is stored — for IPv4 addresses the last two octets are removed, and for IPv6 addresses the last 96 bits, so that only the first two blocks are retained. The stored value can therefore no longer be assigned to an individual connection. At no point do we store the full IP address for this purpose.
We keep this documentation in two stages: after 12 months the abbreviated IP address and the user agent are erased from the record, and after 3 years the record is deleted in its entirety. Section 8 sets out the detail.
6. Recipients and Categories of Recipients
We share your personal data with third parties only where necessary and only to the extent described below. We do not sell your personal data.
6.1 Service Providers (Data Processors)
We engage the following categories of service providers who process data on our behalf under Data Processing Agreements pursuant to Article 28 GDPR:
| Service Provider | Purpose | Location | Transfer Mechanism |
|---|---|---|---|
| Vercel Inc. | Hosting, content delivery, serverless compute | EU (Frankfurt) | EU processing; no third-country transfer |
| Neon Inc. | Managed PostgreSQL database hosting with automatic backups | EU (Frankfurt) | EU processing; no third-country transfer |
| Google Cloud Platform (Google LLC) | File and document storage (Firebase Cloud Storage) | EU (Frankfurt) / USA | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs) |
| Stripe, Inc. | Subscription billing and payment processing | USA / Ireland | EU-US Data Privacy Framework (DPF); Stripe Ireland acts as EU establishment |
| Resend (Plus Five Five, Inc.) | Transactional and service email delivery (account, security, billing, sharing, transfer and reminder messages) | USA | EU-US Data Privacy Framework (DPF); Standard Contractual Clauses (SCCs) |
| Google Ireland Ltd. / Google LLC (Gemini API) | AI-assisted reading of loan and financing documents you select, to extract their figures (per API request; not used for model training under the paid API terms) | Ireland / USA | Standard Contractual Clauses (SCCs); EU-US Data Privacy Framework (DPF) |
| OpenAI (EEA data processed by OpenAI Ireland Ltd.) | AI-powered property valuation, and AI-assisted reading of loan documents as a substitute or a second reading (per API request; not used for model training under the paid API terms) | Ireland / USA | Standard Contractual Clauses (SCCs) incorporated in OpenAI's data processing addendum |
| Google Ireland Ltd. | OAuth authentication (Google Sign-In), where you choose to sign in with Google | Ireland / USA | EU-US Data Privacy Framework (DPF) |
Where a provider is named with both an Irish and a United States entity, our contract is with the Irish entity and the processing takes place in the United States; the transfer safeguards in Section 7 apply to that onward transfer.
6.2 Google Maps (Separate Controller)
We use two services of the Google Maps Platform. For these, Google does not act as our processor: under Google's Maps Platform terms Google is a separate and independent controller for the data it receives, and its own processing is governed by Google's privacy policy rather than by an agreement under Article 28 GDPR. We therefore set them out here rather than in the table above.
Address lookup while you type an address. When you type an address in the platform, the text entered so far, your interface language and, where applicable, a restriction to certain countries are sent from our servers to the Google Places API in order to return address suggestions; the address you then select is looked up in the same way. The request is made by us and not by your browser: Google receives our server's address rather than yours, no script from Google is loaded into your browser, and nothing is stored on or read from your device. Legal basis: Article 6(1)(b) GDPR, because recording a correct address is part of the service you asked for, together with Article 6(1)(f) GDPR in our interest in accurate address data.
Property map on a shared-property page. Where a property has coordinates recorded, a map of its location is displayed in a frame served by Google (Google Maps Embed API) on the page a recipient sees for a property shared with them. This is the only place in the platform where a Google map is displayed. It appears only to a signed-in recipient who has opened a property that was shared with them, and never on our public pages. The only content passed to Google is the property's geographic coordinates and a zoom level; the address, the title and every other attribute of the property remain with us. Because the frame is loaded by the viewer's browser, Google receives the viewer's IP address, browser user agent and the usual connection data. The address of that page carries a share identifier, so the frame is configured to transmit only our domain as the referrer and never the page address itself. The Embed API stores nothing on the viewer's device and reads nothing from it, so no consent under § 25(1) TDDDG is required for it; the processing rests on Article 6(1)(f) GDPR, in our and your interest in a shared property showing where it is. If no coordinates are recorded for the property, no map is rendered and no request reaches Google at all.
Google may transfer the data it receives in this context to the United States. Google LLC is certified under the EU-US Data Privacy Framework, so such transfers rest on the European Commission's adequacy decision (Section 7.1). Information on Google's own processing is available at https://policies.google.com/privacy.
6.3 Third Parties Designated by You
When you use our property sharing feature, the recipients you designate will receive access to the property data and documents you have chosen to share. We facilitate this sharing on your instruction; you are responsible for ensuring the recipient is appropriate.
6.4 Ownership Transfer Participants
In the context of an ownership transfer, data is shared with participants (buyers, sellers, notaries, agents) you have invited to the transfer. Participants only receive access to data relevant to their role, as controlled by the granular permission settings you configure.
6.5 Public Authorities
We may disclose personal data to public authorities (e.g., tax authorities, law enforcement, data protection authorities) where we are legally obligated to do so or where disclosure is necessary for the assertion, exercise, or defence of legal claims.
6.6 Corporate Transactions
In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer and of any changes to the applicable privacy policy.
6.7 Joint Controllers (Article 26 GDPR)
For the collection of personal data through the Meta Pixel on this website and its transmission to Meta, we and Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, D02 AX86, Ireland are joint controllers within the meaning of Article 26 GDPR. Meta is not our processor.
The joint controllership is limited to the collection of the data and its transmission to Meta. Any subsequent processing carried out by Meta is Meta's sole responsibility and is not covered by the joint controllership.
The products covered are the Meta Pixel and the Meta Conversions API, and the purpose is the measurement and targeting of our own advertising on Facebook and Instagram. We have concluded Meta's Controller Addendum with Meta Platforms Ireland Limited; its essence is available at https://www.facebook.com/legal/controller_addendum. Under it, Meta is responsible for providing the information required by Articles 13 and 14 GDPR in respect of its own processing, and Meta is responsible for handling requests under Articles 15 to 20 GDPR relating to the data held by Meta. The legal basis for Meta's own processing, and further information about it, are set out in Meta's data policy.
Article 26(3) GDPR gives you the right to exercise your rights against each of the joint controllers, irrespective of how we and Meta have allocated responsibility between us. You may therefore address us, and we will forward requests concerning Meta's processing to Meta, or you may address Meta directly.
We should be candid about one point. The German supervisory authorities have taken the view that the addendum Meta offers does not, by itself, meet every requirement of Article 26 GDPR. We use it because it is the arrangement Meta makes available to all of its advertisers and no alternative is offered; we describe the allocation of responsibilities here so that it is transparent to you, as Article 26(3) requires, rather than relying on the addendum to speak for itself.
Information on how Meta processes personal data, and the controls available to you, can be found in Meta's Privacy Policy at https://www.facebook.com/privacy/policy and in your Meta ad preferences at https://www.facebook.com/adpreferences.
7. International Data Transfers
Some of our service providers, and our advertising partner Meta (Section 7.5), are established in or process data in countries outside the European Economic Area (EEA), in particular the United States. We ensure that any such transfer is subject to appropriate safeguards in accordance with Chapter V of the GDPR:
7.1 EU-US Data Privacy Framework (DPF)
Where our US-based service providers are certified under the EU-US Data Privacy Framework, transfers are based on the European Commission's adequacy decision of 10 July 2023 pursuant to Article 45 GDPR. That decision is in force. An action to annul it was dismissed by the General Court of the European Union on 3 September 2025 (Case T-553/23, Latombe v Commission); an appeal against that judgment was lodged on 31 October 2025 and is pending before the Court of Justice (Case C-703/25 P). Until the Court of Justice rules, the adequacy decision remains in force. We check that a provider's certification actually covers the category of data we transfer to it before relying on the adequacy decision, and we have Standard Contractual Clauses in place with these providers as a fallback, so that transfers would remain lawful under Article 46(2)(c) GDPR should the adequacy decision cease to apply.
7.2 Standard Contractual Clauses (SCCs)
Where a service provider is not certified under the DPF or is located in a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) pursuant to Article 46(2)(c) GDPR, supplemented by additional safeguards where necessary based on a Transfer Impact Assessment.
7.3 United Kingdom
The European Commission renewed the two adequacy decisions for the United Kingdom on 19 December 2025, each subject to a six-year sunset clause running until 27 December 2031. Data transfers to the United Kingdom are therefore permitted without additional safeguards under Article 45 GDPR.
7.4 Switzerland
Switzerland is recognised as providing an adequate level of data protection by the European Commission. The Swiss Federal Act on Data Protection (nDSG/FADP), in force since 1 September 2023, is broadly aligned with the GDPR. The Swiss-US Data Privacy Framework has been in effect since 15 September 2024.
7.5 Transfers to Meta, and the Residual Risk of Transfers to the United States
Where you have consented to marketing cookies, the data described in Section 3.16 is transmitted to Meta Platforms Ireland Limited in Ireland and may be transferred by Meta to Meta Platforms, Inc. in the United States. Meta Platforms, Inc. is certified under the EU-US Data Privacy Framework, so such transfers are based on the European Commission's adequacy decision pursuant to Article 45 GDPR. In the alternative, Meta relies on the European Commission's Standard Contractual Clauses pursuant to Article 46(2)(c) GDPR.
Residual risk, stated plainly. This applies to every transfer to the United States described in this policy — to Meta, and equally to our AI providers, to our payment provider, to our email provider and to our file storage. Notwithstanding the safeguards set out above, it cannot be ruled out that United States authorities may access data transferred there. A level of protection comparable to that of the EEA cannot be guaranteed in every case, and effective legal remedies against such access may not be available to you in practice.
Two developments since the adequacy decision was adopted are worth knowing about, because they bear on how much weight it can carry. The Privacy and Civil Liberties Oversight Board — one of the institutional safeguards on which the European Commission relied — lost its quorum in January 2025 when three of its five members were removed. And the adequacy decision itself is under appeal before the Court of Justice (Section 7.1). We report this rather than leave it out: it does not make the transfers unlawful, because the adequacy decision is in force and we hold Standard Contractual Clauses as a fallback in every case, but it is the kind of fact you are entitled to weigh yourself.
For marketing cookies specifically, we tell you this so that your decision is an informed one. The transfer itself rests on the adequacy decision and, in the alternative, on the Standard Contractual Clauses, not on your consent. You can withdraw your consent at any time (Section 10.6), after which no further data is transmitted to Meta.
For the transfers that are necessary to operate the platform, the way to avoid a transfer is not to use the feature that causes it: no document is sent to an AI provider unless you select it and start the reading, and no valuation is generated unless you request one.
You may request a copy of the relevant transfer safeguards by contacting us at support@dein-eigentum.de.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by law. The specific retention periods are:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Account data | Duration of the contractual relationship. On deletion the account is immediately deactivated, all sessions are ended and any linked sign-in accounts are removed; the record itself is then irreversibly erased after 90 days, together with everything that hangs from it | Art. 6(1)(b) GDPR |
| Session data | Maximum 24 hours after session expiry | Art. 6(1)(f) GDPR |
| Server log files, including error and diagnostic entries (Section 3.14) | 30 days | Art. 6(1)(f) GDPR |
| Books, annual accounts, inventories and accounting records | 10 years from end of calendar year | § 147(1) No. 1 AO, § 257 HGB |
| Accounting vouchers (invoices, receipts, payment records) | 8 years from end of calendar year | § 147(3) AO, § 257(4) HGB (shortened from 10 to 8 years by the Viertes Bürokratieentlastungsgesetz, in force since 1 January 2025) |
| Commercial correspondence | 6 years from end of calendar year | § 257 HGB |
| Lease contract data | Duration of lease + 10 years (statutory retention) | § 147 AO |
| Security deposit records | Until deposit fully returned + 10 years | § 147 AO |
| Loan and mortgage data | Duration of loan + 10 years | § 147 AO |
| Property valuation data | Duration of account + statutory retention period | Art. 6(1)(b) GDPR |
| Change history for loans and for ownership transfers (Section 3.13) | For as long as the loan or the transfer it belongs to is retained; erased with it | Art. 6(1)(f) GDPR; § 147 AO where the underlying record is subject to retention |
| Legal document acceptance records (including the IP address and user agent recorded at acceptance) | For the duration of your account. They are deleted together with your account when the account record is erased 90 days after deletion | Art. 5(2), Art. 7(1) GDPR |
| Consent records (cookie, marketing) held by us as proof | Two stages: after 12 months the abbreviated IP address and the user agent are erased, leaving the record of the decision itself (categories, timestamp, cookie policy version, consent banner version, display language, pseudonymous consent ID, and any account reference); after 3 years the entire record is deleted | Art. 6(1)(c) GDPR in conjunction with Art. 7(1) and Art. 5(2) GDPR; § 25 TDDDG |
| Cookie decision stored on your device (cookie and local storage) | 6 months, after which we ask for your decision again | Art. 7(1) GDPR; § 25 TDDDG |
Meta marketing cookies _fbp and _fbc on your device | 90 days, or immediately upon withdrawal of your consent | Art. 6(1)(a) GDPR; § 25(1) TDDDG |
| Marketing event data transmitted to Meta (Section 3.16) | Not stored by us beyond transmission. At Meta, event data is deleted after at most two years, and the contact details transmitted for matching are deleted once the match has been carried out; retention at Meta is otherwise governed by Meta's own data policy | Art. 6(1)(a) GDPR |
| Billing consent network identifiers (IP address, user agent) | 180 days (then erased; the consent record itself is retained as proof, unless under legal hold) | Art. 6(1)(f) GDPR (data minimisation) |
| Tax identification number change records (including the IP address and user agent at the change) | For as long as the organisation exists; erased when the organisation's retained billing records are erased | Art. 6(1)(c) GDPR; § 147 AO |
| Ownership transfer data | Completion + 10 years (statutory retention); archived property snapshots retained indefinitely for audit | § 147 AO |
| Property sharing data | Until expiration of the share, its revocation, or erasure of the account | Art. 6(1)(b) GDPR |
| Contact/tenant data (entered by user) | Until deleted by the user (data controller) or account deletion | Art. 28 GDPR (processor obligation) |
| Email communication logs | 6 years | § 257 HGB |
| In-app notifications and alerts | 12 months after being read; 24 months after creation if never read | Art. 5(1)(c) GDPR (data minimisation) |
After the applicable retention period expires, data is securely deleted or irreversibly anonymised.
Consent records (Section 5.5): We keep the record of your cookie decision for three years as proof, on the basis of Article 6(1)(c) GDPR in conjunction with Article 7(1) and Article 5(2) GDPR. The period reflects the limitation period for administrative penalty proceedings under German data protection law, which the German supervisory authorities take as the benchmark here: for as long as a supervisory authority can still call the lawfulness of our processing into question, we must be able to demonstrate the consent on which it rested. The record is reduced in two stages. After 12 months the abbreviated IP address and the browser user agent are erased; they are not needed for the remainder of the period, and what stays is the record of the decision itself — the categories accepted or refused, the time of the decision, the version of the Cookie Policy it relates to, the version of the consent banner and the language it was displayed in, the pseudonymous consent ID, and, where the decision was made while signed in, the reference to the user account. After 3 years the entire record is deleted. A withdrawal does not delete the record of the earlier consent: it is added to it, because the earlier consent is precisely what we may have to prove.
Soft deletion: When you delete a record in the platform — a property, a unit, a lease, a loan, a file, a booking, an organisation or your account — it is first marked as deleted with a timestamp. It disappears from the platform at that moment: it is no longer shown to you, no longer included in any calculation, and no longer reachable by anyone with whom you had shared it. A daily process then erases it irreversibly, together with everything that hangs from it, 90 days after the deletion. The 90 days exist so that a deletion made by mistake can be reversed, and so that a record subject to a statutory retention obligation is identified before it is destroyed. Files are removed from our object storage in the same pass. Where a statutory retention obligation applies to a record, the record is restricted from further processing and kept only to comply with that obligation, and is erased when the obligation ends.
9. Automated Decision-Making and Profiling
9.1 AI-Powered Property Valuations
Our platform uses artificial intelligence (AI) to generate property valuations. This constitutes automated processing within the meaning of Article 22 GDPR. However, these valuations are provided as informational estimates only and do not produce any legal or similarly significant effects on you. No binding decisions are made solely on the basis of automated processing.
You always have the option to:
- Review and disregard any AI-generated valuation;
- Request a manual review of any valuation result;
- Contact us for clarification on the methodology used.
Transparency regarding AI systems. We use AI models from two third-party providers: OpenAI for property valuations, and Google (Gemini API) for reading loan and financing documents you choose to have read, with OpenAI as the substitute or second reading for that feature. Our AI Transparency Notice describes each feature, the provider that performs it, and exactly what is transmitted — including the fact that a document you select for reading is transmitted in full. It also sets out our position under the EU AI Act. We do not use AI for any decision-making that produces legal effects or similarly significantly affects you.
9.2 No Profiling for Automated Decisions
We do not engage in profiling that produces legal effects or similarly significantly affects you. We do not use your data for automated credit scoring, automated rejection of applications, or any other form of automated individual decision-making with legal or similarly significant effect.
Where you have consented to marketing cookies, Meta may use the data described in Section 3.16 to form advertising profiles and to display advertising to you. That profiling is carried out by Meta on its own responsibility (Section 6.7), is based on your consent, and produces no legal effects and no similarly significant effect on you. You can stop it at any time by withdrawing your consent (Section 10.6) and can configure Meta's advertising processing in your Meta ad preferences at https://www.facebook.com/adpreferences.
10. Your Rights as a Data Subject
You have the following rights under the GDPR and applicable national data protection law. To exercise any of these rights, please contact us at support@dein-eigentum.de. We will respond to your request within one month of receipt (extendable by two further months for complex requests, with prior notification).
We may ask you to verify your identity before processing your request in order to protect your data against unauthorised access.
10.1 Right of Access (Article 15 GDPR)
You have the right to obtain confirmation as to whether we process personal data concerning you and, if so, to receive a copy of that data together with information about the purposes, categories, recipients, retention periods, and the source of the data.
10.2 Right to Rectification (Article 16 GDPR)
You have the right to request the correction of inaccurate personal data and the completion of incomplete personal data concerning you.
10.3 Right to Erasure (Article 17 GDPR)
You have the right to request the deletion of your personal data where:
- The data is no longer necessary for the purpose for which it was collected;
- You withdraw your consent and no other legal basis applies;
- You object to processing and there are no overriding legitimate grounds;
- The data was processed unlawfully;
- Erasure is required by law.
This right does not apply where processing is necessary for compliance with a legal obligation (e.g., statutory retention periods) or for the establishment, exercise, or defence of legal claims.
10.4 Right to Restriction of Processing (Article 18 GDPR)
You have the right to request the restriction of processing where:
- You contest the accuracy of the data (for the period of verification);
- Processing is unlawful but you oppose erasure;
- We no longer need the data but you need it for legal claims;
- You have objected to processing pending verification of overriding grounds.
10.5 Right to Data Portability (Article 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller, where the processing is based on consent or contract performance and is carried out by automated means. Several parts of the platform can be exported directly from within it. For a complete export, write to support@dein-eigentum.de; we will provide it in a structured, machine-readable format within one month, and in any event before the record of your account is erased.
10.6 Right to Withdraw Consent (Article 7(3) GDPR)
Where processing is based on your consent, you may withdraw that consent at any time with effect for the future. The withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. Withdrawal must be as easy as giving consent, and we have arranged our systems accordingly.
Marketing cookies and the Meta Pixel: use the "Cookie Settings" link in the footer of our website. Your withdrawal takes effect immediately — the Meta Pixel is no longer executed, the _fbp and _fbc cookies are deleted from your device, and no further data is transmitted to Meta. Data lawfully transmitted to Meta before your withdrawal is unaffected; to have Meta erase it or restrict its use, please use your Meta ad preferences at https://www.facebook.com/adpreferences or address Meta directly (Section 6.7).
All other consent-based processing (currently: the optional sharing of property data with third parties you designate): withdraw it in the platform, where the share can be revoked at any time, or write to support@dein-eigentum.de.
10.7 Right to Object (Article 21 GDPR)
You have the right to object at any time, on grounds relating to your particular situation, to processing of your personal data based on Article 6(1)(e) or (f) GDPR, including profiling based on those provisions. We will cease processing unless we demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defence of legal claims.
Where personal data is processed for direct marketing purposes, you have the right to object at any time to such processing. If you object, your data will no longer be processed for direct marketing purposes.
For the measurement and targeting of our advertising via the Meta Pixel we rely on your consent, not on legitimate interests. The appropriate route there is therefore the withdrawal of consent under Section 10.6, which requires no reasons and takes effect immediately. In addition, you can object to Meta's own advertising processing and configure it at any time in your Meta ad preferences at https://www.facebook.com/adpreferences.
10.8 Right to Lodge a Complaint with a Supervisory Authority (Article 77 GDPR)
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
The supervisory authority for our company is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany https://www.lda.bayern.de poststelle@lda.bayern.de
A list of all German supervisory authorities and their contact details is available at: https://www.bfdi.bund.de
If you are located in Austria, you may also contact: Österreichische Datenschutzbehörde Barichgasse 40-42, 1030 Vienna, Austria https://www.dsb.gv.at
If you are located in Switzerland, you may also contact: Eidgenössischer Datenschutz- und Öffentlichkeitsbeauftragter (EDÖB) Feldeggweg 1, 3003 Bern, Switzerland https://www.edoeb.admin.ch
10.9 Right to Effective Judicial Remedy (Article 79 GDPR)
You have the right to an effective judicial remedy against a controller or processor if you consider that your rights under the GDPR have been infringed.
10.10 Right to Compensation (Article 82 GDPR)
Any person who has suffered material or non-material damage as a result of an infringement of the GDPR has the right to receive compensation from the controller or processor for the damage suffered.
11. Data Security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. These measures include, but are not limited to:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: Our database and our file storage are encrypted at rest by the infrastructure providers that operate them (Section 6.1). Backups are encrypted in the same way.
- Password security: Passwords are never stored in plaintext and never in a recoverable form. They are hashed with scrypt, a memory-hard key-derivation function designed to make large-scale guessing expensive, with a per-password salt.
- Access controls: Role-based access controls (RBAC) ensure that users and employees can only access data relevant to their role and authorisation level.
- Session security: Sessions are secured with unique, randomly generated tokens transmitted in cookies that are marked HttpOnly, Secure and SameSite=Lax, and they expire automatically after at most seven days. Sessions can be revoked, and because the cached copy of a session lives for only 30 seconds, a revocation takes effect within seconds.
- Two-factor authentication: You can protect your account with a second factor (a time-based confirmation code), with single-use backup codes for recovery.
- Infrastructure security: Our hosting infrastructure (Vercel, Google Cloud) maintains SOC 2 Type II, ISO 27001, and other industry certifications.
- Change history: Changes to loans and to ownership transfers are recorded with the person, the time and the values before and after (Section 3.13). Application and access logs are held by our hosting provider for the short period described in Section 3.14.
- Incident response: We maintain an incident response plan for data breaches in accordance with Articles 33 and 34 GDPR.
- Confidentiality and access discipline: Access to personal data is limited to those persons who need it to operate the platform. Any such person is bound to confidentiality and is instructed in data protection before access is granted.
- Vendor assessment: Third-party service providers are assessed for data protection compliance before engagement and regularly thereafter.
12. Obligation to Provide Data
12.1 Contractual Requirement
The provision of certain personal data (email, name, password) is necessary for the conclusion and performance of the contract between you and us. Without this data, we cannot create your account or provide our services.
12.2 Legal Requirement
In certain cases, we are legally obligated to collect and retain data (e.g., billing data for tax compliance). Failure to provide such data may prevent us from offering certain features or fulfilling our legal obligations.
12.3 Voluntary Provision
All other data you provide (e.g., phone number, profile image, property details, tenant data) is voluntary. Not providing this data may limit the functionality of certain features but will not prevent you from using the platform.
13. Third-Party Links and Services
Our platform may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices or content of such third-party services. We encourage you to review the privacy policies of any third-party service you interact with.
14. Children's Data
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete that data promptly. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us at support@dein-eigentum.de.
In Austria, the applicable age for digital consent is 14 years (§ 4(4) Austrian DSG).
15. Multi-Jurisdictional Notice
15.1 European Economic Area (EEA)
This Privacy Policy is designed to comply with Regulation (EU) 2016/679 (GDPR) and applicable national implementing legislation across all EEA Member States.
15.2 Germany
In addition to the GDPR, the following German laws apply:
- Bundesdatenschutzgesetz (BDSG): Federal Data Protection Act
- Telekommunikation-Digitale-Dienste-Datenschutz-Gesetz (TDDDG): Governs cookies and similar technologies (§ 25 TDDDG)
- Handelsgesetzbuch (HGB) and Abgabenordnung (AO): Statutory retention obligations
15.3 Austria
In Austria, the Datenschutzgesetz (DSG) supplements the GDPR. Notable differences include:
- The right to data secrecy (§ 1 DSG) has constitutional force and extends to legal persons.
- The age of digital consent is 14 years (§ 4(4) DSG).
15.4 Switzerland
If you are located in Switzerland, the Swiss Federal Act on Data Protection (nDSG/FADP), in force since 1 September 2023, applies in addition to the GDPR where applicable. Key differences include:
- Criminal liability for data protection violations is personal (fines up to CHF 250,000 against individuals, not organisations).
- The supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC/EDÖB).
- The Swiss-US Data Privacy Framework has been in effect since 15 September 2024.
16. Dispute Resolution
We are committed to resolving any complaints about the collection or use of your personal data. If you have a concern, please contact us at support@dein-eigentum.de. We will endeavour to resolve your complaint within 30 days.
If we cannot resolve your complaint, you have the right to lodge a complaint with the competent supervisory authority (see Section 10.8).
We are neither obligated nor willing to participate in dispute resolution proceedings before a consumer arbitration board (Verbraucherschlichtungsstelle) within the meaning of § 36 VSBG.
17. Changes to This Privacy Policy
We reserve the right to update this Privacy Policy to reflect changes in our data processing practices, legal requirements, or business operations. When we make material changes, we will:
- Update the version number and effective date at the top of this document;
- Notify you through the platform (via a blocking or non-blocking acceptance prompt, depending on the nature of the change);
- Provide a summary of changes in each supported language.
The current version of this Privacy Policy is always available at https://dein-eigentum.de/legal/privacy.
Previous versions are archived and available upon request.
18. Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us at:
Email: support@dein-eigentum.de Postal Address: Ilya Baskakov, Von-Müller-Straße 15a, 82467 Garmisch-Partenkirchen, Germany
The effective date of this version is displayed above this document.