GDPR Compliant

Privacy Policy

Last updated: 11 June 2026

1. Overview

EQUIA Global Property ("we", "us", "our") operates a web-based property portfolio management platform for international real estate investors. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our application, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

By using EQUIA, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the application.

2. Data Controller

The data controller responsible for processing your data is the entity identified in our Legal Notice (Impressum). For any data protection inquiries, please contact us using the details provided there.

3. Data We Collect

We collect and process the following categories of personal data:

Account Information

Name, email address, and authentication credentials. If you sign in via Google, we receive only your name and email address — we never receive or store your Google password. This data is required to create and maintain your account.

Property Portfolio Data

Asset details you provide, including property names, locations, purchase prices, currencies, purchase dates, and property descriptions, plus any Deal Analyzer drafts you save. This data is necessary to deliver the core portfolio management functionality.

Uploaded Documents

Files you upload to the Document Vault, such as Sales Purchase Agreements (SPAs), Title Deeds, passports, and visa documents. These documents may contain sensitive personal and financial information.

Mobility & Residency Data

Visa and residency records, presence day logs, and associated compliance data that you voluntarily enter to track your global mobility status.

Custom Alerts & Reminders

Reminders, deadlines, and notes you create via the Alerts feature, along with the email-delivery status of each scheduled reminder. We use this only to send the reminder at the time you specify.

Marketing Preferences

If you opt in to occasional product updates (either via the landing-page beta-access form or via Settings → Email preferences), we store a marketing_consent flag together with the timestamp of your opt-in (and, if applicable, the timestamp of your subsequent unsubscribe) so we maintain a verifiable audit trail under Art. 7(1) GDPR. The flag is read only when we send a marketing email; transactional emails are unaffected.

Beta-Access Requests

If you submit the "Request beta access" form on the landing page, we store the name, email address, free-text message, originating IP address, browser user-agent, and marketing-consent choice you provided. This data is used solely to evaluate and respond to your access request.

Feedback Submissions

If you send feedback via the in-app Feedback form, we store the category (bug, suggestion, praise, other), the optional severity for bug reports, the free-text body, and the page-of-origin plus browser user-agent. This data is used solely to triage and improve the product.

Usage Data

Technical data generated during your use of the application, including IP addresses (for brute-force and rate-limit protection), timestamps of login attempts, and session metadata.

4. How We Use Your Data

Your data is processed for the following purposes, each with a lawful basis under GDPR:

PurposeLegal Basis
Account creation and authenticationContract performance (Art. 6(1)(b) GDPR)
Portfolio management and FX conversionContract performance (Art. 6(1)(b) GDPR)
AI document analysis via OpenAIConsent (Art. 6(1)(a) GDPR)
Marketing emails & product updatesConsent (Art. 6(1)(a) GDPR) · revocable at any time
Visa expiry notifications and compliance alertsLegitimate interest (Art. 6(1)(f) GDPR)
Security (brute-force protection, rate limiting, session management)Legitimate interest (Art. 6(1)(f) GDPR)

5. Data Encryption & Security

We implement industry-standard security measures to protect your data:

Authentication & Session Security

Passwords are stored only as one-way hashes — never in plain text. Sessions use short-lived access tokens with separately rotated refresh tokens, both transmitted in HTTP-only cookies that browser scripts cannot read. Repeated failed login attempts are throttled and temporarily lock the account.

Document Vault — Envelope Encryption at Rest

Your account data and portfolio information is stored in MongoDB Atlas data centres located in Frankfurt, Germany (European Union). Uploaded documents are encrypted before storage using envelope encryption — a unique data-encryption key (DEK) is generated for every document, then itself wrapped with a master key held only in our backend environment. The encrypted blob is stored in Cloudflare R2's EU-jurisdictional infrastructure, so neither the document content nor the per-document DEK is ever readable by the storage provider.

Documents are only decrypted (a) when you view or download them, or (b) temporarily, in memory, during AI processing as described in § 6 ("How EQUIA uses AI"). The plaintext is never persisted to disk. All file uploads are validated server-side to reject mismatched or malicious binaries, file size is capped at 10 MB per document, and access is mediated exclusively through authenticated backend API endpoints — no direct storage URLs are exposed to the client. Each file is stored under a non-guessable path scoped to the owning user.

Transport Encryption

All communication between your browser and our servers is encrypted using HTTPS with modern TLS. API credentials, session tokens, and document payloads are transmitted exclusively over encrypted channels.

6. How EQUIA Uses AI

When you upload a document, EQUIA may use artificial intelligence to automatically classify the document type, extract key information (such as property details, payment schedules, or contract terms), and provide analysis through features like Contract Risk Radar and the AI Concierge.

This processing is performed via our hosting partner, Emergent Agent, using OpenAI's models. EQUIA does not maintain a direct contractual relationship with OpenAI — Emergent acts as the processor and OpenAI as Emergent's sub-processor for LLM inference. Document content is decrypted only for the duration of this processing and is transmitted securely (TLS-encrypted) to OpenAI's servers in the United States for inference.

Contract Risk Radar uploads are processed in memory only and are never stored — neither by EQUIA nor by our AI processing partners. The encrypted blob never reaches durable storage, and the OpenAI request and response are not retained beyond OpenAI's standard 30-day abuse-monitoring window (after which they are auto-purged).

Document classification on upload (auto-classify) happens by default to help organise your Vault. The AI receives the document content but does not receive your name, email, or other identifying account fields beyond what may appear inside the document itself.

Per OpenAI's API data-usage policy, content submitted via the API is not used to train their models. AI features (document analysis, news summarisation, Concierge chat) generate informational output for your review; they do not produce decisions that legally bind you or any third party (see § 14 on automated decision-making).

7. Sub-processors

We engage the following sub-processors to provide our application's functionality. Data shared with each is limited to what is strictly necessary for the stated purpose. Transfers to sub-processors located outside the European Economic Area are described in § 12 (International Data Transfers), including the specific lawful basis applied to each.

Sub-processorPurposeLocationData involved
Emergent AgentApplication hosting, AI request orchestrationUnited States (EU region on Emergent's roadmap)All application data, including documents sent for AI processing
OpenAI L.L.C. (via Emergent)LLM inference for Smart-Fill, Document Vault classification, Contract Risk Radar, AI Concierge, Regulatory Sentinel summariesUnited StatesDocument content (decrypted at point of processing), contract text, chat messages, asset data entered by user
MongoDB AtlasPrimary database hostingEU (Frankfurt, Germany)User accounts, portfolio data, document metadata, encrypted document keys
Cloudflare R2Encrypted document storageEU (jurisdictional restriction)Encrypted document files (Fernet envelope encryption)
ResendTransactional email deliveryUnited StatesEmail address, name, email content (payment reminders, visa reminders, account notifications)
SentryError monitoringEU (Frankfurt, Germany)Error logs, user IDs, request metadata

Detailed descriptions of each sub-processor follow:

Emergent Agent

Hosting · United States

Emergent Agent provides the underlying Kubernetes hosting for the EQUIA application and orchestrates all AI requests on our behalf via its managed LLM gateway. Emergent currently hosts EQUIA in non-EU infrastructure; an EU region and a customer-facing Data Processing Agreement (DPA) are both in active development at Emergent and not yet available. Until those are released, the lawful basis for processing your data through Emergent rests on your explicit consent under Art. 49(1)(a) GDPR, which you provide on first sign-in. Emergent in turn engages OpenAI as a sub-processor (see below).

OpenAI L.L.C. (sub-processor of Emergent)

AI Inference · United States

AI inference (Smart-Fill, Vault classification, Contract Risk Radar, AI Concierge, Regulatory Sentinel summaries) is performed by OpenAI's models in the United States, accessed through Emergent's enterprise OpenAI account. EQUIA does not have a direct contractual relationship with OpenAI — OpenAI is a sub-processor of our hosting partner Emergent. Until Emergent publishes a customer-facing DPA, this onward transfer also rests on your explicit consent under Art. 49(1)(a) GDPR. Per OpenAI's API policy, content submitted via the API is not used to train their models and is retained for at most 30 days for abuse monitoring. OpenAI's Privacy Policy.

MongoDB Atlas

Primary Database · Frankfurt, EU

Our primary application database is MongoDB Atlas, deployed on AWS in the EU (Frankfurt, eu-central-1). All personal data, portfolio records, residency entries, and authentication metadata are stored here. The cluster is secured with strong authentication, encrypted in transit and at rest, and accessible only from our backend. MongoDB Privacy Notice.

Cloudflare R2

Encrypted File Storage · EU

Uploaded documents are stored in a Cloudflare R2 bucket configured with EU jurisdictional restriction (data physically remains in EU data centres). As described in § 5, all files are encrypted on our backend before upload using envelope encryption, so Cloudflare only ever sees encrypted data. Cloudflare Privacy Policy.

Resend

Transactional Email · United States

We use Resend to deliver transactional emails: password reset links, visa-expiry reminders, payment-milestone reminders, account-deletion confirmations, and account-exists notices. Your email address and the email body are transmitted to Resend solely to deliver the message. Resend does not use your data for marketing. Resend Privacy Policy.

Sentry

Error Monitoring · Frankfurt, EU

We use Sentry, hosted in the EU (Frankfurt), to monitor application errors and a small sampled fraction of performance traces. Captured data includes the user ID, the user email, error stack traces, and request paths. Request bodies and document contents are never sent to Sentry. Sentry Privacy Policy.

Frankfurter API (European Central Bank)

FX Reference Rates · EU

We use the Frankfurter open API to retrieve the European Central Bank's daily reference rates for portfolio valuation and currency conversion. No personal data is transmitted — only currency-pair requests. Frankfurter API documentation.

Emergent Auth (Google OAuth)

Authentication · US

If you choose to sign in with Google, authentication is processed through Emergent's managed OAuth service, which then exchanges credentials with Google. We receive only your name, email address, and profile picture. We never receive or store your Google password.

8. Regulatory Sentinel — Real Sources + AI Summaries

The Regulatory Sentinel feature aggregates real, published articles from public RSS feeds of established publishers (Tagesschau, Der Spiegel, Handelsblatt, Cyprus Mail, and others) and topical Google News searches for your portfolio's jurisdictions (Dubai/UAE, North Cyprus, Germany). For each article, we use an OpenAI language model to generate a short summary and to classify the topic and impact. For Germany items, summaries are returned in the original German legal terminology.

The model never invents headlines, sources, or dates — it only summarises the publisher's own excerpt. Every article on the Sentinel page shows the real publisher name and a clickable link to the original article. We cache the result for 6 hours per user to reduce upstream calls. No personal data is transmitted to RSS publishers; only the article excerpt and the user's jurisdictions are sent to OpenAI.

9. Data Retention

We retain your data as follows:

  • - Account data: retained for the duration of your active account.
  • - Account deletion: when you request deletion, your account enters a 30-day grace period during which you can sign in and cancel the deletion. After 30 days your account and all associated data — assets, deals, documents (including R2 blobs), residencies, presence logs, refresh tokens, and email-reminder logs — are irreversibly hard-deleted.
  • - Portfolio & residency data: retained for the duration of your active account.
  • - Uploaded documents: retained until you delete them or your account is closed. Deleting a document removes both the database record and the encrypted blob from Cloudflare R2 in the same operation.
  • - Login attempt logs: failed login records are automatically cleared upon successful authentication or after 15 minutes.
  • - FX rate history: anonymised, non-personal aggregate data retained indefinitely for arbitrage calculations.
  • - Sentry error events: retained per Sentry's default plan policy (typically 30–90 days), then auto-purged.

10. Your Rights Under GDPR

As a data subject, you have the following rights under the General Data Protection Regulation:

Right of Access (Art. 15 GDPR)

You have the right to request confirmation of whether your personal data is being processed and, if so, to receive a copy of that data along with information about the purposes of processing, categories of data, and recipients.

Right to Rectification (Art. 16 GDPR)

You have the right to request correction of inaccurate personal data or completion of incomplete data. You can update most information directly within the application.

Right to Erasure (Art. 17 GDPR)

You have the right to request deletion of your personal data. You can delete your account yourself directly in the app via Settings → Delete my account. This schedules permanent deletion in 30 days; during that window you can sign back in and cancel the request. After 30 days all your data — including encrypted documents stored in Cloudflare R2 — is irreversibly purged. You can also delete individual documents and assets at any time from within the app.

Right to Data Portability (Art. 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, machine-readable format. You can export your data yourself directly in the app via Settings → Export my data. The export is delivered as a ZIP archive containing your account info, full portfolio (assets + deals), residencies, presence logs, calendar events, payment-reminder log, and your uploaded documents (decrypted to their original form). Up to 5 exports per hour.

Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request restriction of processing in certain circumstances, such as when the accuracy of data is contested or processing is unlawful but you oppose erasure.

Right to Object (Art. 21 GDPR)

You have the right to object to processing based on legitimate interests. Where you object, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or the place of the alleged infringement. The competent supervisory authority for our company is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.

To exercise any of these rights, please contact us using the information provided in our Legal Notice. We will respond to your request within 30 days.

11. Cookies

EQUIA uses only strictly necessary cookies for authentication:

CookiePurposeDuration
access_tokenJWT session authentication1 hour
refresh_tokenSession renewal without re-login7 days

Both cookies are used solely for authentication. We do not use tracking, analytics, or advertising cookies.

12. International Data Transfers

Your stored data remains in the European Union: MongoDB Atlas (AWS Frankfurt, eu-central-1), Cloudflare R2 (EU jurisdictional bucket), and Sentry (Frankfurt). However, EQUIA's application is currently hosted by Emergent Agent in non-EU infrastructure, and AI inference is performed by OpenAI in the United States via Emergent's enterprise account. As of the date of this policy, Emergent has not yet released a customer-facing Data Processing Agreement (DPA) — both an EU hosting region and a customer DPA are on Emergent's published roadmap.

We have therefore chosen the most transparent lawful basis available under GDPR for these transfers: your explicit, informed consent under Article 49(1)(a) GDPR. You provide this consent on first sign-in by accepting the data-processing disclaimer that names the jurisdictions involved. You may withdraw consent at any time by deleting your account (which permanently removes your data within 30 days). The transfers in question are:

  • - Emergent Agent (United States) — application hosting + AI request orchestration. All request data transits Emergent.
  • - OpenAI L.L.C. (United States, via Emergent) — LLM inference for AI features. Document content is decrypted in memory at point of processing and transmitted over TLS for inference; not used for training and retained at most 30 days for abuse monitoring.
  • - Resend (United States) — transactional email delivery. Transfer mechanism: SCCs as incorporated into Resend's DPA.
  • - Google (United States, via Emergent Auth) — only triggered if you choose Google sign-in. Lawful basis: your consent under Art. 49(1)(a) GDPR.

Our roadmap. We are actively planning to migrate to EU-resident hosting and to obtain a comprehensive DPA from our hosting partner (or to switch to one that already provides one) before EQUIA exits private beta. We will update this policy and re-notify users when that migration is complete. Until then, no transfer of your data outside the EU occurs without the consent you give on sign-in.

13. Recipients of Your Personal Data

We do not sell, rent, or share your personal data with marketers, advertisers, data brokers, or any third party for commercial purposes. The only third parties that receive any of your data are the sub-processors listed in § 7, strictly for the technical purposes described there. We may disclose data to public authorities only where legally required by court order or applicable law.

14. Automated Decision-Making & Profiling

EQUIA does not perform automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR. The AI features (document analysis, news summarisation, Concierge chat) generate informational output for your review; they do not produce decisions that legally bind you or any third party. Final decisions on any matter remain entirely with you.

15. Children's Data

EQUIA is intended for adult property investors. We do not knowingly collect personal data from individuals under 16 years of age. If you believe that a minor has provided us with personal data, please contact us using the details in our Legal Notice and we will delete the data without undue delay.

16. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by displaying a notice within the application. The "Last updated" date at the top of this page indicates when the policy was last revised.

© 2026 EQUIA Global Property