GDPR Compliant
Last updated: 11 June 2026
EQUIA Global Property ("we", "us", "our") operates a web-based property portfolio management platform for international real estate investors. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our application, in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
By using EQUIA, you consent to the data practices described in this policy. If you do not agree, please discontinue use of the application.
The data controller responsible for processing your data is the entity identified in our Legal Notice (Impressum). For any data protection inquiries, please contact us using the details provided there.
We collect and process the following categories of personal data:
Name, email address, and authentication credentials. If you sign in via Google, we receive only your name and email address — we never receive or store your Google password. This data is required to create and maintain your account.
Asset details you provide, including property names, locations, purchase prices, currencies, purchase dates, and property descriptions, plus any Deal Analyzer drafts you save. This data is necessary to deliver the core portfolio management functionality.
Files you upload to the Document Vault, such as Sales Purchase Agreements (SPAs), Title Deeds, passports, and visa documents. These documents may contain sensitive personal and financial information.
Visa and residency records, presence day logs, and associated compliance data that you voluntarily enter to track your global mobility status.
Reminders, deadlines, and notes you create via the Alerts feature, along with the email-delivery status of each scheduled reminder. We use this only to send the reminder at the time you specify.
If you opt in to occasional product updates (either via the landing-page beta-access form or via Settings → Email preferences), we store a marketing_consent flag together with the timestamp of your opt-in (and, if applicable, the timestamp of your subsequent unsubscribe) so we maintain a verifiable audit trail under Art. 7(1) GDPR. The flag is read only when we send a marketing email; transactional emails are unaffected.
If you submit the "Request beta access" form on the landing page, we store the name, email address, free-text message, originating IP address, browser user-agent, and marketing-consent choice you provided. This data is used solely to evaluate and respond to your access request.
If you send feedback via the in-app Feedback form, we store the category (bug, suggestion, praise, other), the optional severity for bug reports, the free-text body, and the page-of-origin plus browser user-agent. This data is used solely to triage and improve the product.
Technical data generated during your use of the application, including IP addresses (for brute-force and rate-limit protection), timestamps of login attempts, and session metadata.
Your data is processed for the following purposes, each with a lawful basis under GDPR:
| Purpose | Legal Basis |
|---|---|
| Account creation and authentication | Contract performance (Art. 6(1)(b) GDPR) |
| Portfolio management and FX conversion | Contract performance (Art. 6(1)(b) GDPR) |
| AI document analysis via OpenAI | Consent (Art. 6(1)(a) GDPR) |
| Marketing emails & product updates | Consent (Art. 6(1)(a) GDPR) · revocable at any time |
| Visa expiry notifications and compliance alerts | Legitimate interest (Art. 6(1)(f) GDPR) |
| Security (brute-force protection, rate limiting, session management) | Legitimate interest (Art. 6(1)(f) GDPR) |
We implement industry-standard security measures to protect your data:
Passwords are stored only as one-way hashes — never in plain text. Sessions use short-lived access tokens with separately rotated refresh tokens, both transmitted in HTTP-only cookies that browser scripts cannot read. Repeated failed login attempts are throttled and temporarily lock the account.
Your account data and portfolio information is stored in MongoDB Atlas data centres located in Frankfurt, Germany (European Union). Uploaded documents are encrypted before storage using envelope encryption — a unique data-encryption key (DEK) is generated for every document, then itself wrapped with a master key held only in our backend environment. The encrypted blob is stored in Cloudflare R2's EU-jurisdictional infrastructure, so neither the document content nor the per-document DEK is ever readable by the storage provider.
Documents are only decrypted (a) when you view or download them, or (b) temporarily, in memory, during AI processing as described in § 6 ("How EQUIA uses AI"). The plaintext is never persisted to disk. All file uploads are validated server-side to reject mismatched or malicious binaries, file size is capped at 10 MB per document, and access is mediated exclusively through authenticated backend API endpoints — no direct storage URLs are exposed to the client. Each file is stored under a non-guessable path scoped to the owning user.
All communication between your browser and our servers is encrypted using HTTPS with modern TLS. API credentials, session tokens, and document payloads are transmitted exclusively over encrypted channels.
When you upload a document, EQUIA may use artificial intelligence to automatically classify the document type, extract key information (such as property details, payment schedules, or contract terms), and provide analysis through features like Contract Risk Radar and the AI Concierge.
This processing is performed via our hosting partner, Emergent Agent, using OpenAI's models. EQUIA does not maintain a direct contractual relationship with OpenAI — Emergent acts as the processor and OpenAI as Emergent's sub-processor for LLM inference. Document content is decrypted only for the duration of this processing and is transmitted securely (TLS-encrypted) to OpenAI's servers in the United States for inference.
Contract Risk Radar uploads are processed in memory only and are never stored — neither by EQUIA nor by our AI processing partners. The encrypted blob never reaches durable storage, and the OpenAI request and response are not retained beyond OpenAI's standard 30-day abuse-monitoring window (after which they are auto-purged).
Document classification on upload (auto-classify) happens by default to help organise your Vault. The AI receives the document content but does not receive your name, email, or other identifying account fields beyond what may appear inside the document itself.
Per OpenAI's API data-usage policy, content submitted via the API is not used to train their models. AI features (document analysis, news summarisation, Concierge chat) generate informational output for your review; they do not produce decisions that legally bind you or any third party (see § 14 on automated decision-making).
We engage the following sub-processors to provide our application's functionality. Data shared with each is limited to what is strictly necessary for the stated purpose. Transfers to sub-processors located outside the European Economic Area are described in § 12 (International Data Transfers), including the specific lawful basis applied to each.
| Sub-processor | Purpose | Location | Data involved |
|---|---|---|---|
| Emergent Agent | Application hosting, AI request orchestration | United States (EU region on Emergent's roadmap) | All application data, including documents sent for AI processing |
| OpenAI L.L.C. (via Emergent) | LLM inference for Smart-Fill, Document Vault classification, Contract Risk Radar, AI Concierge, Regulatory Sentinel summaries | United States | Document content (decrypted at point of processing), contract text, chat messages, asset data entered by user |
| MongoDB Atlas | Primary database hosting | EU (Frankfurt, Germany) | User accounts, portfolio data, document metadata, encrypted document keys |
| Cloudflare R2 | Encrypted document storage | EU (jurisdictional restriction) | Encrypted document files (Fernet envelope encryption) |
| Resend | Transactional email delivery | United States | Email address, name, email content (payment reminders, visa reminders, account notifications) |
| Sentry | Error monitoring | EU (Frankfurt, Germany) | Error logs, user IDs, request metadata |
Detailed descriptions of each sub-processor follow:
Emergent Agent provides the underlying Kubernetes hosting for the EQUIA application and orchestrates all AI requests on our behalf via its managed LLM gateway. Emergent currently hosts EQUIA in non-EU infrastructure; an EU region and a customer-facing Data Processing Agreement (DPA) are both in active development at Emergent and not yet available. Until those are released, the lawful basis for processing your data through Emergent rests on your explicit consent under Art. 49(1)(a) GDPR, which you provide on first sign-in. Emergent in turn engages OpenAI as a sub-processor (see below).
AI inference (Smart-Fill, Vault classification, Contract Risk Radar, AI Concierge, Regulatory Sentinel summaries) is performed by OpenAI's models in the United States, accessed through Emergent's enterprise OpenAI account. EQUIA does not have a direct contractual relationship with OpenAI — OpenAI is a sub-processor of our hosting partner Emergent. Until Emergent publishes a customer-facing DPA, this onward transfer also rests on your explicit consent under Art. 49(1)(a) GDPR. Per OpenAI's API policy, content submitted via the API is not used to train their models and is retained for at most 30 days for abuse monitoring. OpenAI's Privacy Policy.
Our primary application database is MongoDB Atlas, deployed on AWS in the EU (Frankfurt, eu-central-1). All personal data, portfolio records, residency entries, and authentication metadata are stored here. The cluster is secured with strong authentication, encrypted in transit and at rest, and accessible only from our backend. MongoDB Privacy Notice.
Uploaded documents are stored in a Cloudflare R2 bucket configured with EU jurisdictional restriction (data physically remains in EU data centres). As described in § 5, all files are encrypted on our backend before upload using envelope encryption, so Cloudflare only ever sees encrypted data. Cloudflare Privacy Policy.
We use Resend to deliver transactional emails: password reset links, visa-expiry reminders, payment-milestone reminders, account-deletion confirmations, and account-exists notices. Your email address and the email body are transmitted to Resend solely to deliver the message. Resend does not use your data for marketing. Resend Privacy Policy.
We use Sentry, hosted in the EU (Frankfurt), to monitor application errors and a small sampled fraction of performance traces. Captured data includes the user ID, the user email, error stack traces, and request paths. Request bodies and document contents are never sent to Sentry. Sentry Privacy Policy.
We use the Frankfurter open API to retrieve the European Central Bank's daily reference rates for portfolio valuation and currency conversion. No personal data is transmitted — only currency-pair requests. Frankfurter API documentation.
If you choose to sign in with Google, authentication is processed through Emergent's managed OAuth service, which then exchanges credentials with Google. We receive only your name, email address, and profile picture. We never receive or store your Google password.
The Regulatory Sentinel feature aggregates real, published articles from public RSS feeds of established publishers (Tagesschau, Der Spiegel, Handelsblatt, Cyprus Mail, and others) and topical Google News searches for your portfolio's jurisdictions (Dubai/UAE, North Cyprus, Germany). For each article, we use an OpenAI language model to generate a short summary and to classify the topic and impact. For Germany items, summaries are returned in the original German legal terminology.
The model never invents headlines, sources, or dates — it only summarises the publisher's own excerpt. Every article on the Sentinel page shows the real publisher name and a clickable link to the original article. We cache the result for 6 hours per user to reduce upstream calls. No personal data is transmitted to RSS publishers; only the article excerpt and the user's jurisdictions are sent to OpenAI.
We retain your data as follows:
As a data subject, you have the following rights under the General Data Protection Regulation:
You have the right to request confirmation of whether your personal data is being processed and, if so, to receive a copy of that data along with information about the purposes of processing, categories of data, and recipients.
You have the right to request correction of inaccurate personal data or completion of incomplete data. You can update most information directly within the application.
You have the right to request deletion of your personal data. You can delete your account yourself directly in the app via Settings → Delete my account. This schedules permanent deletion in 30 days; during that window you can sign back in and cancel the request. After 30 days all your data — including encrypted documents stored in Cloudflare R2 — is irreversibly purged. You can also delete individual documents and assets at any time from within the app.
You have the right to receive your personal data in a structured, commonly used, machine-readable format. You can export your data yourself directly in the app via Settings → Export my data. The export is delivered as a ZIP archive containing your account info, full portfolio (assets + deals), residencies, presence logs, calendar events, payment-reminder log, and your uploaded documents (decrypted to their original form). Up to 5 exports per hour.
You have the right to request restriction of processing in certain circumstances, such as when the accuracy of data is contested or processing is unlawful but you oppose erasure.
You have the right to object to processing based on legitimate interests. Where you object, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
You have the right to lodge a complaint with a supervisory authority in the EU/EEA member state of your habitual residence, place of work, or the place of the alleged infringement. The competent supervisory authority for our company is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
To exercise any of these rights, please contact us using the information provided in our Legal Notice. We will respond to your request within 30 days.
EQUIA uses only strictly necessary cookies for authentication:
| Cookie | Purpose | Duration |
|---|---|---|
| access_token | JWT session authentication | 1 hour |
| refresh_token | Session renewal without re-login | 7 days |
Both cookies are used solely for authentication. We do not use tracking, analytics, or advertising cookies.
Your stored data remains in the European Union: MongoDB Atlas (AWS Frankfurt, eu-central-1), Cloudflare R2 (EU jurisdictional bucket), and Sentry (Frankfurt). However, EQUIA's application is currently hosted by Emergent Agent in non-EU infrastructure, and AI inference is performed by OpenAI in the United States via Emergent's enterprise account. As of the date of this policy, Emergent has not yet released a customer-facing Data Processing Agreement (DPA) — both an EU hosting region and a customer DPA are on Emergent's published roadmap.
We have therefore chosen the most transparent lawful basis available under GDPR for these transfers: your explicit, informed consent under Article 49(1)(a) GDPR. You provide this consent on first sign-in by accepting the data-processing disclaimer that names the jurisdictions involved. You may withdraw consent at any time by deleting your account (which permanently removes your data within 30 days). The transfers in question are:
Our roadmap. We are actively planning to migrate to EU-resident hosting and to obtain a comprehensive DPA from our hosting partner (or to switch to one that already provides one) before EQUIA exits private beta. We will update this policy and re-notify users when that migration is complete. Until then, no transfer of your data outside the EU occurs without the consent you give on sign-in.
We do not sell, rent, or share your personal data with marketers, advertisers, data brokers, or any third party for commercial purposes. The only third parties that receive any of your data are the sub-processors listed in § 7, strictly for the technical purposes described there. We may disclose data to public authorities only where legally required by court order or applicable law.
EQUIA does not perform automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR. The AI features (document analysis, news summarisation, Concierge chat) generate informational output for your review; they do not produce decisions that legally bind you or any third party. Final decisions on any matter remain entirely with you.
EQUIA is intended for adult property investors. We do not knowingly collect personal data from individuals under 16 years of age. If you believe that a minor has provided us with personal data, please contact us using the details in our Legal Notice and we will delete the data without undue delay.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by displaying a notice within the application. The "Last updated" date at the top of this page indicates when the policy was last revised.
© 2026 EQUIA Global Property