Privacy Policy
Version of 2026-08-06
This is a translation. The binding version is the Czech one at realtorz.cz/policy.
1. Who we are
The Realtorz platform (the “platform”) is operated by:
Azamat Kassymbekov
Company ID: 07115652
Vysočanská 237/101, 190 00 Praha 9 – Střížkov
info@realtorz.cz
The platform is software for real-estate agencies: client and deal records, listing publication, market data and an AI assistant.
2. Two roles: controller and processor
We are the controller of the data you give us as a platform user: registration, sign-in, account settings, operational records and billing.
We are a processor for the data an agency enters about its clients, leads and deals. The agency is the controller of that data; we process it on its instructions under a data processing agreement. If you are a client of an agency, please address your requests to the agency first — we will assist it.
3. What we process
- User account: email, name, language, role in the organisation, sign-in time and basic session identifiers.
- Organisation content: contacts, demands, deals, tasks, viewings, notes, documents and attachments — whatever the agency keeps in the platform.
- Communication: if the agency enables mailbox connection, we process messages related to its deals. The agency defines the scope and visibility and informs its staff.
- Technical logs: IP address, browser type, request time and outcome, request identifier — for operations and security.
- Market data: we collect publicly available listings from property portals for internal market analytics (prices, time on market). We do not use this data to contact advertisers and we do not republish it.
4. Legal bases
- performance of a contract (Art. 6(1)(b) GDPR) — running the platform;
- legitimate interest (f) — security, abuse prevention, operational logs;
- legal obligation (c) — in particular Act No. 253/2008 Coll. (anti-money-laundering) and accounting rules;
- consent (a) — marketing messages; withdrawable at any time.
5. Retention and AML
We keep data only as long as the purpose requires. Deal and client records are kept by the agency for the duration of the relationship and a reasonable period after; operational logs for months.
AML exception: identification data collected under Act No. 253/2008 Coll. must be retained for 10 years and therefore cannot be erased on request. The platform stores it separately for exactly this reason — so that a GDPR erasure does not delete what the law requires us to keep.
6. Recipients
- Hetzner Online GmbH (Germany) — servers and database storage.
- Cloudflare (R2 storage, EU jurisdiction) — files, photos, attachments.
- Resend — transactional email and notifications.
- Anthropic PBC (USA) — language model behind assistant features. We send only the text needed for the specific task. The transfer to the USA relies on the European Commission’s Standard Contractual Clauses.
- PostHog (EU hosting) — product and operational analytics, when enabled.
- Video call provider (Jitsi / 8x8) — online viewings.
- Property portals (Sreality and others) — only the data an agency knowingly publishes in a listing.
We do not sell data and do not pass it on for third-party marketing.
7. Artificial intelligence
The assistant produces drafts — listing texts, translations, reply suggestions, property shortlists. A human always confirms before anything is sent to a client. The assistant never has more permissions than the user it runs as, and its actions are recorded in the organisation’s history.
8. Data from your Google account
If you connect your Google account to Realtorz, we access its data strictly within the scope you approved in Google’s consent screen, and only for the purposes below:
- Calendar (
calendar.events) — we read and write events so that viewings and deadlines from Realtorz appear in your calendar and vice versa. We do not access any other calendar data. - Sending email (
gmail.send) — we send a message that you composed and confirmed inside Realtorz, from your own address. We do not read your mail — we deliberately do not request any Gmail read permission at all.
Access and refresh tokens are stored encrypted and used only for the operations above. You can revoke access at any time in Realtorz settings or at myaccount.google.com/permissions; we delete the tokens afterwards.
We do not transfer Google user data to third parties, do not use it for advertising, do not use it to train artificial-intelligence models, and do not allow humans to read it except where you explicitly agree, where the law requires it, or where it is necessary for security and support.
Realtorz’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Data protection and security
We protect personal data — including sensitive data and data obtained from Google APIs — with the following technical and organisational measures:
- Encryption in transit: all communication with the application and all exchanges with Google APIs run exclusively over encrypted TLS (HTTPS) connections.
- Encryption at rest: Google access and refresh tokens are stored encrypted with AES-256-GCM; the encryption key is kept separately from the database. Files and attachments live in storage with server-side encryption (Cloudflare R2, EU jurisdiction).
- EU infrastructure: servers and the database run in the European Union (Germany); the database is not reachable from the internet — only the application on the same server can access it.
- Access control: each organisation’s data is isolated at the database row level (row-level security — a query without the organisation’s context returns nothing), and user permissions follow roles. Sign-in uses short-lived tokens in secure httpOnly cookies. Staff access to data is limited to the necessary minimum and bound by confidentiality.
- Data minimisation: we request only the narrowest Google permissions needed. We do not store third-party events from your calendar — availability is checked at the moment of scheduling and the result is not persisted.
- Audit trail: sensitive operations (access, role changes, work with personal data) are recorded in a separate append-only audit log.
- Backups: daily backups are transferred encrypted and kept in the EU with restricted access; restore procedures are tested regularly.
- Deletion: when you disconnect your Google account we delete the tokens immediately; data is erased or pseudonymised when retention periods expire (Section 5) and upon request (Section 11).
- Incidents: we monitor the platform; any personal data breach is notified to the supervisory authority and affected individuals in line with Art. 33 and 34 GDPR without undue delay.
10. Cookies
We use strictly necessary cookies for authentication (a secure httpOnly cookie scoped to the application domain; it is not shared with agencies’ public websites). Analytics are deployed only in a way that does not identify a visitor without consent.
11. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection (Art. 15–22 GDPR), and may withdraw consent at any time. Write to info@realtorz.cz.
You may lodge a complaint with the Czech Data Protection Authority, Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.
12. Changes
We may update this policy. Every version is dated and previous versions are archived, so it is always possible to show which wording applied on a given day. We notify users of material changes in the application or by email.