Legal
GDPR and UK GDPR notice
What people in the European Union, the EEA and the United Kingdom need to know about how prop.forsale uses their personal information, and how to use their rights.
On this page
The short version
- Kwestra LLC (Florida, USA) is the controller for platform accounts, the prop.forsale property portal and billing.
- For enquiries, subscribers and deal rooms on an agency’s site, the agency is the controller and we are its processor under our data processing addendum.
- Every purpose has a lawful basis, listed in the table below. Analytics only run with your consent.
- Transfers to the US rely on the EU-US Data Privacy Framework where the provider is certified, and on Standard Contractual Clauses otherwise.
- You have the right to access, correct, erase, restrict, port and object. Email privacy@pfs-stage.dev; we answer within one month.
- You can complain to your local data protection authority or, in the UK, the ICO.
This summary helps you find your way. The full text below is what applies.
1. Who is responsible
The controller for the processing described in our privacy policy (/privacy) is:
- Controller
- Kwestra LLC
- Address
- 14 NE 1st Ave, Ste 1403 #146, Miami, FL 33132, USA
- Privacy contact
- privacy@pfs-stage.dev
2. Our representatives in the EU and UK
Kwestra LLC has no office in the EU or the UK. Article 27 of the GDPR and of the UK GDPR requires a business in that position that offers services to people there to name a representative they and the regulators can contact.
- EU representative
- Not yet named. Until one is, contact us directly at privacy@pfs-stage.dev.
- UK representative
- Not yet named. Until one is, contact us directly at privacy@pfs-stage.dev.
3. Data protection officer
We have not appointed a data protection officer. Article 37 requires one only where a business’s core activities involve regular and systematic monitoring of people on a large scale, or large-scale processing of special categories of data, and ours do not. Our privacy contact (privacy@pfs-stage.dev) handles every data protection question.
4. Controller and processor roles
Who decides how your information is used depends on how you met us:
- We are the controller
- For agents and agency staff who sign in, visitors to the prop.forsale property portal, platform emails, billing, security logs and optional analytics.
- The agency is the controller
- For information collected through an agency’s website or deal rooms: enquiries, newsletter subscribers, alerts, deal parties and documents. We are the agency’s processor and act only on its instructions, under article 28 terms in our data processing addendum (/dpa). Ask the agency first about this information; we will help it answer.
- Deal room parties
- Attorneys, originators and other professionals invited to a deal room remain responsible for their own handling of what they download.
5. Purposes and lawful bases
Where we rely on legitimate interests, we have weighed them against your rights and you can object at any time. Where we rely on consent, you can withdraw it at any time.
| Purpose | Personal information | Lawful basis | Who decides (controller) |
|---|---|---|---|
| Creating and running accounts and workspaces | Name, email, sign-in and security records, role | Contract, article 6(1)(b) | prop.forsale |
| Billing and invoicing | Billing contact, Stripe customer reference, transactions | Contract, 6(1)(b); legal obligation for tax records, 6(1)(c) | prop.forsale |
| Service emails (verification, notifications, invitations) | Email address, name, message content | Contract, 6(1)(b) | prop.forsale, or the agency for its own notifications |
| Delivering and securing web pages, stopping abuse, bot checks on forms | IP address, browser and request data | Legitimate interests, 6(1)(f): keeping the service available and safe | prop.forsale |
| Passing an enquiry to the agency you contacted | Name, email, phone, message, listing, consent record | Consent given on the form, 6(1)(a), and steps you ask for before a contract, 6(1)(b) | The agency (we process for it) |
| Agency newsletters and property alerts | Email, name, interests, consent record | Consent, 6(1)(a), confirmed by double opt-in | The agency (we process for it) |
| Deal rooms | Contact details, role, messages, documents (which can include identity and proof-of-funds documents) | Contract or steps before one, 6(1)(b); the agent’s legal obligations such as anti-money-laundering checks, 6(1)(c); legitimate interests in managing the transaction, 6(1)(f) | The agency (we process for it) |
| Agency assistant answering an agent’s questions about a lead | Enquirer name, masked email, recent messages | The agency’s legitimate interests in handling enquiries, 6(1)(f) | The agency (we process for it) |
| AI drafting and listing import | Listing facts, public content of an imported page (may include an advertising agent’s published contact details) | Contract with the agent who asks, 6(1)(b); legitimate interests for published third-party contact details, 6(1)(f) | prop.forsale |
| Optional product analytics and session replay | Pseudonymous id, pages, clicks, device type; account, workspace, plan and role ids when signed in | Consent, 6(1)(a), and consent for cookies under the ePrivacy rules | prop.forsale |
| Cookieless page-view counts | Page, referring site, listing; no IP, cookie or device id | Legitimate interests, 6(1)(f): showing agencies how their pages perform | prop.forsale |
| Security and audit logs, including document access | Account id, action, IP address, browser | Legitimate interests, 6(1)(f), and legal obligation where security law requires, 6(1)(c) | prop.forsale |
| Answering rights requests and legal claims | What the request or claim needs | Legal obligation, 6(1)(c); legitimate interests, 6(1)(f) | prop.forsale, or the agency |
6. Special categories of data
We do not ask for special categories of personal data (such as health, religion or biometric data). Identity documents uploaded to a deal room for anti-money-laundering checks are sensitive, so new uploads are encrypted with a per-agency key, every access is logged, and they are never sent to AI providers or recorded by analytics.
7. Your rights and how to use them
Email privacy@pfs-stage.dev with your request. It is free. We may ask you to confirm your identity, answer within one month, and can extend by two further months for complex requests (we will tell you why within the first month). If the agency is the controller, we pass your request to it promptly and help it answer.
- Access (article 15)
- A copy of your personal information and how we use it.
- Rectification (article 16)
- Correction of anything inaccurate or incomplete.
- Erasure (article 17)
- Deletion where we no longer need it, you withdraw consent, or you object and we have no overriding reason. Deal documents under a legal retention period are kept until it ends.
- Restriction (article 18)
- A pause on use while a dispute about accuracy or an objection is resolved.
- Portability (article 20)
- Information you gave us, in a machine-readable format, where we rely on consent or contract.
- Objection (article 21)
- To processing based on legitimate interests, and to direct marketing at any time.
- Automated decisions (article 22)
- We make no decisions about you based solely on automated processing that have legal or similarly significant effects.
- Withdraw consent (article 7)
- At any time, as easily as you gave it: Cookie settings in the footer, the unsubscribe link, or by email.
8. International transfers
Kwestra LLC is in the United States, so using prop.forsale from the EU or UK involves a transfer. Our main database is in the United States; agency documents and photos can be kept in the European Union if the agency chooses the EU region.
For each provider below: where it is certified under the EU-US Data Privacy Framework (and the UK Extension), that certification covers the transfer; otherwise, and as a fallback if the Framework stops applying, the European Commission’s Standard Contractual Clauses (2021/914) apply, with the UK International Data Transfer Addendum for UK data. You can ask for a copy of the relevant safeguard.
| Provider | Where | Safeguard |
|---|---|---|
| Cloudflare, Inc. | Global network. The main database is in the United States (eastern North America). Agency documents and photos are stored in the region chosen at sign-up: United States (default), European Union, Asia-Pacific or Oceania. | EU-US Data Privacy Framework (participant); Standard Contractual Clauses in Cloudflare’s data processing addendum |
| Clerk, Inc. | United States. | EU-US Data Privacy Framework, UK Extension and Swiss-US framework (certified); Standard Contractual Clauses as a fallback |
| Stripe, Inc. / Stripe Payments Europe | United States and European Union. | EU-US Data Privacy Framework, UK Extension and Swiss-US framework (certified); Standard Contractual Clauses as a fallback |
| PostHog, Inc. | United States. | EU-US Data Privacy Framework, UK Extension and Swiss-US framework (certified); Standard Contractual Clauses as a fallback |
| Resend, Inc. | United States. | EU-US Data Privacy Framework (certified); Standard Contractual Clauses as a fallback |
| Firecrawl (SideGuide Technologies, Inc.) | United States. | Standard Contractual Clauses |
| xAI Corp. | United States. | Standard Contractual Clauses in xAI’s data processing addendum |
| Brave Software, Inc. | United States. | Standard Contractual Clauses in the Brave Search API data processing addendum |
| Serper (serper.dev) | United States. | Standard Contractual Clauses |
| Mistral AI SAS | European Union (Mistral AI SAS, Paris, France). | Processed by an EU company under its data processing addendum; no transfer outside the EU is needed for this service |
| GitHub, Inc. | United States. | Standard Contractual Clauses in GitHub’s data protection agreement |
9. How long we keep it
| Information | How long | Why |
|---|---|---|
| Account and workspace records | While the workspace exists, then 30 days after it is deleted. | To provide the service, and to allow a deletion to be reversed by mistake. |
| Enquiries and leads | Erased automatically 2 years after the last activity on the enquiry (the enquiry itself, a message about it, or an update by the agency). An enquiry linked to a deal is not erased this way: it is kept with the deal's records. The agency can erase one sooner. | To let the agency answer and follow up. |
| Sales enquiries to prop.forsale | Deleted 2 years after the last contact, unless your agency becomes a customer; then kept with its workspace records. | To answer your enquiry and follow up on it. |
| Newsletter subscribers | While subscribed. After unsubscribing: your details are erased 30 days after you unsubscribe. A one-way hash of your email address (not the address itself) is kept permanently so that agency never emails you again, unless you sign up and confirm again. | To send what you asked for, and to respect your opt-out. |
| Deal room documents | At least five years from upload, and they cannot be deleted sooner. | Record-keeping law for property transactions (for example FICA in South Africa). |
| Deal chat conversations | Five years, like the deal's other records, then deleted. Encrypted, and seen only by the person who asked. | Record-keeping law for property transactions. |
| Text the deal chat read from deal documents (when the agency turns document reading on) | Until the document is removed or replaced, and at most 30 days after the deal closes, then deleted. Encrypted with the agency's key; never a searchable index. | To answer questions about the documents a person may open. |
| Raw copies of inbound email | 90 days. Messages filed to a lead or deal stay with it. | Troubleshooting and security. |
| Rejected or ignored inbound email records | 30 days. | Troubleshooting and abuse prevention. |
| Notifications | Read: 90 days. Unread: 180 days. | To show you what happened in your workspace. |
| Search cache | 30 days. | Faster, cheaper repeat searches. |
| Sign-in sessions and one-time links | Deleted when they expire. | Security. |
| Security and audit logs | While the workspace exists. | Security, fraud prevention and legal claims. |
| Database backups | Point-in-time recovery for 30 days, plus a backup copy taken before each release. | Recovering from faults. Erased records drop out of backups as those expire. |
| Billing records | As long as tax and accounting law requires. | Legal obligation. |
| Optional analytics | Under the PostHog project’s retention settings; deleted on request. | Only if you accepted analytics. |
11. Complaints
Please contact us first at privacy@pfs-stage.dev; we will try to put things right. You can also complain to a supervisory authority, in particular in the country where you live or work or where you think the law was broken. In the EU, find yours at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en. In the UK, contact the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint. Because we have no establishment in the EU, we do not have a lead supervisory authority there.