Privacy policy (GDPR)
Data controller
EIRES Real Estate S.à r.l., represented by Michael Eires.
Contact: [email protected] — +352 28 13 83-1
Data collected, purposes and legal bases
- Valuation form: identity, contact details, property address, characteristics, optional photos. Purpose: produce the value statement, qualify the request, get in touch. Legal basis: pre-contractual measures (art. 6.1.b GDPR) and legitimate interest in qualified follow-up (art. 6.1.f GDPR).
- Contact form / appointment booking: name, email, phone, message, time slots. Purpose: respond to the request, schedule a meeting. Legal basis: pre-contractual measures (art. 6.1.b GDPR) or legitimate interest (art. 6.1.f GDPR).
- Anita AI chat (virtual assistant): message content, email/phone if provided, qualification scoring (HOT/WARM/COLD). Purpose: conversational assistance and qualified commercial follow-up. Legal basis: consent (art. 6.1.a GDPR) when opening the chat and legitimate interest in qualification (art. 6.1.f GDPR).
- Newsletter / property alerts: email, language, sending preferences. Purpose: editorial news and new property alerts. Legal basis: explicit consent (art. 6.1.a GDPR), revocable at any time via the unsubscribe link.
- Private / VIP area: login credentials, preferences, off-market browsing history, financial documents transmitted. Purpose: experience personalisation, access to confidential dossiers. Legal basis: contract performance (art. 6.1.b GDPR).
- GDPR data subject requests (DSR): email, hashed IP, reason. Purpose: verify the requester identity and log the request. Legal basis: legal obligation (art. 6.1.c GDPR, articles 15-22 GDPR).
- Cookie consent log: pseudonymous client identifier, hashed IP, accepted/refused categories, timestamp. Purpose: evidence of consent. Legal basis: legal obligation (art. 7.1 GDPR).
- AML/CTF compliance (clients under mandate): ID document, proof of address, identification of the beneficial owner, source of funds. Purpose: anti-money laundering due diligence. Legal basis: legal obligation (art. 6.1.c GDPR + amended law of 12 November 2004).
- Anonymous audience measurement: URL visited, device type, country, referer. Purpose: site improvement. Legal basis: legitimate interest (art. 6.1.f GDPR).
- Technical and security logs: IP, user-agent, admin action timestamps. Purpose: information system security, access traceability. Legal basis: legitimate interest (art. 6.1.f GDPR).
Automated decisions and profiling (art. 22 GDPR)
Some site features rely on algorithmic processing: the Property Matcher (recommendation of properties based on the criteria you declare) and the internal qualification scoring of valuation requests (HOT / WARM / COLD prioritisation to set the call-back time). These are decision-support tools intended for our staff: no decision producing legal effects on you, or affecting you significantly, is taken in a fully automated manner. You may at any time request a human review, contest the result or express your point of view at [email protected].
Retention periods by category
- Valuation requests converted into a mandate: 3 years from the last contact, then 5-year archive for accounting obligations.
- Valuation requests not converted: 13 months (CNIL/CNPD recommended duration for B2C prospection).
- Valuation drafts (auto-save): 14 days, automatic purge.
- Anita AI conversations (raw logs): 6 months, then anonymisation.
- Anita HOT/WARM converted leads: 3 years; COLD non-converted leads: 13 months.
- Visit / appointment requests (Cal.com): 3 years after the appointment date.
- Unsubscribed newsletter subscribers: 3 years (proof of consent and of unsubscription).
- Private / VIP area data: as long as the account is active, then 12 months after deletion.
- Accounting data (signed mandates, invoices): 10 years in line with Luxembourg legal obligations.
- AML/CTF data: 5 years after the end of the business relationship (amended law of 12 November 2004).
- GDPR data subject requests (DSR): 3 years after closure, for proof of processing.
- Cookie consent log: 12 months.
- Technical logs, admin access and security audit: 12 to 24 months.
Recipients
Your data is strictly reserved to authorised EIRES Real Estate staff. It may be transmitted to the technical partners listed below (hosting, transactional email, analytics) and — only with your consent — to listing portals or to our broker for financing pre-qualification. No data is sold or transferred for third-party commercial purposes.
Technical sub-processors
Exhaustive list of sub-processors that may process your data on behalf of EIRES Real Estate (GDPR art. 28). All operate under a data processing agreement with documented safeguards. The detailed list with links to official DPAs is available at /en/privacy/subprocessors.
- Supabase Inc. / AWS eu-central-1 : Database, authentication, edge functions, storage — Germany (EU) — EU — no transfer
- Strapi Cloud : Editorial CMS (articles, enriched listings) — EU — EU — no transfer
- Cloudflare, Inc. : CDN, network security, WAF, DNS — United States (global cache) — EU-US Data Privacy Framework + SCCs
- Resend : Transactional emails (valuation, contact, DSR) — United States — EU-US Data Privacy Framework + SCCs
- Twilio : SMS notifications (appointments, alerts) — United States — EU-US Data Privacy Framework + SCCs
- Cal.com : Online appointment booking — Germany (EU) — EU — no transfer
- OpenAI, L.L.C. & Google LLC (LLM models) : LLM models powering the Anita assistant (via technical AI gateway) — United States — EU-US Data Privacy Framework + SCCs
- Sentry : Application error monitoring — European Union (Sentry EU region) — Sentry DPA · EU hosting
- Plausible Analytics : Cookieless audience measurement — Germany (EU) — EU — no transfer
- PostHog (consent-based) : Anonymised product analytics — EU — EU — no transfer
- Google LLC — GTM (consent-based) : Tag manager — Ireland (EU) / United States — EU-US Data Privacy Framework + SCCs
- Google Maps Geocoding : Address geocoding (valuation, map) — United States — EU-US Data Privacy Framework + SCCs
- NextImmo : Property syndication to partner portals — Luxembourg (EU) — EU — no transfer
Transfers outside the EU
Some technical sub-processors (Cloudflare, Resend, Twilio, Google, OpenAI) may process data from the United States. These transfers are framed by their certification under the EU-US Data Privacy Framework (adequacy decision 2023/1795) and/or by the signature of standard contractual clauses approved by the European Commission (decision 2021/914), in line with articles 45 and 46 GDPR. No transfer is made to a country lacking an appropriate legal framework.
Your rights
In accordance with articles 15 to 22 of the GDPR, you have the following rights at any time:
- Right of access and right to a copy of your data
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object on legitimate grounds
- Right to withdraw your consent at any time
- Right to give post-mortem instructions
- Right not to be subject to a fully automated decision (art. 22)
The simplest way to exercise your rights is via our dedicated form /en/privacy/my-data (email verification, processed within 30 days). You may also write to [email protected] attaching proof of identity.
Data protection contact
Pursuant to article 37 GDPR, EIRES Real Estate is not required to appoint a formal Data Protection Officer (DPO). For the sake of transparency, the single point of contact for any question relating to the processing of your personal data is:
- Contact : Michael Eires, manager
- Email : [email protected]
- Postal address : 44, Rue de Hunsdorf — L-7324 Mullendorf — Luxembourg
Complaints
If, after contacting us, you believe that your rights have not been respected, you may lodge a complaint with the Commission Nationale pour la Protection des Données (CNPD), the Luxembourg supervisory authority: cnpd.public.lu.
WhatsApp Business — message processing
We use WhatsApp Business (Cloud API) as a conversational channel. This processing is separate from the website and requires a timestamped opt-in (form, verbal, VIP or import) logged in our GDPR register.
GDPR legal basis
- Consent (art. 6.1.a) for marketing messages (property alerts, off-market VIP, greetings).
- Legitimate interest (art. 6.1.f) for transactional messages tied to an ongoing service (appointment confirmation, offer received, notary, key handover).
- Contract performance (art. 6.1.b) for messages tied to a signed mandate (weekly report, listing, preliminary contract).
Data collected via WhatsApp
- Phone number (channel identifier).
- Content of exchanged messages (text, images, documents).
- Send / receive / read timestamps.
- Delivery status and conversation category (Meta).
- Timestamped consent (IP, user-agent, source, template).
Processor: Meta Platforms Ireland Ltd
Meta Platforms Ireland Ltd — Merrion Road, Dublin 4, D04 X2K5, Ireland. Hosting of WhatsApp Business Platform infrastructure (Cloud API). DPA: WhatsApp Business Terms of Service. End-to-end encryption between EIRES and you. Transfers outside the EU framed by EU-US Standard Contractual Clauses (SCC).
Retention period
- 24 months for message bodies (beyond: automatic anonymisation, metadata kept for statistics only).
- Consent retained for the entire relationship + 3 years after last exchange (GDPR art. 7.1 evidence).
- Opt-out register retained indefinitely (Meta obligation + compliance proof).
Your rights
- Instant objection: send STOP (or UNSUBSCRIBE / OPT-OUT / REMOVE / HALT) to our WhatsApp number. Immediate automatic processing.
- Access / rectification / erasure: email [email protected].
- Portability: full export of your conversations on request.
- Complaint: CNPD (cnpd.public.lu).
Automated decision-making
No automated profiling within the meaning of GDPR art. 22 is performed on WhatsApp data. Internal classification (prospect / client / VIP) remains under final human decision.