Legal
Privacy notice
What personal data KaufWach processes, on what legal basis, for how long, and what you can require of us. Written for the GDPR and the German BDSG.
Last updated: August 9, 2026
Controller
The controller for the processing described here, within the meaning of Art. 4 (7) GDPR, is:
We have not appointed a Data Protection Officer. Should one become mandatory under Art. 37 GDPR or § 38 BDSG, the contact details will be published here.
- Controller
- [Registered company name]
- Address
- [Street and house number][Postcode] [City]Deutschland
- Data protection contact
- [[email protected]]
What we process
Three kinds of data, kept apart from one another:
- Account data — name, email address, password hash, workspace and role, language and interface preferences.
- Content you provide — listing URLs, uploaded documents (Exposé, Energieausweis, floor plans, WEG minutes), photos, questionnaire answers and notes. These can contain personal data about third parties, for example the name of an agent or a previous owner printed on a document.
- Technical data — IP address, timestamp, user agent, requested URL, error and job logs, produced automatically whenever the service is used.
Purposes and legal bases
We process data only for the purposes below, each with its legal basis under Art. 6 (1) GDPR:
- Providing the service — running analyses, storing your properties and reports: performance of a contract, Art. 6 (1) (b).
- Account administration, invitations and support correspondence: Art. 6 (1) (b), and our legitimate interest in answering enquiries, Art. 6 (1) (f).
- Security, abuse prevention and troubleshooting through server logs: legitimate interest in a stable and secure service, Art. 6 (1) (f).
- Retention of business and tax records: compliance with a legal obligation, Art. 6 (1) (c).
- Anything optional, such as a product newsletter: your consent, Art. 6 (1) (a), withdrawable at any time with effect for the future.
Documents and AI processing
Documents you upload and listing pages you import are transmitted to the AI model providers we engage as processors under Art. 28 GDPR, so that their content can be extracted and scored. That transfer is limited to what a run needs and happens only when you start one.
Your content is not used to train models — neither ours nor a provider's. We contract for this with every provider and disable any training or human-review option they offer.
The output is generated by a model and can be wrong. It is stored together with the source reference for each value so that you can check it; the terms of use set out what this does and does not promise.
Recipients and processors
We do not sell personal data and never pass it on for advertising. Data is disclosed only to:
- Hosting and infrastructure providers operating our servers, database and object storage.
- AI model providers processing the content of a run, bound by a data processing agreement.
- Email delivery for transactional messages such as invitations and password resets.
- Public authorities, where we are legally obliged to disclose.
Transfers outside the EU/EEA
We aim to keep processing inside the EU. Where a processor — a model provider in particular — processes data in a third country, the transfer is based on the European Commission's Standard Contractual Clauses under Art. 46 (2) (c) GDPR together with additional safeguards, or on an adequacy decision under Art. 45 GDPR.
You can request the current list of processors and the safeguards in place at the address above.
Retention
We keep data no longer than its purpose requires:
- Properties, documents and analyses: until you delete them, and in any case until your account is closed. Deletion removes them from the live system immediately and from backups within 30 days.
- Account data: for the life of the account, then deleted or anonymised.
- Server and job logs: 30 days, longer only while a specific security incident is being investigated.
- Invoices and business correspondence: 6 or 10 years, as §§ 147 AO and 257 HGB require.
Your rights
Under the GDPR you have the right to:
- Access — confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification of inaccurate data and completion of incomplete data (Art. 16).
- Erasure (Art. 17) and restriction of processing (Art. 18).
- Data portability in a structured, machine-readable format (Art. 20).
- Object to processing based on legitimate interests, on grounds relating to your particular situation (Art. 21).
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal (Art. 7 (3)).
Complaints
If you believe we process your data unlawfully, you can lodge a complaint with a supervisory authority — in particular in the Member State of your residence, your place of work, or the place of the alleged infringement (Art. 77 GDPR). The authority competent for us is:
- Supervisory authority
- [Competent Landesdatenschutzbehörde]
Security
Traffic is encrypted in transit with TLS. Documents are held in access-controlled object storage, each workspace is isolated, and access is limited to the members you invite. Passwords are stored only as salted hashes. Staff access to production data is restricted to what running the service requires, and is logged.
No system is perfectly secure. If a breach ever affects your data we will notify the supervisory authority and, where Art. 34 GDPR requires it, you.
Changes to this notice
We update this notice when the product or the processing behind it changes. The current version always carries the date shown at the top of this page; material changes are announced in the product before they take effect.