Privacy notice
This notice explains how Property Rooms processes personal data.
Last updated: 22 August 2026
- Operator
- Aliaksandr Karnilovich
- NIP
- 9512513807
- Address
- Wąwozowa 6/6102-796 Warszawa, Polska
- privacy@propertyrooms.pl
1. Who is responsible for the data
Aliaksandr Karnilovich (NIP 9512513807, Poland) is the controller for data used to manage accounts, authentication, platform security, administration and support requests.
A real-estate agency or independent agent decides why and how its clients’ data is used inside rooms. For that data the account owner is the controller and Property Rooms acts as its processor under a data-processing agreement (DPA).
The DPA is provided to the account owner before client-data processing begins and describes scope, purposes, security duties, data-subject support and breach notification.
2. Data categories
The platform may process:
- email address, display name, role, account type and account status;
- account name, optional agency NIP and information linking clients to accounts;
- agent password hashes, hashes of one-time sign-in links and codes, session data and, for platform administrators, encrypted MFA secrets and recovery-code hashes;
- room membership, budgets, locations, housing preferences and notes;
- messages, reactions and collaboration activity;
- optional external listing URLs, manually entered property details and private agent comments; the platform does not fetch source-page content;
- name, email, account type, optional agency name, agent count and handling status of a trial request;
- administrative audit logs, read state, notification delivery status and a small set of product events limited to agents and administrators (sign-in, room created, client invited, property added, room archived) with agent, account and timestamp identifiers, plus aggregate, non-identifying statistics about clients’ in-room engagement (for example counts of client reactions or comments);
- IP address processed in memory for about one hour to prevent abuse of sign-in, trial-request and client-onboarding endpoints.
3. Data sources
Data comes from the user, from an agency or independent agent that creates or links a client account, and from activity within the platform.
Property links and related information are entered manually by agents. Property Rooms does not collect data from listing portals.
Whether GDPR Article 13 or Article 14 applies to a client’s data depends on whether that data was obtained directly from the client, not on whether the client previously contacted Property Rooms — see “Privacy information for clients” below.
4. Privacy information for clients
For personal data processed within client rooms, the account owner — the real estate agency or independent professional — generally acts as the Controller, while Property Rooms processes that data on its behalf as Processor.
The Controller is responsible for providing data subjects with the information required by GDPR Article 13 or Article 14, depending on the source of the personal data and the circumstances in which it was obtained.
In particular:
- GDPR Article 13 applies where the Controller obtains personal data directly from the data subject;
- GDPR Article 14 applies where the personal data was not obtained directly from the data subject, for example where it was provided by another person, a partner or another source.
The fact that a client has not previously used or interacted with Property Rooms does not by itself determine that Article 14 applies.
The Controller is responsible for providing the required information within the period required by the applicable GDPR provision.
Where Property Rooms sends an invitation or another communication to a client on behalf of the Controller, that processing is performed on the Controller’s documented instructions and does not transfer responsibility for the Controller’s transparency obligations to Property Rooms.
Separately, Property Rooms provides its own Privacy Notice for processing where Property Rooms acts as an independent Controller, for example in connection with platform security, administration of its own services or certain technical data.
5. Purposes and legal bases
Account and service-use data is processed to enter into and perform the service contract. Security, abuse prevention, audit and support data may rely on legitimate interests after the required assessment.
Trial-request data is used to make contact, support manual review by a platform administrator, prepare access and manage the relationship before a contract is entered into.
Property Rooms processes client-room data on behalf of the agency or independent agent. The account owner is responsible for selecting its legal basis and providing the correct notice to the client.
Property Rooms maintains limited first-party product analytics for agents and administrators only, not clients, based on its legitimate interest in product improvement — see section 9 for the right to object under GDPR Article 21. Raw analytics events are kept for 90 days, and the resulting long-term metrics are aggregated and kept for up to 24 months. Client-room content and client property preferences are not used for Property Rooms’ own product analytics, and Property Rooms does not keep a separate, identifiable analytics history of client behaviour. Room activity data (such as read state) is used operationally to power unread indicators and grouped email notifications.
Authentication data and administrative logs support sign-in, invitations, account protection, platform administration and accountability for privileged actions.
Consent is not used as a catch-all where processing is actually necessary for a contract or security.
6. Recipients and providers
Room data is available to assigned agents and clients in that room and to authorised owners and administrators of the relevant account. Authorised platform administrators handle trial requests, accounts, agents, audit logs and aggregated product reports but cannot open client rooms.
Subprocessors include OVH for application, database and infrastructure hosting, and Brevo (Sendinblue) for transactional email and @propertyrooms.pl mailboxes.
Activity notifications are addressed to other members of the relevant room and delivered through the configured transactional-email provider. Reactions are not sent by email.
7. Transfers outside the EEA
The application and database infrastructure is hosted by OVH in the European Union. Brevo (Sendinblue) processing locations and any international transfers are governed by the DPA and subprocessor arrangements applicable to the Property Rooms Brevo account.
Any transfer outside the EEA must comply with GDPR Chapter V. The verified transfer mechanism will be documented and made available on request from privacy@propertyrooms.pl.
8. Retention
A one-time sign-in link or code is valid for 15 minutes, an agent or administrator invitation for 48 hours, an MFA challenge for 5 minutes, and a web session for 12 hours.
Account, room and collaboration data is kept for the subscription period and up to 30 days after termination unless law or security requires longer retention. Deployment procedures provide for backups before deployments, and the operational configuration may include daily scheduling and rotation of the latest 14 files.
Trial-request data is kept for up to 12 months from contact or until account activation. Security and audit logs — up to 24 months.
Raw professional-user product-analytics events (see section 5) are kept for 90 days and then deleted; the resulting aggregated monthly metrics are kept for up to 24 months.
Deletion requests can be sent to privacy@propertyrooms.pl; completion depends on the roles of Property Rooms and the account owner and on legal duties.
9. User rights
Depending on the processing role, Property Rooms or the account owner will handle requests for access, correction, erasure, restriction, portability or objection. A request can be started using the contact address below.
The application has no self-service account deletion or complete export. Requests are handled manually under the agreed procedure and may require the relevant agency’s or independent agent’s cooperation.
Requests are answered without undue delay, normally within one month. The requester’s identity may be verified securely.
Users may complain to the President of the Polish Personal Data Protection Office.
10. Automated decisions and profiling
Property Rooms does not make decisions producing legal effects solely by automated means and does not profile users for advertising. Internal product statistics are not used for advertising or cross-site tracking.
Property Rooms does not use any third-party analytics or advertising tools — the product analytics described in section 5 is entirely first-party and server-side.
11. Security and cookies
The platform uses account and room access controls, hashing for agent passwords and one-time tokens and, for platform administrators, MFA with encrypted secrets and hashed recovery codes. Sessions use HttpOnly cookies.
The separate cookie notice describes the current browser-storage categories, purposes and durations.
12. Links and external websites
The Property Rooms server validates only the saved URL format and does not connect to the source page. Selecting the action opens that page directly in the user’s browser.
Opening a property or an external link is not recorded as an identifiable, client-specific event. Use of the comparison tool is reflected only in an aggregate, non-identifying use counter. Neither action causes Property Rooms to retrieve the external page content.
The external portal then acts as a separate controller and may receive the IP address, browser information and standard referral data. Its own terms and privacy notice apply.
13. Demo environment
The demo uses separate URL paths, backend, database and session cookies containing fictional accounts and example content.
The demo environment is for product exploration only. Demo data may be reset without notice.
14. Billing, invoicing and payments
For paid subscriptions, Property Rooms issues invoices to professional customers — real estate agencies and independent agents — for the paid part of the Service (agent seats). Billing and invoicing processing is separate from processing of Client Room Data described elsewhere in this notice and in the DPA; the account owner’s role as Controller for Client Room Data is not affected by billing arrangements.
Property Rooms processes billing data to issue and manage invoices, administer and reconcile payments, perform the subscription agreement, and comply with tax and accounting obligations, including obligations relating to the National e-Invoicing System (KSeF) where applicable. Processing necessary to perform or administer the commercial agreement relies on GDPR Article 6(1)(b). Processing necessary to comply with statutory tax, invoicing and accounting obligations relies on Article 6(1)(c). Where necessary, Property Rooms may also process billing data to establish, exercise or defend claims relating to unpaid invoices, based on its legitimate interest under Article 6(1)(f).
A natural person who purchases Property Rooms for a professional or business purpose, such as an independent agent, is not treated as a consumer merely because the buyer is a natural person. Mandatory KSeF invoicing does not apply to consumer (B2C) invoices, which may be issued outside KSeF under applicable rules.
- customer or business name, and first and last name where applicable;
- billing address;
- NIP or other tax identifier, where applicable;
- billing or contact email address;
- invoice identifiers and dates;
- subscription and agent-seat information needed to issue the invoice;
- invoice amounts;
- payment status;
- bank-transfer information needed to identify and reconcile a payment;
- KSeF identifiers, submission status and related invoice metadata, where applicable.
Billing data is shared with the following recipients: Fakturownia — invoicing and billing software that processes invoice data on Property Rooms’ behalf as a processor and facilitates submission of invoices to KSeF where that feature is enabled; the Head of the National Revenue Administration (Szef Krajowej Administracji Skarbowej) / KSeF — as an independent controller and public authority for data transmitted to KSeF where required or chosen under applicable tax law; and banks and payment institutions involved in a bank transfer — as independent controllers for payment and bank-transfer processing under their own legal obligations. No external accountant currently has access to Property Rooms billing data. Where invoicing is handled through Fakturownia, billing and invoice administration is carried out by the Property Rooms owner together with Fakturownia.
Billing, invoice and payment documentation is retained for the periods required by applicable tax and accounting law and, where necessary, for the establishment, exercise or defence of billing-related claims. Invoices submitted to KSeF are additionally retained within KSeF under the statutory KSeF retention regime. Property Rooms does not apply a shorter deletion period for billing data than applicable tax law requires.
15. Illegal-content reports (DSA)
Property Rooms provides a mechanism for reporting content that the reporter considers illegal, in accordance with Article 16 of the Digital Services Act (DSA). For processing such reports, Property Rooms acts as an independent Controller; reports are not Client Room Data and are not processed on behalf of the account owner.
In connection with a report, we process: the reporter’s identifying and contact information (name, email address), the content and location of the reported material, the explanation of the reasons for the report, and the handling history, including any decision taken and its reasoning.
We process this data to comply with obligations under the DSA, to handle the report, and, where necessary, to establish, exercise or defend claims related to the report. The legal basis is a legal obligation (GDPR Article 6(1)(c), in connection with the DSA) and, for establishing, exercising or defending claims, legitimate interests (GDPR Article 6(1)(f)).
We retain report data for as long as necessary for DSA record-keeping obligations and to defend against related claims; this period is reviewed periodically.
16. Moderation actions and provider-imposed restrictions (DSA Article 17)
Where Property Rooms removes content, disables access to it, or restricts part of the Service or an account because of unlawful content or a breach of the Terms, we process a limited set of data needed to document that action and prepare the statement of reasons required by DSA Article 17. For this processing, Property Rooms acts as an independent Controller; this data is not Client Room Data and is not processed on behalf of the account owner.
We process in particular: data about the person subject to the restriction (an account identifier and, where relevant, the email address used for the notification), the type and scope of the restriction applied, its basis (unlawful content or a Terms violation), the related report under the mechanism described in section 15, where one exists, and the administrative history of the action, including any request for reconsideration and its outcome. We do not disclose the reporter's identity to the person subject to the restriction except where strictly necessary.
The legal basis for this processing is a legal obligation under the DSA (GDPR Article 6(1)(c)) for preparing and delivering the statement of reasons, and legitimate interests (GDPR Article 6(1)(f)) for maintaining platform security and defending against claims related to the restriction.
We retain this data for as long as necessary to document the restriction applied and to defend against related claims; this period is reviewed periodically.
Privacy contact
To ask a question or start a data-rights request, email: privacy@propertyrooms.pl
Polish Personal Data Protection Office