Privacy Policy
Last updated: 16 June 2026
This Privacy Policy explains how PropertyOS collects, uses, shares and protects
personal data, and the rights you have under the EU General Data Protection
Regulation (GDPR) and Belgian data-protection law.
Note — not legal advice. This policy has not had external legal review; it
is provided for transparency during our free preview. Questions:
[email protected].
1. Who we are (data controller)
PropertyOS is operated by Oleksii Veselovskyi, an individual based in
Belgium, offering the service as a free preview. PropertyOS is not yet
registered as an enterprise and operates as a private individual until formal
registration.
- Privacy contact: [email protected]
- General contact: [email protected]
We are the data controller for account holders (landlords, agency staff)
and for the operation of the service. For personal data that a landlord or
agency enters about their tenants, we act as a data processor on their
behalf — see our Data Processing Agreement.
We are not required to appoint a Data Protection Officer, but you can reach our
privacy contact at the address above for any request.
2. Whose data we process
- Account holders — landlords and agency staff who register and sign in.
- Tenants and lease signatories — people whose details a landlord or agency
enters to manage a tenancy (name, contact details, lease and payment data).
- Prospective tenants and invited users — people invited by email to join a
property, sign a lease, or accept an invitation.
3. What data we collect
| Category | Examples |
|---|---|
| Account & identity | Name, email address, password (hashed), role, language, optional 2FA secret |
| Authentication | Login timestamps, refresh-token metadata, Google account identifier (only if you use Google Sign-In) |
| Property & tenancy | Property addresses, units, lease terms, rent charges, deposits, compliance items |
| Documents | Files you upload (leases, certificates, photos) and their metadata |
| Tenant & contact data | Tenant names, emails, phone numbers entered by landlords/agencies |
| Payments | Subscription billing details and payment status (card data is handled by Stripe, not stored by us) |
| Communications | Support requests, ticket messages, in-app notifications |
| Technical & security logs | IP address, user agent, request and error logs stored as server log files, audit records of sensitive actions |
We do not ask for special-category data (health, ethnicity, etc.). Please do
not upload documents containing more sensitive personal data than a tenancy
requires.
4. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the service, your account, and core features | Performance of a contract — Art. 6(1)(b) |
| Send transactional email (confirmations, invites, password resets, reminders) | Contract — Art. 6(1)(b) |
| Billing, invoicing, accounting and tax records | Legal obligation — Art. 6(1)(c); contract — Art. 6(1)(b) |
| Security, fraud and abuse prevention, server logging, backups | Legitimate interests — Art. 6(1)(f) |
| Maintain and improve reliability of the service | Legitimate interests — Art. 6(1)(f) |
| Optional analytics cookies; browser push notifications | Consent — Art. 6(1)(a) |
| Comply with lawful requests from authorities | Legal obligation — Art. 6(1)(c) |
Where we rely on legitimate interests, we have balanced them against your rights;
you may object at any time (see section 8).
5. Who we share data with (sub-processors)
We do not sell your personal data. We share it only with vetted service
providers who process it on our instructions. Our current sub-processors are
listed and kept up to date on the Sub-processors page,
and include cloud hosting, email delivery, payment processing, optional AI
assistance, optional sign-in, push delivery and address geocoding.
We may also disclose data where required by law, or to establish, exercise or
defend legal claims.
6. International transfers
Our infrastructure is hosted in the EU. Where a sub-processor may process data
outside the European Economic Area (for example certain Stripe or Google
operations), that transfer is covered by an adequacy decision or by the European
Commission's Standard Contractual Clauses, together with additional safeguards
where appropriate.
7. How long we keep data
| Data | Retention |
|---|---|
| Account and content (properties, leases, documents) | For the life of your account; deleted or anonymised within 90 days of account closure |
| Invoices and payment records | Up to 7 years (Belgian accounting and tax law) |
| Audit logs of sensitive actions | Up to 12 months |
| Server log files (security/operations) | Rolling retention, up to 90 days |
| Backups | Cycled out of rotation within 35 days |
If the law requires us to keep certain records longer, we will.
8. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and
port your personal data, to object to processing based on legitimate
interests, and to withdraw consent at any time without affecting prior
processing.
- Account holders can export or delete their data directly from account
settings.
- For any other request, email [email protected]. We respond within one
month (GDPR Art. 12).
- If a landlord or agency holds your data as the controller (for example, you
are a tenant), we will forward your request to them and assist as their
processor.
You also have the right to lodge a complaint with the **Belgian Data Protection
Authority** (Gegevensbeschermingsautoriteit / Autorité de protection des
données), Rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be —
or with your local supervisory authority.
9. Cookies and tracking
We use only essential cookies and local storage needed to keep you signed in and
remember preferences. Any optional analytics are loaded only with your consent.
See our Cookie Policy.
10. Security
We apply appropriate technical and organisational measures, including encryption
in transit (TLS), encryption of uploaded files at rest, hashed passwords,
breached-password checks, optional two-factor authentication, role- and
tenant-based access control, rate limiting, malware scanning of uploads, and
audit logging. No system is perfectly secure; we maintain a documented breach
response procedure and will notify you and the supervisory authority where the
law requires.
11. Changes to this policy
We may update this policy as the product evolves. Material changes will be
announced via the in-app changelog or by email. The "last updated" date above
always reflects the current version.
12. Contact
Data protection enquiries: [email protected]