Privacy Policy
Last Updated: January 1, 2024
Version: 1.0
1. Who We Are
Data Controller: SichrPlace
Contact: sichrplace@gmail.com
Address: [Your Address]
Data Protection Officer: sichrplace@gmail.com
2. What Personal Data We Collect
2.1 Information You Provide
- Account Information: Username, email address, password (encrypted)
- Profile Data: Name, contact details, preferences
- Property Listings: Property details, images, descriptions
- Communications: Messages, viewing requests, feedback
- Viewing Requests: Name, email, phone number, preferred dates
2.2 Information We Collect Automatically
- Technical Data: IP address, browser type, device information
- Usage Data: Pages visited, time spent, interaction patterns
- Cookies: Essential, functional, analytics, and marketing cookies
3. Legal Basis for Processing
Purpose | Legal Basis | Data Categories |
---|---|---|
Account management | Contract performance | Identity, contact data |
Property matching | Contract performance | Profile data, preferences |
Communication facilitation | Contract performance | Contact data, messages |
Platform security | Legitimate interests | Technical data, usage patterns |
Marketing communications | Consent | Contact data, preferences |
Analytics | Consent | Usage data, technical data |
4. How We Use Your Data
- Provide and maintain our rental platform services
- Match tenants with suitable properties
- Facilitate communication between users
- Process viewing requests and bookings
- Ensure platform security and prevent fraud
- Improve our services through analytics
- Send service-related notifications
- Send marketing communications (with consent)
5. Data Sharing and Disclosure
We may share your data with:
- Other Users: Limited profile information for platform functionality
- Service Providers: Cloud hosting, email services, analytics providers
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In case of merger, acquisition, or sale
We never sell your personal data to third parties.
6. International Data Transfers
Your data may be processed in countries outside the European Economic Area (EEA). We ensure adequate protection through:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Certification schemes and codes of conduct
7. Data Retention
Data Type | Retention Period | Reason |
---|---|---|
Account data | Until account deletion | Service provision |
Property listings | 2 years after removal | Legal compliance |
Messages/Communications | 3 years | Dispute resolution |
Technical logs | 1 year | Security and debugging |
Marketing consent | Until withdrawn | Consent management |
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
8.1 Right of Access
Request a copy of all personal data we hold about you.
8.2 Right of Rectification
Request correction of inaccurate or incomplete data.
8.3 Right of Erasure ("Right to be Forgotten")
Request deletion of your personal data under certain circumstances.
8.4 Right to Data Portability
Request a copy of your data in a machine-readable format.
8.5 Right to Restrict Processing
Request limitation of how we process your data.
8.6 Right to Object
Object to processing based on legitimate interests or for marketing purposes.
8.7 Rights Related to Automated Decision-Making
Rights regarding automated profiling and decision-making processes.
• Log into your account and visit the Privacy Settings page
• Email us at sichrplace@gmail.com
• Use our online GDPR request form
Response Time: We will respond within 30 days of receiving your request.
9. Cookies and Tracking
We use cookies and similar technologies for:
9.1 Essential Cookies
Required for basic site functionality and security. These cannot be disabled.
9.2 Functional Cookies
Enhance user experience with personalized features.
9.3 Analytics Cookies
Help us understand how users interact with our platform. We use the following analytics services:
Microsoft Clarity
Purpose: User behavior analytics and website optimization
Data Collected: Page views, clicks, scrolls, form interactions (masked), session recordings
Legal Basis: Your consent (GDPR Article 6(1)(a))
Data Retention: 90 days maximum
Data Sharing: Data is processed by Microsoft Corporation (Privacy Shield certified)
Your Rights: You can withdraw consent, request data deletion, or export your data anytime
Privacy Settings: Manage your tracking preferences
Microsoft's Privacy Policy: View Microsoft Privacy Statement
Data Minimization: We have configured our analytics tools to:
- Automatically mask sensitive form fields (passwords, SSN, payment info)
- Anonymize IP addresses
- Respect "Do Not Track" browser settings
- Limit data retention to the minimum necessary period
9.4 Marketing Cookies
Used for targeted advertising and measuring campaign effectiveness.
Cookie Management: You can manage your cookie preferences through our Cookie Settings panel or your browser settings.
10. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption in transit and at rest
- Regular security assessments and audits
- Access controls and authentication
- Employee training on data protection
- Incident response procedures
11. Children's Privacy
Our services are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware of such collection, we will delete the data promptly.
12. Changes to This Policy
We may update this privacy policy from time to time. We will:
- Notify you of significant changes via email or platform notification
- Update the "Last Updated" date at the top of this policy
- Obtain fresh consent where required by law
13. Contact Information & Complaints
Data Protection Contact
Email: sichrplace@gmail.com
Response Time: Within 72 hours
Data Protection Officer: sichrplace@gmail.com
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority:
Germany: Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Website: https://www.bfdi.bund.de/
Email: poststelle@bfdi.bund.de
14. Specific Provisions for German Users
In accordance with German data protection law (BDSG) and GDPR:
- We process personal data in accordance with Art. 6 GDPR
- Data processing is limited to the specified purposes
- We implement appropriate technical and organizational measures per Art. 32 GDPR
- Data protection by design and by default is implemented per Art. 25 GDPR