Skip to content

Privacy Policy

1. Data Controller

The party responsible for data processing on this website is:
Shahriar Robbani
1 0 1 . r t S r e h c a b l i e w h c S
n e l e s r ü W 6 4 1 2 5
Germany
Email: e d . r e t a r e b - r e l k a m @ o f n i

2. Hosting and Infrastructure

This website and the Makler-Berater service are hosted on servers operated by Cloudflare, Inc. (101 Townsend St, San Francisco, CA 94107, USA). Cloudflare operates data centers within the EU and is certified under the EU-U.S. Data Privacy Framework. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place.

When you visit the website, the following data is automatically collected: IP address (anonymised), date and time of access, page accessed, browser type and operating system. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the secure and stable provision of the website).

3. Cookies and Consent Management

This website uses technically necessary cookies required for the operation of the website. Optional cookies (e.g. for analytics or marketing) are only set with your explicit consent.

You can adjust or reset your cookie preferences at any time via the cookie banner at the bottom of the page. Legal basis for non-essential cookies: Art. 6(1)(a) GDPR in conjunction with § 25 TTDSG.

4. Chat Assistant and AI Processing

When you or end users use the AI chat assistant on an estate agent's website:

  • Your messages are forwarded to an AI language model service to recommend suitable properties.
  • AI recommendations are automated suggestions without legal binding force — not purchase advice or legal opinion.
  • Conversation histories are automatically deleted after a maximum of 30 days (configurable by the agent).
  • Contact details are only collected if you voluntarily provide them during the conversation.
  • All data is stored exclusively for the respective agent and is not shared with other agents or third parties.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures) or Art. 6(1)(f) GDPR (legitimate interest).

5. Registration and Customer Account (Agents)

When registering as an agent, we collect: name, email address, and password (stored as a bcrypt hash). Optional: company name, website URL. This data is required to fulfil the contract. Legal basis: Art. 6(1)(b) GDPR.

6. Email Communication (Resend)

For sending transactional and marketing emails, we use the service Resend, Inc. (548 Market St, PMB 72878, San Francisco, CA 94104, USA). Resend processes email addresses and send metadata on our behalf. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place. Resend is certified under the EU-U.S. Data Privacy Framework. Legal basis: Art. 6(1)(b) and (f) GDPR.

7. Payment Processing (Stripe)

Payment processing is handled by Stripe, Inc. (354 Oyster Point Blvd, South San Francisco, CA 94080, USA). We do not store any credit card or bank details on our servers. Stripe is PCI DSS Level 1 certified and registered under the EU-U.S. Data Privacy Framework. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place. Legal basis: Art. 6(1)(b) GDPR.

8. AI Service (Anthropic / AWS Bedrock)

For AI-powered processing, we use the Claude language model by Anthropic, PBC (548 Market St, San Francisco, CA 94107, USA), provided via Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, L-1855 Luxembourg) in the eu-central-1 (Frankfurt, Germany) data center. The following data is processed:

  • Chat messages — to generate suitable property recommendations
  • Property exposés (text and images) — for automatic data extraction
  • Contact details and conversation histories — for automatic lead qualification

All processing takes place exclusively in the EU (Frankfurt). Anthropic does not use messages for AI model training. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place with AWS. Legal basis: Art. 6(1)(b) and (f) GDPR.

9. WhatsApp Integration (Telnyx / 360dialog / Meta)

For the WhatsApp channel, we use the services of Telnyx LLC (311 W Superior St, Chicago, IL 60654, USA), 360dialog GmbH (Friedrichstraße 123, 10117 Berlin, Germany) and/or Meta Platforms Ireland Ltd (Grand Canal Square, Dublin 2, Ireland) as messaging providers. Phone numbers, message contents, and timestamps are processed. Telnyx is certified under the EU-U.S. Data Privacy Framework; 360dialog processes data within the EU; Meta processes data pursuant to its platform policies within the EU. Data processing agreements (DPAs) pursuant to Art. 28 GDPR are in place with the respective providers. Legal basis: Art. 6(1)(b) and (f) GDPR.

10. Error Monitoring (Sentry)

For detecting and resolving technical errors, we use Sentry (Functional Software, Inc.) (45 Fremont Street, San Francisco, CA 94105, USA). Technical data such as IP address (anonymised), browser type, error messages, and stack traces may be transmitted. No message contents or personal profile data are sent to Sentry. Sentry is certified under the EU-U.S. Data Privacy Framework. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in error resolution).

11. Voice Transcription (OpenAI Whisper)

When end users send voice messages via WhatsApp, these are transmitted to OpenAI, L.L.C. (3180 18th St, San Francisco, CA 94110, USA) for transcription. OpenAI processes only the audio file to convert it to text; the transcription is then treated like a normal text message. OpenAI does not use the data for AI model training (API usage is excluded from training). OpenAI is certified under the EU-U.S. Data Privacy Framework. A data processing agreement (DPA) pursuant to Art. 28 GDPR is in place. Legal basis: Art. 6(1)(b) and (f) GDPR.

12. Web Analytics (Plausible)

For anonymous usage analytics, we use Plausible Analytics (Plausible Insights OÜ, Tallinn, Estonia, EU). Plausible does not process personal data, does not set cookies, and does not create individual user profiles. All data is processed exclusively within the EU. Legal basis: Art. 6(1)(f) GDPR.

13. Data Processing Agreement (DPA/AVV)

Insofar as we act as a data processor for the respective estate agent, we provide a Data Processing Agreement (AVV) pursuant to Art. 28 GDPR. The full DPA is available at: api.makler-berater.de/avv

14. Contact Form and Email Enquiries

When you contact us by email or via the contact form, your details (name, email, message) are stored to process your enquiry. We do not pass this data on without your consent. Legal basis: Art. 6(1)(f) GDPR.

15. Your Rights

You have the right to:

  • Access your stored data (Art. 15 GDPR)
  • Rectification of inaccurate data (Art. 16 GDPR)
  • Erasure of your data (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Object to processing (Art. 21 GDPR)
  • Withdraw consent at any time (Art. 7(3) GDPR)

Contact for data protection enquiries: e d . r e t a r e b - r e l k a m @ o f n i

16. Complaint to a Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The competent authority for North Rhine-Westphalia is:
State Commissioner for Data Protection and Freedom of Information NRW (LDI NRW)
Kavalleriestr. 2–4, 40213 Düsseldorf
www.ldi.nrw.de

17. Changes to this Privacy Policy

This privacy policy may be updated as needed to reflect changes in our service or legal requirements. Last updated: April 2026.