Privacy Policy
1. Who we are
Broky ("we") operates this property-intelligence platform. The data controller is the Broky operator, contactable at andreasvourkos@gmail.com (a legal entity name and address will replace this notice at incorporation). We are established in Greece; the GDPR and Greek law 4624/2019 govern our processing.
2. Data we process about you
| Data | Purpose | Legal basis |
|---|---|---|
| Email, name, avatar (from Google or your registration) | Your account and sign-in | Contract — Art. 6(1)(b) |
| Immutable authentication subject and verified-email aliases | Keeping your account available after a verified email change while preventing recycled addresses from taking over account, team, billing or referral records | Contract — Art. 6(1)(b); legitimate interest for account security — Art. 6(1)(f) |
| Sign-in activity (when you last used the platform, request counts) | Security and service administration | Legitimate interest — Art. 6(1)(f) |
| Waitlist email + language | The early access you requested | Consent — Art. 6(1)(a) |
| Alert subscriptions (email + your saved search) | Email digests you request (double opt-in, unsubscribe in every email) | Consent — Art. 6(1)(a) |
| Pending first-party referral touch, accepted referral-offer decision (declines are cleared), referral code and attribution, snapshotted billing workspace, paid-qualification queue, reward status and credit history | Showing the offer before attribution, recording acceptance, operating the referral programme, applying the refund hold and preventing duplicate or same-workspace rewards | Contract — Art. 6(1)(b); legitimate interest for fraud prevention — Art. 6(1)(f) |
| Keyed referral anti-fraud fingerprint derived from IP | Short-window abuse and velocity review; the raw IP is not stored in the referral record | Legitimate interest — Art. 6(1)(f) |
| Opaque referral click ID, keyed browser-touch/consumer fingerprints and server timestamps | Enforcing first-touch attribution, expiry and single-account consumption without storing the browser identifier in readable form | Contract — Art. 6(1)(b); legitimate interest for fraud prevention — Art. 6(1)(f) |
| Technical logs (IP address, browser) at our hosting edge | Security, abuse prevention, operations | Legitimate interest — Art. 6(1)(f) |
| Your country (from IP, at the network edge) | Opening the map on your region — not stored | Legitimate interest — Art. 6(1)(f) |
| AI-chat prompts, responses, selected country, attached files you choose to submit, and the database filters or records needed to answer | Answering your request, preserving the conversation you save, recovering an interrupted response, and preventing the AI from using data outside the active country or your permissions | Contract — Art. 6(1)(b); legitimate interest for service security and reliability — Art. 6(1)(f) |
| Optional thumbs-up/down feedback and the bounded question/answer excerpt connected to it | Human-reviewed quality evaluation and regression testing; it is not used for automatic or online model training | Legitimate interest in improving the service — Art. 6(1)(f) |
We do not sell personal data, show ads, or run third-party marketing/analytics trackers.
3. Personal data inside the platform content (public records)
The platform republishes records that the law already makes public: Greek permits and decisions (Διαύγεια, published under law 3861/2010), public tenders (ΚΗΜΔΗΣ), company registries (ΓΕΜΗ), US public records (NYC Open Data — permits, deeds, property data), and servicers' own public property catalogues. Where these records name natural persons — for example the engineer on a building permit, or a buyer/seller on a recorded deed — that personal data appears on the platform exactly as published by the official source.
- Legal basis: legitimate interest (Art. 6(1)(f)) — market transparency built on statutorily public records. This notice serves as information under Art. 14 GDPR (individual notification is disproportionate for public-register data — Art. 14(5)(b)).
- Minimization: we only take what the source publishes; we never collect owner/debtor data beyond that, we exclude gated or ToS-protected sources, and our company profiles cover businesses, not private individuals.
- Your rights: if a record names you, you may object (Art. 21) or request erasure/rectification (Arts. 16–17) via the contact below — we respond within 30 days and can suppress your name from display while keeping the underlying public record reference.
- No automated decisions: our "heat" scores only rank informational relevance; they produce no legal or similar effect on any person.
4. Cookies & local storage
We set no tracking or advertising cookies. We use first-party browser storage strictly to make the product work: your sign-in session (Supabase), theme, language and map preferences. If you arrive through a referral link, first-party storage keeps the referral code, signed attribution token and expiry for the displayed attribution window (normally 30 days and never more than 90 days). It is removed after attribution, expiry or a terminal rejection. Because this is functional/strictly-necessary storage, no consent banner is required; if we ever add analytics we will ask first.
5. Processors & international transfers
| Processor | What for | Transfers |
|---|---|---|
| Cloudflare | Hosting, edge network, database | SCCs / EU-US Data Privacy Framework |
| Cloudflare Workers AI / AI Gateway | AI inference and secure routing to the selected model provider | SCCs / EU-US Data Privacy Framework |
| Supabase | Authentication | SCCs / DPF |
| Sign-in with Google (identity provider) and, when selected by Broky's governed model router, Gemini AI inference | SCCs / DPF | |
| OpenAI | AI-chat inference when selected by Broky's governed model router | SCCs / DPF |
| Anthropic | AI-chat inference when selected by Broky's governed model router | SCCs / DPF |
| Resend | Transactional team invitations and alert email delivery you request | SCCs / DPF |
| Stripe | Subscription payments, billing status and paid-referral qualification | SCCs / DPF |
We share personal data with no one else, unless required by law.
6. Retention
- Account & sign-in data: for the life of your account; deleted on account deletion.
- Waitlist: until launch or your opt-out. Alerts: until you unsubscribe.
- Edge logs: short rolling retention at our hosting provider.
- Saved AI chats: until you delete the chat or your account. The separate server reasoning context is bounded to the most recent turns rather than retaining an unlimited transcript.
- Interrupted-answer recovery data and immutable result previews: short-lived and automatically expired. Operational AI telemetry contains timings, route identifiers and counts, not prompts, names, addresses or email content.
- AI answer feedback: retained for human review and regression testing until it is no longer needed for those purposes or you delete your account.
- Referral reward history: for the life of the account and as needed for credit/accounting audit. Keyed IP-derived fraud fingerprints are cleared after 90 days. Expired server click reservations and their keyed consumer values are deleted within seven additional days (at most 97 days under the maximum attribution window).
- Public-record content: as long as it remains published by its source and relevant to the service; suppression requests honoured as above.
7. Your rights (GDPR)
You have the right of access, rectification, erasure, restriction, portability, and objection (including to any legitimate-interest processing), and the right to withdraw consent at any time without affecting prior processing. Write to andreasvourkos@gmail.com — we respond within 30 days. This includes requests concerning saved AI chats and AI answer feedback. You may also lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your local EU supervisory authority.
8. US users
We are not currently subject to the CCPA/CPRA or similar US state privacy laws (we do not meet their thresholds and do not sell or share personal information). We nevertheless extend the same rights described above to all users, wherever located. US public-record content (e.g. NYC Open Data) is governed by the publishing agency's terms.
9. Google user data (connected Google account)
If you connect your Google account (Connectors → Gmail / Calendar / Drive), Broky's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
| Scope | What Broky does with it |
|---|---|
gmail.send | Sends a report or message from your own Gmail account, only after you approve an on-screen approval card showing the recipient, subject and content. Broky never reads, lists, or modifies your mailbox. |
calendar.events | Creates an event you explicitly asked for, after you approve the card. Broky does not read your other calendars or events. |
drive.file | Writes a report file Broky itself creates. This scope grants access only to files the app creates — never to your existing Drive content. |
spreadsheets | Writes a spreadsheet Broky itself creates as part of an export you approved. |
We never sell or transfer Google user data, never use it for advertising, and never use it to train generalized AI/ML models. Google user data is used solely to provide the user-facing feature that requested it. Access tokens are stored encrypted (AES-GCM) and are deleted when you disconnect the connector (Connectors → Disconnect) or delete your account. You can also revoke Broky's access at any time at myaccount.google.com/permissions.
10. Changes & contact
We will announce material changes in-app or by email. Questions and privacy requests: andreasvourkos@gmail.com.
Broky