1. Data controller
Reloo (“we”) is the controller of personal data collected through reloo.estate. For privacy questions: privacy@reloo.estate.
2. What data we collect
- Registration data — email, name, phone, password (hashed).
- Listing and search data — description of sought/offered property, city, price, type, photos.
- Communication data — messages and notification preferences (email, phone, Viber, Telegram, WhatsApp).
- Payment data — for broker subscriptions (we do not store card numbers on our servers).
- Technical data — IP address, device, browser, security logs.
3. Processing purposes
We process data to provide the service, match parties, enable communication, send notifications, confirm payments, ensure security, and meet legal obligations.
4. Legal basis (GDPR Art. 6)
- Contract performance — for core platform functions.
- Consent — for marketing notices (you may withdraw anytime).
- Legitimate interest — for security and fraud prevention.
- Legal obligation — for accounting and tax purposes.
5. Sharing data
We do not sell your personal data. We share it only with:
- Other platform users — only when you request contact.
- Service providers (hosting, email, analytics) under strict contracts.
- Public authorities when legally required.
6. Retention
Data is kept while your account is active. After closure we delete personal data within 90 days, unless law requires longer retention (e.g. accounting records — 10 years).
7. Your rights
You have the right to access, rectify, erase, restrict processing, data portability, object to processing, and withdraw consent. To exercise these rights, write to privacy@reloo.estate. You may also complain to the CPDP (cpdp.bg).
8. Cookies
We use technically necessary cookies for the platform (session, auth, security). With your consent we may enable analytics cookies — the choice is stored in the browser and can be changed by clearing site data. Settings appear on first visit via the consent banner. We do not use third-party advertising cookies.
9. Security
We apply industry security measures — encryption in transit (HTTPS), password hashing, database access control (Row-Level Security), and regular audits.
10. Policy changes
We may update this policy. For material changes we will notify you by email or in-platform notice.