Privacy Policy
How we collect, use and protect personal data.
Effective date: [ADD EFFECTIVE DATE] · Version 1.0
The controller is [OFFICIAL LEGAL COMPANY NAME], trading as EzyFlat, registered at[REGISTERED ADDRESS], G.E.MI. [GEMI NUMBER], VAT [VAT NUMBER]. Privacy contact:[PRIVACY EMAIL]. Privacy lead/team: [NAME OR ROLE].
1. Data we collect
- Account: name, surname, email, optional phone, date of birth, age, gender, hashed password, verification status and Google OAuth details.
- Profile and matching: photo, bio, occupation, budget, areas, rental period, sleep, smoking, pets, guests, hobbies and music.
- Listings: address, exact coordinates, property/room details, photos, prices, deposits, availability, rules and host-authority declaration.
- Service activity: saved listings/searches, viewing proposals (the day/time you proposed, sent to the host as a message), tenancy dates, notifications, conversations and messages. (Booking requests are not currently offered.)
- Technical/security: session tokens, sign-in times, IP/device where logged, logs, failed attempts and anti-bot results.
- Support and reports: communications, complaints, evidence and moderation actions.
2. Sources
Data comes from you, from other users when they invite or add you to a home, from Google when you use Google sign-in, from technical systems when you use the service, and from partners or authorities where lawful and necessary.
3. Purposes and lawful bases
- Contract: accounts, profiles, listings, messaging, requests, bookings and support.
- Legitimate interests: security, fraud prevention, performance, improvement, moderation and legal claims, after balancing your rights.
- Legal obligation: tax/accounting records, valid authority requests, data protection and digital-services duties.
- Consent: optional cookies/trackers, optional marketing and specific processing where required. Consent can be withdrawn prospectively.
[LEGAL REVIEW: confirm the specific lawful basis for gender, gender preferences and any sensitive information]
4. Public and visible information
Privacy settings determine which profile fields are shown. Under the current product, age and gender are always visible as trust signals and cannot be hidden; exact date of birth and email are not public.[LEGAL/PRODUCT DECISION: confirm mandatory visibility is necessary, proportionate and lawful, or add a hide option].
Anonymous visitors receive an approximate location. Signed-in users may receive the exact address and exact coordinates. [DECISION: exact address to all signed-in users or only after request acceptance]. Exact addresses should not appear in metadata or share previews.
5. Flatmate matching and profiling
We calculate compatibility indicators using declared preferences and habits such as smoking, pets, guests, sleep, hobbies, music and age compatibility. Fields marked private are excluded from badges shown to others. The result is a search aid and does not automatically decide whether someone may rent or communicate. Change visibility settings or ask for details at [PRIVACY EMAIL].
6. Recipients and providers
- Other users, according to Platform functions and visibility settings.
- Railway for app/API hosting and [ADD DATABASE PROVIDER/REGION].
- Cloudinary for photo hosting and technical processing.
- Resend for transactional emails and notifications.
- Google for OAuth and [CONFIRM MAP/GEOCODING SERVICES].
- OpenFreeMap for map tiles. These load only if you accept Functional cookies — until then no request is made. The provider receives your IP address and technical browser details.
- Cloudflare Turnstile for bot and abuse protection.
- [ADD analytics, error monitoring, support, payment and KYC vendors before use].
- Lawyers, accountants, insurers, investors/successors and authorities where necessary and lawful.
7. Transfers outside the EEA
Some providers may process data outside the European Economic Area. We rely on an adequacy decision, approved Standard Contractual Clauses and supplementary measures where appropriate. [ADD actual countries, transfer mechanisms and vendor-policy links after the vendor audit].
8. Retention
- Unverified accounts: automatically deleted after 3 days.
- Account and active profile: while the account remains active.
- Session records: up to 60 days from creation, or sooner after expiry/logout.
- Messages, requests, listings and tenancy history: [ADD APPROVED PERIOD].
- Reports, fraud/security logs and evidence: [ADD APPROVED PERIOD].
- Future payment tax/accounting records: [ADD LEGAL PERIOD].
On account deletion we remove or anonymise personal information, but may retain limited anonymised tenancy history or information needed for claims, fraud, security or law. [CONFIRM policy and implementation for messages, backups and Cloudinary files].
9. Your rights
Depending on the lawful basis, you may request access, correction, deletion, restriction, portability, objection and withdrawal of consent. Contact [PRIVACY EMAIL] or use[ADD PRIVACY-REQUEST TOOL URL]. We may request proportionate identity confirmation and normally respond within one month.
You may complain to the Hellenic Data Protection Authority or another competent authority.[ADD official HDPA contact/link in final version].
10. Cookies and similar technologies
We use strictly necessary cookies for sessions and language preference. Optional analytics, advertising or other non-essential trackers must not load before valid consent. See [ADD COOKIE POLICY LINK] and manage choices at [ADD COOKIE SETTINGS].
11. Security and breaches
Measures include access controls, session expiry, email verification, anti-bot protection, upload restrictions and error logging. No system is completely secure. Where a breach creates relevant risk, we will follow legal authority and user-notification procedures. Security reports: [SECURITY EMAIL].
12. Children
The service is only for people aged 18 or older. We do not seek to collect children’s data through accounts. If we learn that a minor created an account, we may close it and delete the data, subject to limited lawful retention.
13. Changes
We will update the date and notify users of material changes through email or the Platform. Previous versions will be retained where practical. [ADD PREVIOUS-VERSIONS URL].