Privacy Policy
Version 2026-08-11 · Last updated: 11 August 2026
1. Who We Are
EMVADON LTD ("Emvadon", "we", "us") is a private limited company incorporated in the Republic of Cyprus. We operate the Emvadon real‑estate‑intelligence software‑as‑a‑service (the "Service").
Legal name: EMVADON LTD
Register: Cyprus Department of Registrar of Companies (Companies Register)
Registration no.: HE 479085
Registered office: Dodekanisou 15B, 8028, Paphos, Cyprus
Contact:
1a. Data Protection Contact
While Emvadon is not currently required to appoint a statutory Data Protection Officer, privacy enquiries may be addressed at .
1b. Controller and Processor Roles
Emvadon is the controller of personal data we collect to operate accounts, billing, security, fraud prevention, support, product analytics (where consented), and our own marketing. For that data, this Privacy Policy describes our controller processing.
Where an organisation customer uploads or creates Customer Content that contains personal data about third parties (for example client files, notes, or evidence), that organisation is typically the controller of that content and Emvadon processes it as a processoron the organisation's documented instructions to provide the Service. Enterprise customers may request a data processing agreement (DPA) as part of a written order. Self-serve customers remain responsible for their lawful basis to submit third-party personal data.
2. Personal Data We Collect
- Account identifiers – given name, family name, email address, telephone number.
- Authentication data – password hashes, session tokens, multi-factor authentication factors and recovery materials where you enable them.
- Organisation and access data – organisation membership, roles, seats, and invitations when you use team or organisation features.
- Contract evidence – the legal-document version and cryptographic hash shown to you, acceptance or withdrawal timestamp, account identifier, purchaser type, immediate-access request, and relevant request evidence such as IP address, country, and browser user agent.
- Payment and billing information – limited card details processed by Stripe (we never store full card numbers), billing legal name, billing address, VAT/tax identification number where provided, invoice and tax records, subscription status, refund records, and dispute records.
- Customer content – files, photos, notes, valuation evidence, project data, and other materials you or your authorised users upload or create in the Service.
- Usage and product activity – IP address, browser/OS, timestamps, pages or API calls requested, parcel and map interactions, search queries submitted to the Service, cookies and similar identifiers, and export or report generation activity including provenance or artifact references.
- Security and fraud signals – login attempt metadata, approximate geolocation from IP enrichment, bot-challenge results, and device or visitor identifiers used to protect accounts, authentication, and payments (see section 5).
- Support, demo, or feedback messages you voluntarily submit, including scheduling details when you book a demo.
Please do not upload special-category personal data (such as health data, biometric templates intended for identification, or data revealing racial or ethnic origin, political opinions, religious beliefs, or sexual orientation) unless we have expressly agreed in writing to process it for a defined purpose. If you do so without that agreement, you confirm you have a lawful basis and instruct us only to host it as Customer Content under section 1b.
2a. Children's Privacy
Our Service is not intended for individuals under 18 years of age, and we do not knowingly collect personal data from children.
3. Why We Process Your Data
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide and secure the Service | Performance of contract |
| Process payments and subscriptions | Performance of contract |
| Fraud prevention, abuse detection, and account security | Legitimate interests (security of the Service and users); legal obligation where applicable |
| Troubleshoot, analyse and improve (non-cookie product telemetry) | Legitimate interests; consent where analytics cookies or similar technologies require it |
| Send transactional notices | Performance of contract |
| Marketing emails (optional) | Consent |
| Comply with legal obligations (tax, fraud, consumer rights) | Legal obligation |
Where we rely on legitimate interests, we consider the necessity of the processing against your interests and fundamental rights. You may object under section 8. Marketing emails and optional analytics cookies rely on consent where required and are not based solely on legitimate interests.
4. Data Retention
- Account and organisation data – kept while your account is active. When you request self-service account deletion, we place the account into a pending-deletion state with a recoverable grace period (typically up to 30 days), then complete deletion or anonymisation. Limited residual records may remain where law or legitimate security needs require it.
- Session and authentication tokens – kept until expiry, logout, or revocation (sessions normally expire within 30 days of last use unless refreshed).
- Security, login, and operational logs – retained for up to 12 months for security, abuse investigation, and incident response, unless a longer period is needed to establish, exercise, or defend a legal claim or to meet a legal obligation. Shorter system-specific purges may apply.
- Contract, acceptance, withdrawal, invoice, tax, refund, and dispute evidence – retained for the contract life plus up to 7 years (or longer where Cyprus tax, accounting, or consumer-law record-keeping requires it).
- Customer content – retained while your organisation needs it in the Service and deleted or made inaccessible according to product features and account-closure processes (subject to the same residual legal holds as account data).
- Analytics and diagnostics data (where you consented) – retained according to the tool configuration, typically no longer than 14 months for Google Analytics measurement and no longer than 90 days for session diagnostics, unless you withdraw consent earlier.
- Encrypted backups – retained according to the active production backup policy (typically rolling windows of 30–90 days), then safely destroyed.
4a. Automated Decision‑Making & Profiling
We use security and fraud-risk signals (including bot checks and login enrichment) to protect the Service. We do not use your data for automated decision‑making that produces legal or similarly significant effects about you without appropriate human involvement where required.
5. Cookies & Similar Technologies
We use cookies and similar technologies to provide essential website functionality, protect the Service, and—with your consent where required—to measure and improve use of the site.
Essential Cookies
These cookies are necessary for the website to function and cannot be switched off. They include:
- Session management cookies for user authentication
- Security cookies to prevent CSRF attacks
- Cookie consent preference storage
Security and integrity technologies
We use bot protection (Cloudflare Turnstile), device/visitor identification (Fingerprint), and related security signals to reduce fraud and abuse on authentication, account, payment, and signed-in product paths. These technologies support security and service integrity rather than marketing measurement. They are not used to measure anonymous marketing-page traffic for advertising. They may run before optional analytics consent when you use those security-relevant paths, on the basis of our legitimate interest in securing the Service (and contract performance where you are signing in or paying).
Analytics and diagnostics (with consent where required)
We use Google Analytics 4 and, where enabled, LogRocket session diagnostics only after you grant analytics consent via the cookie banner or Cookie Settings. Until you consent, Google Analytics is not loaded for measurement and analytics storage remains denied.
We also use Cloudflare Web Analytics (a privacy-oriented edge beacon) to understand basic site performance and traffic. That beacon is part of our edge hosting configuration.
Google Analytics may collect pages visited and time spent, browser and device information, approximate location, and traffic sources.
Managing Your Cookie Preferences
You can change or withdraw your analytics cookie preferences at any time by:
- Opening Cookie Settings in the marketing site footer or the signed-in app footer and turning analytics off
- Using the cookie consent banner when you first visit
- Adjusting your browser settings to block or delete cookies
Withdrawing analytics consent does not affect essential cookies needed for login, security, or remembering your privacy choice.
For more information about Google Analytics and privacy, visit Google Analytics Help.
6. Sharing & International Transfers
We share personal data with the sub‑processors below under appropriate contracts (including GDPR Art. 28 terms where they act as processors), and with other recipients only as described in this section:
| Sub‑processor | Purpose | Location |
|---|---|---|
| DigitalOcean LLC | Cloud hosting | Frankfurt (DE) datacentre |
| Cloudflare, Inc. | CDN, WAF, bot protection (Turnstile), Web Analytics | Global edge network (primary EU/US) |
| Stripe Payments Europe, Ltd. | Payment processing, invoicing and tax compliance support | Ireland / USA |
| Resend, Inc. | Transactional email delivery | USA |
| Google LLC | Analytics (with consent) | Ireland / USA |
| LogRocket, Inc. | Session diagnostics (with analytics consent) | USA |
| FingerprintJS, Inc. | Device/visitor identification for security and fraud prevention | EU processing region / USA company |
| MaxMind, Inc. | Login risk and geo enrichment (MinFraud Insights) | USA |
| HERE Europe B.V. / HERE Technologies | Address search and geocoding | EU / USA as applicable to the geocoding service |
| Cal.com, Inc. | Demo scheduling when you book a meeting | USA / global |
| Instatus, Inc. | Public system status page and optional status subscriptions | USA / global |
We may also disclose personal data: (a) to competent authorities when required by law or necessary to protect rights, safety, or fraud prevention; (b) to professional advisers (legal, accounting, insurance) under confidentiality; (c) to a buyer, successor, or affiliate in connection with a merger, acquisition, financing, or corporate reorganisation, subject to appropriate safeguards; and (d) with your direction or another lawful basis.
Where transfers occur outside the EEA, we rely on the EU Standard Contractual Clauses, an applicable adequacy decision (including the EU–US Data Privacy Framework where a recipient is certified), or another lawful transfer mechanism.
7. Security Measures
Emvadon maintains technical and organisational measures intended to protect personal data. The applicable environment's transport, storage, access, backup, and monitoring controls are reviewed through the Security page and customer diligence process; control evidence may change as the service evolves.
8. Your Rights
Under the GDPR and applicable Cyprus data-protection law, you may exercise the following rights where the conditions of the law are met:
- Access – obtain confirmation of processing and a copy of your personal data.
- Rectification – correct inaccurate or incomplete personal data.
- Erasure – request deletion where the law allows (for example when data is no longer needed or consent is withdrawn and no other basis applies).
- Restriction – request that we limit processing in defined cases (for example while accuracy is contested).
- Data portability – receive personal data you provided to us in a structured, commonly used, machine-readable format, and request transmission to another controller where technically feasible.
- Object – object to processing based on legitimate interests, and to processing for direct marketing at any time.
- Withdraw consent – where processing is based on consent (including optional analytics cookies and marketing emails), withdraw that consent at any time without affecting the lawfulness of processing before withdrawal. Use Cookie Settings for analytics preferences, or the unsubscribe link / account notification settings for marketing emails where available.
- Lodge a complaint – contact us first if you prefer, and/or lodge a complaint with a supervisory authority (see section 9).
How to exercise these rights:
- Account deletion and many profile corrections – through account security and profile settings where self-service is available.
- Analytics cookie consent – Cookie Settings in the site or app footer (see section 5).
- Other requests – email .
We respond to data-subject requests within the time required by applicable law (generally within one month of receipt, extendable by up to two further months for complex or numerous requests where permitted). We may need to verify your identity before acting. Some rights are limited by law (for example where we must keep tax or contract evidence). For related diligence material see our Security and Compliance pages; those pages do not replace this Privacy Policy.
9. Complaints
If you believe we have infringed your data‑protection rights, you may lodge a complaint with the Office of the Commissioner for Personal Data Protection, Iasonos 1, 1082 Nicosia, Cyprus, or with your local supervisory authority.
10. Changes
We may update this policy; the "Last updated" date will change. If changes are material, we will notify account holders by email.