Back to home

Privacy Policy of the Real-bro Service

Version
3.0
In force from
September 14, 2026

This Policy describes what personal data the Real-bro service processes, on what legal basis, for how long it is kept and to whom it is disclosed. AI calls process the speech of persons who are not users of the Service; sections 10 to 15 are devoted to them. Information about properties and their authors obtained from external sources is described in points 3.11 and 4.8. This Policy is the information provided under articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

1. Controller and contact details

1.1. Operator — Serhii Poliakov EI, entrepreneur individuel (EI) under French law, micro-enterprise regime, SIRET 10527513500017, address 36 rue Victor Hugo, 76530 Grand-Couronne, France, telephone +33 939 24 93 33. The Operator is the controller of the processing described in this Policy, unless otherwise stated for a particular processing operation.

1.2. Contact details: email [email protected], postal address 36 rue Victor Hugo, 76530 Grand-Couronne, France. Requests concerning personal data are sent to [email protected] (section 20).

1.3. No data protection officer has been designated.

1.4. The Operator is established in the European Union; no representative under article 27 GDPR is required.

1.5. The Operator's lead supervisory authority is the Commission nationale de l'informatique et des libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr. A complaint may also be lodged with the supervisory authority of the country of habitual residence or place of work (article 77 GDPR): in Spain, the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan, 6, 28001 Madrid, www.aepd.es; in Italy, the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, www.garanteprivacy.it; in Portugal, the Comissão Nacional de Proteção de Dados (CNPD), Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, www.cnpd.pt.

1.6. This Policy covers the website real-bro.com and its subdomains, the Service's applications, the Service's Telegram bot and mini-application, and AI calls.

1.7. The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “consent” have the meanings given in article 4 GDPR.

2. To whom this Policy applies

2.1. To users of the Service — registered persons using free or paid access.

2.2. To visitors who are not registered — as regards technical data and cookies (section 21).

2.3. To third parties whose data reaches the Operator otherwise than from themselves: the called parties in AI calls — property owners, agency representatives and other persons whose numbers a user provides (sections 10 to 15) — and persons whose details appear in listings obtained from external sources (points 3.11 and 4.8). Such persons are not users of the Service and conclude no contract with the Operator; they have the rights of data subjects under Chapter III GDPR.

2.4. To persons whose details a user enters in their tenant profile (for example, the composition of the household). The Operator is the controller of that information; the information under article 14 GDPR is given in the profile form, in this Policy and on the page https://real-bro.com/en/legal/third-parties. A user who enters such details represents that they are entitled to disclose them. The information is processed to the extent of the user's visibility settings.

2.5. This Policy does not cover third-party websites and services reached by following links.

3. Data processed and its sources

3.1. Account data provided by the user: email address, an irreversible hash of the password or the identifier of a Google account, role, language, interface and notification settings.

3.2. Profile and tenant profile data entered by the user: name or pseudonym, photographs, descriptions, composition of the household, pets, employment, budget, preferences and housing requirements, links to social networks, tags and markers.

3.3. Content created by the user: listings and property cards, descriptions, messages in chats and discussions, reactions, reviews, notes, proposals and votes in shared-rental groups, complaints and enquiries.

3.4. Technical data: IP address, browser and device type and version, operating system, language, session identifiers and refresh tokens, the time and outcome of requests, push subscription identifiers.

3.5. Usage data: property, professional and tenant profile cards viewed, search queries, filters and tabs, markers and favourites, records of the display of owners' contact details, AI matching tasks and their results, minutes of calls consumed.

3.6. Payment data: the fact, amount, currency, time and status of the payment, the identifiers of the payment and of the payer in the Stripe system, the type and last four digits of the card, the country and billing address, the outcome of payer authentication. Full card numbers and their authentication data are processed by Stripe and are not transmitted to or stored by the Operator.

3.7. Wallet and referral programme data: the balance and movement of silver and gold coins, referral codes and links, click-throughs, the attribution of invitees, accruals and withholdings of remuneration, indicators of abuse (matches of devices, addresses and means of payment). The identity data of a payee is collected and verified by Stripe within Stripe Connect; the Operator receives only the verification status and the outcome of the payout.

3.8. AI call data: the telephone number given for the call; the number of the Service line; the date, time, duration and status of the connection; the language of the conversation; the text transcript and the short summary of the call; technical connection quality metrics. The composition and retention periods are in section 13.

3.9. Data obtained otherwise than from the user: from Google — the email address and account identifier on sign-in through Google; from Stripe — the status of a payment or payout; from Telegram — the account identifier when it is linked; from a user of the Service — a telephone number and details of a listing where a call is addressed to a third party (section 10); from external sources — information about properties and their authors (point 3.11).

3.10. Special categories of data (article 9(1) GDPR) are not requested or deliberately processed. Such information should not be stated in free-text fields; if it is, it becomes part of the user's content and is processed only to the extent necessary to display that content in accordance with the user's settings. The voice of a called party is processed as ordinary personal data: no voiceprints are created and no identification by voice is carried out (point 13.5).

3.11. Data from external sources. Some property cards are obtained by the Service's AI agent, at the request of a user looking for housing, from listings publicly available on the internet — on classified advertising sites and agency websites: information about the property (address or district, price, characteristics, photographs) and about the person who posted the listing — their name and, where published in the listing, their telephone number and email address. The purposes, legal basis, information of those persons and retention periods are in point 4.8.

3.12. Providing the data in points 3.1 and 3.6 is a requirement for concluding and performing the contract: without an email address the account cannot be created, and without payment data no paid service can be bought. All other data is provided at the user's choice; not providing it limits only the corresponding feature.

4. Purposes, legal bases and retention periods: the account and the operation of the Service

4.1. Creating and maintaining the account, signing in, password recovery, confirming the email address. Data: point 3.1, session identifiers and tokens, the technical data in point 3.4. Basis: article 6(1)(b) GDPR — performance of the contract (the Terms of Use). Period: for as long as the account exists, thereafter point 19.6; tokens and sessions until they expire. Recipients: the hosting provider and the email delivery provider as processors; Google on sign-in through Google.

4.2. Providing the Service's features and accounting for the allowances of the plan: search, property and professional cards, tabs and filters, markers and favourites, matching tasks, the allowances of free and paid access. Data: points 3.2, 3.3, 3.5. Basis: article 6(1)(b) GDPR. Period: for as long as the account exists. Recipients: the hosting provider, the file storage provider and the mapping data provider as processors.

4.3. Displaying the contact details of property owners and counting the displays. Data: user identifier, property, time of display; the contact details of the person who posted the listing. Basis: as regards the user, article 6(1)(b) GDPR; as regards the person who posted the listing, article 6(1)(f) GDPR — the legitimate interest in connecting an interested tenant with the person who has published the offer and stated a contact in it; the right to object is given effect under point 4.8. Period: records of displays for 6 years (point 19.4). Recipients: the user to whom the contact was displayed; Stripe and the issuing bank where a particular payment is disputed.

4.4. Discussions, private and group chats, shared-rental groups. Data: the content of messages, participants, time, reactions, read receipts, proposals and votes. Basis: article 6(1)(b) GDPR. Period: for as long as the correspondence exists or until a participant deletes it; a message deleted in a group discussion remains with the other participants as a deletion marker. Recipients: the other participants; the hosting provider as a processor.

4.5. Publication of a tenant profile, listings and property cards. Data: points 3.2 and 3.3. Basis: display to other registered users to the extent of the user's settings — article 6(1)(b) GDPR; availability to unregistered visitors and indexing by search engines — article 6(1)(a) GDPR, consent given by a separate setting which is off by default and may be withdrawn at any time. Withdrawal stops publication for the future; pages saved in search engine caches disappear as the caches are refreshed. Period: until publication is withdrawn or the account is deleted. Recipients: other users and visitors to the extent of the settings; search engines where consent is on.

4.6. Notifications of events in the Service: messages, replies, changes in matching tasks, call results. Data: email address, push subscription identifier, Telegram identifier where linked, the content of the notification. Basis: article 6(1)(b) GDPR; push notifications additionally require the permission given to the browser or device, which may be withdrawn in the same place. Period: a device subscription until it is withdrawn or replaced. Recipients: the email delivery provider, the push service of the browser or operating system, Telegram where linked.

4.7. Support, enquiries and claims. Data: the content of the enquiry and of the correspondence, the time of submission and of the reply. Basis: article 6(1)(b) and (c) GDPR. The Operator replies no later than one month. Period: 6 years. Recipients: the email delivery provider as a processor.

4.8. Listings and property information obtained from external sources. Purpose: to enlarge the catalogue so that a user can find an offer and contact the person who published it. Data: point 3.11. Basis: article 6(1)(f) GDPR — the legitimate interest of the Operator and of users in access to publicly posted offers. Information under article 14 GDPR is provided in this Policy and on the page https://real-bro.com/en/legal/third-parties (article 14(5)(b) GDPR). Upon a request for removal or an objection (article 21(1) GDPR) sent to [email protected], the contact details are deleted and the card is unpublished; the rights of access, rectification, erasure and restriction are exercised under section 20. Period: the card is unpublished when the listing has ceased to be current; thereafter the data is retained only for handling requests and disputes. Recipients: users of the Service within the contact display feature (point 4.3).

5. Purposes, legal bases and retention periods: payment, coins and the referral programme

5.1. Accepting and processing payments, opening paid access, refunds. Data: point 3.6, the composition of the order, the user identifier. Basis: article 6(1)(b) GDPR. Period: 10 years for accounting purposes (point 5.2) and 6 years for evidential purposes (point 19.4). Recipients: Stripe as an independent controller (point 17.3).

5.2. Compliance with accounting and tax obligations. Data: payments and refunds, amounts, dates, counterparty. Basis: article 6(1)(c) GDPR in conjunction with article L123-22 of the French Commercial Code. Period: 10 years. Recipients: the accountant and the tax authorities. A request for erasure of this data cannot be granted (article 17(3)(b) GDPR).

5.3. Maintaining the wallet: the accrual, holding and debiting of silver and gold coins. Data: balances, transactions, the grounds of accruals, the link with the underlying payments. Basis: article 6(1)(b) GDPR. Period: for as long as the account exists; transactions for 6 years as evidence of the settlements. Recipients: the hosting provider as a processor.

5.4. The referral programme: issuing links, recording click-throughs, attributing invitees, calculating and accruing remuneration, holding it until the period for disputing the underlying payment has expired and reversing it where that payment is refunded. Data: codes and links, the time and source of the click-through, the referral attribution identifier stored on the invitee's device (point 21.8), the technical data in point 3.4, attributions, the amounts accrued. Basis: article 6(1)(b) GDPR — performance of the partner programme offer; in respect of the invitee, article 6(1)(f) GDPR — the legitimate interest of the Operator and of the inviting participant in attributing the registration to the link followed. Period: 6 years from the transaction. Recipients: participants in the programme see only the number of invitees and the amounts accrued in their own branch, not the invitees' personal data.

5.5. Payout of remuneration in money. Data: amounts, the status of the payout, the identifier of the connected account. Basis: article 6(1)(b) GDPR; the verification of the payee's identity and anti-money-laundering checks are carried out by Stripe on the basis of article 6(1)(c) GDPR and Directive (EU) 2015/849. Identity data is provided directly to Stripe and is not received or stored by the Operator. Period: 10 years for accounting purposes. Recipients: Stripe.

5.6. Protecting the referral programme and the Service against abuse: detecting multiple accounts of one person, self-referral, automated registration and other schemes for obtaining remuneration without a real introduction. Data: technical indicators derived from the request data (IP address and browser string in hashed form, language and request parameters) and from the payment data (the type and last digits of the card, the billing country) — matches of device, network and means of payment between accounts. No separate tracking identifier is written to the device for this purpose. Basis: article 6(1)(f) GDPR — the legitimate interest in not paying remuneration for introductions that did not take place. Period: click-through records — 90 days; device and payment matches — 13 months; risk assessments — 6 months; where a breach has been established, the records relating to it — 6 years. Recipients: none. Decisions on the outcome of such a check are not taken solely by automated means (point 16.2).

6. Purposes, legal bases and retention periods: evidence of the conclusion and performance of the contract

6.1. Purpose: to prove that the pre-contractual information was provided, what the user confirmed at the moment of purchase and that the service was supplied. The burden of proof on these points lies with the Operator.

6.2. Data: the version and hash of the edition of the contract documents in force at the moment of payment and the Operator's details inserted into it; the wording of the declaration under section 9 of the Payment and Refund Terms; the date and time of confirmation and the time zone; a hash of the IP address from which the declaration was made (the address itself is not stored); the language; the price and the period of access as shown before the contract was concluded; the payment identifier; records of the use of the paid access and of the consumption of minutes; the status of delivery of the purchase confirmation.

6.3. Basis: article 6(1)(c) GDPR — the Operator's legal obligation to prove compliance with its information duties and the supply of the service; article 6(1)(f) GDPR — the legitimate interest in defending its rights in a dispute, including a payment dispute. The user may object under article 21(1) GDPR.

6.4. Period: 6 years from the date of payment.

6.5. Recipients: Stripe and the issuing bank where a particular payment is disputed, to the extent relating to that payment; a court, the Operator's legal advisers, and supervisory and consumer authorities in the handling of a particular dispute.

7. Purposes, legal bases and retention periods: security, moderation and mandatory notifications

7.1. Security of the Service: request logs, detection of password guessing, automated requests and malicious activity, investigation of incidents. Data: the technical data in point 3.4, the time and outcome of requests. Basis: article 6(1)(f) GDPR — the legitimate interest in the operation and security of the Service. Period: for the time necessary for security and the investigation of incidents. Recipients: the hosting provider as a processor.

7.2. Moderation of content and handling of notices concerning listings, profiles, tenant profiles and messages. Data: the content concerned, the notice and the notifying party, the decision and its reasons. Basis: article 6(1)(c) GDPR in conjunction with articles 16 and 17 of Regulation (EU) 2022/2065, and article 6(1)(f) GDPR. Period: for as long as the content or the account concerned exists. Recipients: the notifying party and the person whose content is affected, each as regards their own part.

7.3. Notifying law enforcement or judicial authorities where there is information giving rise to a suspicion of a criminal offence involving a threat to the life or safety of a person. Basis: article 6(1)(c) GDPR in conjunction with article 18 of Regulation (EU) 2022/2065. Recipients: the competent authorities of the Member State concerned or, where it cannot be identified, the French authorities or Europol.

7.4. Complying with requests from public authorities and courts. Basis: article 6(1)(c) GDPR. The Operator complies to the extent required and informs the user unless prohibited by law or by the request itself.

8. Purposes, legal bases and retention periods: artificial intelligence features

8.1. AI matching tasks, AI filters, the assistant in discussions. Data: the matching criteria, the user's messages and questions, information about properties and the course of the conversation, the user's markers on properties delivered. Basis: article 6(1)(b) GDPR. Period: for as long as the task or discussion exists, no longer than the account. Recipients: the providers of language models as processors (point 17.2).

8.2. Translation of text in the Service. Data: the text translated. Basis: article 6(1)(b) GDPR. Period: the translation is performed at the moment of the request; the source text is stored where it was created. Recipients: the providers of machine translation as processors.

8.3. Technical statistics on the AI features: response time, computing units consumed, error rate, cost of processing; no content of messages other than their volume. Basis: article 6(1)(f) GDPR. Period: for the time necessary to monitor quality and costs.

8.4. The Operator does not train its own models on the user's content or conversations. The providers of language models and of speech recognition and synthesis act as processors on the Operator's instructions and do not use the content for their own purposes.

9. Purposes, legal bases and retention periods: emails, push and Telegram

9.1. Service emails: confirmation of an address, password recovery, purchase confirmations, replies to enquiries, notices of changes to the documents. Basis: article 6(1)(b) and (c) GDPR. Service emails cannot be opted out of for as long as the account exists. Period: records of sending — for as long as the account exists; emails relating to the contract — 6 years (point 19.4). Recipients: the email delivery provider as a processor.

9.2. Push notifications and Telegram notifications — at the user's choice and to the extent of their settings. Basis: article 6(1)(b) GDPR; delivery requires the permission given to the browser, the device or Telegram, and may be switched off in the settings of the Service, the browser, the device or Telegram. Recipients: the push service of the browser or operating system; Telegram where linked.

9.3. The Operator does not send marketing mailings. Users' addresses and telephone numbers are not disclosed to advertisers.

9.4. Contact details obtained in AI calls are not used for mailings, invitations to register or offers of the Service's services.

10. AI calls: the feature and the parties

10.1. On the user's instruction the Service connects over a telephone line to a number specified by the user, and the conversation is conducted by a software agent based on artificial intelligence. The agent introduces itself, asks the questions about the property formulated by the user and returns to the user a short structured answer. No employee of the Operator takes part in the conversation.

10.2. The user initiates the call: chooses the number, formulates the task and starts the call. The Operator establishes the connection and conducts the conversation using its own means.

10.3. The Operator is the controller of the called party's data: it determines the purposes and means of the processing — how the agent is built, what it asks, what is retained and for how long (article 4(7) GDPR).

10.4. The called party is the person to whom the call is addressed — the owner of the property, an agency representative or another person whose number appears in the listing. That person is not a user of the Service, concludes no contract with the Operator and has the rights listed in section 14.

10.5. The telephone connection is provided by the telephony provider, the transmission of audio by the media server provider, and speech recognition, speech synthesis and the formulation of the agent's utterances by the providers listed in point 17.2, all acting as processors on the Operator's instructions.

10.6. Data about the called party: the telephone number; details of the listing; the date, time, duration and status of the connection; the language of the conversation; the called party's speech during the conversation and the information given in it about the property (price, availability, viewing arrangements, requirements as to the tenant).

11. AI calls: the legal basis for processing the called party's data

11.1. Basis: article 6(1)(f) GDPR — the legitimate interest in connecting an interested tenant with a person who has publicly posted an offer to let and stated a telephone number for contact in it. A person who has publicly posted a listing with a telephone number can reasonably expect calls about that listing.

11.2. Measures accompanying the processing: the notice at the beginning of the conversation and the disclosure of the artificial nature of the caller (section 12), no audio recording, the retention periods in section 13 and the right to object under section 14.

11.3. The called party's number is used only to make a call about the particular listing within the task set by the user. It is not used to call about other properties, is not included in databases for subsequent calling and is not passed to other users beyond the display of contacts from the listing itself.

11.4. The AI agent does not offer the called party registration in the Service, the purchase of a plan or other services, and does not advertise the Service.

12. AI calls: the notice at the beginning of the conversation and the disclosure of artificial intelligence

12.1. The disclosure that the caller is an artificial intelligence system is the first sentence of every call. The notice about the processing is given after the called party's first reply and before the questions formulated by the user.

12.2. The notice tells the called party:

  • who is calling — the name of the Service;
  • that the conversation is being conducted by artificial intelligence;
  • on whose initiative and about which listing the call is being made, and its purpose — to clarify information about the property;
  • that the conversation is processed automatically, that a text transcript and a short summary are retained and that no audio recording is retained;
  • where to obtain the full information about the processing — the page https://real-bro.com/en/legal/calls;
  • that the called party may end the conversation and ask not to be called again (point 14.1).

12.3. The disclosure of artificial intelligence is given under article 50(1) of Regulation (EU) 2024/1689. The agent does not pass itself off as a human being and, if asked directly, confirms that it is an artificial intelligence system.

12.4. The transcript retained for each call (section 13) includes the notice given.

13. AI calls: what is retained and for how long

13.1. No audio recording of the conversation is retained. The audio is processed by the speech recognition and speech synthesis providers during the conversation; the Operator does not create or store an audio file.

13.2. Retained: the called party's number; details of the listing; the date, time, duration and status of the connection; the number of the Service line; the language of the conversation and any change of language; the text transcript; the short structured summary — the answers to the questions asked; technical connection quality metrics; the identifier of the user who initiated the call.

13.3. Retention periods: the text transcript and the short summary — for as long as the call task exists in the user's AI space; connection data, including the called party's number — for as long as the account of the user who ordered the call exists; data on minutes consumed, needed for settlements with the user — 6 years, without the transcript and without the number. Where a claim, complaint or dispute is raised in relation to a call, the data relating to it is retained until the dispute is resolved (article 17(3)(e) GDPR).

13.4. The transcript and summary are available to the user who initiated the call and to the Operator's staff to the extent necessary for support and for handling complaints. They are not available to other users and are not published.

13.5. The Operator does not create voiceprints, does not identify persons by voice, does not analyse emotions from the voice, does not train models on conversations and does not disclose the content of conversations to third parties save in the cases in section 17.

14. AI calls: the called party's rights

14.1. Right to object (article 21(1) GDPR). The called party may object to the processing at any time, including orally during the conversation, without giving a reason. Upon an objection the number is not called again by the Service.

14.2. Other rights: access and a copy of the data (article 15 GDPR), rectification (article 16), erasure (article 17), restriction of processing (article 18) and portability in so far as applicable (article 20). The called party may request a copy of the transcript of the conversation in which they took part; the copy is provided having regard to the rights of others (article 15(4) GDPR).

14.3. Requests are sent by email to [email protected], stating the telephone number on which the call was received and the approximate date of the call. Additional identification is requested only where there are reasonable doubts as to the identity of the person making the request (article 12(6) GDPR).

14.4. The reply is given within one month from receipt of the request, extendable by two further months where the request is complex, with notice of the extension within the first month (article 12(3) GDPR). The reply is free of charge.

14.5. The called party may lodge a complaint with the supervisory authority of their place of residence (point 1.5) or with the CNIL as the Operator's lead authority, and may bring proceedings before a court (articles 77 and 79 GDPR).

14.6. The information for called parties is also set out on the page https://real-bro.com/en/legal/calls; the notice in the call states the address of that page.

15. Obligations of the user who orders a call

15.1. By ordering a call the user represents that the number was obtained lawfully — from a listing posted by the owner of the property or a person authorised by them — and that the call relates to that listing.

15.2. AI calls may not be used for advertising, offering goods and services, debt collection, pranks, checking other people's numbers, harassment, calling persons who have asked not to be called or calling numbers unconnected with a listing. A breach is a ground for terminating access to the feature.

15.3. The user's representations matter as between the user and the Operator: they entitle the Operator to stop supplying the service and to claim compensation for the loss caused. They do not release the Operator from its own responsibility as controller towards the called party and the supervisory authority.

15.4. The Operator records which user ordered each call, in order to handle complaints from called parties and to enforce point 15.2. Basis: article 6(1)(f) GDPR. Period: as for connection data (point 13.3) and, where there is a complaint, until it is resolved.

16. Transparency of artificial intelligence and automated decisions

16.1. Artificial intelligence is used in property matching tasks, filters and search, the discussions assistant, translation and AI calls. Interaction with artificial intelligence is indicated in the interface; in AI calls it is stated aloud (point 12.1).

16.2. The Operator takes no decisions based solely on automated processing which produce legal effects concerning the user or similarly significantly affect them (article 22(1) GDPR). Content may be restricted automatically on the basis of reports and a referral accrual may be rejected by an automated check; the decision is reviewed after moderation at the request of the person concerned.

16.3. No advertising and no profiling for advertising purposes are carried out in the Service: there are no advertising networks, trackers or advertising profiles (section 21).

16.4. Language models and speech recognition and synthesis are supplied by third-party providers acting as processors. The content transmitted to them is not used to train their models (point 8.4).

17. Recipients of data

17.1. Data is disclosed only to those who need it for the purposes described in this Policy and only to the extent necessary. Data is not sold, rented out or disclosed to advertisers.

17.2. Processors (article 28 GDPR), acting on the Operator's documented instructions under a contract meeting article 28(3) GDPR:

  • the telephony provider (the telephone connection, the number, the time and duration of the call; in so far as required by telecommunications legislation, it acts under its own obligations);
  • the media server provider (real-time transmission of audio);
  • the speech recognition provider;
  • the speech synthesis provider;
  • the providers of language models, including through a request-routing gateway;
  • the providers of machine translation;
  • the object storage provider (photographs and other files);
  • the email delivery provider;
  • the mapping data provider (maps, geocoding, routes);
  • the provider of information about places near a property (the coordinates of the property are transmitted, not the user's data);
  • OVH SAS, 2 rue Kellermann, 59100 Roubaix, France — hosting of the servers and databases.

17.3. Independent controllers, processing data for their own purposes under their own policies:

  • Stripe — accepting payments, paying out remuneration, anti-money-laundering requirements, fraud prevention and verification of payees; as regards the Operator's payment infrastructure, Stripe also acts as a processor;
  • Google — on sign-in through a Google account;
  • Telegram — where the user uses the Service's bot or mini-application;
  • the push services of browsers and operating systems — in delivering push notifications.

17.4. Other users of the Service — to the extent of the user's visibility settings and the nature of the feature: participants in a correspondence see its messages, members of a group see proposals and votes, and users with the corresponding access see published tenant profiles and listings and the contacts disclosed.

17.5. The Operator's professional advisers — lawyers, accountants, auditors — to the extent necessary for the particular matter and under a duty of confidentiality.

17.6. Public authorities, courts and law enforcement bodies — pursuant to binding requests (points 7.3 and 7.4).

17.7. A successor to the Operator — on a transfer of the business in whole or in part, with prior notice to users.

17.8. A list naming the processors, the countries in which they are located and the transfer mechanisms applied is provided on request to [email protected].

18. Transfers of data outside the EEA

18.1. Some of the processors in point 17.2 are located outside the European Economic Area, principally in the United States of America: the providers of speech recognition and synthesis, of language models, of email delivery, of object storage and of mapping data.

18.2. Transfer mechanisms: a European Commission adequacy decision for recipients certified under the EU-US Data Privacy Framework (article 45 GDPR), or the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914 (article 46(2)(c) GDPR) with supplementary measures where required.

18.3. The mechanism applied to each processor is stated in the list provided under point 17.8.

18.4. A copy of the safeguards applied, or information as to where they may be consulted, is provided on request (articles 15(2) and 46(1) GDPR).

19. Retention periods: summary

19.1. Account and profile — for as long as the account exists; after its deletion, point 19.6.

19.2. Content and messages — until the user deletes them or the account is deleted; in group discussions a deletion marker remains in place of a deleted message.

19.3. Payments and accounting — 10 years (article L123-22 of the French Commercial Code).

19.4. Evidence of the conclusion and performance of contracts, of consents and of enquiries — 6 years from the date of payment (point 6.4).

19.5. Technical and security logs — point 7.1; views and markers — point 4.2; AI call data — section 13; information from external sources — point 4.8.

19.6. After an account is deleted, the data is deleted or anonymised within 30 days, apart from what the Operator is obliged or entitled to retain: accounting and payment data, evidence of the conclusion and performance of contracts, and data necessary for the establishment, exercise or defence of legal claims in a dispute that has been raised (article 17(3)(b) and (e) GDPR). Such data is retained until the corresponding period expires and is not used for any other purpose.

19.7. Deleted data is removed from backups as they are rotated; until then backups are used only to restore the working of the Service.

19.8. Where several periods apply to particular data, the longer applies; on its expiry the data is deleted or anonymised.

20. Rights of data subjects and how to exercise them

20.1. Rights: access and a copy of the data (article 15 GDPR); rectification (article 16); erasure (article 17); restriction of processing (article 18); portability of data processed by automated means on the basis of a contract or consent (article 20); objection to processing based on legitimate interest (article 21); withdrawal of consent where the processing is based on it (article 7(3)); not to be subject to a decision based solely on automated processing (article 22).

20.2. Requests are sent by email to [email protected] or by post to 36 rue Victor Hugo, 76530 Grand-Couronne, France. No particular form is required.

20.3. The reply is given within one month from receipt of the request; where the request is complex or requests are numerous, the period may be extended by two further months, with notice of the extension and its reasons within the first month (article 12(3) GDPR).

20.4. Exercising these rights is free of charge. A reasonable fee or a refusal is possible only where a request is manifestly unfounded or excessive (article 12(5) GDPR).

20.5. Additional information to confirm identity is requested only where there are reasonable doubts as to the identity of the person making the request (article 12(6) GDPR).

20.6. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Processing based on a contract or on a legal obligation is not affected by the withdrawal of consent.

20.7. Where a request is refused in whole or in part, the Operator states the reason and the legal basis and informs the person of the right to lodge a complaint and to a judicial remedy. Erasure of accounting and payment data before the period in point 19.3 expires is refused on the basis of article 17(3)(b) GDPR.

20.8. A complaint may be lodged with a supervisory authority (article 77 GDPR) — the CNIL or the authority of the country of residence (point 1.5). The right to a judicial remedy (article 79 GDPR) and to compensation (article 82 GDPR) exists irrespective of any complaint or approach to the Operator.

20.9. The user may give directions as to the fate of their data after their death (article 85 of French Law No 78-17); such directions are sent to [email protected].

21. Cookies and technologies on the device

21.1. Storing information on the user's device and gaining access to it require prior consent, except where strictly necessary to provide the service requested or to transmit a communication (article 5(3) of Directive 2002/58/EC and the national rules transposing it, including article 82 of French Law No 78-17, article 22.2 of Spanish Law 34/2002, article 122 of Italian Legislative Decree No 196/2003, article 5 of Portuguese Law No 41/2004 and § 25 TDDDG).

21.2. Used without consent, as strictly necessary: two authentication cookies (the access token and the refresh token), HttpOnly, which expire with the session or the token, and the referral attribution cookies described in point 21.8. No language cookie is set: the interface language is part of the page address.

21.3. The browser's local storage is used for interface settings: collapsed and expanded panels, input drafts, dismissed hints, recent actions. That information stays on the device and is not used for tracking; it is deleted together with the site data by means of the browser.

21.4. There are no advertising or marketing cookies, traffic counters, advertising pixels or third-party trackers in the Service, and no profiles for advertising are created.

21.5. When the Service is used, the browser contacts third-party resources: the mapping data provider for map tiles, Google on sign-in through Google, the browser's push service on subscription to notifications, and Stripe on payment. Those recipients receive the IP address and the technical data of the request and act under their own policies.

21.6. If cookies or other technologies requiring consent are introduced, consent will be sought before they are used, with the possibility of refusal and of withdrawal, and access to the Service will not be made conditional on it.

21.7. Cookies may be deleted and blocked by means of the browser. Deleting or blocking the authentication cookies makes it impossible to sign in.

21.8. Referral attribution. When the user comes to the Service through a referral link, the Service's API sets two HttpOnly cookies: a visitor identifier (rb_vid), used to count the click-through and link it to a later registration, and the referral code (rb_ref) of the person who invited the user. They are necessary for the referral programme to attribute the registration to the link followed and to accrue the inviting participant's remuneration; they are not used for advertising, profiling or tracking. Both cookies live 30 days; the first code stored is retained, and a later click on another link does not replace it (point 5.4 of the partner programme offer). They may be deleted by means of the browser; without them no attribution is created, which has no bearing on access to the Service.

22. Data security and notification of breaches

22.1. Measures (article 32 GDPR): transmission of data over a secure channel, storage of passwords only as irreversible hashes, segregation of access rights, access logging, limitation of retention periods, backups, updating of components, and contractual security obligations of processors.

22.2. Full card numbers and their authentication data are not transmitted to the Operator: payment details are entered on Stripe's side.

22.3. In the event of a personal data breach the Operator notifies the CNIL without undue delay and, where feasible, within 72 hours after becoming aware of it (article 33 GDPR), and keeps a register of breaches.

22.4. Where a breach is likely to result in a high risk to the rights and freedoms of the persons concerned, the Operator notifies them without undue delay, describing the nature of the breach, its likely consequences, the measures taken and a contact point (article 34 GDPR).

22.5. Users should not disclose their password or confirmation codes and should report signs of unauthorised access to [email protected].

23. Age of users

23.1. The Service is intended for persons aged 18 and over.

23.2. The Operator does not address the Service to children and does not knowingly process their data. An account found to have been created by a person under 18 is blocked and its data deleted, apart from what the Operator is required by law to retain.

23.3. Reports that a child's data is being processed in the Service are sent to [email protected].

24. Changes to this Policy

24.1. Each edition of this Policy has a version number, an effective date and a hash of the text; the Operator's details inserted into the text are recorded separately. The edition in force is published in the Service; the edition in force on a particular date is provided on request free of charge on a durable medium.

24.2. Notice of changes affecting the rights of users — a new purpose of processing, a change of legal basis, a new category of recipients, a longer retention period or a change in the rules of AI calls — is given by email before they take effect.

24.3. A change to this Policy does not make lawful any processing for which there was no basis at the time it was carried out. Where a new purpose requires consent, it is sought separately before the processing begins; continued use of the Service does not amount to consent.

24.4. Corrections of typographical errors, clarifications which do not change the substance and changes brought about by a change in the law take effect on publication of the new edition.

25. Operator's details

Operator: Serhii Poliakov EI, entrepreneur individuel (EI) under French law, micro-enterprise regime

SIRET: 10527513500017

VAT identification number: not applicable — article 293 B of the French General Tax Code (CGI)

Address: 36 rue Victor Hugo, 76530 Grand-Couronne, France

Telephone: +33 939 24 93 33

Email for enquiries, including on personal data matters: [email protected]

Page for called parties in AI calls: https://real-bro.com/en/legal/calls

Page for third parties whose data reached the Service otherwise than from themselves: https://real-bro.com/en/legal/third-parties

Lead supervisory authority: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, www.cnil.fr

Spanish supervisory authority: AEPD, C/ Jorge Juan, 6, 28001 Madrid, Spain, www.aepd.es

Italian supervisory authority: Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Roma, Italy, www.garanteprivacy.it

Portuguese supervisory authority: CNPD, Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal, www.cnpd.pt

Service: real-bro.com

Document version: 3.0. Effective date: 14 September 2026.