Privacy Policy
This policy explains how TKOCY LTD (“we”, “us”), registered in Cyprus under number HE399700, with its registered office at Kiriakou Matsi 9, 4712 Limassol, Cyprus, handles personal data in connection with the website estatecrm.cy and the Estate CRM service at app.estatecrm.cy. We apply the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018 on the protection of natural persons with regard to the processing of personal data.
1. Our two roles
- We are the controller for the personal data of visitors to this website, of people who contact us, and of the users of our customers’ accounts (for their account, security and billing). Sections 3 to 5 cover this.
- We are a processor for the data that estate agencies keep in Estate CRM about their own clients, property owners, leads and staff. Each agency is the controller of that data and decides why and how it is used; we process it only on its instructions under our Data Processing Agreement. If you are a client of an agency that uses Estate CRM, please read that agency’s privacy notice and contact the agency to exercise your rights. Section 6 covers this.
2. How to contact us
For any privacy question or request, write to info@estatecrm.cy, or by post to the address above. [If a Data Protection Officer is appointed, add their contact details here.]
3. Website visitors
- This website sets no cookies, uses no analytics and loads no third-party trackers, fonts or scripts.
- When you visit, our server and our network provider Cloudflare process technical data — your IP address, the page requested, date and time, browser type — to deliver the page and protect the site from abuse. Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR). Server logs are kept for [14] days.
- If you e-mail us (for example to book a demo), we use your name, e-mail address, company and what you write to answer you and arrange the demo. Legal basis: steps at your request before a contract (Art. 6(1)(b)) and our legitimate interest in answering business enquiries (Art. 6(1)(f)). We keep this correspondence for up to [24] months after our last contact, unless it leads to a contract.
4. Users of customer accounts
| Data | Purpose | Legal basis |
|---|---|---|
| Name, work e-mail, phone (optional), role, language, agency | Creating and running the account; sending sign-in, invitation, reminder and service e-mails | Contract with the agency (Art. 6(1)(b)); for users other than the contracting person, our and the agency’s legitimate interest in providing the service they use for work (Art. 6(1)(f)) |
| Password (stored only as a one-way hash), two-step sign-in secret and recovery codes (stored encrypted or hashed), session cookie, sign-in times | Secure sign-in and preventing unauthorised access | Legitimate interest in security (Art. 6(1)(f)); security of processing (Art. 32) |
| Record of changes made (who changed which listing, contact or requirement, and when) | An audit trail for the agency; investigating problems and misuse | Legitimate interest (Art. 6(1)(f)) |
| Optional connections: Google Calendar, Telegram | Syncing the user’s appointments; sending alerts — only if the user connects them | Contract / the user’s request (Art. 6(1)(b)); the user can disconnect at any time |
| Billing contact and billing details of the agency; invoices | Charging subscriptions, accounting and tax records | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Technical error reports (with the user’s internal id only) | Finding and fixing errors | Legitimate interest (Art. 6(1)(f)) |
| Messages to our support | Answering and improving support | Contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)) |
Card details are entered directly with Stripe; we never see or store full card numbers. We do not sell personal data and do not use it for advertising. We do not make decisions with legal or similarly significant effects by automated means.
5. Retention
- Account data: while the account is active, and for 30 days after the agency’s subscription ends; then it is deleted, and removed from backups as they expire (within 60 days).
- A user removed from an agency: their sign-in is deactivated; their name stays on records they created so the agency’s history remains accurate, until the agency’s data is deleted.
- Invoices and accounting records: as long as Cyprus tax and company law requires (currently [six] years).
- Error reports: up to 90 days [confirm the Sentry retention setting].
6. Data we process for agencies (as processor)
- Agencies use Estate CRM to keep data about their clients (buyers, sellers, tenants, landlords), property owners, leads and staff: contact details, what they are looking for, viewings and communications, deals, and — where the agency enters them — identity-document numbers and signatures on viewing forms.
- People who send an enquiry through an agency’s share page or website, or sign a viewing form, give their data to that agency. The agency is the controller; Estate CRM stores the data for it, including the IP address and time of a signature as evidence.
- We use this data only to provide the service to the agency, under its instructions and the DPA. Requests from its clients should go to the agency; if they reach us, we pass them on.
7. Who receives data
We use carefully chosen service providers (sub-processors) for hosting, storage, e-mail, payments and optional features. The full list, with what each does and where, is on our sub-processors page. We may also disclose data where the law requires it, or to protect our rights.
8. Transfers outside the EEA
The service is hosted in the EU. Where a provider processes data outside the European Economic Area, we rely on an adequacy decision (including the EU-US Data Privacy Framework for certified US companies) or on the European Commission’s Standard Contractual Clauses, with additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
9. Security
We protect data with measures including encrypted connections (TLS), separation of each agency’s data at database level (row-level security), encryption of stored secrets, two-step sign-in, role-based access, logging of changes, and regular backups. The DPA (Annex 2) lists them.
10. Your rights
Under the GDPR you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing (including to processing based on legitimate interests), to data portability, and to withdraw consent where processing is based on consent. To use these rights, contact us at info@estatecrm.cy. We will answer within one month. If your data is held by an agency that uses Estate CRM, please contact that agency.
11. Complaints
You may complain to the Cyprus supervisory authority, the Commissioner for Personal Data Protection (Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), www.dataprotection.gov.cy, or to the authority in the EU country where you live or work. We would appreciate the chance to address your concern first.
12. Cookies
This website uses no cookies. The Estate CRM app uses only strictly necessary cookies for signing in and protecting forms. See the cookie notice.
13. Changes
We may update this policy. The effective date at the top shows the current version; we will tell account owners about material changes by e-mail or in the app.