Valevia — Privacy Policy
Last updated: 4 July 2026
1. Who We Are
Valevia is operated by Valevia Consulting UG (haftungsbeschränkt), Am Mühlenberg 12, 54457 Wincheringen, Germany.
For the personal data described in this policy, we are the controller. You can reach us at contact@valevia.eu.
Valevia is an operational intelligence platform that helps real estate agencies automate administrative work — email triage, listing creation and visual marketing.
2. Scope and Our Role
This policy explains how we handle personal data when you visit valevia.eu, use our platform, or interact with us (for example, by submitting a contact form or receiving our business communications).
Two different roles. Much of what our platform does is process data on behalf of our agency clients ("Clients") — for example the contents of an agency's emails, its property data, and its prospects' details. For that data the Client is the controller and we act only as a processor under a Data Processing Agreement (DPA); this policy does not govern it. If you are a buyer, seller, tenant or other person whose data an agency handles through Valevia, please contact that agency directly to exercise your rights.
This policy covers the data for which we are the controller: our website visitors, the agency staff who hold platform accounts, and our own business contacts and prospects.
3. Data We Collect
Website visitors
| Data | Purpose | Legal basis |
|---|---|---|
| Language preference (stored locally in your browser) | Show the site in your language | Legitimate interest |
| Contact-form details (name, work email, company, message) | Respond to and follow up on your enquiry | Pre-contract steps / legitimate interest |
| Consent-gated product analytics (see §8) | Understand and improve how the site and product are used | Consent |
Platform users (agency staff)
| Data | Purpose | Legal basis |
|---|---|---|
| Account & profile data: name, work email, hashed password, role, agency | Provide and secure the service | Performance of a contract |
| Usage & security data: login times, IP address, device/browser, and audit logs of key actions | Authentication, security, abuse prevention and record-keeping | Legitimate interest; legal obligation |
Prospective clients and business contacts
We carry out business-to-business outreach to real estate professionals.
| Data | Purpose | Legal basis |
|---|---|---|
| Business contact details and publicly available professional information (name, work email, company, role) | B2B marketing and qualification | Legitimate interest |
| Engagement with our emails and demo previews | Measure interest and follow up appropriately | Legitimate interest |
| Your publicly-published property listing (address, photos, description), used — only if you engage — to generate a personalized demo for illustration | Show a relevant demonstration of the product | Legitimate interest |
Where we rely on legitimate interests, we have weighed them against your rights and freedoms; you can object at any time (see §10), and you can unsubscribe from our emails using the link in any message.
People in public property records (market intelligence)
To give agencies market context, we reuse public open data published by the French state: the DGFiP register of recorded property sales (Demandes de valeurs foncières, DVF), the ADEME energy-certificate register, and the Base Adresse Nationale.
| Data | Purpose | Legal basis |
|---|---|---|
| Recorded property transactions from DVF (date, price, address, surface, type — no names) | Show agencies comparable sales and where a price sits against the recorded market | Legitimate interest |
| Aggregate, commune-level energy-certificate statistics from ADEME | An aggregate "renovate-or-sell" market indicator | Legitimate interest |
We use this data only as statistics or price positioning; we do not re-identify individuals, and we hold it as a refreshable copy of the public register. Because the source is a public government register, a request about a specific transaction is best directed to the publishing authority (DGFiP), and our copy refreshes from that source.
Aggregate buyer demand. We may also use aggregated, anonymised information about property inquiries — for example, how many buyers are looking for a given type of property, in a given area and budget range — to show agencies the overall level of buyer demand in a market. These figures are grouped across many inquiries, are suppressed for small groups, and never identify you or any individual. No agency ever sees another agency's inquiries or contacts — only the anonymous combined totals. Legal basis: our legitimate interest in providing market context, with anonymisation as the safeguard.
4. How We Use Data, and AI Processing
We use personal data to provide, secure and improve the service, to communicate with you, to process payments, and to meet our legal obligations.
Our platform uses Microsoft Azure OpenAI Service (hosted in the EU) to generate and classify text and to analyse images — for example, drafting property descriptions, classifying incoming email, and creating marketing visuals. Your content is not used to train AI models: Azure OpenAI processes it only to return a result to us, under Microsoft's data-processing terms and EU data-boundary commitments. Before sending email content for classification, we apply automated redaction of common personal identifiers (such as phone numbers and account numbers).
AI output on our platform is reviewed by a person before it is published or sent — we do not make decisions producing legal or similarly significant effects by automated means alone.
5. Who We Share Data With
We share personal data only with service providers ("sub-processors") that process it on our behalf under appropriate contractual and data-protection safeguards:
| Sub-processor | Purpose | Transfer safeguard |
|---|---|---|
| Microsoft Azure (incl. Azure OpenAI Service) | Cloud hosting, storage, databases and AI inference | EEA |
| Stripe | Subscription billing and payments | EEA (SCCs/DPF for any US processing) |
| Resend | Transactional and service emails | SCCs / DPF |
| Twilio | SMS and WhatsApp notifications to agency staff | SCCs / DPF |
| Zernio | Publishing content you approve to your connected social accounts | SCCs |
| PostHog | Consent-gated product analytics (EU-hosted) | EEA |
| Sentry | Error and performance monitoring (EU data region) | EEA (SCCs for any US support access) |
| HubSpot | Managing our sales and contact records (e.g. contact-form enquiries) | SCCs / DPF |
Optional features you enable may involve additional providers — for example publishing to Meta (Facebook/Instagram/WhatsApp) or LinkedIn, or a CRM integration. A current, complete list of our sub-processors is available on request and is provided to Clients under our DPA.
We do not sell personal data, and we do not share it with advertising networks or data brokers. We may disclose data where required by law or legal process, or to protect our rights, our users or the public.
6. International Transfers
We host and process personal data in the European Economic Area (EEA), primarily in Microsoft Azure's EU data centres. Where a provider processes data outside the EEA, we rely on the EU Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework.
7. How Long We Keep Data
We keep personal data only for as long as necessary for the purposes above, or as required by law:
- Account and platform data — for the term of the Client's subscription; archived content is automatically deleted 5 years after its last activity, then removed or anonymised.
- Security and audit logs — for up to 7 years, then deleted.
- Accounting and invoicing records — for the statutory retention period under German law (up to 10 years, §257 HGB / §147 AO).
- Data we process for Clients — for the period set out in our DPA.
- Public market data (DVF/ADEME) — held as a refreshable copy of the public register and replaced on each update (roughly twice a year); no personal data is accumulated beyond what the source already publishes.
8. Cookies and Similar Technologies
We use a small number of essential cookies to keep you signed in and to operate the service, and we store your language preference locally in your browser.
With your consent, we also use privacy-friendly product analytics (PostHog, hosted in the EU) to understand how the product is used. You can accept or decline analytics through our cookie banner and change your choice at any time. We do not use advertising or cross-site tracking cookies.
9. Security
We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls and multi-tenant isolation, network controls, audit logging, and regular review. No method of transmission or storage is completely secure, so while we work to protect your data we cannot guarantee absolute security.
10. Your Rights
Subject to the conditions in the GDPR, you have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and — where processing is based on consent — to withdraw consent at any time. Some of these are available directly in your account settings; otherwise email contact@valevia.eu and we will respond within the statutory time limit (generally one month).
You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (LfDI RLP), Hintere Bleiche 34, 55116 Mainz, Germany — datenschutz.rlp.de. You may also complain to the authority in your own country (e.g. CNPD in Luxembourg, APD/GBA in Belgium, CNIL in France, ICO in the UK).
11. Children
The service is intended for business use and is not directed at children under 16. We do not knowingly collect their data; if you believe we have, contact us and we will delete it.
12. Changes to This Policy
We may update this policy from time to time. We will post the updated version here and, where changes are material, take reasonable steps to notify you. The "Last updated" date above shows the latest revision.
13. Contact
Questions or requests: contact@valevia.eu, or Valevia Consulting UG (haftungsbeschränkt), Am Mühlenberg 12, 54457 Wincheringen, Germany.
14. Australia (Australian Privacy Principles)
This section applies to personal information of individuals in Australia that we handle when providing the service to an Australian agency customer. In that arrangement the agency is the entity primarily accountable under the Australian Privacy Principles (APPs); we act on its behalf under our Data Processing Agreement (Schedule D).
What we collect and why (APP 1 & APP 5). We collect the categories described in §3 (Data We Collect) for the purposes in §4 (How We Use Data, and AI Processing) — agency and user account data, property and owner/vendor data, and, for the Inbox product, email content. Sections 3 and 4 govern; we don't repeat them here.
Cross-border disclosure (APP 8). Your personal information is stored and processed in the European Union (Microsoft Azure, West Europe region) by the sub-processors listed in §5 and in our Sub-Processor Register. By using the service, an Australian customer discloses personal information to Valevia Consulting UG (a German company) as an overseas recipient. We handle it to EU GDPR standards and take reasonable steps to ensure our sub-processors do likewise. We do not currently store Australian data in Australia.
Access and correction (APP 12 & APP 13). You may request access to, or correction of, your personal information — or ask your agency to request it on your behalf — via the contact in §13. This is in addition to the rights in §10.
Notifiable Data Breaches. For an "eligible data breach" under Part IIIC of the Privacy Act 1988 (Cth), we will assess and, where required, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals, in line with our Breach Response Runbook (§4.6a).
Complaints. Contact us first (§13). If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au.