Privacy Policy
Privacy Policy
Last updated: April 13, 2026
1. Controller
The controller responsible for data processing on this website within the meaning of the General Data Protection Regulation (GDPR) is:
Acheros
Benjamin Schnabel
Lutherstr. 35
08468 Reichenbach (Vogt.)
Germany
Email: info@propybot.com
2. Data We Collect
2.1 Server log files
When you visit our website, our hosting provider automatically records data transmitted by your browser ("server log files"). This includes: browser type and version, operating system, referrer URL, host name of the accessing device, time of the server request, and IP address. This data is not merged with other data sources. The legal basis is our legitimate interest in the technical operation and security of the website (Art. 6(1)(f) GDPR).
2.2 User account data
If you create an account, we store your username, email address, and a hashed password. Property data, lists, notes, and attachments you create are stored in our database. Legal basis: contractual necessity (Art. 6(1)(b) GDPR).
If you subscribe to a paid plan, we additionally store: your subscription status, plan selection, billing address, company name and VAT ID (if provided), and a history of invoices. Legal basis: contractual necessity (Art. 6(1)(b) GDPR) and statutory record-keeping obligations (Art. 6(1)(c) GDPR — § 147 AO, 10-year retention for invoices).
2.3 Contact form
If you contact us via the contact form, we process the name, email address, subject, and message you provide in order to respond to your inquiry. Legal basis: Art. 6(1)(b) and (f) GDPR.
3. Cookies
We only use technically necessary cookies that are required for the operation of the website (e.g. session cookies, CSRF protection, login state). These cookies do not require consent under § 25 para. 2 TTDSG. No tracking or marketing cookies are set.
4. Third-Party Services
4.1 Google reCAPTCHA
We use Google reCAPTCHA on our contact form to distinguish human users from automated bots. Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. reCAPTCHA analyzes various information (IP address, time spent on the site, mouse movements) and sends this to Google. Data may be transferred to servers in the United States.
Legal basis: our legitimate interest in protecting the website against abuse and spam (Art. 6(1)(f) GDPR). More information in Google's privacy policy: https://policies.google.com/privacy and the reCAPTCHA terms: https://policies.google.com/terms.
4.2 Google Analytics
We use Google Analytics, a web analytics service provided by Google Ireland Limited. Google Analytics uses cookies and similar technologies to analyze how users interact with the website. The information generated (including your shortened IP address) is transferred to Google servers, potentially in the United States, and stored there. IP anonymization is enabled (the last octet of your IP address is truncated before storage).
Legal basis: your consent under Art. 6(1)(a) GDPR and § 25 para. 1 TTDSG. You can withdraw consent at any time. You can also prevent Google Analytics tracking by installing the browser add-on available at https://tools.google.com/dlpage/gaoptout.
4.3 Google Maps
Property detail pages embed Google Maps (Google Ireland Limited) to display property locations. When the map loads, Google receives your IP address, potentially in the United States. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a user-friendly presentation).
4.4 External content (images, property listings)
Our service allows you to store links to property listings on third-party platforms (e.g. kleinanzeigen.de, immowelt.de). When such content — for example images referenced by URL — is loaded directly from the third-party server in your browser, your IP address and browser information may be transmitted to that third party. We have no influence over how those providers handle your data. Please consult the respective privacy policies.
When you use the availability check feature, our server (not your browser) retrieves the listing page to determine whether it is still active. No personal data of yours is transmitted in this process.
4.5 Content delivery networks (CDN) and fonts
We load Bootstrap, TinyMCE, jQuery, Plotly, and Google Fonts from third-party CDNs (jsdelivr.net, googleapis.com, gstatic.com). Your browser establishes a direct connection to these servers, transmitting your IP address. Legal basis: Art. 6(1)(f) GDPR.
4.6 Stripe (Payment Processing)
We use Stripe (Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland) to process subscription payments. When you subscribe to a paid plan, the following data is transmitted to Stripe: your name, email address, billing address, and the payment details you enter during checkout. Stripe processes this data as an independent controller for payment execution and fraud prevention.
We do not receive or store your full credit card number, bank account details, or other sensitive payment data. We only store a Stripe customer ID and subscription ID to manage your subscription.
Legal basis: contractual necessity (Art. 6(1)(b) GDPR) — the processing is required to fulfill the subscription agreement. Stripe's privacy policy: https://stripe.com/privacy.
Data may be transferred to Stripe servers in the United States. Stripe is certified under the EU–U.S. Data Privacy Framework.
5. Data Retention
We store personal data only as long as necessary for the purposes described above or as required by statutory retention obligations. Account data is deleted on request or upon account closure. Server log files are typically retained for up to 14 days, then deleted.
Invoices and billing records are retained for 10 years in accordance with German tax law (§ 147 AO). Subscription metadata (plan, status, Stripe IDs) is deleted 30 days after account closure, unless retention is required for ongoing disputes or legal obligations.
6. Data Transfer to Third Countries
The use of Google services may result in the transfer of personal data to the United States. Google is certified under the EU–U.S. Data Privacy Framework, which the European Commission considers an adequate level of protection under Art. 45 GDPR.
7. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent at any time (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR)
To exercise your rights, contact us at info@propybot.com.
8. Supervisory Authority
The competent supervisory authority is:
Sächsischer Datenschutzbeauftragter
Devrientstraße 1, 01067 Dresden, Germany
www.saechsdsb.de
9. SSL/TLS Encryption
This website uses SSL/TLS encryption for security reasons and to protect the transmission of confidential content. You can recognize an encrypted connection by the "https://" prefix in your browser's address bar.
10. Changes to This Policy
We may update this privacy policy to reflect changes in our services or legal requirements. The current version is always available at this URL.