Privacy Policy

Effective 1 September 2026

This policy explains what personal information EcoMark collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It covers the EcoMark web application, the EcoMark AI assistant, and the messaging, analytics and billing features that form part of them. “We”, “us” and “EcoMark” mean [Legal entity name], [Registered address].

Who this policy is for

EcoMark is sold to real estate agencies. When an agency subscribes we create an isolated workspace for it; the agency's administrators then invite colleagues, and everyone who works in that workspace holds an individual EcoMark account.

Two groups of people appear in this policy. The first is you as a user of EcoMark — an administrator or an agent with an account. The second is the people your agency records in EcoMark: leads, contacts, property owners, buyers, tenants and anyone else the agency deals with. Both groups have rights over their information, but the route to exercising them differs, and the section “Your rights” explains why.

Our role: controller and processor

For your account and profile — the information we need to give you access, bill your agency and keep the service secure — EcoMark is the data controller. We decide what is collected and why.

For the business records your agency enters and uploads — leads, contacts, inquiries, property files, appointments, messages and documents — your agency is the data controller and EcoMark is the processor. The agency decides whose data goes into its workspace, for what purpose and for how long. We act on its instructions, which reach us through its use of the product and through its subscription agreement.

This distinction has a practical consequence. If you are a client of an agency that uses EcoMark and you want to see, correct or delete the record held about you, that request goes to the agency. We will help the agency answer it, but we will not alter or release a workspace's records on the instruction of someone who is not an authorised member of that workspace.

Information we collect

Some of the information below you give us directly, some is created as you use the product, and some arrives from a service your agency chooses to connect.

  • Account information — your name, email address, a hashed password, email-verification and password-reset tokens, the invitation token used to join a workspace, and, if you choose to sign in with Google, the account identifier, name, email address and profile image Google returns. We never receive your Google password.
  • Profile information — job title, phone number, language, time zone, notification preferences and an optional profile photo you upload.
  • Workspace information — your agency's name, branding, regional and currency settings, subscription plan, team membership, roles (Administrator or Agent) and the permissions attached to them.
  • Client records entered by your agency — leads, contacts and inquiries, including names, contact details, budgets, requirements, sources, notes and pipeline stage. The agency decides what goes here. EcoMark is not designed to hold special-category data such as health, religious or biometric information, and agencies should not enter it.
  • Property and marketing content — listings, prices, addresses, descriptions, photographs, floor plans, 360° tours, videos, uploaded documents, portfolios, published property pages, short links and QR codes.
  • Scheduling information — appointments and viewings, their attendees, locations, times and outcomes.
  • Communications — email and WhatsApp Business messages sent or received through EcoMark's messaging modules, including their content, recipients, timestamps and delivery status.
  • AI interactions — the prompts you write to EcoMark AI, the workspace records the assistant reads to answer them, the drafts and actions it produces, your approvals or rejections, and the credits each task consumes.
  • Usage and log data — the pages and features you use, activity and audit entries recording who did what and when, IP address, browser and device type, approximate location derived from the IP address, and diagnostic logs.
  • Billing information — subscription plan, credit balance and purchase history, invoices, and the billing contact and address. Card details are entered directly with our payment processor and are never stored on EcoMark's systems.

How we use information

We use the information above for the following purposes and no others.

  • To provide the service — authenticate you, keep each workspace isolated from every other, and run the features you use.
  • To run EcoMark AI — carry out the tasks you ask for, hold sensitive actions for approval, and meter the credits a task consumes.
  • To deliver messages — route the email and WhatsApp Business messages you compose through the provider your agency has connected, and report delivery status back to you.
  • To bill and account — take subscription payments and credit purchases, issue invoices, and prevent payment fraud.
  • To support you — answer support requests and investigate the faults you report.
  • To secure the service — detect suspicious sign-ins, rate-limit abuse, maintain audit trails and investigate incidents.
  • To improve the product — understand which features are used and where they fail, working from aggregated and workspace-level statistics rather than reading your client records.
  • To comply with law — meet tax, accounting and other legal obligations and respond to lawful requests from authorities.

What we do not do

We do not sell personal information. We do not serve third-party advertising inside EcoMark, we set no advertising or cross-site tracking cookies, and we do not build advertising profiles from your workspace content.

We do not read your client records to develop the product, other than through aggregate counts that cannot identify a person, and through the specific records an engineer needs to open when you ask us to investigate a fault you have reported.

We do not use your workspace content to train general-purpose AI models, and our contracts with AI providers forbid them from doing so with content we send on your behalf.

Legal bases for processing

Where the GDPR or an equivalent law applies, we rely on the following legal bases for the personal data we control.

Where we process personal data on behalf of an agency — everything the agency enters about its own clients — establishing a legal basis is the agency's responsibility as controller, not ours.

  • Performance of a contract — creating and running your account, providing the workspace, and taking payment for it.
  • Legitimate interests — securing the platform, preventing abuse and fraud, keeping audit trails, understanding product usage in aggregate, and communicating about service changes. We have weighed these interests against your rights and you may object at any time.
  • Consent — where you opt in to something optional, such as connecting a Google account for sign-in or receiving product announcements that are not service-critical. You can withdraw consent at any time without affecting processing already carried out.
  • Legal obligation — retaining invoices and tax records, and responding to lawful requests.

EcoMark AI and your data

EcoMark AI is an assistant that works inside your workspace. When you ask it something, it can read the records your role is allowed to see — leads, properties, appointments, messages, analytics — and use them to answer, draft content, or carry out an action.

The assistant does not reach outside your workspace. It cannot read another agency's data, and a task run by an agent is limited to the same records that agent could open by hand.

Actions that leave the system or change something significant — sending a message, publishing a listing, changing a price, deleting a record — are presented as an approval card and execute only when a person approves them.

To produce a response, the relevant part of your request and the records needed to answer it are sent to a third-party AI model provider under contract. Providers are engaged as sub-processors, are contractually limited to returning a result to us, and are not permitted to retain the content beyond that or use it to train their models.

AI output can be wrong. It may misread a record, invent a detail, or produce text that is unsuitable for your market or legally inaccurate. Every draft must be reviewed by a person before it is sent, published or relied on. EcoMark AI does not provide legal, tax or financial advice.

Each task consumes credits from your workspace's balance. We record what ran, who ran it, when, and what it cost, so that administrators can audit usage and we can bill accurately.

Cookies and browser storage

EcoMark uses a small number of cookies and browser storage entries, all of them necessary to operate the product. There are no advertising cookies and no third-party trackers, which is why you are not asked to dismiss a consent banner.

  • Session cookie — keeps you signed in and identifies your workspace on each request. Cleared when you sign out.
  • Locale preference — remembers the language you chose, so the interface loads in it even before you sign in.
  • Theme preference — remembers whether you chose light, dark or system appearance.
  • Sidebar preference — remembers whether the navigation sidebar is expanded or collapsed.
  • Infrastructure cookies set by our hosting provider — used to route requests and to protect the service against automated abuse.

Messaging: email and WhatsApp Business

The messaging modules stay off until an administrator connects them. Connecting stores the credentials or access tokens for the connected account so that EcoMark can send and receive on your agency's behalf; you can disconnect at any time, which revokes them.

Once connected, message content travels through the relevant provider and is subject to that provider's terms and privacy policy as well as to this one. Copies of the messages sent and received through EcoMark are stored in your workspace so that the conversation history stays attached to the contact record.

Your agency is responsible for having a lawful basis to contact the people it messages, for honouring opt-outs promptly, and for complying with the rules that apply to business messaging in its market.

Sharing and sub-processors

We share personal information only in the circumstances listed here.

  • Inside your workspace — colleagues see records according to their role. Administrators see the whole workspace; agents see the records assigned to or created by them.
  • Sub-processors — vetted suppliers who process data on our instructions so that we can run the service. We use these categories: cloud hosting and database infrastructure; transactional email delivery; messaging providers for the channels your agency connects; AI model providers; a payment processor; and error monitoring for the platform itself.
  • Professional advisers — lawyers, accountants and auditors, all bound by confidentiality.
  • Legal and safety — where the law requires it, or where disclosure is necessary to establish or defend legal claims or to protect the rights and safety of people.
  • Business transfer — if EcoMark is involved in a merger, acquisition or sale of assets, information may pass to the acquirer, who remains bound by this policy until an equivalent one replaces it.

How sub-processors are controlled

Every sub-processor is engaged under a written contract that limits it to our documented instructions, requires appropriate technical and organisational security measures, imposes confidentiality on its staff, and forbids using the data for its own purposes.

A current list of named sub-processors, with the country each operates from, is available on request at [privacy@ecomark.example]. Agencies are notified before a new sub-processor takes on a material role, with enough notice to object.

International transfers

EcoMark stores data in data centres chosen for proximity to our customers. Some of our sub-processors operate elsewhere, which means personal information may be transferred outside the country where it was collected, including outside the European Economic Area and the United Kingdom.

Where that happens we rely on an adequacy decision covering the destination, or on the European Commission's Standard Contractual Clauses together with the UK Addendum where relevant, supported by technical measures such as encryption in transit and at rest. A copy of the mechanism used for a specific sub-processor is available on request.

How long we keep information

We keep personal information only for as long as it is needed for the purpose it was collected for, or for as long as the law requires.

  • Account records are kept while the account is active. If you leave a workspace, the account is deactivated and your name remains on the activity entries you generated, because removing it would break the audit trail the agency relies on.
  • Workspace content — leads, properties, messages, documents — is kept while the agency's subscription is active, and is deleted or returned within 30 days of a written deletion request from an agency administrator.
  • After a subscription ends we hold the workspace in a suspended state for 30 days so that it can be reactivated, then delete it. Backups containing it are overwritten on a rolling cycle of no more than 35 days.
  • Activity, audit and security logs are kept for 12 months.
  • Invoices, payment records and tax documents are kept for the period the applicable tax law requires, commonly between six and ten years.

How we protect information

Security is a continuing practice rather than a fixed state. The measures below are the ones in place today.

No system is perfectly secure. If a breach affects personal information we will notify the competent supervisory authority within 72 hours where the law requires it, and inform affected agencies without undue delay, with what we know and what we advise them to do.

  • Passwords are stored only as salted hashes; we cannot read them, and a reset link is single-use and expires.
  • Traffic is encrypted in transit with TLS, and stored data is encrypted at rest.
  • Every request is scoped to a single workspace, and authorisation is re-checked on the server for every read and every action, not only in the interface.
  • Access to production systems by our staff is limited to named engineers, requires multi-factor authentication, and is logged.
  • Sensitive AI actions require explicit human approval before they execute.
  • Sign-in attempts, invitations, role changes, exports and deletions are recorded in the workspace activity log.
  • We review dependencies for known vulnerabilities and test the platform on a regular cycle.

Your rights

Depending on where you live you have some or all of the following rights over your personal information: to access it, to have it corrected, to have it erased, to restrict how it is processed, to receive it in a portable format, to object to processing based on legitimate interests, and to withdraw consent you have given.

To exercise a right over your own EcoMark account, write to [privacy@ecomark.example] from the address on the account. We respond within one month, and may extend by two further months for a complex request, telling you if we do. We do not charge for this unless a request is manifestly excessive.

If your information sits in an agency's workspace because you are that agency's client, the agency controls it. Send your request to the agency. If you send it to us we will pass it on and support the agency in answering it. Much of it can be answered inside the product: administrators can search, export, correct and delete records themselves.

You may complain to your local data protection authority at any time. We would rather hear from you first, so we can put the matter right.

Children

EcoMark is a professional tool for real estate businesses. It is not directed at children, and we do not knowingly create accounts for anyone under 18. If we learn that an account belongs to a minor we will close it.

Agencies must not enter the personal data of children into a workspace except where it is genuinely necessary for a transaction and lawful in their market.

Changes to this policy

We update this policy when the product or the law changes. The effective date at the top always reflects the current version, and we keep previous versions on request.

If a change materially affects how we handle personal information we will notify workspace administrators by email and inside the product at least 30 days before it takes effect, unless the law requires us to act sooner.

Contact

Questions about this policy, or a request about your information, go to [privacy@ecomark.example].

The controller for account data is [Legal entity name], [Registered address].

If your agency is the controller for the record you are asking about — anything the agency entered about its own clients — contact the agency directly; its administrators can answer inside the product.