Privacy Policy
Last updated: 22 July 2026
This Privacy Policy explains how Dream Properties Network collects, uses, shares, and protects personal data when you use the Dream Properties Network platform, websites, live sessions, and related services (together, the Platform).
1. Who We Are — Data Controller
The data controller is:
[TO CONFIRM — Dream Properties Network legal entity], doing business as Dream Properties Network
[TO CONFIRM — registered address, France]
E-mail: [TO CONFIRM — contact e-mail]
Phone: [TO CONFIRM — phone]
The controller determines why and how the personal data described in this Policy is processed.
The Platform is offered to users in the European Union and European Economic Area. We process personal data in accordance with the General Data Protection Regulation (GDPR). The controller is established within the European Union.
2. How the Platform Works
Dream Properties Network is a real-estate platform that allows users to:
- create an account and public or professional profile;
- publish, browse, and manage property listings;
- apply for verified agent or agency status;
- communicate with other users;
- host, join, and watch live property presentations;
- connect selected advertising and streaming services;
- use AI-assisted property and document features;
- purchase paid Platform features; and
- receive analytics-supported improvements and notifications, subject to their choices.
The processing that applies to you depends on which features you use.
3. Personal Data We Process
3.1 Account and authentication data
When you create an account, we process your:
- username;
- e-mail address;
- chosen language;
- sign-up date; and
- authentication credentials.
Passwords are stored in hashed form and not as plain text.
Purpose: creating and securing your account, enabling sign-in, and sending essential service messages such as password resets and security alerts.
Legal basis: performance of a contract or steps taken at your request before entering into a contract (Article 6(1)(b) GDPR); legitimate interests in securing the Platform (Article 6(1)(f) GDPR).
Required: yes. Without this information, an account cannot be created.
3.2 Profile data
Depending on the type of account, you may provide:
- name;
- profile picture;
- biography;
- company or agency;
- country;
- languages;
- telephone number;
- professional e-mail address;
- website; and
- links to professional social-media profiles.
Purpose: displaying and personalising your profile, allowing other users to identify or contact you, and providing Platform features.
Legal basis: performance of a contract (Article 6(1)(b) GDPR). Where a field is not necessary to provide the service, you choose voluntarily whether to make it available.
3.3 Agent and agency applications
If you apply for agent or agency status, we may process:
- licence number, issuing country, and expiry date;
- company name, registered address, and tax number;
- professional contact details and website;
- countries and cities in which you operate;
- optional professional social-media profiles;
- a copy of a professional licence; and
- insurance or professional indemnity documents.
Purpose: assessing and verifying your application, preventing impersonation and fraud, communicating the result, and meeting applicable professional or legal requirements.
Legal basis: steps taken at your request and performance of a contract (Article 6(1)(b) GDPR); compliance with a legal obligation where applicable (Article 6(1)(c) GDPR); legitimate interests in verifying professionals and protecting Platform users (Article 6(1)(f) GDPR).
Required: the information marked as required in the application is necessary to obtain verified status. Social-media profiles are optional.
3.4 Property listings and uploaded materials
Agents, agencies, presenters, and property developers may upload:
- property descriptions, addresses, and geographic coordinates;
- photographs, videos, floor plans, and other property materials;
- ownership, agency, or listing-related documents;
- presenter or company details; and
- other content used to create, advertise, or present a listing.
Uploaded content may contain personal data. You must have the right to provide that content to us and to make it available through the Platform.
Purpose: creating and displaying listings, running property presentations, supporting search, advertising, and AI-assisted property features.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); legitimate interests in operating and improving listing features (Article 6(1)(f) GDPR).
3.5 Messages and live-session chat
When you communicate through the Platform, we may process:
- message or chat content;
- sender and recipient identifiers;
- timestamps;
- delivery and read status; and
- reports or moderation information.
Messages are not end-to-end encrypted. Authorised personnel may access content where reasonably necessary to investigate reported abuse, maintain the service, protect users, or comply with law.
Purpose: delivering communications, providing conversation history, moderating abuse, and maintaining security.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); legitimate interests in preventing abuse and securing the Platform (Article 6(1)(f) GDPR); compliance with legal obligations where applicable (Article 6(1)(c) GDPR).
3.6 Live sessions, camera, microphone, and screen sharing
When you host or actively participate in a live session, we process the audio, video, display name, chat contributions, and screen content that you choose to transmit. We may also process session events such as joining, leaving, role changes, and technical quality information.
Browser or device permission allows the Platform to access your camera or microphone. Granting a technical device permission does not by itself constitute consent to every separate use of personal data.
Camera, microphone, and screen sharing can be switched off when the relevant feature permits. Passive viewers are not required to transmit camera or microphone content.
A live session may be recorded or restreamed where that feature is enabled. Where recording or public broadcasting applies, users will be informed through the relevant session interface or notice and, where required, consent will be requested.
Purpose: providing live presentations, participant interaction, screen sharing, recordings, restreaming, and technical support.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); consent where required for recording, optional participation, or public disclosure (Article 6(1)(a) GDPR); legitimate interests in service security and diagnostics (Article 6(1)(f) GDPR).
3.7 Advertising and Meta integration
Agents may optionally connect a Meta account to create and manage Facebook or Instagram advertising campaigns through Dream Properties Network. Depending on the selected features, we may process:
- Meta user and business identifiers;
- advertising-account and page identifiers;
- access tokens;
- campaign configuration and performance data;
- Meta Pixel identifiers.
When creating and running campaigns, we send the following to Meta: images and materials from your listings, ad content (headlines, descriptions, and calls to action), the listing URL, targeting parameters (including geographic location and language), the campaign objective, budget, and schedule. From Meta we retrieve advertising performance data, in particular the number of impressions, clicks, and conversions.
Access tokens are encrypted in transit and at rest and are accessible only to authorised integration processes.
If you configure a Meta Pixel, we currently use its identifier as part of the configuration of conversion-optimised campaigns (the leads and sales objectives) and pass it to Meta when such a campaign is created. Dream Properties Network does not embed or fire the Meta Pixel on its pages and does not send conversion events via the Pixel or the Conversions API.
Once this feature is enabled — and only after the required consent or another valid basis has been obtained — conversion measurement may involve firing the Meta Pixel on the device of a visitor to the campaign's destination page and sending events to Meta via the Conversions API. In that case, event data such as the following may be transmitted to Meta: the event name and time (e.g. content view, contact, lead), the page or listing URL, Meta identifiers (fbp, fbc), the IP address and browser information (user-agent), and — where applicable — a hashed e-mail address or phone number used to match the event. Before enabling this feature, we will update this Policy and, where required, request consent.
For events collected through the Meta Pixel on a visitor's device, Meta and the controller act as joint controllers within the meaning of Article 26 GDPR, on the joint-controller terms determined by Meta. Otherwise — for the data of your account and advertising account with Meta and the operation of the Meta platform — Meta acts as an independent controller under its own terms.
Purpose: connecting accounts, creating and managing campaigns, measuring conversions, and optimising advertising.
Legal basis: performance of a contract with the agent using the integration (Article 6(1)(b) GDPR); consent for non-essential advertising identifiers or tracking on a visitor's device (Article 6(1)(a) GDPR); legitimate interests for limited account-security and integration diagnostics (Article 6(1)(f) GDPR).
You may disconnect the integration in Platform settings at any time. Disconnecting immediately removes from active production systems the Meta user and business identifiers, access tokens, the Meta Pixel identifier, and the identifiers of the connected advertising account and page, stops further Platform access, and sends Meta a request to revoke the app's permissions; deletion from our production systems takes place regardless of the outcome of that request. Disconnecting does not automatically delete campaigns you previously created or the performance data collected for them — these remain until the campaign is deleted, a Meta data deletion request is completed, or the account is closed, and we keep accounting and tax records relating to ad spend for the period required by law. We do not control data already processed by Meta acting as a controller — that data is subject to Meta's policies; we also retain data whose retention is required for legal or security reasons.
3.8 YouTube integration and restreaming
Agents may optionally connect a Google or YouTube account. We may process:
- Google OAuth tokens;
- YouTube channel identifiers and basic channel information;
- selected restreaming settings; and
- live-stream status and technical information.
Purpose: connecting a YouTube channel and restreaming live presentations.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); consent or authorisation provided through the Google OAuth flow for access to the connected account (Article 6(1)(a) GDPR where applicable).
You may disconnect YouTube in Platform settings. Disconnecting stops future access by the Platform and removes stored access credentials, subject to security logs and legally required records.
3.9 AI assistant and document processing
When you use AI-assisted features, we may process:
- questions, prompts, and conversation content;
- property information and geographic coordinates;
- documents that you choose to upload;
- document fragments and search embeddings;
- generated answers; and
- diagnostic information about AI feature performance.
Relevant content may be sent to OpenAI to generate responses and to Cohere for AI processing or document reranking. When you ask about a property's surroundings, its geographic coordinates may be sent to Google Places API to identify nearby locations.
We may remove common identifiers such as e-mail addresses, telephone numbers, PESEL numbers, IBANs, and payment-card numbers before storing diagnostic query logs. Automated removal reduces risk but cannot guarantee that every identifier in free-form text or documents will be detected.
Do not upload special-category data, criminal-offence data, or documents containing unnecessary information about third parties unless the feature expressly supports that use and you have a valid legal basis.
We do not use documents submitted to the assistant to train external providers' models unless we inform you and have an appropriate legal basis. We use personal data to train or fine-tune our own models only where the data has been effectively anonymised or where separate valid consent has been obtained.
Purpose: answering questions, searching documents, providing information about properties and their surroundings, maintaining security, diagnosing faults, and evaluating feature performance.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); legitimate interests in security, diagnostics, and service improvement (Article 6(1)(f) GDPR); consent where required for an optional or additional use (Article 6(1)(a) GDPR).
3.10 Payments and transaction records
When you use paid features, we may process:
- wallet balance;
- amounts and currency;
- transaction type and history;
- subscription or purchased-feature information;
- billing or tax information; and
- Stripe transaction or reference identifiers.
Payment-card details are processed by Stripe and are not intended to reach our servers.
Purpose: processing payments, maintaining balances and billing history, preventing fraud, and meeting accounting and tax requirements.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); compliance with legal obligations (Article 6(1)(c) GDPR); legitimate interests in preventing payment fraud (Article 6(1)(f) GDPR).
3.11 Push notifications
If you enable browser notifications, we process a Firebase Cloud Messaging (FCM) device token. The token is a pseudonymous identifier used to route notifications to a browser or device.
Purpose: sending alerts about messages, account activity, and relevant Platform events.
Legal basis: consent (Article 6(1)(a) GDPR).
Notifications are optional. You can withdraw permission in browser settings. You may also remove a registered token through the available Platform settings or by contacting us.
3.12 Maps and location services
The Platform uses Leaflet and map tiles provided by OpenStreetMap. Geographic searches may use the Overpass API. When map content is requested, the relevant provider may receive an IP address and standard HTTP request information.
Purpose: displaying property locations and supporting geographic search.
Legal basis: performance of a contract (Article 6(1)(b) GDPR); legitimate interests in providing useful location features (Article 6(1)(f) GDPR).
3.13 Analytics and session replay
If you accept optional analytics, we use PostHog to understand how the Platform is used and where technical or usability problems occur.
Depending on configuration, PostHog may process:
- a pseudonymous account or session identifier;
- pages and features used;
- clicks and navigation events;
- browser and device information;
- error and performance information; and
- session-replay data showing interactions with the Platform.
Session replay is intended to help reproduce usability and technical problems. Sensitive input fields should be excluded or masked through technical configuration. You should nevertheless avoid entering unnecessary sensitive data into free-form fields.
PostHog is configured to use EU infrastructure. Before analytics consent, it uses memory-only, cookieless operation and is not linked to your account by us. After consent, analytics may use local storage and cookies and may be associated with your account identifier.
Purpose: analytics, diagnosing errors, improving usability, and understanding feature performance.
Legal basis: consent (Article 6(1)(a) GDPR).
You may decline analytics or withdraw consent at any time through cookie settings. Withdrawal stops future analytics collection and session replay on that device.
3.14 Server logs and security data
Our systems and service providers may automatically process:
- IP address;
- request URL and timestamp;
- browser and device information;
- authentication and security events;
- error information; and
- identifiers needed to investigate incidents or prevent abuse.
Sensitive request values should be removed or masked before being written to application logs where technically possible.
Purpose: securing the Platform, preventing abuse and fraud, diagnosing failures, and investigating incidents.
Legal basis: legitimate interests in security and reliable service operation (Article 6(1)(f) GDPR); compliance with legal obligations where applicable (Article 6(1)(c) GDPR).
4. Artificial Intelligence and Profiling
4.1 Interaction with AI
When you use the AI assistant, you are interacting with an automated system and not a human. AI-generated answers may be incomplete or inaccurate and should not be treated as legal, financial, investment, or other professional advice.
The EU AI Act transparency requirements generally apply from 2 August 2026. We aim to provide clear information about AI interaction and generated content in the relevant interfaces.
4.2 AI-supported advertising and recommendations
AI may assist with creating advertising text, property descriptions, translations, summaries, or other content. Human users remain responsible for reviewing content before publication where the Platform provides a review step.
Where content is artificially generated or materially manipulated, it will be labelled or technically marked where required by applicable law and taking into account the respective obligations of the AI provider and the user deploying the content.
4.3 Profiling and automated decisions
The Platform may use limited automated processing to personalise features, support search, recommend content, assess campaign performance, or assist agents in organising enquiries.
Unless we provide a separate notice for a specific feature, we do not use solely automated processing to make decisions that produce legal effects or similarly significant effects concerning you. In particular, the Platform does not automatically decide whether you may buy, rent, view, or enquire about a property, determine your eligibility for housing or credit, or change a property's legal terms based on profiling.
If we introduce behavioural scoring, sentiment analysis, adaptive listing presentation, or another material profiling feature, we will provide information about the data used, purpose, logic, consequences, legal basis, retention, and available controls before the processing begins.
5. Cookies and Similar Technologies
The Platform uses cookies, local storage, and similar technologies for authentication, language settings, consent preferences, analytics, advertising integrations, and push notifications.
Non-essential analytics or advertising technologies are used only after the required consent has been obtained. Further information is available in our Cookie Policy.
6. Who We Share Personal Data With
We do not sell personal data.
We may share personal data with:
- AWS / Amazon Web Services — hosting, file storage, live video, and related infrastructure;
- Stripe — payment processing and fraud prevention;
- Firebase / Google — push notifications;
- PostHog — analytics and session replay (with consent);
- Meta Platforms — account connection, advertising, and Pixel features;
- Google / YouTube — account connection and live restreaming;
- OpenAI — AI response generation;
- Cohere — AI processing and document reranking;
- Google Places API — property-surroundings and nearby-location search;
- OpenStreetMap and Overpass providers — maps and geographic search.
We may also share data with:
- agents, agencies, presenters, or other users where this is necessary to provide a feature you request;
- professional advisers acting under confidentiality;
- authorities, courts, or law-enforcement bodies where disclosure is legally required or necessary to protect rights and safety; and
- a buyer, investor, or successor in connection with a merger, acquisition, restructuring, or transfer of the business, subject to appropriate safeguards.
Service providers that process personal data on our behalf are required to act under appropriate contractual and confidentiality obligations.
Where an agent or agency receives a lead or other personal data for its own follow-up and determines its own purposes and means of processing, it may act as a separate controller and must provide its own privacy information.
7. International Data Transfers
The controller is established in the European Union. Where possible, we use provider infrastructure located in the European Economic Area. Some providers may nevertheless process data outside the EEA.
Where the GDPR requires transfer safeguards, we use an applicable lawful transfer mechanism, such as:
- an adequacy decision, including the EU-US Data Privacy Framework for a certified recipient;
- the European Commission's Standard Contractual Clauses; or
- another mechanism permitted by Chapter V GDPR.
Where appropriate, we assess supplementary technical, contractual, and organisational measures. You may contact us for information about the safeguards applicable to a particular transfer.
8. How Long We Keep Personal Data
We retain personal data only for as long as reasonably necessary for the relevant purpose, including legal, accounting, security, and dispute-resolution requirements.
Our current general retention periods are:
- Account and authentication data — until account deletion, followed by backup deletion cycles of up to 1 year;
- Profile data — until removed by the user or the account is closed;
- Agent or agency application and verification documents — while verified status is active and generally up to 5 years afterwards where needed for claims, compliance, or verification records;
- Property content and uploaded documents — until deleted, the relevant listing or account is closed, or retention is otherwise required;
- Direct messages — until the relevant account or conversation is deleted, subject to abuse reports and legal requirements;
- Live-session recordings — for the period communicated for the relevant recording or until it is deleted, subject to legal requirements and copies published on third-party platforms;
- Payment, billing, and transaction records — for the period required by applicable accounting and tax law, generally at least 5 years;
- Meta access tokens and connection identifiers (Pixel, advertising account, page) — until the integration is disconnected, the token expires, or the account is closed; removed on disconnection;
- Meta campaign configuration and performance data — until the campaign is deleted, a Meta data deletion request is completed, or the account is closed, subject to accounting requirements;
- YouTube access credentials — until the integration is disconnected, the credential expires, or the account is closed;
- AI diagnostic query logs — generally up to 90 days;
- AI documents and embeddings — until deleted by the user or the relevant account is closed;
- Push-notification tokens — until removed, invalidated, permission is withdrawn, or the account is closed;
- Application and security logs — generally up to 90 days, unless needed for an active incident, claim, or legal obligation;
- Analytics and session-replay data — according to our configured PostHog retention period and consent settings;
- Consent records — for as long as needed to demonstrate consent and address related legal claims.
Deletion from active systems may not immediately remove data from encrypted backups. Backup copies are isolated from ordinary use and deleted or overwritten according to backup cycles.
9. Your Rights
Where the GDPR applies, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- receive data you provided in a structured, commonly used, machine-readable format;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- obtain information about relevant automated decision-making and profiling; and
- lodge a complaint with a data-protection supervisory authority.
You may complain to the authority in the country where you live, work, or believe an infringement occurred. The supervisory authority for the controller is:
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
https://www.cnil.fr
Users in Poland may also lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, https://uodo.gov.pl.
Rights are not absolute. For example, we may retain information required for tax records, fraud prevention, legal claims, or compliance with law.
To exercise a right, contact [TO CONFIRM — contact e-mail]. We may need to verify your identity. We normally respond within one month, subject to extensions permitted by law for complex or numerous requests.
If data has been shared with an agent acting as a separate controller, you may also need to contact that agent regarding its subsequent processing.
9.1 Account deletion
To delete your account, send a request to [TO CONFIRM — contact e-mail] from the e-mail address associated with the account. We may take reasonable steps to verify your identity. We delete your account, profile, and related content without undue delay, generally within 30 days of receiving the request. If completing the request requires additional information or the deadline must be lawfully extended, we will inform you.
We retain certain data for the period required by law or justified by a valid legal basis, in particular accounting and tax records and a limited set of security logs (see Section 8). Data removed from production systems may temporarily remain in encrypted backups, which are deleted or overwritten in line with our backup cycle. These backups are isolated from ordinary operations, are not accessible in the normal functioning of the Platform, and are not restored to an active account.
10. Security
We use technical and organisational measures appropriate to the nature and risk of the processing. These may include encryption in transit and at rest, access controls, token protection, logging, backups, and monitoring.
No online service can guarantee absolute security. You are responsible for protecting your password, devices, connected third-party accounts, and any content you choose to share publicly.
11. Children
The Platform is intended for adults and is not directed to children under 18. We do not knowingly create accounts for or collect personal data directly from children. If you believe a child has provided personal data, contact us so that we can investigate and take appropriate action.
12. Changes to This Policy
We may update this Policy when the Platform, providers, or legal requirements change. The revision date at the top identifies the current version.
If a change materially affects how we process personal data, we will provide an appropriate notice through the Platform, by e-mail, or by another suitable method before the change takes effect where required.
13. Contact
[TO CONFIRM — Dream Properties Network legal entity] (Dream Properties Network)
[TO CONFIRM — registered address, France]
E-mail: [TO CONFIRM — contact e-mail]
Phone: [TO CONFIRM — phone]