Privacy Policy

How Estaid collects, uses, and protects your personal data under GDPR.

Privacy Policy

Last updated: September 17, 2026


1. Data Controller

  • ESTAID ApS, a company registered under Danish law
  • Store Kongensgade 65A, ST., 1264 Copenhagen K, Denmark
  • CVR: 46213998
  • Email: info@estaid.com

We are the controller of your personal data. No Data Protection Officer is appointed (GDPR Art. 37 not triggered).


2. Personal Data We Collect (GDPR Arts. 13–14)

Provided by you:

  • Name
  • Email address
  • Company name
  • Investment data (property addresses, financial figures, portfolios — may contain personal data)

Payment data:

  • Handled by a third-party processor
  • We store only the transaction ID

Technical data:

  • IP address
  • Browser type
  • Device information
  • Usage logs

Analytics & marketing:

  • Google Analytics 4 and Microsoft Clarity — only if you accept the Analytics cookie category
  • Session recordings made by Microsoft Clarity while you are signed in are tagged with your account identifier, which makes them pseudonymous rather than anonymous. See the Cookie Policy
  • Meta Pixel and Meta Conversions API, and Google Ads conversion tracking — only if you accept the Marketing cookie category
  • Campaign parameters from the link you arrived through (utm_*, gclid, fbclid)

Activity on the platform (signed-in users only):

If you are signed in and you have accepted the Analytics cookie category, we keep a record on our own servers of how you use the platform. It is stored against your account identifier and contains:

  • Pages you open, and when
  • Service categories and partner profiles you view
  • Searches you run on the platform
  • Account events such as signing up or contacting a partner
  • The campaign or referrer that first brought you to the site

We use it for two things: to understand which parts of the platform are worth building on, and to brief a member of our team before they contact you personally, so that the conversation is relevant rather than generic. It is never sold, never shared for anyone else's advertising, and is not collected at all for visitors who are signed out or who declined Analytics.

Withdrawing Analytics consent stops further recording. To have what has already been recorded deleted, write to privacy@estaid.com.

Cookies & trackers:

  • Each one is named, with its purpose and retention, in our Cookie Policy

Special categories:

  • None collected

Providing data is necessary for the performance of a contract; refusal may prevent account creation or use of the Service.


Perform contract

  • Deliver the platform
  • Manage subscriptions

Legitimate interests

  • Improve the Service
  • Prevent fraud
  • Security measures (balanced against your rights)
  • Analytics and marketing cookies and similar technologies (see Cookie Policy)
  • Nothing in either category loads until you accept it
  • Bookkeeping and tax compliance (Danish Bookkeeping Act)

Automated processing and profiling (GDPR Arts. 4(4), 22)

We do not make decisions about you that produce legal effects, or similarly significant effects, on the basis of automated processing alone (GDPR Art. 22).

We do use automated analysis in one place you should know about. The activity record described in section 2 is summarised by an AI service into a short internal briefing — roughly "what has this person been looking at, and how interested do they seem" — which a member of our team reads before deciding whether to contact you. That is profiling within the meaning of GDPR Art. 4(4). A person always makes the decision and writes the message; the summary only informs them, and it is never shown to anyone outside Estaid. The legal basis is our legitimate interest in contacting people who have shown interest in the service, and you can object to it at any time under Art. 21 by writing to privacy@estaid.com.


4. How We Use Your Data

  • Operate the platform
  • Process subscriptions
  • Send transactional emails
  • Analyse usage, including AI-assisted analysis (see sections 3 and 5)
  • Answer questions you ask our AI assistant about a property report
  • Comply with legal obligations

5. Recipients (GDPR Art. 13)

  • Processors: EU hosting providers, third-party payment processors (SCCs)
  • Analytics & advertising providers, where you have consented: Google Ireland Limited (Analytics, Ads), Microsoft Ireland Operations Limited (Clarity), Meta Platforms Ireland Limited (Pixel, Conversions API). Contact details sent to Meta are SHA-256-hashed before they leave our server
  • AI provider: OpenAI Ireland Limited — see below
  • Affiliates: under GDPR-compliant agreements
  • Public authorities: when required by law

OpenAI

Several features of the platform are built on OpenAI's API, which means some of your data is sent to OpenAI to be processed and the result sent back. OpenAI acts as our processor: it works on our instructions under a data processing agreement and does not use what we send for its own purposes.

What is sent, and when:

FeatureWhat is sent
AI assistant on a property reportYour question, and the contents of the report it concerns — which can include an address and financial figures
Property analysisThe property details being analysed
Search assistance on property searchThe search text you typed and the filters it produced
Internal customer briefingYour email address, display name, signup category, the campaign source you arrived through, and the activity record described in section 2
Weekly site reviewAggregate usage statistics per page. No personal data — no names, no identifiers, no individual sessions

The internal customer briefing is the only one of these that sends contact details, and it is generated for Estaid staff only — never shown to you, another user, or a partner.

OpenAI processes data on servers in the United States. That transfer relies on the European Commission's standard contractual clauses, incorporated in OpenAI's data processing agreement. Under that agreement, data submitted through the API is not used to train OpenAI's models.

Their privacy policy: https://openai.com/policies/privacy-policy

We do not sell personal data.


6. International Transfers (GDPR Chapter V)

Primary storage and processing occur within the EU/EEA.
Any transfers outside the EU/EEA rely on:

  • Standard Contractual Clauses (SCCs), which the AI processing described in section 5 relies on
  • Adequacy Decisions, including the EU–U.S. Data Privacy Framework, which the analytics and advertising providers above rely on
  • Binding Corporate Rules

7. Retention Periods

  • Account & investment data: until deletion request + 30 days (or longer if in dispute)
  • Financial transactions: 5 years from end of fiscal year (Danish Bookkeeping Act § 10)
  • Analytics data: up to 26 months; individual cookie lifetimes are listed in the Cookie Policy
  • Activity on the platform (the record described in section 2, and the AI briefing generated from it): 12 months from the event. It is also erased on request, under section 8
  • Session recordings (Microsoft Clarity): up to 30 days, as set by the provider
  • Security logs: 12 months

Data is securely deleted after retention expires.


8. Your Rights (GDPR Chapter III)

  • Access (Art. 15)
  • Rectification (Art. 16)
  • Erasure (Art. 17)
  • Restriction (Art. 18)
  • Data portability (Art. 20)
  • Objection (Art. 21)
  • Withdraw consent (Art. 7)

Consent to cookies is withdrawn through Cookie settings in the site footer, which reopens the consent dialog. Exercise your other rights free of charge at privacy@estaid.com.
We respond within 1 month (extendable to 3 months for complex requests).

You may also complain to Datatilsynet (https://www.datatilsynet.dk) or your local supervisory authority.


9. Security Measures (GDPR Art. 32)

  • TLS encryption in transit
  • Encryption at rest where appropriate
  • Pseudonymisation (hashed passwords)
  • Strict access controls
  • Regular security audits
  • Backups
  • Vulnerability scans
  • Staff training

10. Data Breach Notification (GDPR Arts. 33–34)

  • We notify Datatilsynet within 72 hours unless the breach is unlikely to pose a risk.
  • If a breach poses high risk to your rights, we notify you without undue delay, describing:
    • The nature of the breach
    • Likely consequences
    • Measures taken

11. Children

The Service is not intended for individuals under 18.
We do not knowingly process children’s data. Any discovered data is deleted immediately.


12. Changes to this Policy

Material changes will be notified via email or in-app at least 30 days in advance.
Continued use of the Service constitutes acceptance of the updated policy.


13. Contact