Privacy Policy
Last updated: 3 September 2026 (version 3.1)
1. Who we are
The data controller for personal data we hold about you, the registered account holder, is AGUA EXCLUSIVE, S.L. (NIF B21931795), Avenida Bartolomé Vicente Ramón, 1, 1º, 1ª, 07800 Eivissa, Illes Balears, Spain (also referred to as “Farmhouse”, “we”, “us”). We operate the Farmhouse Sales platform at sales.farmhouse.app (the “Service”). For data you upload about other people or entities inside your workspace (other owners, agents, buyers, the people you invite to view an off-market property, your service partners, their staff), you are the controller and we act as your processor under our Data Processing Agreement. For privacy questions, write to privacy@farmhouse.app; for formal data-protection enquiries you can also reach us at dpo@farmhouse.app.
Farmhouse Sales is a software platform that connects property owners, buyers, sales agencies and service partners. We are not a real-estate agent, broker, valuator, lawyer, notary, translator, financial advisor or mortgage broker, and nothing on the Service constitutes professional advice. Every sale, pitch, valuation, offer, contract and payment is between the relevant users; we facilitate the workflow but are not a party to any of them.
If you arrived here from a private property link. You may be reading this because an agent sent you a personal link to a property that is not publicly listed. You do not have an account with us. Section 5a explains exactly what we record about your visit, why, and who is responsible for it. Please read it.
2. Information we handle
We follow data minimisation: only the information needed to operate the Service is handled. We do not sell, enrich, or build advertising profiles. The categories are:
- Your profile: basics you provide on sign-up (name, email, phone, role, language) and an encrypted password set after admin approval.
- Service usage: standard technical signals (IP, device, session, pages visited, login times) used to keep your account secure and the platform working.
- Your listing & sale content: property details, photos, floorplans, energy certificates, valuations, deeds, IBI receipts and other dossier documents you upload, plus your asking price, motivation notes, exclusivity preferences and any free-text notes.
- Off-market network content: private property cards you create, the photographs, video, floorplans and documents attached to them, your mandate details and any mandate document you upload, the names and contact details of the agents and clients you invite, and the record of who opened what and when. Section 5a covers this in full.
- Pitches, offers and representation: pitches submitted by verified agencies, buyer offers routed through the chosen agency, signed representation contracts, and the audit trail showing who saw what when.
- Buyer search profiles and saved matches: criteria you save (regions, budget, must-haves), the AI-explained matches surfaced to you, and your interactions with them.
- Access codes and passcodes: where you protect an off-market link with a passcode, we store only a one-way fingerprint of it, never the passcode itself. The same is true of the link tokens themselves. We cannot read either back to you, and neither can anyone who obtained a copy of our database.
- AI-tool inputs and outputs: text, photos and documents you feed to optional AI features (Concierge Chat, property intake, photo triage, marketing kit, AI Studio renders, valuation range, pitch score, pitch generator, offer evaluator, document parser, document verifier, match explainer), and the outputs returned to you. See §10.
- Service-partner interactions: quote requests you send to partners, scope text, partner replies, your reviews, and any documents you choose to share.
- Verification documents: for sales agencies and service partners only: real-estate licence, insurance, track-record references, IBAN certificate, VAT certificate and the verification notes we add (whether human or AI-assisted).
- Billing information: required only on paid plans (billing address, VAT number, last four digits of card). Full card data is handled by our PCI-DSS payment provider, not by us.
- Support correspondence: anything you send us when contacting support, kept only as long as needed to resolve the matter.
3. How we use this information
We use it to provide and improve the Service for you (matching buyers with relevant listings, running readiness checklists, routing sealed agency pitches, operating the off-market network and its access controls, processing AI-tool jobs, sending transactional emails, generating reports for your dashboard), to keep the Service safe from fraud and abuse, and to meet our legal obligations. We do not build advertising profiles or sell your data. Optional uses (e.g. marketing emails) require your separate, withdrawable consent.
The legal bases are Articles 6(1)(b), 6(1)(f), 6(1)(c) and 6(1)(a) of the GDPR. You may object to processing carried out under our legitimate interests on grounds relating to your particular situation (see §9).
4. Data you upload about other people
When you upload personal data of buyers, owners, agents, employees, service-partner staff or other third parties (for example a buyer-lead row in your mini-CRM, proof-of-funds documents from a buyer, a buyer’s identity card, a counterparty’s email in a representation contract, or the name and phone number of a client you invite to view an off-market property), you are the controller of that data and we act as your processor. You are solely responsible for having a lawful basis to upload it, for informing the data subjects as required by law, and for honouring any rights they assert. We will not respond to such requests on your behalf except to route them to you.
5. Audience-specific notes
Owners & sellers: your address and exterior identifying photos can be anonymised on the public marketplace via the “Anonymise” toggle on each listing. Verified agencies can still see full details to pitch. Listing fields you mark as “internal notes” are not shown to agencies.
Buyers: offers route through the listing’s representing agency. The agency receives your name, contact details, offer amount, funding source, and any conditions you submit. We do not share your search criteria or saved properties with sellers without an offer. Match notifications you receive are based only on your saved search profile and the listing’s public fields.
Enquiries without an account: if you use the enquiry form instead of signing up, we hold what you tell us there (your name, email, phone, and your budget, areas and requirements or your property’s location and rough value) solely to contact you about that enquiry and to introduce you to suitable agencies. It is never published, and it is not used to create an account for you. If you never take it further, we delete the enquiry within 24 months. Ask us sooner and we delete it sooner.
Sales agencies: we publish your agency profile to owners and buyers so they can compare agencies. That includes your registered legal name and address, company registration and VAT numbers, the professional register you are entered in and your number in it, your business contact details, the year you were founded, the regions you cover, your rating and your track-record summary. Most of that is business information rather than personal data, but where you trade as a sole trader your registered details may also identify you personally, so we say plainly that they are published. Licence and insurance expiry dates are held so we can prompt you before they lapse; the uploaded documents themselves stay in private storage, are seen only by our reviewers, and are never published. Internal pitch drafts and your CRM data are visible only to your team. The daily “who to call” digest is computed only from buyer-lead rows you have entered.
Service partners: we publish your verified directory entry (brand, category, description, member-discount, rating). Quote requests reveal the requesting owner’s name and listing.
5a. The off-market network: private property links
The off-market network lets an agent share a property that is not publicly listed with named individuals only. Because that feature deliberately records who looked at what, it deserves to be set out plainly rather than buried in a list.
Who is responsible for what
The agent who creates the property card decides who is invited, what each person may see, and how long their access lasts. For the personal data of the people they invite, that agent is the controller and we are their processor. The agent is responsible for having a lawful basis to hold and use your details and to record your activity, and for telling you that they do. We provide the mechanism; we do not choose who is invited and we do not read the cards.
What we record when you open a private link
- The name and contact details the agent recorded for you, plus any correction or addition you make at the confidentiality gate.
- Your acceptance of the confidentiality terms: the name you gave, the version of the terms you accepted, and the date and time. This is kept as evidence of what was agreed, and is never edited or overwritten.
- Each visit: when it started, when you were last active, roughly how long you spent, and how many photographs you opened. Repeated requests within one sitting are grouped into a single visit rather than logged individually.
- Technical signals: your browser’s user-agent string and the country your connection appears to come from. We store a one-way fingerprint of your IP address, not the address itself: it lets us tell one visitor from another without keeping the address, and it cannot be reversed.
- A short-lived sign-in cookie, which is set after you accept the terms so that you do not have to re-enter your details on every page. It expires within twelve hours.
Photographs carry your name
Where the agent has enabled it, every photograph served to you has your name and the contact detail the agent holds for you rendered into the image before it reaches your browser. This means a screenshot or a saved copy identifies you as the person it was shown to. You are told this at the gate, before you accept and before any photograph is shown. If you do not want your name on the images, do not proceed, ask the agent to show you the property another way.
Who can see your activity
The agent who holds the mandate can see your visits. Where you were invited by a second agent acting between you and the mandate holder, that agent can also see your visits, and the mandate holder can see both. Nobody else can, not other viewers, not other agencies, and not the wider platform. Our staff access this data only where necessary to operate the Service, investigate abuse, or comply with a legal obligation.
Access codes sent to you by email
Where the agent has chosen email verification, we send a one-time code to the address the agent recorded for you, never to an address typed into the page, because that would defeat the purpose. Only a one-way fingerprint of the code is stored, the code expires within fifteen minutes, and the record is deleted within thirty days.
Your rights
You have the full set of GDPR rights over this data. Because the agent is the controller, the fastest route is to ask them directly. You may also write to dpo@farmhouse.app and we will identify the agent and route your request to them without undue delay. We will not delete or alter an agent’s access records on our own initiative, because doing so would destroy the record of an agreement you entered into, but we will tell you what is held, tell you who holds it, and pass on your request.
Legal bases: performance of the contract you enter into when you accept the confidentiality terms (Article 6(1)(b)), and the legitimate interests of the agent and the property owner in keeping a confidential sale confidential and in being able to demonstrate who was given access and on what terms (Article 6(1)(f)). You may object under Article 21 on grounds relating to your particular situation; the practical consequence of a successful objection is that access is withdrawn, because the record and the access are the same thing.
6. Retention
We keep your data while your account is active. After closure we delete it within 12 months, except where law requires longer retention (tax / accounting records: 6 years; audit logs: up to 7 years; signed representation contracts: per the contract’s own term).
For the off-market network specifically: visit records are kept for 24 months from the visit; acceptance records of the confidentiality terms are kept for the duration of the non-circumvention period they evidence and for a further 12 months after it ends, because their whole purpose is to be available if a dispute arises; one-time email codes are deleted within 30 days; passcode and link fingerprints are deleted with the invitation they belong to. Withdrawing someone’s access stops it immediately but does not erase the record that they once had it.
AI-tool inputs / outputs expire from cache after 90 days; rate-limit records after 30 days; chat threads with the Concierge after 12 months of inactivity. Back-ups roll off on a 30-day cycle.
7. Recipients & international transfers
We share personal data only with a small set of sub-processors bound by written confidentiality and data-protection obligations. We disclose the categories of recipients here, as permitted by Article 13 GDPR:
- a cloud-database and authentication provider;
- an application-hosting provider;
- an object-storage provider for documents and photos;
- a transactional-email provider;
- one or more AI sub-processors, used only when you choose to use AI features (text generation / image generation);
- a DNS and edge-network provider;
- a payment-processing provider, used only on paid plans.
Off-market photographs and documents are not shared with any AI sub-processor unless you separately choose to run an AI feature over them.
Data is primarily stored in the European Union. Where a sub-processor processes data outside the EEA, we rely on EU Standard Contractual Clauses or another valid GDPR Article 46 transfer mechanism with supplementary safeguards as required by Schrems II.
The full named list of sub-processors, with the country in which each operates and the role each plays, is available on request to privacy@farmhouse.app. We will notify workspace administrators by email of any material change to the list (e.g. swapping one vendor for another, or adding a new category) at least 30 days in advance, so they have an opportunity to object before the change takes effect.
If the business is reorganised, merged, acquired, or its assets are sold, personal data may pass to the successor as part of that transaction. It is not sold on its own, and it is not treated as a detachable asset: any recipient takes it subject to this Policy, for the same purposes and no wider ones. Where the change means a different controller or materially different processing, we will tell you before it takes effect so that you can exercise the rights in section 9, including closing your account, while the current terms still apply.
We are not responsible for the independent data-handling practices of any third party with whom you choose to communicate or contract through the Service (e.g. agencies, buyers, service partners). They are separate controllers.
8. Security & account protection
We use industry-standard technical and organisational measures consistent with Article 32 GDPR, encryption in transit and at rest, role-based access controls enforced in the database itself, audit logs, rate limits, deferred-password signup (no password hash exists for an account before admin approval), HIBP password-leak protection on password-set, and routine security reviews. Multi-factor authentication on administrative or financial-privilege accounts is mandatory.
Off-market material is held in private storage. No direct file link is ever issued: every photograph, video and document is delivered through an authorising proxy that re-checks permission on each request, so withdrawing access takes effect within seconds rather than when a link happens to expire. Link tokens and passcodes are stored only as one-way fingerprints.
Material you are shown is not yours to copy
Everything you can see through the Service, whether a public listing or a private off-market card, is shown to you so that you can decide whether to transact on it. It stays the property of whoever created it. Copying, downloading, republishing or redistributing it, or feeding it to a scraper or an AI model, is prohibited by clause 6.1 of the Terms of Service and may also infringe the rights of the owner, the agency or the photographer. Access is recorded, and we act on breaches.
What these measures cannot do
They control who can reach material. They cannot stop a person who has legitimately been given access from photographing their own screen, and no technology can. We therefore do not represent that content shared through the Service is copy-proof, screenshot-proof or incapable of being redistributed. Watermarking, access logging and the confidentiality terms are deterrents that make a leak attributable. They are not a guarantee that a leak cannot happen. Please read section 11 of the Terms of Service before relying on the feature.
No system is perfectly secure. To the maximum extent permitted by law, we cannot accept liability for security events caused outside our control, including (without limitation) compromised user credentials, devices or networks; a link or passcode you shared with the wrong person; content uploaded by you or any third party that itself contains malicious code or prompt-injection payloads; or attacks against our sub-processors’ infrastructure. If a personal-data breach affects your workspace, we notify you without undue delay (typically within 72 hours) so you can meet your own notification duties.
9. Your rights
Under the GDPR you have the rights to access, rectification, erasure, restriction, portability, objection, and to withdraw consent. To exercise any of them, write to dpo@farmhouse.app (or privacy@farmhouse.app). We respond within one month; this may extend by two months for complex requests. You can also lodge a complaint with the Spanish data-protection authority, AEPD. If your request concerns data uploaded to another user’s workspace, or the record of a private property link you were sent, that user is the controller, we will forward your request to them but cannot decide it on their behalf.
10. AI-assisted tools
Optional features use AI sub-processors to generate or transform content from inputs you supply, including: the Concierge Chat, property intake, buyer intake, photo triage, marketing-kit generation, AI Studio renders, valuation ranges, pitch scoring and generation, offer evaluation, document parsing, document verification, and proactive match explanations. Only the content necessary to produce the requested output is transmitted. The sub-processors are contractually prohibited from training any model on your data.
AI outputs are advisory only and may contain errors, hallucinations, mis-readings, omissions or fabrications. They do not constitute legal, financial, valuation, mortgage, tax, architectural or any other professional advice. You are solely responsible for reviewing every generated asset and field before publishing, sharing, signing, or relying on it. Confidence scores are heuristics, not guarantees. A manual path is always available alongside every AI feature; if you prefer not to use AI for any reason, do not feed your photos, documents or text into those flows.
11. Cookies & minors
We use strictly necessary cookies only, to keep you signed in, remember your locale and basic preferences, and (on a private property link) to hold your session after you accept the confidentiality terms. No advertising or analytics cookies are set without your prior consent. The Service is restricted to persons aged 18 or over and we do not knowingly process data of children. Please write to us if you believe otherwise and we will delete it.
12. Changes
We may update this Policy from time to time. The version number and date at the top reflect the current version. Material changes will be communicated by email or in-app notice. The policy in force at the time of any processing applies to that processing.