Data Protection

This privacy policy applies to all offerings under the domain www.nestiq.io, including all subdomains (subpages).

1. Introduction to our privacy policy and procedures

The service available at www.nestiq.io is provided by Immooly GmbH (“the company,” hereinafter referred to as “we,” “us,” or “our”), Demetriusweg 11, 70563 Stuttgart, Germany, and is legally represented by its managing director, Dinesh Brull. Immooly GmbH is the controller within the meaning of applicable data protection law.

At nestIQ (owned and operated by Immooly GmbH), we firmly believe that personal data belongs to our users and not to us. Therefore, we do not share or use personal data without the express permission of the customer, unless this is expressly permitted under the contracts concluded with us or required by law under certain circumstances. We attach great importance to the protection of your personal data and have taken measures to ensure compliance with the European Union's General Data Protection Regulation (GDPR). With this in mind, we are committed to adhering to the following data protection principles in general:

  • Lawfulness, fairness, and transparency: The company will process personal data in a lawful, fair, and transparent manner and will inform data subjects about the processing of their data.
  • Purpose limitation: The company will collect and process personal data only for specified, explicit, and legitimate purposes. It will ensure that the data is not used in a manner incompatible with those purposes.
  • Data minimization: The company collects and processes only the personal data that is necessary to fulfill the specified purposes. It ensures that the data is factually correct and up to date.
  • Storage limitation: The company stores personal data only for as long as is necessary to fulfill the specified purposes. It will take appropriate measures to ensure the protection of the data.

You can use our website and services without revealing your identity, but with certain restrictions. Some services require proper identification, and we are legally obligated to collect a minimum amount of personal data from our users on behalf of Immooly GmbH.

The following sections contain detailed information about how we collect, use, disclose, and store personal data through your use of the “nestIQ” platform and other electronic or non-electronic media controlled by us. In this privacy policy, we will also explain your legal rights in this matter.

Please note that our services are currently only intended for persons residing in Europe and that our privacy policy applies to all services we offer. It does not extend to linked websites or third-party online platforms.

2. Responsible party & questions

2.1 Responsible party

The entity responsible for processing personal data within the scope of this privacy policy is:

immooly GmbH

Demetriusweg 11

D-70563 Stuttgart

2.2 Questions about data protection

If you have any questions about data protection in relation to our company or our website, or if you wish to make a complaint regarding data protection issues, you can contact our data protection officer.

Data Protection Officer:
[email protected]

Address:
immooly GmbH

Demetriusweg 11

D-70563 Stuttgart

3. Your individual rights under the GDPR

Under the EU General Data Protection Regulation (GDPR), individuals have several rights regarding the processing of their personal data. These rights are set out in various articles of the GDPR. Here are some of the rights of individuals and the corresponding article numbers:

  1. Right to information (Articles 13 and 14): Individuals have the right to be informed by the controller about the collection and use of their personal data. Organizations must provide clear and transparent information about the purposes, legal bases, retention periods, and other relevant details of data processing.
  2. Rights of access of the data subject (Articles 12 and 15): Individuals have the right to access their personal data and obtain information about how it is processed. They can request a copy of their data and be informed about the purposes, categories of data, recipients, and other relevant details.
  3. Right to rectification (Article 5(1)(d), Articles 12, 16, 19): Individuals have the right to request the rectification of inaccurate or incomplete personal data. If the data has been disclosed to third parties, organizations must inform them of the rectification, unless this is impossible or involves disproportionate effort.
  4. Right to erasure (Articles 6, 9, 17): Also known as the “right to be forgotten,” individuals have the right to request the erasure of their personal data. This right is not absolute and may be restricted in certain circumstances, such as when data processing is necessary to comply with a legal obligation.
  5. Right to restriction of processing (Article 18): Individuals have the right to request that the processing of their personal data be restricted. This means that organizations may store the data but may not use it for other purposes until the restriction is lifted.
  6. Right to data portability (Article 20(1)): Individuals have the right to receive their personal data in a structured, commonly used, and machine-readable format. They may also request that their data be transferred to another organization, provided that this is technically feasible.
  7. Right to object to processing (Article 21): Individuals have the right to object to the processing of their personal data, including profiling. Organizations must stop processing the data unless they can demonstrate compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the individual.
  8. Rights relating to automated individual decision-making and profiling (Article 22(1)): Everyone has the right not to be subject to a decision based solely on automated processing, including profiling, if that decision significantly affects them. Exceptions apply if the decision is necessary for the performance of a contract, is permitted by law, or is based on explicit consent.
  9. Right to withdraw your consent (Article 7(3)).
  10. Right to lodge a complaint with a data protection supervisory authority regarding our processing of your personal data (Article 77).

4. What information nestIQ collects and processes

When you register with nestIQ to use the services we offer or to publish your property listing, you can create a user account. This account allows you to manage your data (including account settings, contact details, saved searches, messages, etc.) in the relevant areas. To register, you only need to provide a valid email address and a username. Additionally:

  • As a real estate provider, we store the information you enter in connection with your real estate advertisement and the associated services. This includes, for example, your name and contact details, as well as data about the property you are advertising.
  • As a subscriber to newsletters and emails with promotional content, we store your email address and other information about the newsletter you have subscribed to (category, frequency setting, time of unsubscription) and about your usage behavior on our offers. You can unsubscribe from these emails at any time by clicking on the corresponding link at the end of the newsletter.
  • When using our social media content, all data required to use the functions of our offerings is processed or stored. In addition, the social media platform may collect information about you via your device using cookies and other technologies.
  • As a real estate agent, seller, buyer, or even just a visitor, we store the information you enter when searching for our potential offers in order to provide you with the appropriate functionality of the services.
  • When you provide us with feedback, all data required for the duration of the feedback evaluation will be stored temporarily.

4.1 Information you provide to us directly or indirectly

  1. Personal data: This includes information that can directly identify a person, such as name, address, email address, phone number, social security number, or other unique identifier.
  2. Demographic information: This includes data about a person's age, gender, nationality, ethnicity, language, or other similar characteristics.
  3. Usage data: This includes data about how individuals interact with the website or online services, such as IP addresses, browser type, device information, operating system, clickstream data, and other usage patterns.
  4. Geolocation information: This includes data that can be used to determine a person's physical location, either through GPS coordinates or information derived from their IP address.
  5. Cookies and tracking information: This includes data collected through the use of cookies, web beacons, and similar technologies that can track users' behavior, preferences, and interests.
  6. Payment information: This includes data related to financial transactions, such as credit card details, bank account information, or other payment methods used for purchases or subscriptions.
  7. Information from social media: This includes data originating from social media platforms, such as profile information, social connections, or content shared on these platforms.
  8. User-generated content: This includes all information, text, images, videos, or other content that users voluntarily transfer or upload to the website or online services.

4.2 Automatically collected information & access data

4.2.1 Automatically collected information

We also receive and store certain types of information when you interact with our website and its services. We automatically receive access data. This data cannot be attributed to a single person and is not used to identify an individual.

We may use this data to develop new services or improve existing ones, and it may be passed on to third parties in order to provide users with the services they require. In addition, we collect data about your usage behavior on our information, offers, services, and tools using cookies and other tracking methods.

4.2.2 Access data

When a person interacts with our website, the website may receive and store various types of information. Some common examples are:

  1. IP address: The website may receive and store the IP address of the user's device. This helps to identify the approximate location of the user and may be used for security purposes.
  2. Cookies: Our website uses cookies to store information about the user's preferences, login status, and browsing behavior. These cookies can be used to personalize the user's experience and track their activities on the website.
  3. User agent: The website can obtain and store information about the user's web browser, operating system, and device type. This helps optimize the display and functionality of the website for different devices.
  4. Form data: When the user fills out a form on the website, the website can receive and store the information entered by the user. This may include personal details, contact information, and any other data requested in the form.
  5. Clickstream data: The website can track the user's navigation path within the website, including the pages visited, links clicked, and actions taken. This data helps analyze user behavior and improve the design and content of the website.
  6. Referrals: The website can receive and store the URL of the previous website that led the user to the current website. This information is useful for understanding the source of traffic and optimizing marketing efforts.
  7. Analytics data: Websites often have analytics tools built in that collect and store data about user interactions, like page views, time spent on each page, and conversion rates. This data helps measure how well the website is doing and makes data-driven decisions.
  8. Browser information: The website may collect details about the visitor's web browser, such as the browser type, version, and language settings. This information helps to optimize the display and functionality of the website.
  9. Operating system: The website may collect information about the visitor's operating system, such as the type and version. This helps to ensure compatibility and provide a better user experience.
  10. Page interactions: The website may collect data about how visitors interact with the site, such as clicks, scrolling behavior, and form submissions. This information helps to improve the design and functionality of the website.

4.3 Information collected using cookies

When you visit a website, small text files called cookies are stored on your device, such as a computer or mobile device. These cookies are created by the website and store information about your browsing behavior, preferences, and other data. Cookies are used on websites for various purposes, such as session management, personalization, tracking and analysis, advertising, shopping carts, e-commerce, and security. The use of cookies may be necessary for technical reasons or for other purposes, such as analyzing and evaluating website usage. This privacy policy applies only to our use of cookies and does not extend to the use of cookies by third parties, including our third-party partners and service providers.

In addition to the access data already mentioned, cookies are also stored in your Internet browser when you use our website. These cookies are small text files with numbers that are stored locally in your browser's cache. They do not become part of your computer system and cannot execute any programs. The purpose of these cookies is to improve the user-friendliness of our website.

4.3.1 Technically necessary cookies

These cookies, also known as essential cookies, are necessary for a website to function properly. These cookies are essential for providing basic functionality and ensuring a seamless user experience. Here is a list of some common technically necessary cookies:

  1. Session cookies: These cookies are used to obtain information about the user session, such as login status, during a browser session. They are essential for the proper functioning of the website.
  2. Authentication cookies: These cookies are used to authenticate and identify a user once they have logged in. They are necessary to enable access to restricted areas of a website.
  3. Cookies for consent management: These cookies are used to store the user's preferences regarding the use of cookies on a website. They are necessary to comply with data protection regulations.

The user data collected by technically necessary cookies is not used to create user profiles. We also use session cookies, which store a session ID so that various requests from your browser can be linked to the same session. Session cookies are essential for the use of the website, in particular to recognize the device you are using when you visit the website again. If you have an account with us, we use this cookie to identify you on subsequent visits so that you do not have to log in each time. The legal basis for this processing is Article 6(1)(f) of the General Data Protection Regulation (GDPR). We use session cookies to increase the attractiveness and effectiveness of the website. These session cookies are deleted when you log out or close your browser.

4.3.2 Cookies that are not technically necessary

Cookies that are not technically necessary are cookies that are not essential for the functioning of a website or the provision of a service. These cookies are often used for non-essential purposes, such as tracking user behavior for advertising or analysis purposes. We also use cookies on the website that enable analysis of users' surfing behavior. The following data, for example, is stored and processed in the cookies:

  • Search terms and parameters
  • Frequency of page views
  • Use of website functions

These cookies are also used to improve the efficiency and attractiveness of the website. The legal basis for this processing is Article 6(1)(f) of the General Data Protection Regulation (GDPR). Cookies that are not technically necessary are automatically deleted after a certain period of time, which may vary depending on the cookie. You have the right to object to the processing of your data by cookies. If you prefer not to use cookies, you can change your browser settings to selectively or completely block or remove cookies. You can also choose to receive instructions before a cookie is set. Please note, however, that changing your browser settings or disabling cookies may limit the functionality of this website. If we incorporate third-party cookies on our website, we will inform you separately below.

5. Legal basis for data processing and purpose of use

5.1 Legal basis for data processing

According to the GDPR, there are several types of legal bases for data processing. Those used by Immooly GmbH are listed below:

  • The legal basis for processing personal data on the basis of consent is Article 6(1)(a).
  • The legal basis for the processing of personal data based on contractual relationships is Article 6(1)(b).
  • The legal basis for processing personal data to fulfill a legal obligation is Article 6(1)(c).
  • The legal basis for processing personal data to protect the vital interests of you or another natural person is Article 6(1)(d).
  • The legal basis for processing personal data based on the legitimate interests pursued by Immooly or a third party is Article 6(1)(f), unless these interests override your interests or fundamental rights and freedoms.

If the legal basis is your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.

If the legal basis is a legitimate interest, you also have the right to object to the processing of personal data concerning you at any time for reasons arising from your particular situation. In this respect, Art. 21 GDPR applies.

5.2.1 Enabling all users to use our platform and the associated services

Your data will primarily be processed in order to provide you with personalized features tailored to your individual interests in the handling of real estate transactions. These can be listed as follows:

  • Services listed on the platform (Article 6(1)(a)). The legal basis for the processing of personal data based on consent is Article 6(1)(a).
  • Verification of registration on our platform (Article 6(1)(b))
  • Various types of contractual agreements. In certain cases, tools may also be necessary for the performance of a contract or for the implementation of pre-contractual measures; in this case, processing is carried out in accordance with Article 6(1)(b) and (c).
  • Publication of your exposé and the associated information on various platforms as well as on nestIQ (Article 6(1)(a), (b), and (c)).
  • Improvement of functionality and optimization of the platform and other related technologies and processes (Article 6(1)(f)).
  • Analysis of the platform to determine user behavior (Article 6(1)(a)).
  • Display of online advertising (which may involve the use of cookies and other technologies). We also process your data for direct email marketing and for security and legal tracking purposes. We use tools that are necessary for the operation of our website based on our legitimate interest pursuant to Article 6(1)(f) of the GDPR.

In addition, we may process your data for other purposes listed below, specifying the relevant legal basis.

5.2.2 Creating and maintaining a trustworthy and secure environment

To detect and prevent fraud, spam, abuse, security incidents, and other harmful activities; to implement fraud prevention measures, security checks, and risk assessments; to verify or authenticate the information you provide; to perform checks against databases and other sources of information, including background checks, to comply with our legal obligations and protect the health and well-being of users, to resolve disputes with our members, to enforce agreements with third parties, to comply with laws, to respond to legal requests, to prevent harm, and to protect our rights. The legal basis is the legitimate interest and vital interest of users (Article 6(1)(d) and (f)).

5.2.3 Statistical analysis

By using our services, we create anonymous usage profiles for statistical evaluation. It should be noted that we store and process property data (such as address, size, location, price, etc.) beyond the duration of the advertisement for statistical evaluations. If this data can be linked to you personally, it constitutes personal data, which we process on the basis of our legitimate interests (Article 6(1)(f) GDPR) in order to improve our services and develop new ones. On our website, we use Google Analytics, a web analytics service provided by Google Ireland Limited (Ireland, EU). Google Analytics uses cookies to collect and analyze data about visitor behavior on our website. This includes personal data in the form of online identifiers (including cookie identifiers), IP addresses, device identifiers, and information about interactions with our website.

Google Ireland will process the collected data on our behalf in order to evaluate user activity on our website, compile reports on website activity, and provide us with other services related to website and internet usage. Pseudonymous usage profiles may be created from the processed data. We only use Google Analytics with IP anonymization enabled, i.e., the user's IP address is truncated by Google Ireland within member states of the European Union or in other countries of the European Economic Area. The user's IP address transmitted by your browser will not be merged with other data. For more information on data use for advertising purposes, please refer to Google's privacy policy at www.google.com/policies/technologies/ads/.

5.2.4 Plugins

To improve the functionality of our websites and apps, we use software plugins provided by external manufacturers. These plugins include:

  • Google Ads
  • Google Tag-Manager
  • Mailer Lite
  • HubSpot
  • X2
  • Google Analytics
  • AWS SES

As part of this process, providers may process your IP address and, where applicable, other data that indicates human interaction and is collected when you access the website. Detailed information about the providers' privacy policies can be found on their respective websites. The data processing described above is based on legal provisions that permit the processing of personal data, as Immooly GmbH has a legitimate interest in doing so (Article 6(1)(f)).

5.2.5 Creating market transparency and establishing a data lake

To generate market insights within our organization, we may analyze the property data provided by our advertisers (such as property address, size, location, asking price, actual notarized sale price, etc., without names or other specific communication details of the advertiser or owner). This analysis helps us to create a data lake that enables Immooly GmbH to gain valuable market insights. Before evaluation, all information about the advertiser of the respective property is anonymized. The processing of this data is based on our legitimate interests (Art. 6 (1) (f)) in an economic evaluation of the real estate data.

5.2.6 Provision, personalization, measurement, and improvement of our advertising and marketing

We may use the information you provide for the following purposes:

  • Sending advertising messages, marketing materials, advertisements, and other information based on your preferences, including advertising on social media platforms.
  • Personalization, evaluation, and improvement of our advertising measures.
  • Enabling referral programs, rewards, surveys, contests, sweepstakes, or other promotional activities or events sponsored or conducted by Nestiq or our business partners.
  • Analyzing your characteristics and preferences to send you advertising messages, marketing materials, advertisements, and other information that we believe may be of interest to you.
  • Invitations to events and relevant offers.
  • Sending advertising messages, marketing material, advertisements, and other information that may be of interest to you, based on your preferences and with your consent.

We use all other tools, especially those for marketing purposes, on the basis of your consent in accordance with Article 6(1)(a) GDPR when user profiles are created for advertising or market research purposes. Data processing with these tools only takes place if we have obtained your prior consent.

6. Transfer and disclosure of your personal data

We do not disclose your personal data to third parties (companies, organizations, individuals, etc.) outside of Nestiq. Exceptions, which only exist with your express consent, are described below.

If you give your consent, we will share your data in accordance with the terms and conditions specified at the time of consent. This may include, for example, authorizing an external application or website to access your Nestiq account or participating in promotional campaigns with Nestiq affiliates or third parties. In accordance with applicable laws, we may also use certain personal data, such as your email address. However, before we share this information, we anonymize or pseudonymize it and then share it with third-party providers to generate leads and increase traffic to our platform. The following are the events that lead to the sharing of your data in order to provide you with the services you request and to make our services competitive.

6.1 Disclosure in connection with the provision of our services

As part of providing our offers and the associated functions and services, we pass on your data to providers and interested parties of real estate functions, e.g. when you use the respective service that requires information to be transmitted. You will receive further information about the recipient or category of recipients and the purpose of the respective data transmission in separate information texts before you use the respective data transmission.

6.2 Disclosure of information within the internal structures of Immooly GmbH

Certain personal data, such as the data provided by the user during registration, may be shared within our group of companies for internal administrative purposes, including joint customer service and analysis, where necessary and permitted by law. This sharing is done in accordance with legal provisions that allow us to process personal data when necessary for the provision of a service or the fulfillment of a contract (Article 6(1)(b)).

6.3 Shared use by members

In order to facilitate services or other interactions between users, we may need to share certain information. The seller's information may be made available to potential buyers, real estate appraisal committees, building inspection authorities, the Department of Justice, etc. The buyer's information would be transmitted to the seller via a third-party service if the buyer expressly requests this.

6.4 Service providers contractually obligated to protect personal data

In certain cases, we use service providers to perform specific data processing activities. These service providers are bound by our instructions and process the data on our behalf in accordance with Article 28 of the GDPR. We have entered into appropriate data protection agreements to ensure that this transfer and processing of data is permissible without the need for a separate legal basis. The areas in which we engage these companies include IT, sales, marketing, finance, consulting, and customer service. However, such transfers are made in accordance with applicable data protection laws. If the European Commission has not classified a third country as providing an adequate level of protection, we take appropriate measures to ensure the protection of your data.

(http://ec.europa.eu/justice/data-protection/international-transfers/transfer/index_en.htm)

6.5 Service companies

We may share personal data with affiliated and non-affiliated service providers (and their service providers) to facilitate the operation of our business and to fulfill their compliance purposes. This includes companies that assist us with: (i) verifying your identity or authenticating your identification documents; (ii) matching information with public databases; (iii) conducting background checks, fraud prevention, security checks, and risk assessments; (iv) performing product development, maintenance, and improvements; (v) enabling the provision of our services through third-party platforms and software tools (e.g., through integration with our interfaces); (vi) providing support, advertising, or payment services to us; These companies have access to your personal data in order to perform these tasks. They are contractually obligated to protect your personal data.
These service providers may use other services to process your data, such as email programs or software products that support Nestiq. These services are beyond our control and are subject to applicable laws worldwide, which may have different data protection regulations. However, these providers are bound by the laws of their respective jurisdictions regarding the protection of personal data.

6.6 Transfer to third countries

If data is transferred to third countries (countries outside the European Union or the European Economic Area) or personal data is processed there and the level of data protection there does not correspond to that of the European Union, and if no adequacy decision (Art. 45 GDPR) for these countries, we will take appropriate measures to ensure that an adequate level of data protection is guaranteed for such data transfers. These include, for example, the standard contractual clauses of the European Union or binding internal data protection regulations. If this is not possible, we invoke exceptions under Art. 49 GDPR, in particular your express consent or the necessity of the transfer for the performance or initiation of a contract.

If we transfer personal data to another country and there is no explicit confirmation of the adequacy of data protection measures or appropriate safeguards, there is a potential risk that authorities in that country (e.g., police authorities) may access the transferred data for analysis. This could mean that your data protection rights may not be fully enforceable. We would also inform you about such transfers when you give your consent via our cookie banner.

7. Storage period for personal data at Immooly GmbH

In accordance with the GDPR, personal data should be stored by a digital platform such as Nestiq for a reasonable period of time for the purposes of legal defense. The specific retention period may vary depending on the applicable legal requirements and the type of data.

As a digital do-it-yourself platform dealing with real estate transactions, it is important for us to store data in order to prove user consent and to fulfill any legal obligations relating to real estate data, contracts, etc. However, we have established and documented specific retention periods based on the principle of storage limitation. We regularly review and delete unnecessary data to ensure compliance with data protection regulations.

Your personal data will be stored for as long as necessary to fulfill the aforementioned purposes or as required by law. After that, the data will be routinely blocked, deleted, or anonymized in accordance with legal requirements. Your registered accounts will not be deleted unless you expressly request this, even if you have not used your account for 10 years. If you request the deletion of your account, it will be physically deleted after a waiting period of 14 days. However, we may need to retain the data for legal reasons or to protect our legitimate interests. In such cases, the data will not be deleted or anonymized, but blocked for further processing. If there are legal retention obligations, such as those under the German Commercial Code (HGB) and the German Fiscal Code (AO), we are obliged to retain your data for up to ten years before we finally delete it. If your data is passed on to third parties when you use our services (e.g., when contacting real estate sellers or government agencies), these third parties are responsible for storing and deleting your data. You have access to the contact details of these third parties so that you can assert your rights directly with them.

8. Changes to the privacy policy

We are constantly developing our offering and continuously improving the services and quality of Nestiq. Any changes may affect the use of your personal data. The current data protection information can be accessed at any time on our homepage.

Present smarter.
Publish faster.

Exposé in minutes, social posts included, unlimited listings.

No fees. No subscription. Made for agents.

// Diesen Code in deine Webflow-Seite einfügen (vor ) document.addEventListener('DOMContentLoaded', function() { const form = document.querySelector('.w-form form'); const successDiv = document.querySelector('.w-form-done'); const errorDiv = document.querySelector('.w-form-fail'); if (form) { form.addEventListener('submit', async function(e) { e.preventDefault(); // Form-Daten sammeln const formData = { email: form.querySelector('input[type="email"]')?.value, name: form.querySelector('input[name="name"]')?.value, message: form.querySelector('textarea[name="message"]')?.value, source: window.location.pathname }; // Submit-Button deaktivieren const submitBtn = form.querySelector('input[type="submit"]'); const originalText = submitBtn.value; submitBtn.value = 'Wird gesendet...'; submitBtn.disabled = true; try { // An Google Apps Script senden const response = await fetch('https://script.google.com/macros/s/AKfycbzYj2akvRUGEe2b5efhVG6mzErigwoTm0wu8VKp1IQANkP_G9STHxqG--G3hA4eFuRXiw/exec', { method: 'POST', mode: 'cors', headers: { 'Content-Type': 'application/json', }, body: JSON.stringify(formData) }); const result = await response.json(); if (result.success) { // Erfolg anzeigen form.style.display = 'none'; if (successDiv) successDiv.style.display = 'block'; // Optional: Form nach 3 Sekunden zurücksetzen setTimeout(() => { form.reset(); form.style.display = 'block'; if (successDiv) successDiv.style.display = 'none'; submitBtn.value = originalText; submitBtn.disabled = false; }, 3000); } else { throw new Error('Submission failed'); } } catch (error) { // Fehler anzeigen if (errorDiv) errorDiv.style.display = 'block'; submitBtn.value = originalText; submitBtn.disabled = false; console.error('Form submission error:', error); } }); } });