Privacy Policy
Last updated: 2026-05-24
This policy describes how irrealista ("we", the "service") collects, uses, and protects your personal data when you use the site at irrealista.pt. It is written to comply with the General Data Protection Regulation (GDPR, EU 2016/679) and Portuguese Law 58/2019.
1. Who we are
For GDPR purposes, the data controller is irrealista, reachable at privacidade@irrealista.pt. We do not have a designated Data Protection Officer (we don't meet the statutory thresholds); the email above is the contact channel for all privacy matters.
2. What we collect
- Account: email (required, from Google OAuth or magic-link), name (optional), profile photo (optional, Google sign-in only).
- Contact: phone number (optional, stored only if you opt into WhatsApp notifications).
- Saved searches: the criteria you define (property type, zones, price range, features, keywords, etc.).
- Agent activity: records of offers sent on your behalf and seller responses.
- Technical data: IP address, browser type, pages visited, usage events (via Google Analytics 4 in cookieless mode — no persistent client-id storage).
3. How we use it
- Service delivery (contract performance, Art. 6(1)(b) GDPR).
- Notifications (contract + consent for optional channels like WhatsApp, Art. 6(1)(a) and (1)(b)).
- Marketing communications (consent, Art. 6(1)(a)) — only if you subscribed; unsubscribe via the link in every email.
- Product improvement and security (legitimate interest, Art. 6(1)(f)) — aggregate metrics and abuse detection.
4. Who we share with
We do not sell your data. We share only what's necessary with these processors:
- Google LLC — OAuth + Analytics (transferred to the US under approved Standard Contractual Clauses).
- Mapbox Inc. — interactive map rendering.
- Brevo (Sendinblue SAS, EU) — transactional and newsletter emails.
- Google Cloud Platform (Belgium, europe-west1) — application + database hosting.
- OLX Portugal — public source of monitored listings; we share the messages the agent sends on your behalf.
5. Retention
- Account + searches: as long as the account is active. Delete anytime via /perfil or by email.
- Agent activity: 24 months after the last offer sent.
- Newsletter subscribers: until you unsubscribe.
- Technical logs: 90 days.
6. Your rights
Under GDPR you can:
- Access your data (Art. 15)
- Correct inaccurate data (Art. 16)
- Delete your account and data (Art. 17)
- Restrict processing (Art. 18)
- Receive your data in a structured format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time (Art. 7(3))
Write to privacidade@irrealista.pt to exercise these rights. We respond within 30 days.
If you believe processing violates the law, you can lodge a complaint with the Portuguese Data Protection Authority (CNPD) at cnpd.pt.
7. Cookies
We use strictly necessary cookies (session, security) without requiring consent. Google Analytics runs in cookieless mode and respects the consent banner shown on first visit. Change preferences anytime via the "Cookies" link in the footer.
8. Security
HTTPS throughout, hashed auth tokens, database access controls, audit logs, and regular security updates. No system is 100% secure; in case of a breach posing high risk to your rights we notify you within the legal deadline (Art. 34).
9. Children
The service is for users 18+. We don't knowingly collect minors' data; accounts found to belong to minors without parental consent will be deleted.
10. Changes
We may update this policy. The date above reflects the last change; material changes are emailed to registered users.