Security

Your agency's data, handled properly

You are trusting us with your client book. This page sets out exactly how that data is protected, who can reach it, where it goes, and how to get it back or have it deleted.

Encrypted in transit

Every request is served over TLS. In production the server refuses plain HTTP and sends Strict-Transport-Security with a one-year max-age and includeSubDomains, so browsers will not downgrade the connection.

Encrypted at rest

Stored credentials, meaning connected mailbox tokens and any API keys held on your behalf, are encrypted with AES-256-GCM as versioned envelopes rather than kept in plaintext.

Scoped access

Every data endpoint requires a per-account token; the admin surface sits behind a separate session. Session cookies are httpOnly, sameSite and secure-only in production, and authentication is rate limited against brute force.

Mailbox access stays narrow

If you connect a mailbox, ImmoEx reads only what it needs to classify property correspondence and extract viewing times. It does not send mail on your behalf without your action, and a message it judges unrelated to property is never shared with your team.

Who else touches the data

Three third parties are involved in running the service. Nobody else receives your data, and none of it is sold, shared with advertisers, or used to train a model on your behalf.

Sub-processorWhat it handlesWhen
AnthropicText and files submitted to any AI feature, in order to generate the responseWhenever you use the assistant, AI import, or listing enrichment
GoogleGmail and Calendar contents, via the official APIsOnly if you explicitly connect a mailbox or calendar
RailwayApplication hosting and the database volumeAlways, as the infrastructure provider

GDPR and your rights

For your own account data we are the controller. For the client records you enter, you are the controller and ImmoEx is the processor acting on your instructions, which is the correct arrangement for an agency holding data on the people it represents.

What we deliberately do not do

Some of the strongest guarantees are the absences.

Reporting a vulnerability

If you believe you have found a security issue, email contact@immoex.xyz with enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is resolved. Please give us a reasonable window to fix the issue before disclosing it publicly, and do not access, modify or delete data belonging to anyone else while investigating.

Data processing agreement

Agencies that need a signed DPA before onboarding can request one at contact@immoex.xyz. Tell us the legal entity name and we will return a copy for signature. For the full legal terms, see Terms and Privacy.