You are trusting us with your client book. This page sets out exactly how that data is protected, who can reach it, where it goes, and how to get it back or have it deleted.
Every request is served over TLS. In production the server refuses plain HTTP and sends Strict-Transport-Security with a one-year max-age and includeSubDomains, so browsers will not downgrade the connection.
Stored credentials, meaning connected mailbox tokens and any API keys held on your behalf, are encrypted with AES-256-GCM as versioned envelopes rather than kept in plaintext.
Every data endpoint requires a per-account token; the admin surface sits behind a separate session. Session cookies are httpOnly, sameSite and secure-only in production, and authentication is rate limited against brute force.
If you connect a mailbox, ImmoEx reads only what it needs to classify property correspondence and extract viewing times. It does not send mail on your behalf without your action, and a message it judges unrelated to property is never shared with your team.
Three third parties are involved in running the service. Nobody else receives your data, and none of it is sold, shared with advertisers, or used to train a model on your behalf.
| Sub-processor | What it handles | When |
|---|---|---|
| Anthropic | Text and files submitted to any AI feature, in order to generate the response | Whenever you use the assistant, AI import, or listing enrichment |
| Gmail and Calendar contents, via the official APIs | Only if you explicitly connect a mailbox or calendar | |
| Railway | Application hosting and the database volume | Always, as the infrastructure provider |
For your own account data we are the controller. For the client records you enter, you are the controller and ImmoEx is the processor acting on your instructions, which is the correct arrangement for an agency holding data on the people it represents.
Some of the strongest guarantees are the absences.
robots.txt and an enforcing X-Robots-Tag.If you believe you have found a security issue, email contact@immoex.xyz with enough detail to reproduce it. We will acknowledge within two working days and keep you updated until it is resolved. Please give us a reasonable window to fix the issue before disclosing it publicly, and do not access, modify or delete data belonging to anyone else while investigating.
Agencies that need a signed DPA before onboarding can request one at contact@immoex.xyz. Tell us the legal entity name and we will return a copy for signature. For the full legal terms, see Terms and Privacy.