Premium real estate · Costa del Sol
Sign in Register your agency
📍 Marbella, Costa del Sol ✉ info@solendi.es
Schedule a demo
Sign in

Privacy policy

How we collect, use and protect your personal data.

Last updated: 2 October 2026

Who the controller is

The Solendi platform is operated by AVOCATURA COM SRL, registered office at Str. Nicolae Bălcescu nr. 56, demisol, Galați, 800001, Romania, tax code 16234725, intra-EU VAT number RO35052932, registered with the Trade Register under J17/380/12.03.2004. Data contact: info@solendi.es.

One distinction matters before any other, because it determines who you must approach to exercise your rights. Solendi involves two separate processing operations with different controllers:

Data Controller Processor
The agency account, its users, subscription billing and security logs Solendi —
Contacts, enquiries, properties, documents and messages the agency enters about its own clients The agency Solendi
The client account: the email address, language, creation and last sign-in dates, the agencies added to the account and the requests sent from it Solendi —

In plain terms: when an agency stores a buyer's record in Solendi, it is the agency that decides what it is used for and for how long. We merely host and process that data on its instructions. If you are a client of an agency and want to exercise your rights over your data, you must approach that agency; we will assist it technically.

By contrast, the account data itself — who works at the agency, when they signed in, what we invoice — we process as controller.

What data we collect

From platform users

First and last name, email address, password stored in hashed form, phone, profile picture if uploaded, language and time zone, role labels, last sign-in date, digitised handwritten signature if saved, and the secret for your two-factor authentication.

About the agency's clients

Whatever the agency itself chooses to enter. Typically: name and surname, email, phone numbers, language, country, city and address, search preferences, agent notes, history of contacts and viewings, and a record of the consent obtained. Where a transaction requires it, also NIE or DNI, IBAN, identity documents, proof of funds and anti-money-laundering questionnaires.

From communications

The content of messages exchanged through the platform, email synchronised from the agent's mailbox, WhatsApp messages where that channel is connected, and file attachments.

Technical and security data

IP address, browser identifier, the date and outcome of every sign-in attempt — including failed ones, with the email address used — and a record of which screens were used, without content, so we know which parts of the product are genuinely in use.

What is encrypted in the database

Stored encrypted, over and above the transport encryption that protects the whole connection: the NIE or DNI, the IBAN, handwritten signatures, the credentials of the mailboxes and portals you connect, and two-factor authentication secrets.

For transparency: the remaining fields — name, email, phone, address, notes and message bodies — are not encrypted field by field. They are protected by access control, by the isolation between agencies and by storage-level encryption, but we do not want to imply protection that does not exist.

What we use it for

  • Providing the contracted service: managing the agency's portfolio, its enquiries, properties, appointments and documents.
  • Authenticating users and protecting accounts against unauthorised access.
  • Assisting the agent's work with automated features: extracting data from a document, drafting text, classifying an enquiry, transcribing a voice note, scoring an enquiry under deterministic rules.
  • Invoicing the subscription and meeting our accounting and tax obligations.
  • Providing support and communicating material service changes.
  • Measuring, in aggregate, which parts of the product are used, to decide what to build. This count deliberately excludes our own team.

We do not use the data for advertising, we do not sell it, we do not disclose it for commercial purposes, and we do not build profiles with legal effects on individuals.

Legal basis for processing

Processing Basis
Providing the service to the agency and invoicing Performance of a contract — Art. 6(1)(b) GDPR
Processing the agency's client data As determined by the agency as controller; we act on its behalf — Art. 28 GDPR
Platform security and access logs Legitimate interest — Art. 6(1)(f) GDPR
Aggregate measurement of product usage Legitimate interest — Art. 6(1)(f) GDPR
Retention of anti-money-laundering and accounting records Legal obligation — Art. 6(1)(c) GDPR
Automatic voice transcription The agent's individual consent, withdrawable at any time
The client account Performing the service requested by the client — Art. 6(1)(b) GDPR

How we read the agent's mailbox

This feature deserves its own explanation, because it is the most intrusive in the product and should be understood before it is switched on. It is optional: it works only if an agent voluntarily connects their mailbox.

When they do:

  • The connection uses IMAP with an app password that the agent generates at their email provider and which we store encrypted. We do not yet use OAuth for this feature.
  • We read the inbox and also the sent folder, so that the conversation is complete from both sides.
  • Reading repeats every minute. On first connection we go back thirty days.
  • Before storing anything we discard newsletters, automatic replies, no-reply style senders, and messages too short to mean anything.
  • If the sender is a known contact of the agency, the message is filed in their conversation. Attachments are saved only in this case, up to 15 MB and only in document and image formats.
  • If the sender is unknown, the message is quarantined with its full body, so the agent can decide whether that person should become a contact. We do not create records automatically.

The consequence anyone connecting a mailbox must accept: personal or unrelated correspondence may end up in the agency's database if it arrives in that mailbox. We recommend connecting professional mailboxes only.

The client space and the client account

If you are a client of an agency that works with Solendi, you can come into contact with the platform in two ways.

The client space

The agency can send you a personal link. Through it you see what the agency has prepared for you: property selections, scheduled viewings, documents to sign and copies of signed ones, any anti-money-laundering questionnaire, and messages. The link is valid for 30 days; in the database we keep only a cryptographic fingerprint of it, not the link itself. The agency can close it at any time.

What you do in the space reaches the agency: confirming or rescheduling a viewing, your opinion after a viewing and your messages appear in your record, with your agent. The agency also sees when you last opened the space. All this data belongs to the agency, which processes it as controller.

The client account

From the space you received from an agency you can choose to keep that agency in an account, so that all the agencies you work with are in one place. You sign in with your email address and a 6-digit code, with no password. The code is valid for 10 minutes and is kept only temporarily, long enough to be checked.

For the account, Solendi is the controller and keeps only: the email address, the language, the dates the account was created and last used, the agencies you have added and the requests you have sent from the account. The legal basis is performing the service you ask us for — Art. 6(1)(b) GDPR.

A few things the account does not do:

  • No agency appears in the account unless you added it yourself, from the link it sent you — not even if it has you on record with the same email address.
  • An agency does not learn which other agencies you have in the account and sees nothing of your relationship with them.
  • You can keep an agency's space in the account only by signing in with the email address you gave that agency.

From the account you can ask each agency, separately, for a copy of your data or for its erasure. The request reaches your agent as a task to resolve, and the agency has one month to respond. From there you can also remove an agency from the account; your data stays with the agency, you simply no longer see it in the account.

Artificial intelligence and your data

Several features send data to language models operated by third parties. We prefer to describe this precisely rather than with a reassuring formula:

  • Identity documents and supporting evidence. When automatic data extraction from a document is used, the file is sent in full to the model provider, which returns the identified fields. This includes passports, DNI or NIE and proof of funds. If you do not want a document to pass through this feature, enter its data manually.
  • CVs. In the recruitment module, the CV is sent to the model in full in order to extract its data.
  • Email. The body of synchronised messages may be analysed to summarise the conversation and suggest the next step.
  • Voice notes. The audio file is sent as is to the transcription service.
  • Anti-money-laundering files. Here we did the opposite on purpose: the model receives only the risk level and the factors behind it. It never receives the NIE, the passport, the IBAN, the phone, the email or the surname.
  • Bank statements. When the agency uploads a statement to reconcile incoming payments, the file is read and discarded — it is not kept. Matching against the expected fees and rents is done first in our own system, without a model. Only if the agency asks the assistant for help with the rows still unmatched are those rows sent to the model, with the date, the amount, the transfer description and the names of the parties involved (the payer, the tenant or the client). The IBAN is never sent in full: it is replaced by its last four characters. To recognise the same payer the following month, we keep a cryptographic fingerprint of the account, from which the IBAN cannot be reconstructed.

In every case, text originating outside the system is cleaned before the instruction is built, so that an incoming message cannot manipulate the system's behaviour. Of each call we keep only metadata — feature, model, units consumed, cost and duration — never the content sent nor the reply.

Our providers do not use this data to train their models.

Who we share it with

We do not disclose data to third parties other than the providers we need in order to deliver the service, always under a processing agreement. This is the complete list:

Provider Purpose What it receives
Anthropic Language models Complete documents and CVs, text of messages and records, depending on the feature used; in payment reconciliation, at the agency’s request, the names of the parties in the statement rows left unmatched (without IBAN)
Groq Voice transcription The audio file
Cloudflare File storage Property photographs in a public bucket and private documents in a separate bucket with no public address
Stripe Subscription payment The agency's name and email, amounts. Card details never reach our servers
Meta Platforms Ireland WhatsApp Business, if the agency connects it Phone number and message content
Brevo System email (alerts, invitations, sign-in codes) Recipient address and the content of the notice
Google, Microsoft Sign-in, if that route is chosen Account identifier, name and email
OpenStreetMap Geocoding and points of interest Property addresses, not personal ones
European Commission (VIES) VAT number validation The agency's VAT number
Google Cloud Storage Backups An encrypted copy of the database and of private documents
Google Fonts Typefaces on public pages The visitor's IP address, by the mere fact of loading the file

We also disclose data where a competent authority lawfully requires it.

Transfers outside the EU

Two of our providers are established in the United States: Anthropic and Groq. Transfers rely on the standard contractual clauses approved by the European Commission, supplemented by the technical measures described above, among them the deliberate exclusion of identifiers from anti-money-laundering files.

The remaining providers deliver the service from within the European Union or have equivalent mechanisms in place.

How long we keep it

Data Period
Contact record of an agency client 24 months from the last genuine interaction, with 30 days' prior notice. The agency may set a different period
Anti-money-laundering files 10 years — Ley 10/2010, art. 25
Contacts with a signed contract 6 years from signature
Identity documents and proof of funds 5 years
Mandates, reservations, inter-agency agreements, invoices received 10 years
Listings captured from external portals 30 days active, then archived and deleted at 90
Recruitment applications 12 months
Access and security logs 24 months
Aggregate record of screen usage 400 days
Internal notifications 30 days once read, 90 in any case
Active session 120 minutes of inactivity
Backups 14 days on the server, 30 in external storage
The client space link 30 days, after which it no longer opens anything
The client account sign-in code 10 minutes
The client account Until you ask for its erasure. Erasing the account does not erase the data held by agencies, which is theirs

Conversations and their messages are kept while the agency account is active and are deleted with it.

How we protect the data

  • Each agency is isolated from the others in the database query layer itself, not merely in the interface.
  • Two-factor authentication is mandatory for all internal accounts.
  • Private documents are held in a bucket with no public address and are released only after permissions are checked.
  • An automatic control inspects text about to leave the agency towards a third party and blocks sending if it contains an IBAN, a NIE or the owner's phone number where the recipient must not see them.
  • Encryption in transit on all connections, and daily backups.
  • In the event of a security breach entailing risk, we will notify the competent authority within 72 hours and, where appropriate, the individuals affected.

Your rights

You may request access to your data, its rectification, its erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. You may also withdraw at any time any consent you gave, without affecting the lawfulness of processing before withdrawal.

Two honest clarifications:

  • If your data sits in an agency's portfolio, the request must be addressed to that agency, which is the one deciding about it. If you write to us, we will tell you who to approach and will assist the agency technically.
  • Erasure is carried out as irreversible anonymisation: we remove the name, email, phone, address, NIE and IBAN, and detach the record from any identifier, keeping only statistical data from which nobody is identifiable. We do not physically delete records, because that would break the integrity of the files the law obliges us to keep.
  • If you have a client account, you can ask for a copy or the erasure of your data directly from the account, separately for each agency. To erase the account itself, write to us at the address below.

We will respond within one month of receiving the request.

How to delete your data

If you want your data removed from Solendi, write to info@solendi.es, stating the name of the agency you dealt with, if you know it, and the email address or phone number under which you appear.

If you have a client account and want to close it, write to us from the account's email address. We erase the address, the language and the links to agencies; your data at each agency stays there, and for that you contact the agency or use the request in the account before closing it.

We will verify your identity before acting — normally by confirming the request from the registered email address — and will pass the request to the responsible agency, which has one month to resolve it. When erasure is carried out, your identifying data is removed irreversibly as described in the previous section.

If the channel through which we came into contact was WhatsApp, you may request deletion through that same channel by writing the word STOP, and equally by email to the address above.

Documents we are required to retain by law are excluded from immediate erasure; they are deleted when the periods set out in the retention section expire.

Cookies and similar technologies

Solendi uses no analytics, advertising or tracking cookies. We use only those strictly necessary to maintain the session and protect forms. The detail is in the Cookie policy.

How to lodge a complaint

If you believe we have handled your data improperly, we would be grateful if you told us first at info@solendi.es: almost everything is resolved sooner that way.

In any event, you have the right to complain to a supervisory authority. As Solendi is established in Romania, the competent authority for our own processing is the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP, Bucharest). If you reside in Spain you may equally approach the Spanish Data Protection Agency (AEPD, www.aepd.es), or the authority of your country of residence.

For processing decided by an agency, the competent authority will be that of the country where the agency is established.

Changes to this policy

We will update this document when the processing, the providers or the applicable rules change. The effective date of the version you are reading appears at the top of the page, and earlier versions are retained. Material changes are notified to agencies thirty days in advance.

Questions about this page
For any question about this document, write to us at info@solendi.es.
Back to the home page