Privacy Policy
This policy explains how Caeiro ("Caeiro", "we", "us"), a product of RealUtil operated by Yuval Kleinfeld in Portugal, handles personal data when an estate agent ("you") uses Caeiro for Business.
1. Two roles, two kinds of data
Caeiro handles personal data in two distinct capacities. Which one applies depends on whose data it is.
- Your own account data — we are the controller. The data you give us to open and run your account (your name, WhatsApp number, email, billing details, and your use of the service) is processed by us as the data controller. This policy governs it.
- Your clients' data — you are the controller, we are the processor. When your buyers or leads talk to your Caeiro assistant, the personal data in those conversations belongs to your business. You are the controller; we only process it on your instructions, under a separate Data Processing Agreement (DPA). The DPA, not this policy, governs that data.
2. What we collect (your account)
- Identity and contact: your name, WhatsApp phone number, email address.
- Account and usage: the entities you create, settings, and operational logs needed to run and support the service.
- Your messages to your Caeiro assistant and any media you send it.
- Payment details when you pay for a plan, handled by our payment providers (Ko-fi and PayPal).
3. Why we process it
To provide, operate, secure, and support the service you signed up for. The lawful basis is performance of a contract (GDPR Article 6(1)(b)). Where we rely on legitimate interests (for example, securing the service against abuse), we do so under Article 6(1)(f). Any marketing messages would require your separate consent (Article 6(1)(a)).
4. Who we share it with (sub-processors)
We use the following sub-processors. Each acts only on our instructions and under a data processing agreement.
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic | AI model inference | US |
| OpenAI | AI model inference | US |
| AI model inference | US / EU | |
| Groq | AI model inference (fallback) | US |
| Mistral | Internal classification & translation tasks | EU (France) |
| Meta / WhatsApp | Messaging transport | US + global |
| Hetzner | Hosting (primary servers) & backup storage | EU (Germany) |
| Cloudflare | Website delivery / CDN | Global edge |
| Ko-fi | Payment / membership platform | UK |
| PayPal | Payment processing (via Ko-fi) | EU (Luxembourg) / US |
We keep an up-to-date sub-processor list and give at least 30 days' notice before adding a new sub-processor.
5. The AI providers do not train on your content
The AI providers above run our requests under their paid API terms, on which your content is not used to train their models. They may retain request data for a short period for abuse monitoring (typically around 30 days on standard terms) after which it is deleted; zero-retention terms are available from some providers on request.
6. Where your data goes (international transfers)
Some sub-processors are in the United States, so your data may be transferred outside the EEA. Google and Meta are certified under the EU-US Data Privacy Framework (verified June 2026), so transfers to them rely on that. Anthropic, OpenAI, and Groq are not on the Data Privacy Framework list, so transfers to them rely on the EU Standard Contractual Clauses in their data processing agreements. You can check the current status of any provider on the official list at dataprivacyframework.gov/list. Payments are handled by Ko-fi (UK, covered by the UK adequacy decision) and PayPal (EEA payments are handled by its Luxembourg entity; PayPal is not on the Data Privacy Framework list, so any onward US transfer relies on the Standard Contractual Clauses).
7. How long we keep it
We keep your account data for as long as your account is active, and for up to 30 days after you ask us to delete it, to complete deletion across our systems and backups. Backups rotate on a roughly 30-day cycle. Where law requires us to keep certain records (for example, accounting records), we keep those for the legally required period (GDPR Article 17(3)).
8. Where it is processed
Primary processing runs on a dedicated server we operate in the EU (Hetzner, Germany); backups are also stored in the EU (Hetzner, Germany). Data is encrypted in transit, and access is limited to the operator. We do not use end-to-end encryption, because your messages are processed in clear text in order to answer them.
9. Your rights
Under the GDPR you have the right to access (Article 15), rectify (16), erase (17), restrict (18), port (20), and object (21). To exercise any of them, email contact@realutil.com. We respond within one month. You also have the right to complain to the Portuguese supervisory authority, the CNPD (cnpd.pt).
10. Security
We protect data with encryption in transit (TLS), encryption at rest for backups, and access controls. No system is perfectly secure; we do not claim end-to-end encryption, because your messages are processed in clear text by the service in order to answer them.
11. Cookies
We use only strictly necessary cookies — for login, session, and demo access. We do not use analytics, advertising, or tracking cookies, so no cookie-consent banner is required. Some features also use your browser's local storage to keep your chat history handy on your device.
12. Changes
If we change this policy materially, we will update the effective date above and notify account holders.
13. Contact
Yuval Kleinfeld · NIF 314122370 · Portugal · contact@realutil.com