1. Introduction
Keypilot ("we", "us", "Keypilot") places great importance on protecting your personal data. This privacy policy describes how we collect, use, store, and protect information when you use our property management services.
By using Keypilot, you agree to the practices described in this privacy policy. We act in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy legislation.
2. What Data We Collect
Personal Identification Data
- Name, email address, and phone number
- Billing address and business information
- Identification documents (if required for verification)
Property-Related Data
- Property information and addresses
- Tenant data and rental agreements
- Financial transactions and payment history
- Maintenance notifications and communication
Technical Data
- IP address and browser information
- Usage statistics and platform activity
- Cookies and similar technologies
- Device and connection information
3. How We Use Your Data
We use your personal data for the following purposes:
- Service Delivery:
Providing property management services and platform functionalities
- Account Management:
Creating, maintaining, and securing your account
- Communication:
Sending contract updates, payment reminders, and platform notifications
- Financial Management:
Processing payments and rental administration
- Compliance:
Meeting legal obligations and regulations
- Improvement:
Analyzing and improving our services
4. Legal Basis for Processing
We process your data based on:
- Contractual necessity:
For performing our services
- Legal obligation:
For compliance with tax and legal obligations
- Legitimate interest:
For platform security and fraud prevention
- Consent:
For marketing communication (with opt-out option)
5. Data Sharing
We never sell your personal data to third parties. We may share data with:
- Service Providers:
The subprocessors listed below (hosting, payment processing, email delivery and AI features), each bound by a data processing agreement
- Legal Requirements:
When required by law or regulation, or court order
- Business Transfer:
In case of merger, acquisition, or sale of assets (with notification)
All third parties are contractually obligated to protect your data in accordance with GDPR standards.
6. International Data Transfer
Your data is stored and processed within the European Economic Area (EEA) where possible. Where a subprocessor processes data outside the EEA (for example in the United States), the transfer only takes place under one of these safeguards:
- EU-approved standard contractual clauses
- Adequacy decisions from the European Commission (such as the EU-US Data Privacy Framework)
- Other legally recognized security mechanisms
7. Security of Your Data
We implement industry-standard security measures:
- TLS/SSL encryption for data transfer
- Encryption of sensitive data in storage
- Regular security audits and penetration tests
- Access controls and authentication mechanisms
- Regular backups and disaster recovery plans
Despite these measures, no online service can guarantee 100% security.
8. Retention Period
We retain your personal data as long as:
- Your account is active
- Necessary for service delivery
- Required by law or regulation (e.g., tax documentation: 7 years)
After account termination, your data remains available for export for 90 days and is then deleted or anonymized, unless legal retention obligations apply.
9. Your Rights under GDPR
You have the following rights:
- Right of access:
Obtain a copy of your stored data
- Right to rectification:
Correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"):
Delete your data under certain circumstances
- Right to restriction:
Restrict the processing of your data
- Right to data portability:
Receive your data in a structured, machine-readable format
- Right to object:
Object to processing based on legitimate interest
- Right to withdraw consent:
For processing based on consent
To exercise these rights, contact us at privacy@keypilot.eu. We respond within 30 days.
10. Cookies and Tracking
We use cookies and similar technologies for:
- Essential Cookies:
Necessary for platform functionality and security
- Analytical Cookies:
For understanding user behavior and platform improvements (with consent)
- Functional Cookies:
For remembering preferences and settings
You can manage cookies through your browser settings. Note: disabling essential cookies may limit platform functionality.
11. Privacy Rights of Minors
Keypilot is not intended for persons under 18 years of age. We do not knowingly collect data from minors. If you discover that a minor has provided data, please contact us immediately.
12. Changes to this Privacy Policy
We may update this privacy policy periodically. Significant changes will be communicated via email or platform notification. The "Last updated" date at the top reflects the most recent revision.
13. Contact and Complaints
For questions or concerns about this privacy policy:
Keypilot
Email: privacy@keypilot.eu
Registered office: Spoorweglaan 25, 9120 Melsele, Belgium
Company & VAT number: BE 0701.838.748
Privacy contact: privacy@keypilot.eu
You also have the right to file a complaint with the Data Protection Authority if you believe your data is not being processed correctly.
Subprocessors
Keypilot relies on the following subprocessors to deliver the service. A Data Processing Agreement (DPA) is in place with each of them. Where data is processed outside the EEA, it is done on the basis of the European Commission's Standard Contractual Clauses (SCCs).
Optional integrations (at your initiative)
When you connect a third-party service yourself — your bank via Ponto, your calendar (Google or Microsoft), cloud storage (Google Drive, OneDrive or Dropbox) or listing portals (Immoweb, ImmoScout24) — data is exchanged with that service at your initiative. Those parties process your data under their own privacy policies. You can disconnect any integration at any time via Settings.
Use of Artificial Intelligence (OpenAI)
When you use AI features (automatic property description generation, the AI Pilot assistant), the strictly necessary data (property attributes, your prompt) is sent to OpenAI for processing. OpenAI processes this data as a processor and does not use it to train its models (API "no training" setting). We never send full tenant PII such as national register numbers or bank account numbers to OpenAI. You can opt out by simply not using the AI features.
Cookies we use
We keep cookies to a minimum. Analytics cookies are only placed after your consent via the cookie banner:
| Cookie | Purpose | Duration |
|---|
| connect.sid (session cookie) | Essential: keeps you securely logged in | Session (expires on logout) |
| keypilot.cookieConsent | Essential: remembers your cookie choice (stored locally in your browser) | Until you change it |
| PostHog analytics | Usage statistics — only after consent | Max 12 months |
Retention periods
We do not keep personal data longer than necessary. Key periods:
| Account data | While the account is active + 90 days after termination (export window), then deleted or anonymized |
| Lease contracts and related documents | 10 years (Belgian accounting law) |
| Payment and invoicing data | 7 years (tax obligation) |
| Communication history | 5 years or while the account is active |
| Session and authentication logs | 12 months |
| Audit logs (security events) | 24 months |
| Product analytics (PostHog) | Max 14 months, only with consent |
Your rights under the GDPR
You may exercise each of these rights by simple request to privacy@keypilot.eu or directly in the app:
- Right of access (art. 15):
Obtain the personal data we process about you.
- Right to rectification (art. 16):
Have inaccurate data corrected.
- Right to erasure (art. 17):
Permanently delete your account via Settings → Account → Delete.
- Right to portability (art. 20):
Download all your data in structured JSON via Settings → Account → Export.
- Right to object (art. 21):
Object to certain processing activities.
- Right to restriction (art. 18):
Have the processing restricted.
- Right to withdraw consent:
At any time, without affecting prior lawful processing.
- Right to lodge a complaint:
With the Belgian Data Protection Authority (DPA), www.dataprotectionauthority.be.
Security measures
We implement appropriate technical and organizational measures, including:
- TLS 1.2+ encryption of all data in transit
- Encryption at rest of the database
- Strong password hashing (bcrypt, cost factor 12)
- Secure sessions (httpOnly, secure, sameSite cookies)
- Rate limiting against brute-force attacks
- Strict Content Security Policy and HSTS
- Multi-tenant isolation (each user only sees their own data)
- Logs redacted of sensitive fields
- Regular security reviews and threat modeling
Data breaches and notification
In the exceptional case of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Belgian Data Protection Authority within 72 hours of discovery and, where legally required, you directly.
Data controller contact
For any question about data processing or to exercise your rights, contact privacy@keypilot.eu. We respond within 30 days.