Privacy Policy
Effective date: July 2026
Fitpa B.V. · Singel 425, 1012 WP Amsterdam, The Netherlands · KvK: 42030266 · VAT: NL869384855B01
1. Introduction
This Privacy Policy explains how Fitpa B.V., trading as Conciairge ("Conciairge", "we", "us", "our"), collects, uses, and protects personal data in connection with the Conciairge platform (the "Service").
Conciairge is a software platform used by private landlords, property investors, property management companies, and family offices ("Customers") to manage, let, or invest in residential property — whether they operate as an individual or through a registered legal entity. This Policy is directed at our Customers and their authorized Users. It also explains, at a high level, how personal data of Customers' tenants and suppliers is processed through the Service, for transparency purposes — although the primary relationship with such individuals is between them and our Customer, not Conciairge.
This Policy should be read together with our Terms of Service and, where applicable, our Data Processing Agreement.
2. Personal Information We Collect
We collect and process the following categories of personal data:
- Account and User data: name, work email address, phone number, role, organization, login credentials, and authentication metadata.
- Tenant Data: names, contact details, communication content (email/WhatsApp), payment status, and lease-related information, submitted by or on behalf of the Customer for the purpose of property management.
- Supplier Data: names, contact details, and communication content relating to maintenance and repair coordination.
- Property Data: property addresses, portfolio information, and related documents (e.g., lease agreements, inspection reports).
- AI interaction data: prompts submitted to the Platform, AI-generated responses, and associated metadata.
- Uploaded documents: files uploaded by Users, which may contain personal data of tenants, suppliers, or other third parties.
- Usage and activity logs: actions taken within the Platform, approval records, timestamps, and audit trail entries.
- Billing information: invoicing details and payment status (processed via our payment provider; we do not store full card details).
- Technical data: IP address, browser type, device identifiers, and log data collected automatically when using the Platform.
3. How We Collect Personal Data
- Directly from Customers and Users, through account registration, configuration, and use of the Platform.
- From Customers on behalf of their tenants and suppliers, where the Customer submits or connects such data (e.g., via email/WhatsApp integration, document upload, or manual entry).
- Automatically, through the Customer's connected integrations (Gmail, Outlook, WhatsApp, PSD2 banking providers, calendar providers, cloud storage, or property management software), where the Customer has authorized such connections.
- Automatically, through cookies and similar technologies when using our website or Platform (see Section 8).
4. How We Use Personal Data
- To provide, operate, and maintain the Service, including AI-driven communication drafting, task execution, maintenance coordination, and rent monitoring;
- To authenticate Users and manage Organization accounts and permissions;
- To generate AI Output, including summarizing communication, drafting responses, and recommending or executing actions on the Customer's behalf;
- To maintain activity logs and audit trails for transparency, accountability, and dispute resolution;
- To process billing and manage the Customer relationship;
- To provide customer support and respond to inquiries;
- To detect, investigate, and prevent fraud, abuse, or security incidents;
- To improve and develop the Service, including analyzing aggregated or de-identified usage patterns; and
- To comply with legal obligations.
5. Legal Basis for Processing
Where we act as a Data Controller (see Section 12) — for example, in relation to Account and User data of our Customers, and billing information — we rely on the following legal bases under the GDPR:
- Performance of a contract (Article 6(1)(b)): to provide the Service under our agreement with the Customer;
- Legitimate interests (Article 6(1)(f)): to secure and improve the Platform, prevent fraud, and communicate with Customers about the Service, balanced against individual rights and interests;
- Legal obligation (Article 6(1)(c)): to comply with tax, accounting, and other statutory requirements; and
- Consent (Article 6(1)(a)): where required, for example for certain non-essential cookies or optional marketing communications.
Where we act as a Data Processor on behalf of the Customer — for example, in relation to Tenant Data and Supplier Data — the Customer, as Data Controller, determines the legal basis for processing such data, and we process it solely on the Customer's documented instructions, as further described in Section 12 and our Data Processing Agreement.
6. AI Processing
The Platform uses large language models and related AI services, including third-party AI providers, to generate summaries, draft communications, recommend actions, and execute Tasks. In connection with this processing:
- Personal data (including Tenant Data and Supplier Data) may be transmitted to AI model providers acting as sub-processors, solely for the purpose of generating AI Output within the Service;
- We take contractual and technical measures to ensure that sub-processors do not use Customer Data to train their general-purpose models, except where a Customer has explicitly opted in;
- AI Output may be reviewed, edited, or corrected by Users before being sent to a tenant, supplier, or other third party, depending on the Customer's configured approval settings; and
- We maintain audit logs of AI-generated actions, including whether they were autonomously executed or required Approval, to support transparency and accountability.
Individuals who interact with AI-generated communication (e.g., tenants) may be entitled to know that they are communicating with, or receiving content generated by, an AI system, in accordance with applicable transparency obligations, including under the EU AI Act. Customers are responsible for ensuring appropriate disclosures are made to their tenants, as described in our Terms of Service.
7. Third-Party Processors and Sub-Processors
We engage carefully selected third-party service providers to help us operate the Service, including:
- Cloud hosting and infrastructure providers;
- AI model and inference providers;
- Communication integration providers (email, WhatsApp Business API);
- PSD2-licensed account information service providers, where the Customer connects bank data;
- Payment processors; and
- Analytics and monitoring providers.
These providers act as sub-processors and are contractually bound to confidentiality and data protection obligations consistent with this Policy and applicable law. A current list of sub-processors is available upon request at legal@conciairge.nl, and we will notify Customers of material changes to this list in accordance with our Data Processing Agreement.
8. Cookies and Analytics
We use cookies and similar technologies on our website and Platform to: (a) enable core functionality and authentication ("strictly necessary" cookies); (b) understand usage patterns and improve the Service ("analytics" cookies); and (c) remember preferences.
Non-essential cookies are only set with your consent, where required by applicable law. You can manage cookie preferences through our cookie banner or your browser settings. Disabling certain cookies may affect the functionality of the Service.
9. Security Measures
We implement technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration, including:
- Encryption of data in transit and at rest;
- Role-based access controls and authentication safeguards;
- Audit logging of actions taken within the Platform, including AI-driven actions;
- Regular security review of our infrastructure and sub-processors; and
- Incident response procedures, including notification obligations under applicable law in the event of a personal data breach.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data Retention
We retain personal data for as long as necessary to provide the Service and fulfil the purposes described in this Policy, including:
- Customer Data (including Tenant Data, Supplier Data, and Property Data): for the duration of the Customer's subscription, and for up to 30 days after termination to allow for data export, unless a longer period is required by law, requested by the Customer (e.g., for an ongoing tenancy dispute), or necessary for the establishment, exercise, or defense of legal claims;
- Account and billing data: for the duration of the Customer relationship and thereafter as required by applicable tax and accounting law (generally up to 7 years in the Netherlands);
- Activity and audit logs: for a period sufficient to support accountability and dispute resolution, as configured with the Customer or as required by law.
Specific retention periods for Tenant Data and Supplier Data may be configured by the Customer as Data Controller, subject to the Platform's technical capabilities and our Data Processing Agreement.
11. International Data Transfers
Personal data is primarily processed within the European Economic Area (EEA). Where personal data is transferred to a country outside the EEA that does not benefit from an adequacy decision of the European Commission, we ensure that appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where necessary, to ensure a level of protection consistent with the GDPR.
12. Data Controller vs. Data Processor Responsibilities
In connection with the Service, the parties generally act in the following capacities:
Conciairge as Data Processor: with respect to Tenant Data, Supplier Data, and other personal data submitted by the Customer for property management purposes, Conciairge acts as a Data Processor, processing such data solely on the documented instructions of the Customer, as further set out in our Data Processing Agreement.
Customer as Data Controller: the Customer determines the purposes and means of processing Tenant Data, Supplier Data, and Property Data, and remains responsible for ensuring a lawful basis for such processing, providing appropriate disclosures to tenants and suppliers, and responding to data subject rights requests relating to such data (with our reasonable assistance).
Conciairge as Data Controller: with respect to Account and User data, billing information, and data relating to our direct relationship with the Customer and its Users, Conciairge acts as an independent Data Controller.
13. Your GDPR Rights
Subject to applicable law, individuals whose personal data we process as Data Controller have the right to: access their personal data; rectify inaccurate data; request erasure; restrict processing; object to processing based on legitimate interests; request data portability; and lodge a complaint with a supervisory authority, including the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise these rights in relation to data for which we act as Data Controller, contact us at legal@conciairge.nl. If your request relates to Tenant Data or Supplier Data for which our Customer is the Data Controller, we will refer you to the relevant Customer, or assist the Customer in responding to your request, as appropriate.
14. Children's Privacy
The Service is intended for use by adults engaged in the management, letting, or investment of residential property, and is not directed at, or intended for use by, individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete it.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or legal requirements. We will notify Customers of material changes by email or in-Platform notification at least 15 days before the changes take effect.
16. Contact Information
For questions about this Privacy Policy or our data practices, contact:
Fitpa B.V.
Singel 425, 1012 WP Amsterdam, The Netherlands
Chamber of Commerce (KvK): 42030266
VAT: NL869384855B01
Email: legal@conciairge.nl
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), www.autoriteitpersoonsgegevens.nl.
