Privacy Policy — ImoInspect
1. Who we are
ImoInspect is a property inspection application for estate agencies and property managers. It is operated by:
Awake Design, a sole proprietorship (eenmanszaak) under Dutch law
Buizerdlaan 57
2496 HG Den Haag, the Netherlands
Chamber of Commerce (KvK) number: 42044426
D-U-N-S: 473904434
ImoInspect is a trade name of Awake Design. The app carries the ImoInspect name, but the company responsible for your data — the controller, in the language of the GDPR — is Awake Design. Where this policy says "we", it means Awake Design.
Questions about this policy or about your personal data: privacy@imoinspect.com
We have not appointed a Data Protection Officer. We are not required to.
2. Two different roles, and why it matters to you
This is the most important section of this policy, because which rights you have and who you should contact depends on which of the two groups you fall into.
A. When you work for an estate agency that uses ImoInspect (you sign in to the app or the admin panel)
Your account details are processed by us, as the controller. We decide what an account looks like and why it exists. Section 3A describes that data.
B. When you are a tenant, landlord or owner whose property is inspected
You are not our customer and you do not have an account with us. The estate agency that carried out the inspection decides which data is recorded about you and why — that agency is the controller. We only supply the software that stores and delivers it, which makes us a processor acting on that agency's instructions.
In practice: if you want your inspection data corrected or deleted, contact the estate agency named in your report. They are the ones who can decide. If you do not know who to contact, write to us at the address above and we will point you to the agency — we cannot make that decision for them, but we will not leave you stranded.
3. What data we process
3A. Account data (agency staff)
| What | Why |
|---|---|
| First and last name | to identify who carried out an inspection, and to address you in emails |
| Email address | sign-in, password resets, sending reports |
| Phone number | contact details within your organisation |
| Password | stored only as a bcrypt hash — we never hold the password itself |
| Role and status (admin/inspector, active/inactive) | access control |
| Language preference | to send you email in your own language |
| Organisation you belong to | to keep each agency's data separate |
3B. Inspection data (tenants, landlords, owners)
Recorded in the app by the inspector, on behalf of the estate agency:
| What | Notes |
|---|---|
| Full name | of tenants and of landlords |
| Email address and phone number | used to deliver the report |
| NIF (Portuguese tax number) | currently a required field |
| Date of birth | tenants only, where recorded |
| Address, postal code, city | of the landlord and of the inspected property |
| Company name | where the landlord is a company |
| Handwritten signature | drawn on the device screen at the end of the inspection |
| Photographs of the property | including rooms, defects, meters and documents |
| Meter readings, room condition, remarks | the substance of the inspection |
Photographs may incidentally show personal belongings. They are taken to record the condition of the property; please tell the inspector if something should not be photographed.
3C. Data on the device
The app is offline-first: an inspection is completed on the device, without a network connection, and everything in 3B is stored in a local database on that device until the report is sent. Sign-in tokens are stored in the operating system's secure storage (Android Keystore).
Signing out does not erase this data — deliberately, because on an offline-first app the device may hold the only copy of a day's work. The local database is erased when a device is claimed by a different organisation, so that a shared work phone never shows the previous inspector's tenants.
3D. Error reports
When the app or our server hits an error, a report is sent to Sentry so we can fix it. This includes the type of error, the version of the app, and the device model.
An error report does not include a picture of your screen. The app was configured to attach one, which on an inspection screen would have carried a tenant's name, NIF, signature or photographs into an error report; that was switched off before release (17 August 2026). What we receive is the technical description of the failure, not the contents of the form you were filling in.
3E. What we do not collect
- No location or GPS data. The app does not request that permission.
- No advertising identifiers, no advertising SDKs, no tracking across apps or sites.
- No profiling and no automated decision-making.
- We do not sell personal data, and we never will. There is no business model here in which that would make sense: agencies pay us for the software.
4. Why we process it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing accounts and running the service for agencies | performance of a contract (Art. 6(1)(b)) |
| Storing and delivering inspection reports | on the agency's instructions, as processor — the agency relies on its own basis, normally its contract with the tenant or landlord, or legitimate interest |
| Sending password reset and account emails | performance of a contract |
| Keeping the service secure and diagnosing errors | legitimate interest (Art. 6(1)(f)): a working, secure application |
| Meeting legal obligations, e.g. tax records | legal obligation (Art. 6(1)(c)) |
A NIF is a national identification number. It is not a special category of data under Article 9, but it is sensitive in practice and we treat it accordingly: it is never used for anything other than identifying a party to the inspection.
5. Who else sees the data
We use a small number of suppliers. Each is bound by a data processing agreement, and none of them is permitted to use the data for their own purposes.
| Supplier | What for | Where |
|---|---|---|
| Amazon Web Services | servers, database and report storage | Frankfurt, Germany (eu-central-1) — inside the EU |
| Sentry | error reports | EU region (ingest.de.sentry.io) |
| Postmark (ActiveCampaign) | sending email | United States |
| Google (Gemini) | the assistant on our website | United States |
About Postmark and the United States. Postmark has no European servers. When we send you a report or a password reset, the recipient's email address, the subject line and the content of that email are processed in the US and, by Postmark's own policy, retained there for 45 days before being deleted. This transfer relies on the European Commission's Standard Contractual Clauses. If that is unacceptable for your organisation, tell us — this is a supplier choice, not a design constraint.
About the assistant on our website. imoinspect.com has a chat where you can ask questions about the product. What you type is sent, by way of our own server, to Google's Gemini service so that it can compose an answer, and the answer comes back the same way. Your browser never contacts Google directly, no cookie is involved, and nothing about the conversation is stored on your device: it exists only while the page is open and is gone when you leave. We do not keep a copy of it either.
It is a way to ask about the product, not a channel for personal or tenancy details -- please do not type anything into it that you would not put in an ordinary email. This transfer to the United States relies on the EU-US Data Privacy Framework together with the Standard Contractual Clauses.
Beyond these suppliers we disclose personal data only where the law requires it.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | for as long as the agency uses ImoInspect — see the note below |
| The download link for a report | 30 days, after which the link stops working |
| The report file itself | 12 months from the day it was sent, then deleted automatically |
| Email content at Postmark | 45 days (their retention, not ours) |
| Error reports at Sentry | 90 days (Sentry's project retention) |
| Server logs | 30 days |
| Encrypted database backups | 7 days, then rotated out |
| Inspection data on the device | until the inspection is deleted in the app, the app is uninstalled, or the device is claimed by another organisation |
The report file. The download link stops working after 30 days, and the stored PDF is deleted 12 months after it was sent. That period is enforced by the storage itself (an AWS S3 lifecycle rule on the reports/ prefix, in place since 17 August 2026), not by anyone remembering to do it. Twelve months is chosen because the dispute a report has to settle usually surfaces at the end of a tenancy, when the check-in report is the evidence. After that the report is no longer downloadable from the admin panel. The estate agency and the parties keep the PDF they were sent; we are not an archive.
Account data. Removing a user in the admin panel deactivates the account — the record stays, because inspections must keep showing who carried them out. Account data is erased when the agency stops using ImoInspect and asks us to delete its data, or on request under section 7. There is no automatic deletion after a fixed number of days, and we would rather write that down than describe a process that does not run.
7. Your rights
Under the GDPR you may ask to access your data, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable form.
- Agency staff: write to privacy@imoinspect.com. We will respond within one month.
- Tenants, landlords and owners: contact the estate agency named in your report, for the reason explained in section 2. If they ask us to act, we will.
You also have the right to complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). If you are in Portugal, you may complain to the CNPD (cnpd.pt).
8. Deleting your account
Your account is created for you by your organisation's administrator, who can also deactivate it. ImoInspect is invite-only: there is no way to create an account from inside the app. To have your account and its data removed, ask your administrator, or write to us at privacy@imoinspect.com and we will act on your organisation's instruction.
Removing an account does not by itself remove the inspection reports your organisation has produced. Those belong to the agency, which decides how long to keep them — see section 2 and section 6.
9. Security
Traffic between the app and our servers runs over HTTPS; from release 1.0.0 the app can no longer fall back to an unencrypted connection. Passwords are stored as bcrypt hashes. Access to the production environment is limited to named administrators. Report download links use an unguessable token and expire.
No system is perfectly secure. If you believe you have found a vulnerability, please write to security@imoinspect.com before disclosing it publicly, and we will work with you.
10. Children
ImoInspect is a professional tool and is not directed at children. We do not knowingly process the data of anyone under 16 except where a minor happens to be named as a tenant on a lease, in which case that data reaches us from the estate agency in the ordinary course of the inspection.
11. Changes to this policy
If we change this policy we will update the date at the top and, where the change is significant, tell account holders by email. The current version is always available at [https://imoinspect.com/privacy].
12. Contact
Awake Design (trading as ImoInspect) Buizerdlaan 57, 2496 HG Den Haag, the Netherlands KvK 42044426 privacy@imoinspect.com