1. Data controller
The data controller for the activities described in this policy is SFV S.R.L., with registered office at Via Terra di Santa Lucia 56, 95030 Mascalucia (CT), Italy, tax code and VAT number 05881360878, hereinafter "SFV" or the "Controller".
This policy, provided under Articles 13 and, where applicable, 14 of Regulation (EU) 2016/679 ("GDPR"), concerns the Domusify platform, its public website available at https://domusify.com, the registration and authentication pages, the administration panel and the communications connected with managing the service, limited to the processing for which SFV determines the purposes and the essential means.
For information and to exercise your rights concerning personal data, you can use the contact details published on the SFV S.R.L. website or write to the certified email address (PEC) [email protected].
The public websites created by real estate agencies through the platform have their own privacy policies. This policy does not replace the policies of the individual agencies.
2. Who this policy applies to
This policy concerns, in particular:
- visitors to the platform's public website;
- people who create and use an account;
- the owners, directors and staff of the agencies who access the platform;
- anyone who contacts SFV for information, support or other requests relating to the service.
When an agency invites a person to join its workspace, before the account is created SFV processes the email address and the invitation data on behalf of the agency, as described in section 4. When the person creates or uses their own platform account, the data needed for the authentication identity, security and account management are instead processed by SFV for the purposes described in this policy.
3. Data processed by SFV as controller
Browsing and security
While using the platform website, the authentication pages and the panel, the following may be processed:
- IP address;
- date and time of requests;
- pages and resources requested;
- outcome of requests;
- information about the browser and the device;
- session identifiers and data;
- user agent;
- technical signals needed for security, the prevention of abuse and the diagnosis of malfunctions.
Cookies and other tools present on the device are described separately in the platform's Cookie policy.
User account
To create and manage an account, the following are processed:
- name;
- email address;
- password, stored exclusively as a hash and never in plain text;
- date and status of email address verification;
- language associated with the account;
- technical tokens needed for credential recovery procedures;
- technical data relating to sessions and authentication.
The user's authentication identity is distinct from the professional profile and the authorisations that an agency may associate with the same person within its workspace.
Creating and technically managing the agency's workspace
To set up and maintain the agency's workspace on the platform, the data needed to provide the service may be processed, including:
- the name given to the workspace;
- the
tenant_key, that is, the technical identifier chosen for the agency's workspace; - currency;
- time zone;
- any custom domains configured;
- technical settings needed for the service to be available.
The tenant_key permanently identifies the agency's workspace in the system and is also used to build the website's technical address.
This information does not necessarily constitute personal data; it becomes personal data when it relates to a natural person, for example in the case of a sole trader, or when it allows a person to be identified directly or indirectly.
Communications with SFV
When a user, a representative of an agency or a potential client contacts SFV, the contact details provided, the content of the communication and the information needed to reply and handle the request are processed.
Data subjects are asked not to disclose special categories of data under Article 9 GDPR, data relating to criminal convictions or offences, or other personal information not needed for the request.
4. Data processed by SFV on behalf of agencies
Through the platform, agencies can enter, organise, publish and manage data relating to their business.
Depending on the features used, this may include, among others:
- identifying, tax, legal and contact data of the agency and its offices;
- professional data, contact details, photographs and other information about agents, staff and members of the organisation;
- association of users with the agency's workspace;
- access profiles, roles and permissions assigned by the agency;
- invitations sent by the agency to its staff, including email address, access profile, permissions, status and technical data of the invitation;
- data relating to properties, including addresses, coordinates, features, descriptions, prices, floor plans, photographs and other media;
- editorial content, pages, contact details, social links and settings of the agency's website;
- data contained in enquiries sent by visitors to the agencies' websites;
- further data entered or managed by the agency through the features of the service.
For this processing, where the purposes and content are determined by the agency and SFV provides the platform and technical tools following the agency's instructions, the agency is the data controller and SFV acts as the data processor within the meaning of Article 28 GDPR.
The same person may therefore be affected by processing carried out by SFV in different roles. For example, SFV processes as controller the email, credentials and technical data needed for the account and security; it processes on behalf of the agency, instead, the assignment of the person to a specific workspace, the professional profile and the authorisations the agency decides to grant.
Invitations to join an agency are issued by an authorised user of the agency. The token contained in the invitation link is stored in the database exclusively in hashed form, and the link is valid for seven days. The agency determines the recipient of the invitation and the permissions offered.
Enquiries sent through the forms on the agencies' websites are not stored by the platform in a leads database: they are handled as described in the privacy policy of the relevant agency website.
Processing carried out by SFV as processor is governed by the data processing agreement applicable to the service. SFV does not use the data processed on behalf of agencies for its own advertising purposes, does not create commercial profiles of data subjects on the basis of that data and does not sell it to third parties.
5. Purposes and legal bases of the processing for which SFV is the controller
| Purpose | Legal basis |
|---|---|
| Creating and managing the account of a person who signs up to the service directly, verifying the email address, enabling authentication and access recovery | Performance of a contract or of pre-contractual measures requested by the data subject, Article 6(1)(b) GDPR |
| Managing accounts and authentication for persons authorised by an agency who are not personally party to the contract with SFV | Legitimate interest of SFV and the agency in allowing individual, controlled and secure access to the service, Article 6(1)(f) GDPR |
| Setting up and technically managing the agency's workspace and the B2B relationship | Performance of a contract where the data subject is personally party to it; otherwise, legitimate interest of SFV and the agency in the proper performance and administration of the professional relationship, Article 6(1)(b) or (f) GDPR |
| Responding to requests for information, sales or support | Pre-contractual measures or performance of a contract where the request comes from the data subject within a direct relationship; otherwise, legitimate interest in handling the professional communications received, Article 6(1)(b) or (f) GDPR |
| Providing, maintaining and protecting the website and the platform, preventing unauthorised access, fraud and other unlawful use, diagnosing errors and handling incidents | Legitimate interest in the security, integrity and continuity of the service, Article 6(1)(f) GDPR |
| Sending communications strictly necessary for verification, security and account management | The same legal basis applicable to the feature or relationship to which the communication relates |
| Complying with administrative, tax or accounting obligations or with requests from authorities, where applicable | Legal obligation, Article 6(1)(c) GDPR |
| Establishing, exercising or defending a right of SFV or of third parties | Legitimate interest in the protection of rights, Article 6(1)(f) GDPR |
| Measuring the use of the platform's public website with Google Analytics 4, when enabled | Consent, Article 6(1)(a) GDPR, and consent to tracking tools where required |
Where processing is based on legitimate interest, SFV assesses the necessity of the processing and the balancing against the rights and freedoms of data subjects, taking into account the professional nature of the service, the reasonable expectations of the people involved and the measures adopted to limit the data processed.
No decisions are taken based solely on automated processing that produce legal effects or similarly significantly affect the data subject.
Account data is not used for newsletters or promotional campaigns in the absence of a separate legal basis. Any future introduction of promotional communications, payment systems or further purposes will require the relevant assessment and, where necessary, an update of this policy before it is enabled.
6. Google Analytics 4 on the platform website
The platform provides for the use of Google Analytics 4 on the public website to understand how the pages are used and to obtain statistics such as visits, page views, traffic sources and general device characteristics.
GA4 is enabled only after consent to the Statistics category. Before consent, the website does not send GA4 any events or measurement signals, not even through cookie-free transmissions.
Analytics may process online identifiers, device information and browsing events. The availability of aggregated reports does not mean that all the data processed at source is anonymous.
The configuration provided does not use advertising features, remarketing or Google Signals. Names, email addresses, credentials and data entered in the authentication or restricted areas are not transmitted to Analytics.
If consent is refused, Analytics is not enabled and the necessary features of the platform remain usable. Consent can be changed or withdrawn through "Cookie preferences".
For how cookies work, their duration and how to manage your preferences, see the platform's Cookie policy. For Google's practices, see the Google Privacy Policy.
7. Providers and recipients
The data is accessible to SFV's authorised staff and collaborators, within the limits of their respective duties, and to the providers needed for the website and the service to operate.
| Service | Function and data involved |
|---|---|
| Cloudflare | Content delivery and traffic protection; IP address, connection data and technical security signals |
| DigitalOcean | Hosting of the application and database; data needed for the platform to operate |
| Elastic Email | Sending verification, credential recovery and other transactional emails relating to the account; email addresses, message content and technical delivery data |
| Google Analytics 4 | Optional statistical analysis of the platform's public website, under the conditions in section 6 |
The providers act as processors or sub-processors for the activities carried out on behalf of SFV or, for any processing they determine autonomously, in the role provided for by their respective services and contractual documents.
Elastic Email may also be used, on behalf of agencies, for communications originating from the features of their websites. Such processing does not change the agency's role as controller for its own purposes.
The data may also be disclosed to professional advisers, authorities or other parties where this is necessary to comply with a legal obligation, respond to a legitimate request from an authority or establish, exercise or defend a right.
SFV does not sell the personal data processed through the platform.
8. Service emails
The platform uses Elastic Email to send the communications needed for the service to operate, including:
- email address verification;
- credential recovery;
- operational or security communications relating to the account.
Sending may involve processing the recipient's address, the subject and content of the message, the date and time, the delivery outcome, bounces and other technical data needed for delivery and the prevention of abuse.
These communications are functional to the account or the service and do not, in themselves, constitute promotional communications.
The provider's settings may include tools for measuring opens and clicks. For the platform's service emails, these tools are not used in the absence of a suitable legal basis and, where processing requires consent, of specific consent from the data subject. The technical data needed for delivery and security remains distinct from optional tracking.
Invitations issued by agencies to their staff are technically sent through the same email service, but belong to the processing carried out on behalf of the agency described in section 4.
See the Elastic Email Privacy Policy and its Data Processing Addendum.
9. Place of processing and international transfers
The main hosting and database infrastructure is configured in European regions.
This configuration does not mean that every processing activity carried out by all providers takes place exclusively within the European Economic Area. Some international providers, their networks or their support services may involve processing or access from countries outside the EEA.
Where processing subject to the GDPR involves an international transfer, SFV relies on the grounds provided for in Chapter V GDPR, such as, depending on the recipient:
- an adequacy decision of the European Commission;
- the EU–US framework where the recipient is validly certified and the transfer falls within the scope of the certification;
- standard contractual clauses;
- any supplementary measures required in relation to the specific transfer.
The contractual documents of Cloudflare, DigitalOcean, Google and Elastic Email govern the respective processing in the services concerned.
Any consent requested for an optional tool, such as Google Analytics, does not replace the safeguards required for an international transfer.
You can request information about the applicable safeguards using the contact details given in section 1.
10. Retention
Data is retained for as long as necessary for the specific purpose. Where a single duration cannot be indicated in advance, criteria are used that are linked to the duration of the relationship, the technical validity of the data, the applicable obligations and the need to protect rights.
| Category | Period or criterion |
|---|---|
| User account | For the duration of the account and use of the platform; after it ends, data that is no longer necessary is deleted or made non-identifying, without prejudice to data that must be retained for legal obligations or the protection of rights |
| Password | The password is not stored in plain text; the hash of the credential is kept as long as the credential remains valid or until the account is deleted |
| Password recovery tokens | 60 minutes from generation, under the current configuration of the procedure, unless invalidated or replaced earlier |
| Authentication sessions | The current standard configuration provides for 120 minutes of inactivity before the session expires; technical data that is no longer valid is removed according to the system's cleanup cycles |
| Technical configuration data of the agency's workspace processed by SFV as controller | For the duration of the service and for the period afterwards strictly necessary for the technical and administrative termination of the relationship, without prejudice to legal obligations and the protection of rights |
| Support communications and requests | For the time needed to handle the request and any follow-up; further retention occurs only where necessary for legal obligations, documentation of the relationship or the protection of rights |
| Application and security logs | For the operational cycle needed for security, diagnosis and incident management; data relating to a specific incident or abuse may be extracted and retained longer where necessary to establish it or protect a right |
| GA4 user- and event-level data subject to the relevant setting | Two months, under the configuration adopted; deletion follows the service's technical times, and any reset for new activity concerns user-level data |
| Aggregated statistical reports | For the period in which they are useful for managing and analysing the service, without using them to reconstruct individual profiles |
| Documentation subject to tax, accounting or administrative obligations | For the periods provided for by the legislation applicable to the specific documentation |
| Data needed for disputes or the protection of rights | Limited to what is necessary to handle the dispute and until the time limits applicable to the protection of the right expire |
| Backup copies | Overwritten or deleted according to the technical copy rotation cycle; used for restoration, continuity and security of the service |
Data that SFV processes on behalf of agencies, including roles, permissions and invitations configured by the agency, is not subject to autonomous purposes set by SFV. Its retention depends on the instructions of the agency as controller, on the features of the service and on the data processing agreement, without prejudice to the temporary technical copies needed for security, backup and restoration.
For GA4, the retention of data on servers is distinct from the duration of the cookies present on the device. The relevant information is given in the Cookie policy.
11. Whether providing data is required
The data requested in the registration, authentication and technical configuration procedures for the service is required where it is indicated as mandatory.
Failure to provide it may prevent you from:
- creating or using an account;
- completing email address verification;
- recovering access;
- setting up or using a workspace;
- using a feature that requires the specific data.
Optional data may be omitted without preventing the use of features that do not require it.
For the data that the agency enters or configures in its own workspace as data controller, whether providing it is mandatory or optional depends instead on the purpose pursued by the agency and on its own policies.
12. Security and separation between agencies
SFV adopts technical and organisational measures appropriate to the risk in order to protect the data against unauthorised access, loss, alteration or improper disclosure.
The measures include, depending on the processing, protection of connections, authentication, email address verification, secure storage of credentials, access controls, separation of the data of different agencies, protection of the infrastructure and backup and restoration procedures.
A user's access to an agency's data depends on the association of the account with that specific workspace and on the authorisations granted by the agency.
Users must keep their credentials safe and promptly report any anomalous access or activity.
13. Data subject rights
In the cases provided for by the GDPR, data subjects may request:
- access to their personal data;
- rectification of inaccurate data and completion of incomplete data;
- erasure;
- restriction of processing;
- portability of data in the applicable cases;
- objection to processing based on legitimate interest, on grounds relating to their particular situation;
- withdrawal of consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
Requests concerning the processing for which SFV is the controller may be addressed to:
SFV S.R.L.
Via Terra di Santa Lucia 56
95030 Mascalucia (CT), Italy
PEC: [email protected]
Website: www.sfv.srl
SFV replies without undue delay and in any event within one month of receiving the request. In the cases provided for by Article 12 GDPR, taking into account the complexity and the number of requests, the period may be extended by a further two months, informing the data subject within the first month and stating the reasons for the extension.
Where a request concerns data that SFV processes on behalf of an agency, the agency remains the point of reference as data controller. SFV provides the controller with the assistance required by Article 28 GDPR and by the applicable agreement.
In case of reasonable doubts about the requester's identity, only the additional information necessary to verify it may be requested.
You may lodge a complaint with the Italian Data Protection Authority or the competent supervisory authority, and bring the matter before the courts in the cases provided for.
14. Minors
The platform is intended for professional use by real estate agencies, their owners, directors, agents and staff, and is not designed as a service aimed at minors.
SFV does not intentionally require minors to register for the professional use of the platform. If an account created in breach of the applicable conditions is identified, the measures necessary to verify it and terminate access may be taken.
15. Links and external services
The platform website may contain links to third-party websites or services.
The mere presence of a link does not, in itself, involve the transfer of data to the destination service. When the user follows the link, the relevant provider processes the data according to its own terms and policies.
16. Updates
This policy may be updated to reflect legal, organisational, contractual or technical changes, or the introduction or modification of platform features.
Updates are published on this page.
Where a change substantially affects the processing or requires a new choice by the data subject, SFV provides the additional information needed or collects the required consent before enabling the new processing.
The future introduction of payment systems, promotional newsletters, new integrations, profiling tools or further purposes is not automatically covered by this policy and must be assessed before it is enabled.
Last updated: 20 September 2026