Privacy Policy
Last updated: 9 July 2026
Kloser is an AI-powered operating system for real estate professionals. This Privacy Policy explains what personal data we process, why, on what legal basis, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and applicable national data protection law.
Data controller: JCUNHAFONTE, LDA, registered in Portugal under company/VAT number PT515097365, with registered office at Rua da Presa 25, 3830-262 Ílhavo, Aveiro, Portugal (“Kloser”, “we”, “us”, “our”). For any privacy matter, including to exercise your rights, contact us at privacy@kloser.org.
This policy applies to the Kloser web and mobile applications, our websites, and the public agency portals we host on our customers’ behalf. The English version prevails in case of any discrepancy between translations.
1. The two roles we play
Kloser plays two different data protection roles, and which one applies determines who is responsible for your data.
As a controller: for personal data about our own account holders — the real estate professionals, agencies and organisations who register for and administer Kloser — we decide why and how the data is processed, so we are the controller. This policy describes that processing.
As a processor: for the lead, client and contact data that our customers upload to or capture through Kloser, our customer is the controller and Kloser acts only as a processor on their documented instructions. If you are a lead or client of an agency that uses Kloser and want to exercise your rights, please contact that agency. This processing is governed by a Data Processing Agreement under Article 28 GDPR that forms part of our Terms of Service.
2. Personal data we process
Depending on how Kloser is used, we may process the following categories of personal data:
- Account and identity data: name, email address, hashed password, telephone number, profile photo, job role and language preference.
- Organisation and agency data: agency name, branding (logo, colours), business address, tax identification, locale and measurement-unit settings, and your role and permissions within the organisation.
- Lead, client and contact data (entered by our customers): names, telephone numbers, email and postal addresses, messages, property preferences, budget, source and notes.
- Property and listing data, which may include the names and contact details of owners or interested parties.
- Communications data: the content and metadata of messages sent and received through integrated channels, including WhatsApp, email and in-app messaging.
- Documents and extracted data: files uploaded to the platform and information extracted from them by optical character recognition, which can include identity-document details such as name, document number and tax number (see section 5).
- Contract, signature and transaction data: contract content, signatory names, signing audit information (timestamps, IP address), and transaction, commission and pricing details.
- Calendar and scheduling data, where you connect a calendar.
- Advertising and portal data: leads and metrics received from connected advertising platforms and property portals.
- Usage, device and log data: IP address, device and browser information, pages and features used, and diagnostic logs.
- Cookies and similar technologies (see section 9).
3. Where the personal data comes from
We obtain personal data from: you and the organisation you belong to; our customers, who enter or import data about their own leads and clients; and connected third-party services such as messaging providers, advertising platforms and property portals that pass leads and interactions to us.
Where we receive data about you from a customer or third party rather than directly from you (for example, because an agency added you as a lead), the categories of data and the sources are as described in this policy.
4. Why we process personal data and our legal bases
- To provide, operate and maintain the service and your account, and to provide support — necessary for the performance of our contract with you (Article 6(1)(b) GDPR).
- To secure the platform, prevent fraud and abuse, ensure tenant isolation, and develop and improve our products — our legitimate interests in running a safe and competitive service (Article 6(1)(f)).
- To send administrative and service messages about your account, security and changes to the service — performance of our contract or our legitimate interests.
- To send marketing communications about Kloser, where you have consented or where permitted for existing customers — consent or legitimate interests (Article 6(1)(a)/(f)); you can opt out at any time.
- To comply with legal obligations such as accounting, tax and responding to lawful requests from authorities — compliance with a legal obligation (Article 6(1)(c)).
When we act as a processor on a customer’s behalf, we process personal data only to provide the service and on that customer’s documented instructions; the customer is responsible for establishing a legal basis for that processing.
5. Identity documents and special category data
Some features let our customers upload identity and property documents that are processed, including by automated text extraction. These documents can contain sensitive information. Kloser does not seek to process special categories of data (Article 9 GDPR) and asks customers not to upload data they have no lawful basis to process. Where a customer uploads such data, the customer is the controller and is responsible for meeting any additional condition required under Article 9 and national law.
6. AI features and automated decision-making
Kloser uses artificial intelligence, including third-party large language model providers, to help qualify and score leads, suggest assignments, and draft messages and content. To do this, relevant data may be sent to these providers solely to perform the requested processing, and we minimise what is sent. We engage these providers as sub-processors; most are contracted on terms that prohibit using the data to train their own models. Some providers we use as fallbacks operate on standard or free service tiers whose terms may allow them to use submitted content to maintain and improve their services, including their models. We never send Google user data (see section 8) to any AI provider for any purpose, and you can contact us to learn which providers are currently in use.
These features assist, and do not replace, human professionals. We do not use them to make decisions that produce legal effects concerning you or similarly significantly affect you without human involvement. If any such decision were made, you would have the right to obtain human intervention, to express your point of view and to contest the decision (Article 22 GDPR). AI output can be inaccurate and should be reviewed before it is relied upon.
7. Messaging channels (WhatsApp, email and others)
Kloser integrates with the WhatsApp Business Platform operated by Meta Platforms Ireland Limited. When an organisation connects a WhatsApp number, messages exchanged with that number are processed to capture leads, store conversation history and enable replies. Meta processes message data under its own terms and privacy policy, which we recommend you review. Use of WhatsApp must comply with the WhatsApp Business Messaging Policy.
We also send and receive email through our email delivery provider and may support other channels over time. Marketing messages always include a way to unsubscribe.
8. Google user data (Google Calendar)
If you connect Google Calendar, Kloser accesses your Google account through the Google Calendar API using the calendar.events scope, which allows reading and writing events on the calendars you connect.
- What we access: events on the connected calendar — titles, descriptions, dates and times, attendees, locations and meeting links.
- How we use it: solely to provide two-way calendar synchronisation — showing your external events inside Kloser (including as busy time for scheduling and public booking availability) and creating, updating or deleting the Google events that mirror appointments you manage in Kloser.
- Where it is stored: synced event data and access tokens are stored with the hosting sub-processors listed in section 10 for as long as the connection is active, protected by the measures described in section 13.
- What we never do: we do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your consent, for security or abuse investigation, to comply with the law, or where it is aggregated and anonymised. We never transfer Google user data to, or process it with, any artificial-intelligence or machine-learning provider, and it is never used to create, train or improve any AI/ML model.
You can disconnect Google Calendar at any time in Kloser's calendar settings, after which we stop accessing your Google account and stop syncing. You can also revoke Kloser's access from your Google account security settings.
Kloser's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
9. Cookies and similar technologies
We use strictly necessary cookies and similar technologies to operate the service — for example, to keep you signed in and remember your language and theme. With your consent where required, we use analytics technologies to understand how the product is used so we can improve it.
You can manage non-essential cookies through the cookie controls we present and through your browser settings. Strictly necessary cookies cannot be switched off without affecting the service.
10. Sharing your data and our sub-processors
We do not sell personal data. We share personal data only with:
- Service providers acting as our sub-processors under written contracts requiring appropriate safeguards — including cloud hosting and database providers, messaging and email delivery providers, AI/large language model providers, analytics and error-monitoring providers, and payment providers.
- Other members of your own organisation, according to the roles and permissions configured in Kloser.
- Authorities, advisers or acquirers where necessary to comply with the law, enforce our terms, protect our rights, or in connection with a merger, acquisition or reorganisation.
A current list of our sub-processors is available on request at privacy@kloser.org.
11. International data transfers
We aim to host and process personal data within the European Economic Area (EEA). Some sub-processors are located outside the EEA. Where personal data is transferred outside the EEA, we rely on an appropriate safeguard under Chapter V GDPR — such as a European Commission adequacy decision or the European Commission’s Standard Contractual Clauses, together with additional measures where needed. You can request a copy of the relevant safeguard at privacy@kloser.org.
12. How long we keep personal data
We keep personal data only for as long as necessary for the purposes set out in this policy, including to provide the service and to meet legal, accounting and reporting obligations. Account data is kept for the life of the account and for a limited period afterwards. Personal data we process as a processor is retained according to the customer’s instructions and is deleted or returned at the end of the service relationship, subject to any retention required by law. When data is no longer needed, we delete it or irreversibly anonymise it.
13. How we protect personal data
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption of sensitive credentials at rest, access controls on a need-to-know basis, and strict tenant isolation so each organisation’s data is logically segregated from every other. No system is perfectly secure, but we work continuously to protect personal data and to detect and respond to incidents.
14. Personal data breaches
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours where required, and inform affected individuals or, where we act as a processor, the relevant controller without undue delay, in line with Articles 33 and 34 GDPR.
15. Your rights
Subject to the conditions in the GDPR, you have the right to: be informed about our processing; access your personal data; have inaccurate data rectified; have data erased; restrict processing; object to processing (including to direct marketing and to processing based on legitimate interests); data portability; and, where processing is based on consent, withdraw that consent at any time without affecting processing carried out beforehand.
To exercise your rights, contact privacy@kloser.org. We will respond within one month, which may be extended by a further two months for complex or numerous requests (we will tell you if so). Exercising your rights is free unless a request is manifestly unfounded or excessive.
16. When Kloser acts as a processor
If your personal data was provided to Kloser by one of our customers (for example, the agency that holds you as a lead or client), that customer is the controller and you should direct your rights requests to them. If you contact us, we will refer your request to the relevant customer and assist them in responding, as required by our Data Processing Agreement.
17. Children
Kloser is a professional business tool. It is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children.
18. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you through the service or by email and update the date above. Your continued use of Kloser after a change takes effect means you accept the updated policy.
19. Complaints and supervisory authorities
If you have a concern about how we handle your personal data, please contact us first at privacy@kloser.org so we can try to resolve it. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.
In Portugal, the authority is the Comissão Nacional de Proteção de Dados (CNPD). In Spain, it is the Agencia Española de Protección de Datos (AEPD).
20. How to contact us
Controller: JCUNHAFONTE, LDA, Rua da Presa 25, 3830-262 Ílhavo, Aveiro, Portugal. Privacy and data protection enquiries: privacy@kloser.org.