Privacy Policy
Last updated: August 16, 2026
1. Introduction
This Privacy Policy ("Policy") describes how Ruaa ("Company," "we," "us," or "our"), the operator of the Ruaa marketplace at ruaa.app, collects, uses, stores, shares, and protects your personal data when you access or use the marketplace.
The marketplace is operated by Alhussein Ammar, Athens, Greece, under the name "Ruaa", and he is the data controller for personal data processed through it. Ruaa is a trading name and is not, at present, a registered company; until a company is incorporated, every obligation in this notice is owed by that individual. We have assessed that we are not required to appoint a Data Protection Officer under Article 37; the contact below handles all data protection matters.
This Policy is designed to comply with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Greek data-protection framework (Law 4624/2019), and applicable Greek and EU directives governing online marketplaces and rental-platform operators (including Greek Law 5047/2023 implementing EU Directive 2021/514, "DAC7").
By creating an account, listing a property, or sending an inquiry, you acknowledge that you have read and understood this Policy. If you do not agree with how we process your data, please do not use the marketplace.
2. Data Controller Information
Data Controller: Alhussein Ammar, trading as Ruaa
Address: Athens, Greece
Email for privacy inquiries: legal@ruaa.gr
Data Protection Contact: Alhussein Ammar — legal@ruaa.gr
3. What Data We Collect and Why
3.1 Account information
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Email address | Account creation, authentication, service communications | Contract performance: Art. 6(1)(b) |
| Full name (optional) | Account identification, addressing the User in messages | Contract performance: Art. 6(1)(b) |
| Password (stored only as a salted one-way hash) | Account security and authentication | Contract performance: Art. 6(1)(b) |
| Phone number (optional) | Verified phone reveal on listings (Section 3.3); SMS authentication where used | Consent: Art. 6(1)(a) |
| Preferred language | Localized UI | Legitimate interest: Art. 6(1)(f) |
3.2 Listing data (Publishers only)
When you publish a listing, we collect:
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Property address (street, number, postal code, district) | Display on listings, mapping, district analytics, AVM proximity features | Contract performance: Art. 6(1)(b) |
| KAEK (Cadastral Code, optional) | Verified-Owner badge cross-check; sold/rented confirmation; Cadastre quarterly reconciliation | Contract performance: Art. 6(1)(b); legitimate interest: Art. 6(1)(f) |
| AFM (Greek Tax ID, optional unless rented) | DAC7 reporting to AADE when a long-term rental closes (Section 3.6) | Legal obligation: Art. 6(1)(c) |
| IBAN (collected only at rented status) | DAC7 reporting; encrypted at rest, never displayed publicly | Legal obligation: Art. 6(1)(c) |
| Property attributes (sqm, bedrooms, bathrooms, floor, year, energy class, condition) | Listing display, AVM features, search filtering | Contract performance: Art. 6(1)(b) |
| Photos uploaded to listings | Listing display, photo fingerprints for duplicate detection | Contract performance + legitimate interest |
| Listing description (EL/EN) | Listing display | Contract performance: Art. 6(1)(b) |
| Asking price / monthly rent | Listing display, AVM and Ruaa-Score calibration | Contract performance: Art. 6(1)(b) |
| Cadastre extract (PDF/JPG/PNG/HEIC, optional) | Verified-Owner badge review; stored in private bucket with RLS to owner + admins only | Consent: Art. 6(1)(a) for the verification program |
| DAC7 declaration (legal name, AFM, IBAN, monthly rent, lease start, lease term, consent timestamp and version) | Statutory annual reporting to AADE | Legal obligation: Art. 6(1)(c) |
3.3 Phone-reveal audit log
Where a Publisher exposes a verified phone number on a listing and an authenticated User reveals it, we log: an anonymized session identifier, listing ID, source channel, and timestamp. This audit log is used for fraud detection, abuse prevention, and rate-limiting. It is retained for ninety (90) days, then deleted. The Publisher may disable phone exposure at any time, in which case past reveal logs are retained for the standard ninety-day window and then deleted.
3.4 Inquiry and messaging data
Inquiries sent to a Publisher record: inquirer name (where provided), inquirer email (where provided), authenticated buyer ID (where signed in), message body, source channel, and listing ID. On-platform messages between authenticated Users are stored to allow both sides to read the thread. Message content is filtered before email previews are generated: an offensive-content filter strips slurs from the email preview, and a PII filter masks phone numbers in email previews to discourage off-platform handoff before mutual interest is established. The unfiltered message remains visible inside the Platform once the recipient signs in.
3.5 Saved listings, saved searches, and reports
- Saved listings: a list of listing IDs you have shortlisted. Used to render your "Saved" page.
- Saved searches: the search criteria you have saved (city, district, price range, bedrooms, surface, etc.). Used to render your "Saved searches" page and, if you opt in, to send you alerts about new matches.
- Listing reports: when you report a listing, we record the report reason, optional details, your reporter ID (if authenticated) or email (if anonymous), and the listing ID. Used to triage and review reported listings.
- Block list: when you block another User, we record the relationship (blocker → blocked). Used to suppress messages and inquiries between blocked Users.
3.6 DAC7 transactional data
Greek Law 5047/2023 implementing EU Directive 2021/514 ("DAC7") requires platform operators that facilitate the rental of immovable property to collect and report annually to the Independent Authority for Public Revenue (AADE) the following information about Publishers and rental transactions: legal name, AFM (Greek Tax ID), IBAN, address, monthly rent, lease start, lease term, and reporting year. Your AFM is requested when you create a listing, and the remaining fields (IBAN, monthly rent, lease start, lease term) only if and when you record that a long-term rental closed through the Platform, with your consent recorded at that point. Where a rental closes through another channel, no reporting record is created. Reporting is made annually for the prior calendar year.
3.7 Sale-confirmation data
When a Publisher marks a sale listing as sold, we collect: confirmed sale price (EUR), transaction date, KAEK, and self-reported confirmation source. This data is used for AVM calibration and is reconciled quarterly against publicly available Greek Cadastre records. It is not displayed publicly.
3.8 Free property valuation tool
When you use the free property valuation tool at /value-my-property, we collect the property address, surface area, bedrooms/bathrooms, and other attributes you enter, and your email if you submit it for the magic-link gate. The valuation result and inputs are saved against your email so you can return via the magic link. AVM inputs are also used in aggregated, anonymized form to improve the AVM model.
3.9 Usage data
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Pages visited within the Platform | Platform improvement and feature development | Legitimate interest: Art. 6(1)(f) |
| Listing views (anonymized session ID + listing ID) | Owner-facing view-trend analytics; aggregate demand signals | Legitimate interest: Art. 6(1)(f) |
| Districts and listings viewed | Search ranking, demand-signal computation | Legitimate interest: Art. 6(1)(f) |
| Timestamps of activity | Service operation, security, rate-limiting | Legitimate interest: Art. 6(1)(f) |
Legitimate-interest assessment: we collect usage data to understand how the marketplace is used so we can fix bugs, improve search, and ensure quality. We have assessed that this processing is proportionate and does not override your rights and freedoms because: the data is used only for internal product improvement; it is not shared with third parties for marketing; and you can request erasure at any time.
3.10 Data we do NOT collect
We want to be clear about what we do not collect:
- Government-issued identification beyond AFM at the rented-status step (no passports, national ID cards, residency permits collected through the marketplace).
- Credit-card or bank-account numbers (Promotion Tier payments are processed exclusively by Stripe — we never see your card data).
- Biometric data or health data.
- Geolocation data from your device (the marketplace renders a map based on listings' lat/lng; it does not track your physical location).
- Data from minors. The marketplace is not intended for individuals under 18.
3.11 Photo handling
When you upload photos to a Ruaa Properties listing, we compute a one-way fingerprint of the image file and store it alongside the listing. We use these fingerprints to detect duplicate uploads and prevent photo theft within our own platform — for example, flagging when the same photo has been uploaded across two different listings.
The original photos remain your property. You can request deletion of your photos and the associated hashes at any time using the data-subject rights process described in §10.
Photo comparison is limited to photos uploaded to this marketplace. We do not compare uploaded photos against any external source of photos.
4. How We Use Your Data
We process your personal data for the following purposes:
- Providing the marketplace: creating and managing your account, authenticating your identity, displaying listings, routing inquiries and messages, and providing customer support.
- Verified-Owner program: reviewing Cadastre extracts you upload to determine eligibility for the Verified-Owner badge.
- AVM and Ruaa Score: running our spatial-regression model and composite-scoring engine to estimate market value, rent, and investment quality. AVM and Ruaa-Score outputs are derived from the listing data you provide plus aggregated district benchmarks.
- Photo moderation: computing one-way fingerprints of uploaded photos to detect duplicate uploads within our own marketplace (first-party dedup), plus a Claude-vision NSFW/relevance check at upload time. See §3.11.
- AI-powered features: when AI summary or sentiment features are used, your query parameters and relevant market data context are transmitted to Anthropic's Claude API for processing. Under Anthropic's commercial API terms, your data is not used for AI model training.
- DAC7 reporting: collecting and reporting rental-transaction data to AADE annually, as required by Greek Law 5047/2023.
- Sale-price calibration: using sold-status confirmations to calibrate the AVM model against actual transaction prices.
- Service improvement: analyzing usage patterns in aggregate to improve marketplace features, fix bugs, and develop new functionality.
- Security: protecting the marketplace against unauthorized access, fraud, scams, harassment, and abuse — including running offensive-content and PII filters on messages.
- Legal compliance: complying with applicable legal obligations, including DAC7 reporting, tax record-keeping, and responding to lawful requests from authorities.
- Transactional communications: sending essential service emails (inquiry-received notifications, message-received notifications, listing-published confirmations, listing-expiry reminders, verification-decision notices, DAC7 reminders, security alerts, Terms updates).
We do not currently send marketing emails. If we introduce marketing communications in the future, we will obtain your consent and provide an easy opt-out mechanism.
5. Legal Basis for Processing (GDPR)
Under GDPR Article 6(1), we rely on the following legal bases:
- Contract performance — Article 6(1)(b): processing necessary to deliver the marketplace services you have signed up for: account management, authentication, listing publication, inquiry routing, messaging, the Verified-Owner program, AVM, and Ruaa Score.
- Legal obligation — Article 6(1)(c): processing necessary to comply with legal obligations, particularly DAC7 reporting to AADE under Greek Law 5047/2023, and retention of financial records for tax purposes under Greek and EU law.
- Legitimate interest — Article 6(1)(f): processing for our legitimate interests where those interests are not overridden by your rights — usage analytics, photo-moderation, abuse prevention, fraud detection, and aggregate AVM/Ruaa-Score calibration.
- Consent — Article 6(1)(a): processing where consent is the appropriate basis — Verified-Owner Cadastre upload, Golden-Visa cross-listing to ruaa.gr, and any future marketing communications. Where consent is the basis, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
6. Third-Party Services That Process Your Data
6.1 Supabase (authentication, database, storage)
- Role: Data processor.
- Data shared: email, name, hashed password, listing data, messages, saved-listings/searches, audit logs, uploaded verification documents.
- Purpose: user authentication (GoTrue), database hosting, private file storage with row-level security, edge-function execution.
- Privacy Policy: supabase.com/privacy.
6.2 Stripe (payment processing for Promotion Tiers)
- Role: independent data controller for payment data.
- Data shared: email address, Promotion Tier selection. Stripe directly collects payment-card data; we never see your card data.
- Purpose: processing one-time Promotion Tier payments and any future paid features.
- PCI compliance: Stripe is certified as a PCI Level 1 Service Provider.
- Privacy Policy: stripe.com/privacy.
6.3 Anthropic (AI processing — Claude API)
- Role: data processor.
- Data shared: query parameters, selected district/market context, and relevant data inputs when AI summary or sentiment features are used.
- Purpose: generation of AI summary content and sentiment analysis.
- Server location: United States.
- Data training: under Anthropic's commercial API terms, data submitted via the API is not used for model training.
- Privacy Policy: anthropic.com/privacy.
6.4 Resend (transactional email)
- Role: data processor.
- Data shared: email address of the recipient, message subject and body for transactional emails (inquiry, message, expiry, verification-decision notifications).
- Purpose: reliable delivery of transactional email through the Ruaa marketplace.
- Privacy Policy: resend.com/legal/privacy-policy.
6.5 Mapbox (map rendering and geocoding)
- Role: data processor.
- Data shared: no personal data is intentionally shared. Mapbox may collect anonymous usage data through its map and Geocoding SDKs.
- Purpose: rendering interactive maps and address autocomplete.
- Privacy Policy: mapbox.com/legal/privacy.
6.6 PostHog (privacy-respecting product analytics)
- Role: data processor.
- Data shared: anonymized usage events (page visits, button clicks, feature interactions), and masked session replays during the demo phase described below.
- Purpose: understanding how the marketplace is used at an aggregate level. We do not use PostHog for advertising or for cross-site tracking.
- Privacy Policy: posthog.com/privacy.
Demo phase. The marketplace is in a pre-launch demo phase. During this phase product analytics and masked session replay run for every visitor, whether or not you accept the "Analytics" category, so that we can see how the product is actually used and fix what does not work. Replays mask all on-screen text and everything you type, and the message inbox is excluded from capture entirely. This is a deliberate, time-boxed choice and it ends at public launch, when analytics goes back to running only after you accept the Analytics category. Your rights in section 9 are unaffected: write to legal@ruaa.gr and we will erase the usage data recorded from your sessions.
6.7 Render and ruaa-avm-service
- Role: data processor.
- Data shared: property attributes (district, sqm, bedrooms, bathrooms, lat/lng, etc.) when an AVM estimate is requested.
- Purpose: running the statistical model that produces our property value estimates. It receives the attributes of the property being valued, not your identity.
6.8 AADE (Greek Independent Authority for Public Revenue)
- Role: public authority recipient under DAC7.
- Data shared: DAC7 declarations (legal name, AFM, IBAN, address, monthly rent, lease start, lease term, reporting year) for rental transactions.
- Purpose: annual statutory reporting under Greek Law 5047/2023 implementing EU Directive 2021/514.
6.9 GreekHomeLoans (mortgage partner)
- Role: independent data controller. GreekHomeLoans (operated by Loan Labs) is a licensed Greek mortgage broker, separate from Ruaa.
- Data shared: only when you request mortgage pre-qualification and explicitly consent — your name, email, phone, the property and price you are considering, and the financing inputs you entered (deposit, loan amount, term, indicative rate). We do not share your details unless you opt in.
- Purpose: so GreekHomeLoans can contact you about financing and prepare a free, no-obligation assessment.
- Privacy Policy: greekhomeloans.com.
6A. Infrastructure, and where your listing travels
Cloudflare serves this marketplace and protects it from abuse, so every request passes through its network and it processes connection data including your IP address. Its Turnstile widget on our forms receives a challenge token only, never the contents of a form.
Ruaa runs three connected properties on shared infrastructure: this marketplace, the analytics platform at ruaa.pro, and the Golden Visa site at ruaa.gr. Three flows are worth naming plainly.
Your listing is projected into our analytics platform. When you publish, the listing's attributes, price and exact coordinates are written into the analytics side so it can inform market statistics and our valuation models. Note that the public marketplace map deliberately shows an approximate position rather than the exact one; the analytics side holds the precise figure, and it is not shown as a pin on a public page.
Cross-listing. If you opt in, an eligible listing is also published on our Golden Visa site. That is your choice and you can withdraw it.
Off-market introductions. Where you ask to be introduced on an off-market deal, the name, email address, phone number and message you give us are sent to the licensed partner brokerage that handles that transaction. That brokerage is a separate business and decides for itself how it handles what it receives. We tell you which brokerage it is before we make the introduction, and we do not send your details anywhere else.
One account identity spans all three properties, so if you sign in on one you may be recognised on another, and our internal customer records link the enquiries you make across them.
7. International Data Transfers
7.1 Transfers to the United States
Some of our processors (Anthropic, Stripe, PostHog, Resend, and potentially Supabase) process data in the United States. For data transfers from the European Economic Area (EEA) to the United States, we rely on the following safeguards:
- EU-US Data Privacy Framework (DPF): where the receiving processor is certified under the EU-US Data Privacy Framework, as recognized by European Commission Implementing Decision (EU) 2023/1795, such certification provides an adequate level of data protection for the transfer.
- Standard Contractual Clauses (SCCs): we maintain Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914) with our processors as a complementary and fallback transfer mechanism.
- Transfer Impact Assessments: we conduct documented Transfer Impact Assessments for data transfers to the United States.
7.2 Your rights regarding transfers
You may request information about the specific safeguards applied to international transfers of your data by contacting legal@ruaa.gr.
8. Data Storage and Security
8.1 Storage infrastructure
Your data is stored on Supabase-managed infrastructure (Postgres database + private object storage). Payment data is stored exclusively on Stripe's PCI-compliant infrastructure.
8.2 Security measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit using TLS/SSL.
- Encryption of data at rest within the database.
- Passwords are never stored in readable form; only a salted one-way hash is kept.
- Postgres Row-Level Security (RLS) policies enforcing per-row read/write access by user role and ownership for all tables containing personal data.
- Private storage buckets for verification documents (Cadastre extracts), readable only by the uploading owner and Ruaa administrators, through short-lived links that expire.
- JWT session tokens for authenticated access; service-role keys are never exposed to the browser.
- Edge-function environment for sensitive server-side flows (DAC7, AVM, payments, photo moderation).
- Offensive-content filter and PII filter applied to message previews to reduce harassment and unsafe handoffs.
- Regular review of security practices and access controls.
8.3 Limitations
While we take reasonable precautions to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security and are not responsible for unauthorized access resulting from circumstances beyond our reasonable control.
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required or permitted by law.
| Data category | Retention period | Basis |
|---|---|---|
| Account data (email, name, profile) | Duration of active account + 30 days after deletion request | Contract performance; grace period for account recovery |
| Listings (active) | Duration of active listing + 30 days after expiry/deletion | Contract performance |
| Listing photos and their fingerprints | Duration of the live listing plus twelve months; the fingerprint alone is kept beyond that, with no link to you, so the same photo cannot be re-uploaded | Legitimate interest: cross-listing fraud detection |
| Cadastre verification documents | Duration of active listing + 30 days, then securely deleted | Contract performance + consent withdrawal |
| DAC7 transactional records | 10 years from the reporting year | Legal obligation: Greek tax law |
| Confirmed sale records (price, KAEK, transaction date) | Indefinitely in anonymized form for AVM calibration; identified records retained 7 years | Legal obligation; legitimate interest |
| Inquiries and messages | Duration of active account + 30 days after account deletion | Contract performance |
| Promotion Tier records (Stripe charge IDs, tier, dates) | 7 years | Legal obligation: Greek tax law |
| Saved listings, saved searches, blocks | Duration of active account | Contract performance |
| Listing reports | 3 years from resolution | Legal obligation: demonstrating compliance |
| Phone-reveal audit logs | 90 days | Legitimate interest: fraud detection |
| Server logs containing IP addresses | 90 days | Legitimate interest: security |
| Data-subject request records | 3 years from request resolution | Legal obligation: demonstrating GDPR compliance |
After the applicable retention period, data is securely deleted or irreversibly anonymized. Anonymized data (from which you cannot be identified) is no longer personal data and may be retained indefinitely for aggregate analytics, AVM calibration, and Ruaa-Score improvement.
10. Your Rights
10.1 Rights under GDPR (EU-based Users)
If you are located in the European Economic Area, you have the following rights under GDPR:
- Right of Access (Article 15): you may request confirmation of whether we process your personal data and obtain a copy of that data.
- Right to Rectification (Article 16): you may request correction of inaccurate personal data or completion of incomplete data.
- Right to Erasure / "Right to Be Forgotten" (Article 17): you may request deletion of your personal data, subject to retention obligations under DAC7 and Greek tax law.
- Right to Restriction of Processing (Article 18): you may request that we restrict processing while we verify accuracy or assess an objection.
- Right to Data Portability (Article 20): you may request a copy of your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV).
- Right to Object (Article 21): you may object to processing based on legitimate interest at any time.
- Right to Withdraw Consent: where processing is based on consent (e.g., Verified-Owner program, ruaa.gr cross-listing), you may withdraw at any time without affecting the lawfulness of prior processing.
- Right Not to Be Subject to Automated Decision-Making (Article 22): AVM, Ruaa Score, and photo-moderation outputs are informational tools and are not used to make automated decisions with legal or similarly significant effects on you.
10.2 How to exercise your rights
To exercise any of the rights described above, contact us at legal@ruaa.gr. We will respond within one (1) month per GDPR. This period may be extended by two further months where necessary. We may ask you to verify your identity before processing your request.
10.3 Right to lodge a complaint
If you believe your data-protection rights have been violated, you have the right to lodge a complaint with a supervisory authority:
For EU/Greece-based Users:
Hellenic Data Protection Authority (HDPA)
Address: Kifissias 1-3, 115 23, Athens, Greece
Phone: +30 210 6475600
Email: complaints@dpa.gr
Website: www.dpa.gr
11. Cookies and Similar Technologies
11.1 Our cookie usage
The marketplace uses strictly necessary cookies and local-storage entries required for it to function, plus analytics cookies and local storage for PostHog product analytics. During the pre-launch demo phase those analytics run for every visitor and the banner says so; you cannot switch them off there, and section 6.6 explains why and how to have your session data erased. Advertising and retargeting tags sit in a separate "Marketing" category that stays off unless you accept it. PostHog runs on EU infrastructure, masks form inputs and on-screen text, and may link your activity across our properties (ruaa.app, ruaa.pro, ruaa.gr) into a single analytics profile to understand cross-product journeys.
11.2 Cookies and storage we use
| Item | Provider | Purpose | Type |
|---|---|---|---|
| Supabase auth session token | Supabase (first-party) | Maintains your authenticated session | Strictly necessary |
| Anonymized session ID (localStorage 'ruaa-vsid') | Ruaa (first-party) | View-tracking and phone-reveal audit log without identifying you | Strictly necessary |
| i18n preference (localStorage) | Ruaa (first-party) | Remembers your selected language | Strictly necessary / functional |
| PostHog distinct ID + analytics state | PostHog (EU-hosted) | Product analytics to improve the marketplace; set for every visitor during the pre-launch demo phase (section 6.6) | Analytics (demo phase) |
11.3 Analytics cookies and local storage
Strictly necessary cookies are set without asking, because the marketplace does not run without them. Analytics storage is treated separately: section 6.6 sets out what it collects, what is masked, and which pages are excluded from it altogether.
The marketplace is in a pre-launch demo phase. During it, analytics storage is set for every visitor rather than on opt-in, and the banner tells you so before you use the site. The basis is our legitimate interest in getting a pre-launch product working before it is sold (Article 6(1)(f)), balanced by the masking and the route exclusions described in section 6.6, and by the erasure route there. You can object at any time under Article 21. When the marketplace launches publicly, analytics move to opt-in consent under Article 6(1)(a) and the banner regains the Analytics toggle.
11.4 Future changes
If we introduce additional non-essential cookies or trackers beyond the analytics described above, we will update this section and obtain your consent before setting them.
12. Children's Privacy
The marketplace is designed for adults and is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18, we will take immediate steps to delete that data. If you believe a child under 18 has provided us with personal data, please contact us at info@ruaa.gr.
13. Data Breach Notification
13.1 Our obligations
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the Hellenic Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.
- Where the breach is likely to result in a high risk to your rights and freedoms, notify affected individuals without undue delay in clear and plain language, in accordance with GDPR Article 34.
13.2 Breach-notification content
Our breach notifications will include: (a) the nature of the breach; (b) the name and contact details of our data-protection contact; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address and mitigate the breach.
13.3 Internal procedures
We maintain an internal breach register documenting all data-security incidents, including those that do not trigger notification requirements, in accordance with GDPR Article 33(5).
14. Changes to This Privacy Policy
14.1
We may update this Privacy Policy from time to time to reflect changes in our data-processing practices, legal requirements, or marketplace features.
14.2
For material changes, we will: (a) post the updated Policy on the marketplace with a revised "Last updated" date; (b) where the change materially affects how we handle your data, tell you in the Platform, by email, or by re-showing the consent banner before it takes effect; and (c) where required by law, obtain your renewed consent for any new processing activities.
14.3
Non-material changes (such as clarifications or formatting updates) may be made without prior notice. We encourage you to review this Policy periodically.
14.4
Your continued use of the marketplace after the effective date of an updated Policy constitutes your acceptance of the changes.
15. AI Processing Transparency
In accordance with the EU AI Act (Regulation (EU) 2024/1689) and emerging best practices for AI transparency:
- We disclose that summary content and sentiment analysis on this marketplace are generated using Anthropic's Claude API, a generative AI system.
- The AVM and Ruaa Score are statistical models, not generative AI; their methodologies are described in our public documentation and on listing pages.
- Photo moderation compares uploads only against other uploads to this marketplace plus a Claude-vision NSFW/relevance check, not generative AI for content creation. See §3.11 for the photo-handling specifics.
- When you use AI-powered features, query parameters, selected districts and markets, and relevant contextual data may be transmitted to Anthropic's servers in the United States for processing.
- AI-generated outputs do not constitute automated decision-making with legal or similarly significant effects under GDPR Article 22. AI features are informational tools designed to assist, not replace, human judgment.
15.1 Ask Ruaa conversations and service improvement
The "Ask Ruaa" assistant stores your conversations (your messages, the assistant's replies, and related interaction metadata). We process conversation content to provide the service — maintaining your history and context — under Article 6(1)(b), and to improve the assistant (evaluating answer quality, fixing errors, improving prompts, tools, and safety filters) under our legitimate interest, Article 6(1)(f), with a documented legitimate-interest assessment. You can exclude any conversation from service-improvement use with the per-conversation opt-out in the assistant panel, and deleting a conversation removes it from your history and from future service-improvement use. Message content is processed by Anthropic as described in §6.3; under Anthropic's commercial API terms it is not used by Anthropic to train its models. Conversation logs are kept for two years from your last message, and you can ask us to delete them sooner. This follows the same retention period in §9.
16. Data Minimisation, Retention, and Cross-Border Transfer Posture
Ruaa maintains formal internal records documenting how we apply GDPR principles of data minimisation (Art. 5(1)(c)), purpose limitation (Art. 5(1)(b)), storage limitation (Art. 5(1)(e)), and cross-border transfer safeguards (Chapter V). The summaries below describe what each record covers; they do not replace the records themselves.
16.1 Data Minimisation and Purpose Limitation Record
For each personal-data field collected on the marketplace — account information, listing data including KAEK and AFM, phone-reveal audit, inquiries, DAC7 transactional data, sale-confirmation data, and photo fingerprints — we document where it is collected, the specified purpose it serves, whether collection is necessary, the GDPR legal basis (Art. 6(1)(a)–(f)), and the applicable retention period. We also maintain an explicit list of categories we deliberately do not collect (see §3.10). The record is reviewed quarterly and updated whenever a schema field is added or changed.
16.2 Retention Policy Record
We maintain a per-category retention table covering the categories listed in §9 of this Policy plus internal operational categories. Marketplace listing data is retained for the listing's live duration plus twelve months. Photos and their fingerprints cascade-delete with the parent listing. Transaction records (DAC7 and sale confirmations) are retained for ten years where a tax-reporting obligation applies to them, and otherwise for five years, matching §9.
16.3 Transfer Impact Posture
For cross-border transfers to non-EEA recipients, we rely on vendor-published Data Processing Agreements that incorporate the 2021 Standard Contractual Clauses (Module 2) by reference, together with the supplementary measures those DPAs document (encryption in transit and at rest, tenant isolation, government-request transparency reporting, EO 14086 alignment for US-DPF participants). The EU-US Data Privacy Framework adequacy decision of 10 July 2023 covers transfers to DPF-certified US recipients. We keep this posture under review and produce a formal per-vendor Transfer Impact Assessment where a change in a vendor's circumstances or in the law calls for one.
16.4 Right to Erasure (GDPR Art. 17) — Deletion Request Protocol
To request deletion of your personal data, email legal@ruaa.gr. The request must come from the registered account email address; we may ask a simple challenge question if doubt remains as to identity. Within 30 calendar days of a verified request we will:
- Delete or anonymise your account record, listings, photos and their fingerprints, inquiries, and any AI summary outputs attributable to you, except where retention is required by a legal obligation (DAC7 and sale-confirmation records are retained for the periods in §9).
- Mark your Stripe customer record inactive. Stripe retains transaction records for seven years per their tax obligation; we retain the reference but no card details.
- Request vendor-side deletion from any processor that holds derivative copies (Supabase Auth, where applicable).
- Send you a confirmation email itemising the scope of deletion, any retained categories with the legal basis for retention, and the completion date.
We retain the deletion-request record itself for five years post-completion as proof of compliance, on the basis of Art. 6(1)(c) legal obligation.
17. Contact Us
For any questions, concerns, or requests related to this Privacy Policy or our data-processing practices:
Ruaa
Athens, Greece
Data subject rights and privacy requests: legal@ruaa.gr
General contact: info@ruaa.gr
Website: ruaa.app
We aim to respond to all privacy-related inquiries within 5 business days, and to formal data-subject rights requests within the statutory timeframe of one month (GDPR).