Privacy Policy
Last updated: 7 July 2026
1. Who we are (Data Controller)
Origire Technologies operates the Origire Platform (origire.com) and Origire Invest. For questions about this policy or your data, contact us at office@origire.com.
2. What personal data we process
- Account data: email, name, role, authentication identifiers.
- Property and deal data: details you enter about properties, deals, valuations, contacts.
- Third-party contact data: agents, sellers, buyers, service providers whose details are shared with us by our users or scraped from public real-estate listings (e.g. Spitogatos).
- Usage data: pages viewed, actions taken, device/browser, IP address, referrer.
- Submissions: forms, inquiries, GDPR requests.
3. Purposes and lawful bases (Art. 6 GDPR)
- Providing the service — contract (Art. 6(1)(b)).
- Analytics, security, fraud prevention, product improvement — legitimate interests (Art. 6(1)(f)).
- Analytics cookies (Google Analytics, Microsoft Clarity) — consent (Art. 6(1)(a)), gathered via our cookie banner.
- Legal and tax obligations — legal obligation (Art. 6(1)(c)).
- Marketing emails to opted-in users — consent, withdrawable at any time via unsubscribe.
4. Third-party contact data (scraped and shared)
The platform contains contact details of real-estate professionals (agents, phones, offices) sourced from publicly available listings and from data our users enter. Lawful basis is our legitimate interest in operating a professional B2B real-estate intelligence tool. If you are one of those individuals you can object or request erasure via the request form; we will remove or suppress your details within 30 days unless we have an overriding legal ground to retain them.
5. Retention
- Account data: while the account is active, plus up to 6 months after deletion for backup rotation.
- Form submissions (form_attempts): 12 months, then automatically purged.
- Activity log: 24 months, then automatically purged.
- Notification / nudge history: 12 months, then automatically purged.
- Deal, property, and financial records: as long as required by Greek tax/AML law (typically 5–10 years).
6. Recipients / processors
- Supabase (EU hosting, database, auth).
- Cloudflare (edge network, DDoS protection).
- Google Analytics 4 & Microsoft Clarity (only with your consent).
- Email delivery providers for transactional and marketing email.
- Payment processors when transactions occur.
A current subprocessor list is available on request.
7. International transfers
Where a processor is outside the EEA, transfers rely on adequacy decisions or the EU Standard Contractual Clauses.
8. Your rights (Chapter III GDPR)
- Access, rectification, erasure ("right to be forgotten").
- Restriction and objection to processing.
- Data portability (machine-readable export).
- Withdraw consent at any time (does not affect prior processing).
- Lodge a complaint with the Hellenic Data Protection Authority — dpa.gr.
Signed-in users can self-serve export and deletion from their profile. Anyone can file a request at /privacy/request.
9. Security
Transport encryption (TLS), encryption at rest at the database layer, row-level security on user data, principle of least privilege for staff access, and audit logging of admin actions.
10. Automated decision-making
Valuation and matching features produce statistical estimates but do not constitute automated decisions with legal or similarly significant effects on you under Art. 22 GDPR.
11. Changes
Material changes will be highlighted on this page and (where we have your email) notified by email.