Datapeers SAS d/b/a “datapeers” and “Danna” and our affiliates and subsidiaries (“we”, “us”, “our” or “datapeers”) provide companies involved in the real estate and construction sector and their clients, buyers, and property owners with conversational services for purchasing and leasing and assistance to residents with artificial intelligence, including bots (“Services”). Property developers communicate with customers and residents, potential residents, and other individuals through our Services, including via email, phone, text message, and web chat. We record these communications and use them for the purposes set forth in this Privacy Policy, including providing and improving the Services.
This Privacy Policy (“Privacy Policy”) explains how we collect, process, store, and share personal information. It also provides important information about your personal information rights and how to exercise them.
By using, interacting with, or accessing our Services, or by providing us with your personal information:
- You acknowledge that you accept our privacy practices and policies described below;
- You agree that we may collect, process, store, and share your information as described in this Privacy Policy;
- You acknowledge that you are communicating with bots when using the Services; and
- You agree that we may record all your communications made through the Services, including by email, phone, text message, and web chat.
Notice about the collection of personal information
Definition of personal information
We collect, process, store, and share information that identifies, relates to, or could reasonably link, directly or indirectly, to a particular person or household (“personal information”). Personal information does not include publicly available information from government records or non-personal information, such as anonymous, de-identified, or aggregated data (even if it originally comes from personal information).
Categories of personal information we collect
We collect, process, store, and may share with third parties the following categories of personal information:
- Contact information, such as full name, postal address, email address, and phone number
- Personal information and identifiers, which may be contained or otherwise reflected in records uploaded to our platform in connection with the Services, such as education, employment, work history, bank account number, bank statements, rental history (including rent paid on previous or current residences), income, date of birth, gender and/or sex, age, marital status, family size, information about your pets, government identification numbers (such as Social Security number, driver's license or state ID number, passport number, tax identification number, and any similar number you provide) and documents evidencing immigration, disability, or veteran status
- Account information, including username and password for Datapeers accounts
- Commercial information, such as purchase history and consumer profiles
- Content of mail, emails, or text messages not directed to us on behalf of property managers. For example, you may transmit communications to a property manager through our Services. Additionally, in cases where a property manager uses a Datapeers virtual assistant and connects Google (or other) email and calendar accounts via OAuth, we may obtain and store OAuth access and refresh tokens and copy relevant inbox and calendar content needed to provide our Services to property managers. We do not collect or store Google account passwords.
- Sensory data, for example, we may collect voice recordings of interactions with our Services or customer service team
- Geolocation data, such as the city where your device is located
- Preference information, including your preferences related to marketing, privacy, and communications, including consents for text message communications
- Other information you choose to provide when interacting with our Services (for example, rental or purchasing preferences such as move-in date and apartment size preferences; customer service inquiries; promotions; feedback; or communications through online form, email, text message, phone, and web chat)
- Other information that property managers choose to provide when interacting with our Services, for example, availability and pricing of apartment units, availability of tours, community information, preferences for Services, marketing information, and access credentials
- Device information, such as device type, operating system, device settings, application identifiers, unique device identifiers, and crash data
- Internet identifiers, such as domain name, Internet Protocol (IP) address, and type and configuration of browser
- Internet activity and analytics, such as cookie data, interactions with web pages, web page/referring source through which you accessed the Services, non-identifiable request identifiers, and statistics related to the interaction between your device or browser and the Services
- Service usage data, such as your login activity, date and time of visits, search terms, views, clicks, and downloads, including property managers, people, features, content, and links you interact with while using the Services
- Inferences drawn from any of the personal data listed in this section; for example, to create a profile of an individual's preferences and characteristics
Google user data (OAuth integrations)
When a property manager or authorized user connects a Google account to Datapeers (for example, Gmail and/or Google Calendar) to power our virtual assistant and related Services, we access Google user data only through Google’s OAuth 2.0 authorization flow and only after the user grants consent for the specific scopes requested.
What Google user data we access
Depending on the scopes authorized, we may access:
- OAuth access tokens and refresh tokens
- Basic Google account profile information needed to identify the connected account (such as name and email address)
- Email messages, labels, and metadata from connected Gmail inboxes that are required to operate the virtual assistant and related features for property managers
- Calendar events and related calendar data from connected Google Calendars that are required to schedule, update, or assist with appointments and related features
We request only the minimum scopes necessary to provide the connected features.
AI Processing and Google Workspace Data
Datapeers includes AI-powered features for lead qualification and customer conversations. These AI features are separate from Google Workspace integrations.
Google Workspace data, including Google Calendar data obtained through Google APIs, is not used to develop, improve, fine-tune, or train generalized artificial intelligence or machine learning models.
Google Calendar data is used exclusively to provide calendar synchronization and appointment scheduling features requested by the user.
When AI functionality is used, only the minimum information necessary for the requested feature is processed. Google Calendar event data obtained through Google Workspace APIs is not transferred to AI providers for model training or secondary purposes.
How we use Google user data
We use Google user data solely to:
- Provide and operate the Datapeers Services the user requested (including reading and acting on emails and calendar events on behalf of the property manager through the virtual assistant)
- Maintain, secure, troubleshoot, and improve those user-facing features
- Comply with applicable law and enforce our agreements
Limited use. Our use of data obtained from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use Google user data only to provide or improve user-facing features that are prominent in the Datapeers application
- We do not sell Google user data
- We do not use Google user data for targeted advertising, personalized advertising, retargeted advertising, or interest-based advertising
- We do not transfer Google user data to data brokers or information resellers
- We do not use Google Workspace APIs (or data obtained through them) to develop, improve, or train generalized artificial intelligence and/or machine learning models
- Human access to Google user data is limited to cases where it is necessary to provide the Services with the user’s consent, for security/compliance investigations, or where required by law
With whom we share Google user data
We do not transfer or disclose Google user data to third parties except:
- To subprocessors (such as cloud hosting and infrastructure providers) that help us provide the Services, under contractual confidentiality and security obligations, and only as needed to operate the connected features
- When required by law, legal process, or to protect the rights, safety, or security of users, Datapeers, or others
- In connection with a merger, acquisition, financing, or sale of assets, subject to continuing confidentiality and security protections
We do not share Google user data with third parties for their own marketing or advertising purposes.
Retention and deletion of Google user data
- OAuth tokens are retained only while the Google account remains connected to Datapeers
- When a user disconnects Google from Datapeers, or when tokens are revoked or expire and are not renewed, we revoke remaining tokens where applicable and delete stored OAuth tokens and associated Google user data copies within 30 days, except where a longer retention period is required by law or needed to resolve disputes or enforce agreements
- Users may disconnect Google access at any time from within Datapeers (where available) and/or from their Google Account permissions page (https://myaccount.google.com/permissions)
- Users and property managers may also request deletion of Google user data by contacting us at hello@datapeers.co
Data protection mechanisms for sensitive data
We maintain administrative, technical, and organizational security procedures designed to protect the confidentiality, integrity, and availability of personal information, including sensitive data such as OAuth tokens and data obtained through Google and other third-party integrations.
These measures include, as applicable:
- Encryption in transit. Data transmitted between users, Datapeers, and our service providers is protected using TLS (HTTPS) or equivalent encryption.
- Encryption at rest. Sensitive credentials, including Google OAuth access and refresh tokens, and other sensitive datasets are encrypted at rest using industry-standard encryption. Tokens are not stored in plain text.
- No password storage for Google accounts. We never request or store Google account passwords. Access is granted and revoked solely through OAuth 2.0.
- Token minimization and least privilege. We request the minimum OAuth scopes required for the features in use and retain tokens only while the connection remains active.
- Access controls. Access to systems that store or process sensitive data is restricted to authorized personnel and systems on a need-to-know / least-privilege basis, with authentication controls appropriate to the sensitivity of the data.
- Environment segregation. Production environments that process customer and Google user data are segregated from development and testing environments to the extent practicable.
- Monitoring and logging. We maintain logging and monitoring practices intended to detect unauthorized access, misuse, or other security incidents.
- Vendor and subprocessors security. Service providers that process personal information on our behalf are subject to contractual obligations requiring appropriate security and confidentiality protections.
- Incident response. We maintain procedures to investigate and respond to suspected security incidents and, where required by applicable law, to notify affected users and authorities.
While we implement safeguards designed to protect your information, no method of transmission or storage is completely secure. We continually work to improve our security practices.
Categories of third parties with whom we share your personal information
We may share your personal information with the categories of third parties listed in this section.
Property managers
- Property managers control how we collect and process the personal information we collect from users of the Services on their behalf
- Property managers are considered “controllers” or “owners” of such personal information under applicable privacy law; and are not considered third parties under applicable privacy law or this Privacy Policy
- This Privacy Policy does not govern how property managers use your personal information, which may differ from the uses described in this Privacy Policy; please consult the corresponding property manager’s privacy policy for more information on how the property manager uses your personal information
Other third parties
- Our providers who help us provide the Services or perform business functions on our behalf, including hosting, technology, and communication providers; analytics providers; support and customer service providers; our attorneys, advisors, auditors, and accountants; and payment processors
- Parties you access, authorize, or authenticate, including third parties you access through the Services, such as identity verification service providers; the information provided to such third parties is subject to the privacy policies of such third parties; consult the corresponding third party’s privacy policy before providing any information to a third party
- Parties for legal purposes, including government authorities, law enforcement, or other third parties in connection with any of the activities stated in the section beginning with “Complying with legal and regulatory requirements” in the next section titled Our business purposes for collecting and sharing personal information
- Parties for business changes, for example, your personal information that we collect may be shared or transferred to a third party if we undergo a merger, acquisition, sale, capital or debt financing, bankruptcy, or another transaction in which a third party invests, finances, or acquires control of our business or assets (in whole or in part)
Our business purposes for collecting and sharing personal information
This section details the business purposes for which we collect, process, store, and/or share your personal information.
- Provide, improve, and protect our Services, including providing the Services to Property Managers and interacting with other users (such as potential residents) through the Services on behalf of Property Managers; enhancing or personalizing the Services; developing new services or products; preventing or addressing service errors, security or technical issues; analyzing and monitoring use, trends, or other activities; responding to requests and inquiries from, or otherwise communicating with, property managers, users, and third parties
- Improve your user experience, for example, we use cookies and other device and Internet information to track your search criteria or other usage data to provide content of interest to you or to store your information so you don’t have to re-enter it each time you log in
- Market to you, including through profiling, for example, to market and advertise properties on behalf of property managers; and to create a profile for you (including “profiling”, i.e., the automated processing of your personal information to identify your preferences and interests). This marketing use does not apply to Google user data obtained through Google APIs, which is used only as described in the “Google user data (OAuth integrations)” section above
- Deidentify personal information, including aggregating and anonymizing personal information so it is no longer personal information
- Support our daily operations, including using outside vendors and service providers for business purposes (such as hosting, technology, and communications)
- Comply with legal and regulatory requirements, including performing audits, monitoring and reporting; supporting information security and anti-fraud operations; investigating and responding to disputes; exercising and defending legal claims; protecting the rights, property, or safety of you, us, or a third party; responding to legal processes (including subpoenas) and requests, investigations, or governmental, judicial, or law enforcement orders; and complying with and enforcing applicable laws, regulations, policies, procedures, and agreements
- Evaluate or engage in business changes, including a merger, acquisition, sale, capital or debt financing, bankruptcy, or another transaction in which a third party invests or acquires control of our business or assets (in whole or in part)
We do not sell or share your personal information for targeted advertising
We do not sell personal information. For purposes of this Privacy Policy, “sell” means the disclosure of personal information to a third party in exchange for money or other valuable consideration.
We do not share personal information with third parties for third-party direct marketing purposes.
We do not share personal information with third parties for cross-context behavioral advertising or targeted advertising.
Retention of personal information
We retain personal information about you for as long as we deem necessary or advisable for the purposes described in the preceding section titled Our business purposes for collecting and sharing personal information (such as providing the Services to Property Managers) or as directed by Property Managers. For example, following the termination of our agreement with a Property Manager, at the written request of such Property Manager, we will delete the names, emails, and phone numbers of potential residents and residents associated with such Property Manager that are not included in the body of emails, text messages, and/or submissions in the comment box.
We may retain your personal information after you have stopped using or engaging with our Services; for example, we may retain your personal information to improve our Services, comply with legal obligations, or resolve disputes or collect owed fees.
When the retention period expires for a given type of data, we delete or destroy it, or deidentify it so it is no longer personal information, except where a longer period is required or permitted by law.
Retention and deletion of Google user data are additionally governed by the “Google user data (OAuth integrations)” section above.
Applicability of this Privacy Policy
This Privacy Policy covers how we handle personal information we acquire from you or other sources related to our Services or other interactions with us. This Privacy Policy does not cover the policies or practices of property managers or third parties to which you may access or connect through the Services.
Sources of personal information
We collect personal information about you from the following categories of sources:
- Directly from you, such as when you access or use our Services or when you communicate or interact with us in any way, including by postal mail, email, phone, text message, web chat, QR code, or social media
- Indirectly from you, for example, we collect data from cookies and other information from your device, browser, or activity on the Internet or in our Services
- From our external providers, for example, from our analytics providers
- From property managers or other users of our Services
- From Google and other connected third-party services, when you authorize an integration via OAuth or a similar mechanism
Property managers and third parties
This Privacy Policy does not apply to property managers’ use of personal information or to the websites, applications, or services of third parties that you access or connect through the Services. We do not have control over the privacy practices or content of property managers or third parties, nor over their websites, applications, products, or services. As such, we are not responsible for the privacy practices employed by property managers or third parties or the content provided by them, including websites, applications, or services linked to our Services or accessible from them or in connection with them.
Refer to the privacy policy and terms of service of the relevant property manager or third party for information on their privacy practices and uses of personal information. Also, direct any privacy requests directly to the property managers or third parties regarding the personal information that is under their control.
Personal information of other people you share with us
You may not disclose personal information of another person or make it available on the Services, unless you have prior written consent from the person who is the subject of the information and that person is 18 years of age or older. To the extent that you provide us personal information of another person or use it in the Services, you acknowledge and agree that you are responsible for compliance with all applicable laws regarding such personal information.
Personal information of minors
You must be 18 years old to use the Services. By accessing or using the Services, you represent and warrant that you are at least 18 years old.
We do not intentionally collect, process, store, or share personal information about individuals under 18 years of age. If you are under 18 years of age, do not attempt to access or use the Services or send us personal information. If we learn that we have collected personal information from a minor under 16 years of age, we will delete that data as soon as possible. If you believe that a minor under 16 years of age may have provided us with personal information, please contact us at hello@datapeers.co
To the best of our knowledge, we do not sell or share personal information of children under 16 for cross-context behavioral advertising or targeted advertising.
Your rights and privacy options
Notice about your personal information rights
Depending on where you live, you may have rights regarding your personal information, which may include the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete personal information
- Request deletion of your personal information
- Object to or restrict certain processing
- Request portability of certain personal information
- Withdraw consent where processing is based on consent
- Opt out of the sale or sharing of personal information for targeted advertising (we do not sell or share personal information for targeted advertising as described above)
To exercise these rights, or if you have questions about this Privacy Policy, contact us at hello@datapeers.co. We may need to verify your identity before fulfilling a request. If we process personal information on behalf of a property manager, we may direct your request to that property manager when they are the controller of the data.
If you are not satisfied with our response, you may have the right to lodge a complaint with a supervisory authority in your jurisdiction.
Site language and approximate location
To show you the website in Spanish or English, the first time you visit datapeers.co your browser asks a third-party geolocation provider (api.country.is or, as a fallback, get.geojs.io) for the approximate country associated with your IP address. We use the country code only to choose the language; we do not link it to your identity or store it on our servers.
The detected country and the language you choose with the language selector are saved in your browser’s local storage (for up to 7 days in the case of the country) so the lookup is not repeated. You can delete them at any time from your browser settings.
Website cookies and analytics
We use Google Analytics 4, a service of Google LLC, to measure how our website is used: pages visited, where the visit came from (for example, a search engine or a campaign), approximate country and city, device and browser type, and actions such as opening the configurator, switching languages or clicking to book a demo. We use this information only to understand and improve the site; we do not use it for advertising.
When you visit the site we show you a cookie notice. Until you accept, Google Analytics runs without cookies and only receives anonymous, aggregated data. If you accept, analytics cookies (for example, _ga) are stored so repeat visits from the same browser can be recognized. You can change your choice at any time with the “Cookies” link at the bottom of every page or by clearing your browser’s cookies.
Google processes this data under its own privacy policy (https://policies.google.com/privacy) and may process it outside Colombia. We do not share data that directly identifies you, such as your name or email address, with Google.
We also use PostHog, an analytics tool that we host on our own infrastructure (backdp.datapeers.co), to measure visits, sessions, page views, where visits come from (including UTM campaign parameters) and clicks on site elements. PostHog follows the same choice you make in the cookie notice: until you accept, it runs without cookies and does not recognize repeat visits; if you accept, it stores a random identifier in a cookie and in your browser’s local storage. We do not record sessions, we do not build visitor profiles, and we do not send PostHog your name, email address, phone number or other data that directly identifies you.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. If we change how we use Google user data in a material way, we will notify users as required and, where applicable, obtain updated consent before using Google user data in a new way.
Contact us
Datapeers SAS / datapeers
Email: hello@datapeers.co
Website: https://www.datapeers.co
Privacy Policy URL: https://www.datapeers.co/en/policy