We use cookies to keep the site working, remember your language and protect against spam. With your consent we may also use analytics and marketing cookies. Read our Cookie Policy and Privacy Policy.
In effect from August 1, 2026 · version 1.0
This policy explains what personal data Kvartly.com collects, why we collect it, whom we share it with, and what you can do about it. It applies to kvartly.com in every language version and to the services we provide through it. Cookies are described separately in our Cookie Policy.
This document is written in English and translated into the other languages of the site automatically. If a translation differs from the English text, the English version prevails.
Kvartly.com, registration number 584856168498451, registered at San Marco Argentano, 45, Italy, Rome, operates kvartly.com and the services described in this policy. In the language of data-protection law we are the controller of the personal data described here: we decide why and how it is processed.
If you have a question about this policy, or want to exercise any of the rights set out in section 11, write to privacy@kvartly.com. We answer in English, Russian or Georgian.
Representative in the European Union. Under Article 27 of the GDPR we have appointed Yuri Palienko, established in Italy, as our representative in the European Union. Data subjects and supervisory authorities in the EU may contact the representative directly at San Marco Argentano, 45, Italy, Rome, or by e-mail at legal@kvartly.com, on any question concerning the processing of personal data.
This policy covers kvartly.com in all of its language versions and everything we do through it: the catalog of new developments, our own research and editorial materials, accounts, favourites, comments, contact requests and service notifications. It also covers the personal data of company representatives that we hold in the catalog, including people who never created an account with us.
It does not cover the websites and sales offices of developers, other third-party sites we link to, or messaging services such as WhatsApp and Telegram: as soon as you leave our site or open a conversation in a messenger, that provider's own terms and privacy policy apply alongside ours. Cookies are described in the Cookie Policy, and the contractual side of our relationship in the Terms of Service.
Depending on how you use the site, we may hold the following.
We do not ask for special categories of data — health, religious or political views, biometric data — and you should not send them to us. We do not process payments on the site, so we never hold your card or bank details.
Much of this is optional and the choice is yours: leaving a phone number, adding contacts to your profile, or signing a comment with your real name. Where a field is genuinely required in order to provide the service, we say so where we ask for it.
Personal data reaches us in three ways.
The catalog on this site is our own product. We built it before any developer asked us to: we researched projects, went to look at them, checked open sources and wrote the descriptions ourselves. Where such material contains the name and business contact details of a person representing a company, that is personal data obtained from a source other than the data subject. Articles 14(1) and 14(2) of the GDPR require us to say where it came from and what we do with it — this policy is that notice, published permanently and in every language of the site. Writing to each representative individually would involve a disproportionate effort, which Article 14(5)(b) recognises.
If you are named in the catalog and want the entry corrected, restricted, or your personal contact details removed, section 6 explains what we can and cannot do, and section 11 explains how to ask.
Every use of your data has a purpose and a legal basis under Article 6 of the GDPR.
We also process data where the law requires it — for example identification checks in a real-estate transaction — and where we need to establish, exercise or defend a legal claim, Articles 6(1)(c) and 6(1)(f). Where we rely on legitimate interest we weigh it against your rights: the information we hold about company representatives is professional rather than private, we keep it to what the purpose needs, we do not use it for unrelated marketing, and we stop when you object and we have no overriding ground to continue.
You can object to any processing based on our legitimate interest at any time — see section 11 and Article 21 of the GDPR.
Information about a company or a building is not personal data. The name of a development, its address, its prices, its construction stage and the company behind it describe legal entities and objects, not individuals. Personal data appears only where a particular person can be identified — a named contact in a sales department, or someone who holds an account with us.
A developer or partner who wants to correct and enrich an entry can ask us for access. We check that the applicant genuinely represents the company, then open a company account with roles, and the person holding it invites colleagues by e-mail. From that point they can update project details, prices, availability, descriptions and media. What they upload, and the warranties they give us about it, is governed by the Terms of Service.
When a representative leaves, an account is closed, or access is withdrawn, we delete that person's personal data along with their access. The catalog entry itself does not disappear: information about the company and the project, and the research, reports and opinions we published about it, are our own editorial material and remain available. Article 17(3)(a) of the GDPR expressly preserves processing that is necessary for exercising the right to freedom of expression and information, and that is the basis on which we continue to publish it.
That is not a refusal to listen. If you believe something we publish about a company or a project is inaccurate, tell us: the complaints procedure in the Terms of Service commits us to answer within 10 working days and, where we are wrong, to correct the material or to publish your reply beside it.
The main store of personal data is in the European Union. Our database, authentication and file storage are hosted in EU (Frankfurt, Germany), which means accounts, contact requests, comments and the contact details of company representatives physically reside in the EU.
Some supporting services operate outside the European Union: hosting and server logs, error monitoring, e-mail delivery, spam protection, maps, and the messaging services listed in section 7. Where data reaches a country without an EU adequacy decision, the transfer relies on the standard contractual clauses in our providers' data-processing agreements, or — where the service is used on your own initiative, such as a chat you open in a messenger — on your decision to use it. Write to privacy@kvartly.com if you want details of the safeguards for a particular provider.
We keep personal data for as long as it serves the purpose it was collected for, and no longer.
Two things outlive these periods: copies inside backups, which are overwritten on their own cycle, and anything we must keep by law or need in order to establish, exercise or defend a legal claim. Information about developers, their projects and their public representatives is kept for as long as it remains relevant to the catalog.
Protection is built into the way the database is written, not added on top of it.
No service can promise perfect security. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where the law requires it, you.
Where the GDPR or Georgian data-protection law applies to you, you have the following rights.
To exercise any of these rights, write to privacy@kvartly.com. We answer within 30 days. We may need to verify who you are before we act, particularly on a request to delete data or to receive a copy of it. Deleting an account and exporting your data are handled by us manually on request — there is no self-service button for either yet, and we would rather say so than describe a feature that does not exist.
Erasure has limits, and we prefer to state them in advance. We do not delete information about a company or a development, which is not personal data; we do not withdraw research, reports and opinions we have published, which Article 17(3)(a) of the GDPR protects as an exercise of the right to freedom of expression and information; and we keep whatever the law requires us to keep or we need in order to defend a legal claim. Everything else about you — your account, your profile, your contact details as an individual — we delete.
The site is meant for adults dealing with real estate. We do not knowingly collect personal data from children under 16, and anyone holding an account must be old enough to enter into a contract under the law that applies to them. If you believe a child has given us personal data, write to privacy@kvartly.com and we will delete it.
We update this policy when what we do with data changes. The version and the date it takes effect are printed at the top of this page. If a change materially affects your rights we announce it on the site and, where we hold your address and the law requires it, by e-mail.
Questions, requests and complaints about personal data: privacy@kvartly.com. Postal address: Kvartly.com, San Marco Argentano, 45, Italy, Rome.
This policy is written in English and translated into the other languages of the site automatically. In case of any discrepancy between versions, the English text prevails.