Privacy Policy

In effect from August 1, 2026 Β· version 1.0

This policy explains what personal data Kvartly.com collects, why we collect it, whom we share it with, and what you can do about it. It applies to kvartly.com in every language version and to the services we provide through it. Cookies are described separately in our Cookie Policy.

This document is written in English and translated into the other languages of the site automatically. If a translation differs from the English text, the English version prevails.

1. Who we are

Kvartly.com, registration number 584856168498451, registered at Via S. Marco Argentano, 48, 00128 Roma RM, Italy, operates kvartly.com and the services described in this policy. In the language of data-protection law we are the controller of the personal data described here: we decide why and how it is processed.

If you have a question about this policy, or want to exercise any of the rights set out in section 11, write to privacy@kvartly.com. We answer in English, Russian or Georgian.

Representative in the European Union. Under Article 27 of the GDPR we have appointed Yuri Palienko, established in Italy, as our representative in the European Union. Data subjects and supervisory authorities in the EU may contact the representative directly at Via S. Marco Argentano, 48, 00128 Roma RM, Italy, or by e-mail at legal@kvartly.com, on any question concerning the processing of personal data.

2. What this policy covers

This policy covers kvartly.com in all of its language versions and everything we do through it: the catalog of new developments, our own research and editorial materials, accounts, favourites, comments, contact requests and service notifications. It also covers the personal data of company representatives that we hold in the catalog, including people who never created an account with us.

It does not cover the websites and sales offices of developers, other third-party sites we link to, or messaging services such as WhatsApp and Telegram: as soon as you leave our site or open a conversation in a messenger, that provider's own terms and privacy policy apply alongside ours. Cookies are described in the Cookie Policy, and the contractual side of our relationship in the Terms of Service.

3. Data we collect

Depending on how you use the site, we may hold the following.

  • Account data: your e-mail address, your name or display name, your preferred language, and a cryptographic hash of your password. We never see or store the password itself. If you sign in through another provider, we receive the identifiers that provider sends us.
  • Profile details you choose to add: phone number, additional e-mail addresses, messenger handles, postal address.
  • Contact requests: your name, phone number, e-mail address, the company you name if you name one, and the text of your message.
  • The context of a request: the page you sent it from, the page that referred you, campaign parameters in the link, the approximate city derived from your IP address, the type of device, and the development and price you were looking at. We use it to understand what the request is about.
  • Comments: the name you sign with β€” a pseudonym is acceptable β€” the text you publish, and, for comments left without an account, the IP address the comment was sent from, which is stored but never shown publicly.
  • Technical data generated as you use the site: IP address, browser and device information, the pages you request, and, when something breaks, the technical details of the error.
  • Information about developers, their projects and the people who represent them publicly: company and registration details, project details, and business contact details of representatives. Section 4 explains where this comes from.

We do not ask for special categories of data β€” health, religious or political views, biometric data β€” and you should not send them to us. We do not process payments on the site, so we never hold your card or bank details.

Much of this is optional and the choice is yours: leaving a phone number, adding contacts to your profile, or signing a comment with your real name. Where a field is genuinely required in order to provide the service, we say so where we ask for it.

4. Where we get it

Personal data reaches us in three ways.

  • From you: when you create an account, fill in your profile, send a contact request, publish a comment, or write to us by e-mail or in a messenger.
  • Automatically from your device as you use the site: the IP address, browser data and technical records described in section 3.
  • From public sources and our own research: public registers, developers' own websites and marketing materials, sales offices, visits to construction sites, publications in the media, and our own automated collection of publicly available listings and project information.

The catalog on this site is our own product. We built it before any developer asked us to: we researched projects, went to look at them, checked open sources and wrote the descriptions ourselves. Where such material contains the name and business contact details of a person representing a company, that is personal data obtained from a source other than the data subject. Articles 14(1) and 14(2) of the GDPR require us to say where it came from and what we do with it β€” this policy is that notice, published permanently and in every language of the site. Writing to each representative individually would involve a disproportionate effort, which Article 14(5)(b) recognises.

If you are named in the catalog and want the entry corrected, restricted, or your personal contact details removed, section 6 explains what we can and cannot do, and section 11 explains how to ask.

5. Why we use it, and on what basis

Every use of your data has a purpose and a legal basis under Article 6 of the GDPR.

  • To create and operate your account, keep you signed in and remember your settings and favourites β€” performance of a contract with you, Article 6(1)(b).
  • To receive and handle a contact request, call you back, answer your question and prepare a possible transaction β€” performance of a contract, or steps taken at your request before entering into one, Article 6(1)(b).
  • To provide agency services under a separate agreement, including arranging viewings and accompanying a purchase β€” performance of that contract, Article 6(1)(b).
  • To build, verify and keep up to date the catalog of developments, developers and their public representatives, and to publish our own research and editorial materials β€” our legitimate interest in running an informational service, and the interest of the public in accurate information about the market, Article 6(1)(f).
  • To publish and moderate comments and to protect the site from spam and abuse β€” which is why we record the IP address a comment was sent from and apply rate limits and block lists β€” our legitimate interest in a usable and safe service, Article 6(1)(f).
  • To send service messages about your account, your requests, moderation of your comments and invitations to a company account β€” performance of a contract, Article 6(1)(b), and our legitimate interest in keeping you informed, Article 6(1)(f).
  • To keep the site secure and working, including error monitoring and the investigation of abuse β€” our legitimate interest, Article 6(1)(f).
  • To use optional cookies or send you marketing messages, if and when we introduce them β€” your consent, which you can withdraw at any time, Article 6(1)(a).

We also process data where the law requires it β€” for example identification checks in a real-estate transaction β€” and where we need to establish, exercise or defend a legal claim, Articles 6(1)(c) and 6(1)(f). Where we rely on legitimate interest we weigh it against your rights: the information we hold about company representatives is professional rather than private, we keep it to what the purpose needs, we do not use it for unrelated marketing, and we stop when you object and we have no overriding ground to continue.

You can object to any processing based on our legitimate interest at any time β€” see section 11 and Article 21 of the GDPR.

6. Developers, their profiles and their data

Information about a company or a building is not personal data. The name of a development, its address, its prices, its construction stage and the company behind it describe legal entities and objects, not individuals. Personal data appears only where a particular person can be identified β€” a named contact in a sales department, or someone who holds an account with us.

A developer or partner who wants to correct and enrich an entry can ask us for access. We check that the applicant genuinely represents the company, then open a company account with roles, and the person holding it invites colleagues by e-mail. From that point they can update project details, prices, availability, descriptions and media. What they upload, and the warranties they give us about it, is governed by the Terms of Service.

When a representative leaves, an account is closed, or access is withdrawn, we delete that person's personal data along with their access. The catalog entry itself does not disappear: information about the company and the project, and the research, reports and opinions we published about it, are our own editorial material and remain available. Article 17(3)(a) of the GDPR expressly preserves processing that is necessary for exercising the right to freedom of expression and information, and that is the basis on which we continue to publish it.

That is not a refusal to listen. If you believe something we publish about a company or a project is inaccurate, tell us: the complaints procedure in the Terms of Service commits us to answer within 10 working days and, where we are wrong, to correct the material or to publish your reply beside it.

7. Who we share it with

We do not sell personal data and we do not share it for other companies' marketing. We do rely on service providers that process data on our behalf under contract, and in a few cases data goes to recipients that decide for themselves what to do with it.

  • Vercel β€” hosting of the site and its server functions; handles all traffic, including IP addresses and server logs.
  • Supabase β€” our database, authentication and file storage. The project is hosted in EU (Frankfurt, Germany), so accounts, requests, comments and catalog data are stored there.
  • Bunny CDN β€” delivery of images; receives the IP address and the request of anyone loading a picture.
  • Resend β€” delivery of transactional e-mail such as confirmations, invitations and notifications; receives the recipient address and the content of the message.
  • Rollbar β€” error monitoring; receives the technical details of a failure, which can include an IP address, browser data and the page you were on.
  • Google reCAPTCHA Enterprise β€” spam protection on forms; receives your IP address and interaction signals when a form is submitted.
  • Mapbox β€” map tiles on project pages; receives your IP address when a map loads.
  • Telegram β€” new contact requests are announced in our internal staff channel through the Telegram Bot API, and that message contains the request itself, including the name, phone number and e-mail address you gave us. Access to the channel is limited to the people who handle requests.
  • WhatsApp and Telegram as conversation channels β€” if you start a chat with us there, everything you write passes through that provider under its own terms.
  • Developers and partners β€” we pass your contact details to a developer only when you ask us to, for a specific project. From that moment the developer is an independent controller of what it receives and its own privacy policy applies.
  • Professional advisers, and public authorities or courts, where the law requires it or where we need to establish or defend a legal claim.
  • Google Analytics β€” audience measurement; receives your IP address, the pages you open and a randomly generated identifier, and only once you have accepted analytics cookies. Withdraw that consent and the tag stops loading.
  • Google LLC β€” sign-in with a Google account, if you choose to use it. Google authenticates you under its own terms and privacy policy and sends us your e-mail address, your name and your profile picture; we store them in your account. We never see your Google password. If you sign in with your e-mail and password instead, no data goes to Google for this purpose.

We use machine translation (DeepSeek and OpenAI models) for our own content β€” catalog descriptions, articles, reports and interface strings. Personal data of users is not sent to those services.

Providers acting on our behalf are bound by contract to process data only on our instructions and to protect it. Recipients that decide for themselves what to do with data β€” a developer you asked us to contact, a messenger you write to, an authority β€” act as independent controllers, and their own policies govern what happens next.

8. International transfers

The main store of personal data is in the European Union. Our database, authentication and file storage are hosted in EU (Frankfurt, Germany), which means accounts, contact requests, comments and the contact details of company representatives physically reside in the EU.

Some supporting services operate outside the European Union: hosting and server logs, error monitoring, e-mail delivery, spam protection, maps, and the messaging services listed in section 7. Where data reaches a country without an EU adequacy decision, the transfer relies on the standard contractual clauses in our providers' data-processing agreements, or β€” where the service is used on your own initiative, such as a chat you open in a messenger β€” on your decision to use it. Write to privacy@kvartly.com if you want details of the safeguards for a particular provider.

9. How long we keep it

We keep personal data for as long as it serves the purpose it was collected for, and no longer.

  • Account data β€” until you delete your account, plus up to 30 days while it disappears from backups.
  • Profile contact details β€” together with the account.
  • Contact requests, including the message and its context β€” 3 years from the request, so that the history of a transaction can be traced and claims arising from it answered.
  • Statistics of clicks on the WhatsApp and Telegram buttons, which contain no personal data β€” 12 months.
  • Comments β€” until you or moderation remove them.
  • The IP address recorded with a comment β€” for as long as the comment stays published, because it is the key we use for rate limits and block lists. It is recorded only for comments left without an account, it is never shown publicly, and it is deleted together with the comment.
  • Moderation decisions and their history β€” 3 years, so that a disputed decision can be reconstructed.
  • Invitations to a company account β€” until accepted or withdrawn, plus the record that the invitation existed.
  • Error reports held by our monitoring provider β€” for the limited period set by that provider's own retention policy.

Two things outlive these periods: copies inside backups, which are overwritten on their own cycle, and anything we must keep by law or need in order to establish, exercise or defend a legal claim. Information about developers, their projects and their public representatives is kept for as long as it remains relevant to the catalog.

10. How we protect it

Protection is built into the way the database is written, not added on top of it.

  • Every table is protected by row-level security, and applications reach data through audited server-side functions rather than by querying tables directly.
  • The IP address stored with a comment is not visible publicly and is not returned by any public interface; only server-side moderation logic can see it.
  • Privileged database keys exist only on the server and are never sent to a browser.
  • All traffic between your browser and the site is encrypted in transit.
  • Access to personal data inside the company is limited to the people who need it for their work, including the internal channel where new requests are announced.
  • Passwords are stored only as cryptographic hashes by our authentication provider; nobody at Kvartly.com can read them.

No service can promise perfect security. If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where the law requires it, you.

11. Your rights

Where the GDPR or Georgian data-protection law applies to you, you have the following rights.

  • Access β€” to learn whether we hold data about you and to receive a copy of it.
  • Rectification β€” to have inaccurate data corrected and incomplete data completed.
  • Erasure β€” to have your data deleted where there is no overriding reason to keep it; the limits are set out below.
  • Restriction β€” to have processing paused while an objection, or a dispute about accuracy, is examined.
  • Portability β€” to receive the data you gave us in a structured, machine-readable format.
  • Objection β€” to object at any time to processing based on our legitimate interest, including your presence in the catalog, under Article 21 of the GDPR.
  • Withdrawal of consent β€” where we rely on consent you can withdraw it at any time, without affecting what was lawful before.
  • Complaint β€” to complain to a supervisory authority: the Personal Data Protection Service of Georgia, or the authority of your country of residence in the European Union.

To exercise any of these rights, write to privacy@kvartly.com. We answer within 30 days. We may need to verify who you are before we act, particularly on a request to delete data or to receive a copy of it. Deleting an account and exporting your data are handled by us manually on request β€” there is no self-service button for either yet, and we would rather say so than describe a feature that does not exist.

Erasure has limits, and we prefer to state them in advance. We do not delete information about a company or a development, which is not personal data; we do not withdraw research, reports and opinions we have published, which Article 17(3)(a) of the GDPR protects as an exercise of the right to freedom of expression and information; and we keep whatever the law requires us to keep or we need in order to defend a legal claim. Everything else about you β€” your account, your profile, your contact details as an individual β€” we delete.

12. Sign in with Google

You can create an account on kvartly.com, and sign in to it, with your Google account instead of choosing a password. This is optional β€” an e-mail address and a password work just as well β€” and it is the only place on this site where we use data from a Google account.

When you choose Sign in with Google, we ask Google for the basic profile of the account you select, through the standard openid, userinfo.email and userinfo.profile scopes. Google then sends us the following, and our authentication provider stores it as part of your account record.

  • The identifier Google uses for your account. This is what lets us recognise you the next time you sign in.
  • Your e-mail address, and whether Google has confirmed it. It becomes the e-mail address of your account with us.
  • The name on your Google account. It becomes the name your account is created with; you can change it afterwards in your profile.
  • The address of your Google profile picture. We receive it, but we do not publish it anywhere on the site: the picture shown next to your name is the one you upload yourself, or your initials.

We use this to create and identify your account, to keep you signed in, to address you by name in the interface, and to send you service notifications about your requests and the developments you save β€” performance of a contract with you, Article 6(1)(b) of the GDPR, the same basis as section 5 sets out for accounts in general. We ask Google for nothing beyond that basic profile: no contacts, no calendar, no files, and no access to any other Google service.

Kvartly.com's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this information, we do not use it for advertising or to build advertising profiles, and no person reads it except where that is necessary to keep the service secure, where the law requires it, or where you have asked us to.

You can disconnect kvartly.com from your Google account at any time in your Google account settings. That stops any further sign-in, but it does not delete the account you already hold with us: to have that account and the data listed above deleted, write to privacy@kvartly.com. Section 9 explains how long anything survives deletion, and section 11 the rest of your rights.

13. Children

The site is meant for adults dealing with real estate. We do not knowingly collect personal data from children under 16, and anyone holding an account must be old enough to enter into a contract under the law that applies to them. If you believe a child has given us personal data, write to privacy@kvartly.com and we will delete it.

14. Cookies

We use a small number of cookies to keep you signed in, remember your language and protect forms from spam, and we ask for your consent before using any that are not strictly necessary. Which cookies we set, why, and for how long is described in the Cookie Policy; you can review or change your choice at any time in .

15. Changes and contact

We update this policy when what we do with data changes. The version and the date it takes effect are printed at the top of this page. If a change materially affects your rights we announce it on the site and, where we hold your address and the law requires it, by e-mail.

Questions, requests and complaints about personal data: privacy@kvartly.com. Postal address: Kvartly.com, Via S. Marco Argentano, 48, 00128 Roma RM, Italy.

This policy is written in English and translated into the other languages of the site automatically. In case of any discrepancy between versions, the English text prevails.

We value your privacy

We use cookies to keep the site working, remember your language and protect against spam. With your consent we may also use analytics and marketing cookies. Read our Cookie Policy and Privacy Policy.