Privacy policy for SustainProp
Effective: January 2025
The following privacy policy informs you about the nature, scope, and purpose of the processing of personal data on our website and platform “SustainProp”. We place great importance on protecting your data and act in accordance with the applicable data protection laws, including the GDPR and the EU AI Act.
1. Data Controller
E-mail: datenschutz@sustainprop.com/en2. Processing of Personal Data
We process personal data solely within the limits permitted by law. The data processed include:
- Name, address, telephone number, e-mail address
- Building data (address, year built, building type, energy consumption)
- IP address and usage data when visiting our website
- Data retrieved from public and private databases (e.g., building characteristics)
Purpose of Data Processing:
- Conducting AI-supported analyses and scenarios
- Optimizing building analysis and calculations
- Fulfilling contracts and business relationships
- Providing our platform and web services
Legal Bases:
- Consent (Art. 6 para. 1 lit. a GDPR) for specific analyses and marketing
- Contract performance (Art. 6 para. 1 lit. b GDPR) for services
- Legitimate interest (Art. 6 para. 1 lit. f GDPR) to improve our offerings
3. Use of Tools and Third Parties
We use the following third-party providers and technologies:
- Google Cloud: Hosting and storage of data. The standard contractual clauses apply for data transfers to third countries.
- Mapbox and OpenStreetMap: Display of maps and building data.
- Rechenkern: AI-based calculations and scenarios for building analysis.
- Cookies and Tracking:
- We use essential cookies for the operation of the website.
- Optional cookies for analysis purposes (consent required).
- You can revoke your consent at any time.
4. Data Sharing and Storage
Data Sharing:
We share personal data only within the scope of the purposes described with:
- Hosting provider (Google Cloud)
- Providers of mapping and analysis tools (Mapbox, OpenStreetMap, Rechenkern)
Retention Periods:
- Data will be deleted when a business relationship ends or if no business relationship is established within 4 weeks after initial contact.
- Statutory retention periods remain unaffected.
5. Rights of Data Subjects
You have the following rights under the GDPR:
- Right of access to your data (Art. 15 GDPR)
- Right to rectification of inaccurate data (Art. 16 GDPR)
- Right to erasure of your data (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object to processing (Art. 21 GDPR)
To exercise your rights, please contact: datenschutz@sustainprop.com/en
6. Compliance with the EU AI Act
The AI systems we use comply with the requirements of the EU AI Act. We ensure:
- Transparency: Explanation of how our algorithms function.
- Monitoring: Regular review of the AI models.
- Data Security: Protection of data through encryption and access restrictions.
7. Security of Your Data
We implement technical and organizational measures to protect your data from loss, manipulation, and unauthorized access.
8. Changes to the Privacy Policy
This privacy policy will be adjusted if there are changes to our data processing. Please check our privacy policy regularly for updates.

