1. Who We Are
EstatAI ("we", "us", "our") is a software-as-a-service platform providing AI-powered lead generation and property consultation tools for UK estate agencies. Our registered business operates under the domain estatai.co.uk.
For any privacy-related queries, contact us at: hello@estatai.co.uk
2. Data We Collect
We collect the following categories of personal data:
Account & Registration Data When you register for EstatAI, we collect your name, email address, company name, and website URL.
Widget Visitor Data (on behalf of agencies) When a visitor interacts with an EstatAI widget installed on an estate agency's website, we may collect: name, email address, phone number, and the content of their conversation with the AI widget. This data is collected on behalf of the estate agency (our client) who acts as the data controller for their visitors.
Usage & Analytics Data We collect information about how you use our platform including pages visited, features used, session duration, and browser/device information.
Technical Data IP addresses, cookies, browser type, operating system, and referring URLs.
Payment Data We do not store card details directly. Payments are processed by third-party providers (Stripe). We retain transaction records only.
3. How We Use Your Data
We use your personal data for the following purposes:
• Service delivery — to provide, operate, and maintain the EstatAI platform • Account management — to manage your account, subscription, and billing • Lead notifications — to send estate agencies email notifications when their widget captures a lead • Customer support — to respond to your queries and provide technical assistance • Product improvement — to analyse usage patterns and improve our platform • Legal compliance — to comply with applicable UK laws and regulations • Marketing — with your consent, to send product updates and relevant communications (you can unsubscribe at any time)
Legal basis under UK GDPR: • Contract performance — for delivering the service you have subscribed to • Legitimate interests — for platform improvement, fraud prevention, and security • Legal obligation — for compliance with UK law • Consent — for marketing communications
4. Data Sharing
We do not sell your personal data. We share data only in the following circumstances:
Service Providers We work with trusted third-party providers who process data on our behalf under strict data processing agreements: • OpenAI (AI conversation processing — data processed under GDPR-compliant terms) • Render.com (server hosting — Frankfurt, EU) • Stripe (payment processing) • Vercel (frontend hosting)
Estate Agencies Visitor data collected through a widget is made available to the estate agency that owns that widget. They are the data controller for their visitors.
Legal Requirements We may disclose data if required by law, court order, or regulatory authority (such as the ICO).
Business Transfer If EstatAI is acquired or merged, your data may transfer to the new entity, subject to the same protections.
5. Data Retention
We retain personal data for as long as necessary to fulfil the purposes outlined in this policy:
• Account data — retained for the duration of your subscription plus 2 years after account closure • Widget conversation data — retained for 12 months, then permanently deleted unless you request earlier deletion • Payment records — retained for 7 years to comply with UK financial regulations • Server logs — retained for 90 days
You may request deletion of your data at any time by contacting hello@estatai.co.uk. We will action deletion requests within 30 days.
6. Your Rights Under UK GDPR
Under the UK GDPR and Data Protection Act 2018, you have the following rights:
• Right of access — request a copy of the personal data we hold about you • Right to rectification — request correction of inaccurate or incomplete data • Right to erasure — request deletion of your personal data ("right to be forgotten") • Right to restrict processing — request that we limit how we use your data • Right to data portability — receive your data in a structured, machine-readable format • Right to object — object to processing based on legitimate interests or for direct marketing • Rights related to automated decision-making — not to be subject to solely automated decisions that significantly affect you
To exercise any of these rights, contact us at hello@estatai.co.uk. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. International Data Transfers
Our servers are located in Frankfurt, EU. Some of our third-party providers (including OpenAI) may process data outside the UK/EEA. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the UK ICO, to protect your data.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
• 256-bit SSL/TLS encryption for all data in transit • Encrypted database storage • Access controls and authentication requirements • Regular security reviews • Incident response procedures
No method of transmission over the internet is 100% secure. In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the ICO within 72 hours as required by UK GDPR.
10. Children's Privacy
EstatAI is a business-to-business platform intended solely for use by estate agencies and property professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately at hello@estatai.co.uk.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of any material changes by email and will update the "Last updated" date at the top of this page. Continued use of EstatAI after changes are posted constitutes acceptance of the updated policy.
12. Contact Us
For any questions about this Privacy Policy or to exercise your data rights:
Email: hello@estatai.co.uk Subject line: Privacy Request
For complaints or concerns that we are unable to resolve, you may contact the Information Commissioner's Office (ICO): Website: ico.org.uk Helpline: 0303 123 1113