Legal
Privacy policy
How prop.forsale collects, uses and protects personal information, and the choices you have.
On this page
The short version
- Kwestra LLC runs prop.forsale. For information an agency collects about its clients, the agency is in charge and we process it for them.
- We collect only what the service needs: account details, listings, enquiries you send, deal room records and, if you accept, product analytics.
- We do not sell personal information, do not share it for advertising, and use no advertising cookies.
- Your information is stored mainly in the United States, with documents in the region the agency chose, under contracts that protect it.
- You can ask for a copy, a correction or deletion at any time: email privacy@pfs-stage.dev. We honour Global Privacy Control.
- More detail for Europe and the UK is at /gdpr, and for US states at /us-privacy.
This summary helps you find your way. The full text below is what applies.
1. Who we are
prop.forsale is operated by Kwestra LLC, 14 NE 1st Ave, Ste 1403 #146, Miami, FL 33132, USA ("we"). We give property agents, agencies and agency networks their own websites, listing tools, enquiry handling, deal rooms, newsletters and billing, and we run the prop.forsale property portal.
Information Officer: Information Officer, Kwestra LLC. Privacy contact: privacy@pfs-stage.dev.
- We are in charge (controller)
- For people who sign in to the platform, visitors to the prop.forsale property portal, platform emails and billing. POPIA calls this the "responsible party"; the GDPR calls it the "controller".
- The agency is in charge (we are its processor)
- For information an agency collects through its own site or deal rooms: enquiries, newsletter subscribers, deal parties and documents. We act only on the agency’s instructions under our data processing addendum (/dpa). Each agency site shows the agency’s own privacy notice.
2. What we collect
We collect only what the service needs:
- Agents and agency staff: name, email address, sign-in and security records, role, and the agency, network and listing details you enter (brand, contact details, listings, photos, content).
- Deal room parties invited by an agent (buyers, sellers, attorneys, bond originators and others): name, email, optional phone number, your role in the deal, messages, and the documents you or the agent upload. These documents can include identity documents, proof of address and proof of funds, because agents need them for anti-money-laundering checks.
- Enquirers (on behalf of agencies): name, email, optional phone number, message, the listing concerned, your consent choices and a one-way hash of your IP address as evidence of consent.
- Newsletter subscribers: email, optional name, interests, consent record, confirmation and unsubscribe events, and delivery, bounce or complaint status.
- Imported and AI-assisted content: when an agent imports a property page or asks for AI help, the public content of that page and the listing facts.
- Deal chat: the questions you ask in a deal room and the answers. When the agency turns on document reading, the chat also reads the text of the deal documents you may open (scanned pages are read with OCR by Mistral AI in the EU); that text is stored only encrypted with the agency's key.
- Billing: the billing contact and Stripe customer reference. Card details go directly to Stripe; we never see or store them.
- Technical data: IP address, browser and request information needed to deliver pages, stop abuse and keep the service secure; cookieless page-view counts; and, only if you accept analytics, product analytics (see the cookie notice).
3. Why we use it, and on what basis
We process personal information only for a specific, lawful purpose. The GDPR lawful basis for each purpose is set out in full at /gdpr#lawful-bases.
- To provide the service an agent or agency signed up for, and to run deal rooms they invite you to (performance of a contract, or the agency’s legitimate interest in managing its transaction).
- To deliver an enquiry to the agency you contacted and let it reply, including by email or a WhatsApp link you choose to follow (your consent, which you give on the form).
- To send newsletters you confirmed by double opt-in (your consent; every email has a one-click unsubscribe).
- To import and improve listings with AI when an agent asks (performance of a contract).
- To answer questions in a deal room's chat from what the person asking may see there, including the documents they may open when the agency turns document reading on (the agency's legitimate interest in managing its transaction).
- To take payment and keep financial and record-keeping obligations, including deal documents under anti-money-laundering rules (contract and legal obligation).
- To secure the service, prevent spam and abuse, and fix faults (legitimate interest).
- To understand how the product is used, only if you accept analytics (consent).
5. Where your information is processed
We are a global platform, so personal information is processed outside the country you are in.
Our main database (accounts, listings, enquiries, deal room records and subscribers) is hosted by Cloudflare in the United States (eastern North America) for every agency. Agency documents and photos are stored in the region the agency chose at sign-up: United States (default), European Union, Asia-Pacific or Oceania. There is no African storage region yet, so South African agencies are stored in the United States unless they choose otherwise.
Our service providers mainly process in the United States and the European Union. For information from South Africa, every transfer is covered by written agreements that require protection substantially similar to POPIA, as POPIA section 72 requires. For information from the EU, UK or Switzerland, we rely on the EU-US Data Privacy Framework and its UK and Swiss extensions where the provider is certified, and on the European Commission’s Standard Contractual Clauses (with the UK addendum) otherwise. The safeguard for each provider is in the table above.
6. How long we keep it
We keep personal information only as long as the purpose requires. Automatic clean-up jobs apply these periods:
| Information | How long | Why |
|---|---|---|
| Account and workspace records | While the workspace exists, then 30 days after it is deleted. | To provide the service, and to allow a deletion to be reversed by mistake. |
| Enquiries and leads | Erased automatically 2 years after the last activity on the enquiry (the enquiry itself, a message about it, or an update by the agency). An enquiry linked to a deal is not erased this way: it is kept with the deal's records. The agency can erase one sooner. | To let the agency answer and follow up. |
| Sales enquiries to prop.forsale | Deleted 2 years after the last contact, unless your agency becomes a customer; then kept with its workspace records. | To answer your enquiry and follow up on it. |
| Newsletter subscribers | While subscribed. After unsubscribing: your details are erased 30 days after you unsubscribe. A one-way hash of your email address (not the address itself) is kept permanently so that agency never emails you again, unless you sign up and confirm again. | To send what you asked for, and to respect your opt-out. |
| Deal room documents | At least five years from upload, and they cannot be deleted sooner. | Record-keeping law for property transactions (for example FICA in South Africa). |
| Deal chat conversations | Five years, like the deal's other records, then deleted. Encrypted, and seen only by the person who asked. | Record-keeping law for property transactions. |
| Text the deal chat read from deal documents (when the agency turns document reading on) | Until the document is removed or replaced, and at most 30 days after the deal closes, then deleted. Encrypted with the agency's key; never a searchable index. | To answer questions about the documents a person may open. |
| Raw copies of inbound email | 90 days. Messages filed to a lead or deal stay with it. | Troubleshooting and security. |
| Rejected or ignored inbound email records | 30 days. | Troubleshooting and abuse prevention. |
| Notifications | Read: 90 days. Unread: 180 days. | To show you what happened in your workspace. |
| Search cache | 30 days. | Faster, cheaper repeat searches. |
| Sign-in sessions and one-time links | Deleted when they expire. | Security. |
| Security and audit logs | While the workspace exists. | Security, fraud prevention and legal claims. |
| Database backups | Point-in-time recovery for 30 days, plus a backup copy taken before each release. | Recovering from faults. Erased records drop out of backups as those expire. |
| Billing records | As long as tax and accounting law requires. | Legal obligation. |
| Optional analytics | Under the PostHog project’s retention settings; deleted on request. | Only if you accepted analytics. |
7. How we protect it
We use encryption in transit, strict separation between agencies, new deal room documents encrypted with a per-agency key (AES-256-GCM) on top of storage encryption, hashed tokens, bot protection on forms, least-privilege access for staff, and logging of administrative actions and document access.
If a security compromise affects your information we will notify you and the relevant regulator as the law requires (POPIA section 22, GDPR articles 33 and 34, and US state breach laws).
8. Your rights
Wherever you live, you can use these rights by emailing privacy@pfs-stage.dev. We will confirm who you are before we act, and answer within one month (45 days where US state law sets that period). For information an agency holds, you can also contact the agency directly; we will help it respond.
- Access: ask whether we hold personal information about you and get a copy (POPIA section 23, GDPR article 15).
- Correction and deletion: ask us to correct information that is wrong or incomplete, or delete information we no longer need or hold unlawfully (POPIA section 24, GDPR articles 16 and 17).
- Objection and restriction: object to processing based on legitimate interests, ask us to restrict processing, and stop direct marketing at any time.
- Portability: where we process on the basis of consent or contract, ask for your information in a common machine-readable format.
- Withdraw consent at any time, without affecting processing that took place before you withdrew it.
- Complain to a regulator: in South Africa the Information Regulator (https://inforegulator.org.za); in the EU your local data protection authority; in the UK the Information Commissioner’s Office (https://ico.org.uk).
| Where you live | Main law | Your main rights | Where to complain |
|---|---|---|---|
| South Africa | Protection of Personal Information Act, 2013 (POPIA) | Access, correction, deletion, objection (including to direct marketing), and to be told about a security compromise. | Information Regulator: https://inforegulator.org.za |
| European Union and EEA | General Data Protection Regulation (GDPR) | Access, rectification, erasure, restriction, portability, objection, withdrawing consent, and not being subject to solely automated decisions. Details at /gdpr. | Your national data protection authority: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en |
| United Kingdom | UK GDPR and Data Protection Act 2018 | The same rights as in the EU. Details at /gdpr. | Information Commissioner’s Office: https://ico.org.uk/make-a-complaint |
| United States | State privacy laws, including California (CCPA as amended by the CPRA) | Know and access, delete, correct, opt out of sale, sharing, targeted advertising and profiling, limit use of sensitive information, and equal service when you use your rights. Details at /us-privacy. | Your state attorney general, or in California the California Privacy Protection Agency: https://cppa.ca.gov |
| United Arab Emirates | Federal Decree-Law No. 45 of 2021 (PDPL) | Information about processing, access, correction, erasure, restriction, stopping processing, portability, and objecting to automated decisions. | The UAE federal data protection authority |
| Anywhere else | Local law | We give everyone access, correction and deletion on request, whatever the local law requires. | Us first, using the privacy contact on this page; then your local regulator. |
9. Marketing messages
We and the agencies on the platform send marketing email only to people who opted in and confirmed. Every message says who sent it and has a one-click unsubscribe; we act on an unsubscribe straight away. The platform does not send marketing SMS or WhatsApp messages; WhatsApp is only a link you choose to follow.
10. Prospect outreach to agents
prop.forsale staff may invite a property agent to join by preparing a private preview of that agent's own publicly listed properties. We use only the agent's published business contact details (or a referral or the agent's own enquiry), and we record which of these applies. This is one targeted business contact, based on our legitimate interest in offering the service to estate agents (POPIA section 69 and GDPR article 6(1)(f)).
The preview is private: it needs both the link and a separate code, it is never indexed or published, and the listing text is rewritten. The original page address is kept internally only. Nothing is published unless the agent signs up and publishes the listings from their own workspace.
Every message and the preview page offer an opt-out ("don't contact me again"). Opting out stores a one-way hash of the contact detail so we never contact it again, and revokes the link. You can also report a listing that is not yours from the preview page.
A preview expires after 14 days (staff may extend it once by 7 days). Its listing text, photos and contact details are then deleted; a minimal record (reference, country, counts and dates) is kept for 24 months and then deleted.
11. Links to other services
Listing pages may link to WhatsApp, maps and other sites. Nothing is sent to them unless you follow the link; after that their own privacy policies apply.
12. Children
The service is for adults (18 or over). It is not directed at children and we do not knowingly collect information from anyone under 16. If you think a child has given us information, email us and we will delete it.
13. Changes and more information
Cookies are described in our cookie notice (/cookies). The EU and UK detail is at /gdpr, US state rights at /us-privacy, and how to request records under South African law in our PAIA manual (/paia-manual). We will post any change to this policy on this page with a new version and date, and tell signed-in users about material changes.