ImoInspect
Back to home

Privacy Policy — ImoInspect

Last updated: 2 September 2026Version: 1.1

1. Who we are

ImoInspect is a property inspection application for estate agencies and property managers. It is operated by:

Awake Design, a sole proprietorship (eenmanszaak) under Dutch law
Buizerdlaan 57
2496 HG Den Haag, the Netherlands
Chamber of Commerce (KvK) number: 42044426
D-U-N-S: 473904434

ImoInspect is a trade name of Awake Design. The app carries the ImoInspect name, but the company responsible for your data — the controller, in the language of the GDPR — is Awake Design. Where this policy says "we", it means Awake Design.

Questions about this policy or about your personal data: privacy@imoinspect.com

We have not appointed a Data Protection Officer. We are not required to.


2. Two different roles, and why it matters to you

This is the most important section of this policy, because which rights you have and who you should contact depends on which of the two groups you fall into.

A. When you work for an estate agency that uses ImoInspect (you sign in to the app or the admin panel)

Your account details are processed by us, as the controller. We decide what an account looks like and why it exists. Section 3A describes that data.

B. When you are a tenant, landlord or owner whose property is inspected

You are not our customer and you do not have an account with us. The estate agency that carried out the inspection decides which data is recorded about you and why — that agency is the controller. We only supply the software that stores and delivers it, which makes us a processor acting on that agency's instructions.

In practice: if you want your inspection data corrected or deleted, contact the estate agency named in your report. They are the ones who can decide. If you do not know who to contact, write to us at the address above and we will point you to the agency — we cannot make that decision for them, but we will not leave you stranded.


3. What data we process

3A. Account data (agency staff)

WhatWhy
First and last nameto identify who carried out an inspection, and to address you in emails
Email addresssign-in, password resets, sending reports
Phone numbercontact details within your organisation
Passwordstored only as a bcrypt hash — we never hold the password itself
Role and status (admin/inspector, active/inactive)access control
Language preferenceto send you email in your own language
Organisation you belong toto keep each agency's data separate

3B. Inspection data (tenants, landlords, owners)

Recorded in the app by the inspector, on behalf of the estate agency:

WhatNotes
Full nameof tenants and of landlords
Email address and phone numberused to deliver the report
NIF (Portuguese tax number)currently a required field
Date of birthtenants only, where recorded
Address, postal code, cityof the landlord and of the inspected property
Company namewhere the landlord is a company
Handwritten signaturedrawn on the device screen at the end of the inspection
Photographs of the propertyincluding rooms, defects, meters and documents
Meter readings, room condition, remarksthe substance of the inspection

Photographs may incidentally show personal belongings. They are taken to record the condition of the property; please tell the inspector if something should not be photographed.

3C. Data on the device

The app is offline-first: an inspection is completed on the device, without a network connection, and everything in 3B is stored in a local database on that device until the report is sent. Sign-in tokens are stored in the operating system's secure storage (Android Keystore).

Signing out does not erase this data — deliberately, because on an offline-first app the device may hold the only copy of a day's work. The local database is erased when a device is claimed by a different organisation, so that a shared work phone never shows the previous inspector's tenants.

3D. Error reports

When the app or our server hits an error, a report is sent to Sentry so we can fix it. This includes the type of error, the version of the app, and the device model.

An error report does not include a picture of your screen. The app was configured to attach one, which on an inspection screen would have carried a tenant's name, NIF, signature or photographs into an error report; that was switched off before release (17 August 2026). What we receive is the technical description of the failure, not the contents of the form you were filling in.

3E. What we do not collect


PurposeLegal basis (GDPR Art. 6)
Providing accounts and running the service for agenciesperformance of a contract (Art. 6(1)(b))
Storing and delivering inspection reportson the agency's instructions, as processor — the agency relies on its own basis, normally its contract with the tenant or landlord, or legitimate interest
Sending password reset and account emailsperformance of a contract
Keeping the service secure and diagnosing errorslegitimate interest (Art. 6(1)(f)): a working, secure application
Meeting legal obligations, e.g. tax recordslegal obligation (Art. 6(1)(c))

A NIF is a national identification number. It is not a special category of data under Article 9, but it is sensitive in practice and we treat it accordingly: it is never used for anything other than identifying a party to the inspection.


5. Who else sees the data

We use a small number of suppliers. Each is bound by a data processing agreement, and none of them is permitted to use the data for their own purposes.

SupplierWhat forWhere
Amazon Web Servicesservers, database and report storageFrankfurt, Germany (eu-central-1) — inside the EU
Sentryerror reportsEU region (ingest.de.sentry.io)
Postmark (ActiveCampaign)sending emailUnited States
Google (Gemini)the assistant on our websiteUnited States

About Postmark and the United States. Postmark has no European servers. When we send you a report or a password reset, the recipient's email address, the subject line and the content of that email are processed in the US and, by Postmark's own policy, retained there for 45 days before being deleted. This transfer relies on the European Commission's Standard Contractual Clauses. If that is unacceptable for your organisation, tell us — this is a supplier choice, not a design constraint.

About the assistant on our website. imoinspect.com has a chat where you can ask questions about the product. What you type is sent, by way of our own server, to Google's Gemini service so that it can compose an answer, and the answer comes back the same way. Your browser never contacts Google directly, no cookie is involved, and nothing about the conversation is stored on your device: it exists only while the page is open and is gone when you leave. We do not keep a copy of it either.

It is a way to ask about the product, not a channel for personal or tenancy details -- please do not type anything into it that you would not put in an ordinary email. This transfer to the United States relies on the EU-US Data Privacy Framework together with the Standard Contractual Clauses.

Beyond these suppliers we disclose personal data only where the law requires it.


6. How long we keep it

DataRetention
Account datafor as long as the agency uses ImoInspect — see the note below
The download link for a report30 days, after which the link stops working
The report file itself12 months from the day it was sent, then deleted automatically
Email content at Postmark45 days (their retention, not ours)
Error reports at Sentry90 days (Sentry's project retention)
Server logs30 days
Encrypted database backups7 days, then rotated out
Inspection data on the deviceuntil the inspection is deleted in the app, the app is uninstalled, or the device is claimed by another organisation

The report file. The download link stops working after 30 days, and the stored PDF is deleted 12 months after it was sent. That period is enforced by the storage itself (an AWS S3 lifecycle rule on the reports/ prefix, in place since 17 August 2026), not by anyone remembering to do it. Twelve months is chosen because the dispute a report has to settle usually surfaces at the end of a tenancy, when the check-in report is the evidence. After that the report is no longer downloadable from the admin panel. The estate agency and the parties keep the PDF they were sent; we are not an archive.

Account data. Removing a user in the admin panel deactivates the account — the record stays, because inspections must keep showing who carried them out. Account data is erased when the agency stops using ImoInspect and asks us to delete its data, or on request under section 7. There is no automatic deletion after a fixed number of days, and we would rather write that down than describe a process that does not run.


7. Your rights

Under the GDPR you may ask to access your data, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable form.

You also have the right to complain to a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). If you are in Portugal, you may complain to the CNPD (cnpd.pt).


8. Deleting your account

Your account is created for you by your organisation's administrator, who can also deactivate it. ImoInspect is invite-only: there is no way to create an account from inside the app. To have your account and its data removed, ask your administrator, or write to us at privacy@imoinspect.com and we will act on your organisation's instruction.

Removing an account does not by itself remove the inspection reports your organisation has produced. Those belong to the agency, which decides how long to keep them — see section 2 and section 6.


9. Security

Traffic between the app and our servers runs over HTTPS; from release 1.0.0 the app can no longer fall back to an unencrypted connection. Passwords are stored as bcrypt hashes. Access to the production environment is limited to named administrators. Report download links use an unguessable token and expire.

No system is perfectly secure. If you believe you have found a vulnerability, please write to security@imoinspect.com before disclosing it publicly, and we will work with you.


10. Children

ImoInspect is a professional tool and is not directed at children. We do not knowingly process the data of anyone under 16 except where a minor happens to be named as a tenant on a lease, in which case that data reaches us from the estate agency in the ordinary course of the inspection.


11. Changes to this policy

If we change this policy we will update the date at the top and, where the change is significant, tell account holders by email. The current version is always available at [https://imoinspect.com/privacy].


12. Contact

Awake Design (trading as ImoInspect) Buizerdlaan 57, 2496 HG Den Haag, the Netherlands KvK 42044426 privacy@imoinspect.com