Hauzed Logo
Hauzed
HomeRentTenantsPricing
LoginPublish Property

Privacy Policy

Last updated: 1 August 2026 (v2.5) Version: 2.5 Effective date: 1 August 2026

1. Who we are

This Privacy Policy applies to the website hauzed.com and the Hauzed mobile application (together, the "Platform") operated by:

GET HAUZED, S.L.
Calle Circumval·lació, 77, 3º 3ª, 08240 Manresa, Barcelona, Spain
Tax ID (CIF): B27694181
Registered with the Mercantile Registry of Barcelona (registration in process)
Activity code (CNAE): 6312 — Web portals
Sole Director: Neifi Alcantara Meliano
Contact: info@hauzed.com

For the purposes of EU Regulation 2016/679 (the "GDPR") and Spanish Organic Law 3/2018 ("LOPDGDD"), GET HAUZED, S.L. ("Hauzed", "we", "us", "our") is the data controller of the personal data processed through the Platform. The Irish Data Protection Act 2018 ("Irish DPA") may apply only where processing or operations are linked to Ireland and require it.

2. Scope and purpose of this Policy

This Policy explains:

  • What personal data we collect and from whom;
  • The legal bases on which we process your personal data;
  • How we use, share, store and protect your data;
  • How we use Artificial Intelligence (AI) and document processing tools;
  • Your rights under GDPR and LOPDGDD, and under the Irish DPA where it applies to Ireland-linked operations;
  • How to contact us with privacy questions or complaints.

The Platform is currently available to users in Ireland and Spain. The Platform is not directed to children under 18 years of age, and we do not knowingly collect personal data from anyone under 18.

The Hauzed mobile application uses a native iOS/Android shell that displays the Hauzed web application in a WebView. Personal data collected through that WebView is treated as data collected through the Platform, because the content is controlled by Hauzed.

3. Personal data we collect

3.1 Data you provide directly

CategoryExamples
Identity & contactName, surname, profile photo, date of birth, postal address, country, email, phone number
Account credentialsUsername, encrypted password, two-factor authentication tokens
Verification dataGovernment-issued ID image, selfie, liveness check video, KYC verification result (via Veriff)
Tenant supporting documentsPayslips, employment contracts, landlord references, bank statements, study certificates, residence permits, and any other supporting documentation a tenant chooses to upload to support a rental application
Property data (landlords)Property address, photographs, rental price, terms, BER rating, tenant requirements
CommunicationsMessages sent through our chat, attachments, voice/video call audio (when applicable)
Payment dataPayment-method tokens (handled by Stripe; we do not store full card numbers), billing address, deposit transaction records
Preferences and matching dataMove-in dates, budget, preferred districts, lifestyle preferences, group composition
Landlord listing onboarding leadWhen you start the landlord property-listing flow: email address, and, once you provide them, your full name and telephone number
Mobile app settingsPush-notification preferences, Expo/APNs/FCM push tokens, device platform and device name when available

3.2 Data we collect automatically

CategoryExamples
Device dataDevice manufacturer, OS, browser type and version, screen resolution, language
Connection dataIP address, ISP, network identifier, timestamps
Usage dataPages visited, search queries, clicks, time on page, navigation paths, conversion events
Approximate locationCountry and city, derived from IP address (we do not collect precise GPS without consent)
Cookies and similar technologiesSee our Cookies Policy
Mobile app diagnosticsApp launches, WebView errors, push-registration status, native bridge events, crash and performance data where available
Technical operations diagnosticsRandom per-request request, trace and span identifiers; route templates, operation, service surface, source flow, response status, timing, deployment version and structured failure codes; for authenticated requests, a versioned pseudonymous reference derived from the internal account identifier

We may process IP addresses in server logs, security logs and analytics systems. Where possible, we minimise or aggregate this data. We do not ask the mobile operating system for precise GPS location unless a feature clearly requests it and you grant permission.

We process the technical operations diagnostics described above on the server to diagnose failures, protect the Platform and maintain reliability. This processing continues independently of your optional analytics consent. It does not place or read analytics cookies, use localStorage, run session replay or autocapture, fingerprint your device, or create a persistent browser identifier. Anonymous requests receive only random identifiers for that individual request and trace. Operational events are designed not to contain request or response bodies, query strings, raw headers, IP addresses, email addresses, phone numbers, names, postal addresses, documents, payment identifiers or raw account identifiers.

The mobile app stores a compact, opaque Hauzed session token in the device secure store. Supabase access and refresh tokens are not retained by the mobile app. The server stores only a cryptographic hash of the opaque token so that a mobile session can be expired, rotated or revoked.

When you start the landlord property-listing onboarding flow, we create a server-side onboarding lead record using the email address you entered. We update that record with your name and telephone number when you provide them. This supports starting and resuming the requested listing flow, as well as protecting it from duplicate or abusive submissions. This limited server-side processing does not set or read optional analytics or marketing cookies, and it does not send the record to Meta. It therefore continues if you decline optional cookies; the separate cookie-based analytics and marketing activities remain subject to your consent choices.

When you first complete registration as a tenant or landlord under this version of the Policy, Hauzed may initiate one welcome conversation on WhatsApp. We use your name, telephone number and onboarding language solely to personalise and send that short message and record its delivery. We do not use this permission for later promotions or to enable other WhatsApp notifications. You can ask not to receive further messages on this channel by replying to the message or contacting info@hauzed.com.

3.3 Data we receive from third parties

  • Identity verification providers (Veriff): name match, document authenticity result, PEP / sanctions list flag.
  • Payment processors (Stripe): payment success/failure status, dispute notifications, refund records.
  • Authentication providers (if you sign in with Google, Apple or similar): email, basic profile information, depending on the permissions you grant.
  • Analytics and campaign measurement providers (PostHog, Meta Pixel): product-interaction events, session/device identifiers, approximate location derived from IP, campaign attribution data and diagnostic information, depending on your consent choices and our configuration.
  • Mobile platform and notification providers (Expo, Apple, Google): push tokens, delivery status and device/platform identifiers required to deliver push notifications.

4. Special categories of data

Documents that tenants upload to support rental applications (such as payslips or employment contracts) may incidentally contain special category data under Article 9 GDPR, including data revealing trade union membership (where union dues appear on a payslip), health data (where sick-leave deductions appear), or racial or ethnic origin (where employment forms record it).

We process incidental special-category data only with your explicit authorization, given through the unticked checkbox when you upload the document. We record the version and time of that authorization. You are not obliged to upload documents containing this information and may redact sensitive fields first. When detected, unnecessary special-category information is discarded during extraction and never becomes evidence or an application-readiness reason. You can withdraw the authorization by deleting the document; this stops new processing and triggers deletion of derived content.

Identity verification through Veriff may involve photographs, video, liveness checks, document images, face measurements and other data used to confirm that the person submitting the document is the legitimate holder. Depending on applicable law, some of this information may be considered biometric or sensitive personal data. We use it only for identity verification, fraud prevention, legal compliance and platform safety, and not for advertising or unrelated profiling.

5. Legal bases for processing

We rely on the following legal bases under Article 6 GDPR:

Legal basisPurposes covered
Contract performance / steps at your request before entering a contract (Art. 6(1)(b))Creating and managing your account; receiving the contact details needed to start or resume a landlord listing; processing your rental application or listing; facilitating chat and viewings; processing escrow deposits when activated.
Legal obligation (Art. 6(1)(c))Identity verification (KYC) under anti-money-laundering regulations; tax and accounting record-keeping; responding to lawful requests from authorities; complying with the Irish Residential Tenancies Board (RTB) requirements where applicable.
Legitimate interests (Art. 6(1)(f))Fraud prevention and platform safety; security logging, rate limiting and abuse detection; diagnosing whether requests and asynchronous operations worked, how long they took and why they failed; network and information-system security; service reliability; defending and exercising legal claims; AI-assisted matching and trust signals (where they support, not replace, human decisions). We balance these interests against your rights and freedoms; you have the right to object (see Section 11).
Consent (Art. 6(1)(a))Marketing communications; non-essential cookies and analytics; push notifications; processing of incidental special-category data in tenant documents and biometric/sensitive verification data where consent is required (Art. 9(2)(a)); precise location data when applicable. You may withdraw consent at any time.

6. How we use your data

We process personal data for the following specific purposes:

  • Account management: registration, login, profile maintenance, password recovery.
  • Landlord listing onboarding: when you choose to start the landlord listing flow, recording your email address and, once supplied, your name and telephone number to start or resume that flow and prevent duplicate or abusive submissions. This is separate from optional browser analytics and marketing cookies.
  • One-time WhatsApp welcome: after you first complete registration as a tenant or landlord, using your name, telephone number and onboarding language to send one message welcoming you and briefly explaining Hauzed. This purpose does not authorise later promotions or other WhatsApp notifications.
  • Verification and trust: KYC checks via Veriff, identity badges, profile signals such as "Identity Verified", "Income Evidence Submitted", "References Available", "Trusted Profile". We do not display badges that suggest negative or sensitive conclusions about a user (e.g. "low income" or "high risk"), and we do not use protected characteristics to generate badges.
  • Matching and discovery: surfacing properties to tenants and tenants to landlords based on stated preferences, verification status and AI-supported relevance signals.
  • Communication: enabling secure chat between users, sending transactional emails, processing voice/video calls when used.
  • Payments and deposits: processing payments and, when activated, holding security deposits in regulated escrow via Stripe Connect, with release upon tenant confirmation.
  • Fraud prevention and safety: detecting fake listings, identity fraud, suspicious behaviour, and preventing scams.
  • Mobile app functionality: enabling native account access, temporary WebView session handoffs, deep links, native payment flows, and optional push notifications.
  • Technical operations: recording minimised server-side request, trace, worker and structured failure metadata to diagnose errors, investigate security incidents and maintain Platform reliability. This is separate from optional browser analytics and does not depend on analytics consent.
  • Service improvement: analytics to understand product usage and improve features. Where analytics is not strictly necessary, we respect your consent choices.
  • Legal compliance: complying with applicable laws, regulations, court orders and lawful requests.

7. How we use AI and automated tools

We use AI and automation to assist rental workflows. AI on Hauzed does not make final, binding or fully automated decisions about tenant eligibility, access to housing, or acceptance of applications. Final decisions are always made by humans (the landlord, the agent, or you).

A separate AI Disclosure explains in detail which AI agents we run, what data they consume, and how their outputs are used. The most relevant points for this Privacy Policy:

  • Document processing: when you authorize a supporting-document upload, AWS Textract extracts a bounded representation and Amazon Bedrock may propose the document type and grounded facts. A deterministic policy or an authorised human, not the model, decides whether anything becomes evidence. In the current version these results are internal shadow data and do not change ranking, eligibility, invitations or landlord-facing UI.
  • AI-assisted signals and matching: we may use AI tools to generate signals, scores or recommendations that support - but never replace - human decision-making. These are used to prioritise matches, surface trust badges, detect fraud patterns and improve safety. They are not determinative of any tenancy outcome.
  • Enterprise AI providers: when we use third-party AI providers, including Amazon Bedrock and OpenAI where applicable, we do so under enterprise or business terms with appropriate data-processing safeguards. Bedrock document processing uses an EU inference profile, model-invocation logging is disabled and provider retention must be configured to zero before real-document processing is enabled.
  • No use of protected attributes: we do not intentionally use protected or sensitive personal attributes (race, ethnicity, religion, sexual orientation, disability, family status, gender identity) to generate signals, scores or matches.
  • Right to human review: you have the right to request that any signal, score or recommendation about your profile be reviewed by a human at Hauzed. Contact info@hauzed.com.

For the purposes of Article 22 GDPR, you have the right (a) not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, (b) to obtain human intervention, (c) to express your point of view, and (d) to contest any such decision. As Hauzed does not make final automated decisions about housing access, Article 22 generally does not apply to our service; nonetheless, we honour these rights as a baseline standard.

8. Sharing your data — recipients and sub-processors

We share personal data with the following categories of recipients:

8.1 Other Platform users

  • Landlords and agents receive limited information about tenants who apply to their properties (verified profile, application message, declared budget, move-in dates, and any documents the tenant chooses to share through chat). When a tenant shares a document directly with a landlord through chat, the landlord becomes an independent data controller of that copy of the document; we do not control how the landlord stores or uses it after sharing.
  • Tenants receive limited information about landlords whose properties they apply to (verified profile, listing details, response time).

You always control what you share through chat. We recommend sharing only what is necessary for the rental application.

8.2 Service providers (sub-processors)

We rely on the following sub-processors to operate the Platform. Each sub-processor is bound by a Data Processing Agreement (DPA) that requires them to process personal data only on our instructions and to apply appropriate security measures.

ProviderServiceCountry / regionSafeguards
VercelWeb hosting, edge functions, ISREU regions (Frankfurt)DPA + Standard Contractual Clauses (SCCs)
SupabaseDatabase, authentication, file storageEU regionDPA + SCCs
Amazon Web Services (S3, Textract and Bedrock)Private document storage, extraction, bounded AI-assisted document interpretation and backupsEU regions for the document flowAWS GDPR DPA; Bedrock zero-retention mode required for real documents
VeriffIdentity verification (KYC)Estonia (EU)DPA, GDPR-compliant by default
StripePayments and escrow (Stripe Connect)EU and US (dual processing)DPA + SCCs + DPF certification
Expo / EASMobile build, updates and push-notification infrastructureUS / globalDPA + SCCs where applicable
AppleiOS distribution, Apple Pay, APNs push notifications, TestFlight/App Store servicesEU / US / globalApple platform terms and applicable safeguards
GoogleAndroid distribution, Google Pay, FCM push notifications, Play servicesEU / US / globalGoogle platform terms, DPA where applicable, SCCs/DPF where applicable
OpenAIAI assistance under Enterprise / API agreementUSDPA + SCCs + DPF certification; no training on customer data
PostHogConsent-based product analytics; server-side landlord-onboarding lead records; and, in the existing EU project under a distinct technical scope, minimised pseudonymous logs and error traces without person profiles, browser SDK, autocapture or session replayEU regionDPA + SCCs
Meta Platforms IrelandCampaign measurement and advertising attributionEU / globalPlatform terms, DPA and SCCs where applicable
ResendTransactional emailEU regionDPA + SCCs
TwilioDelivery and delivery-status processing for the one-time WhatsApp welcomeEU / US / globalDPA + SCCs/DPF where applicable
MailchimpNewsletter (currently paused)

We update this list when we add or remove sub-processors.

8.3 Legal recipients

We may share personal data with regulators, courts, law enforcement and other authorities where required by law (for example, in response to a court order, anti-money-laundering obligations, or tax inspections).

9. International transfers

Some of our sub-processors are located outside the European Economic Area (EEA), in particular in the United States. When we transfer personal data outside the EEA, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • EU-US Data Privacy Framework (DPF) certifications, where the recipient is certified;
  • Adequacy decisions of the European Commission, where applicable;
  • Additional technical and organisational measures (encryption in transit and at rest, pseudonymisation, access controls).

You have the right to request a copy of the safeguards we apply to a specific transfer by writing to info@hauzed.com.

10. Data retention

We keep personal data only for as long as necessary for the purposes for which it was collected, and in line with the following indicative retention schedule:

Data categoryRetention period
Active account dataWhile the account is active
Inactive account data30 days after account closure, then deletion (account-closure grace period)
Tenant supporting documentsUp to 12 months from upload, or earlier deletion/withdrawal by the tenant; noncurrent object versions expire within a further 30 days
Raw extraction and bounded AI interpretation dataUp to 30 days after processing
KYC verification results5 years from end of relationship (anti-money-laundering compliance)
Chat messagesActive for the duration of the conversation; archived for 2 years after last activity
Push-notification tokensUntil logout, account deletion, app uninstall, token expiry, or withdrawal of notification consent
Security logs and IP-derived fraud signalsUsually 30 to 90 days, unless required for investigation, legal claims or compliance
First-party technical operations index30 days
Pseudonymous technical operations logs and error traces in PostHogUp to 13 months under the shared project retention; reviewed when the project is separated or an independent period is required
Product analytics events and landlord-onboarding lead recordsUp to 13 months where they remain personal data, then deleted, aggregated or anonymised
Marketing dataUntil you withdraw consent, then deleted within 30 days
WhatsApp welcome evidence and delivery statusWhile the account is active and until the account profile is deleted under the account-deletion schedule; the destination evidence uses an HMAC fingerprint and is deleted with the profile
BackupsUp to 90 days after deletion from primary systems, then overwritten
Aggregated, anonymised analyticsIndefinitely (no longer personal data)

You have the right to request deletion of your data before these periods expire (see Section 11), subject to our legal obligations.

11. Your rights

You have the following rights under GDPR and LOPDGDD, and under the Irish DPA where it applies to Ireland-linked operations:

  • Access (Art. 15) — receive a copy of the personal data we hold about you.
  • Rectification (Art. 16) — correct inaccurate or incomplete data, including data extracted by our document-processing tools or by any AI tool we use.
  • Erasure / "right to be forgotten" (Art. 17) — request deletion of your data, subject to retention obligations described above.
  • Restriction of processing (Art. 18) — limit the processing of your data in certain circumstances.
  • Data portability (Art. 20) — receive your data in a structured, machine-readable format and transmit it to another controller.
  • Object to processing (Art. 21) — object to processing based on legitimate interests, including technical operations diagnostics and AI-assisted profiling for matching. We will assess your objection against compelling security, reliability and legal grounds.
  • Withdraw consent (Art. 7) — at any time, where processing is based on your consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Not be subject to automated decision-making (Art. 22) — request human review of any AI-generated signal or recommendation about your profile (see Section 7).

How to exercise your rights: write to info@hauzed.com from the email address linked to your account. We may need to verify your identity before acting on your request. We will respond within 30 days; this may be extended by a further 60 days for complex requests, in which case we will explain the reason.

Right to lodge a complaint: if you are not satisfied with our response, you have the right to lodge a complaint with:

  • Spanish Data Protection Agency (AEPD) — www.aepd.es — for matters related to GET HAUZED, S.L. as the controller;
  • Irish Data Protection Commission (DPC) — www.dataprotection.ie — for matters related to processing in Ireland.

12. Security measures

We apply appropriate technical and organisational measures under Article 32 GDPR to protect your personal data, including:

  • TLS 1.3 encryption for all data in transit;
  • AES-256 encryption at rest for stored documents and backups;
  • Role-based access control (RBAC) with least-privilege principles;
  • Multi-factor authentication for staff accounts;
  • Audit logs of access to personal data and tenant documents, including actor, reason, time range, filters and result count for technical-log searches linked to a known user;
  • Regular security reviews and dependency updates;
  • Encrypted backups with limited retention;
  • Documented incident-response procedure.

No system is completely secure. If you become aware of any security issue, please report it to info@hauzed.com.

13. Personal data breaches

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (AEPD or DPC) within 72 hours of becoming aware of the breach, and we will notify you without undue delay where the breach is likely to result in a high risk to your rights and freedoms, in accordance with Articles 33 and 34 GDPR.

14. Children

The Platform is not intended for users under 18. The digital age of consent in Ireland is 16; however, our service requires the legal capacity to enter into rental agreements, which is generally 18. We do not knowingly collect data from anyone under 18. If you believe we have inadvertently collected data from a minor, please contact info@hauzed.com and we will delete it promptly.

15. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date at the top reflects the most recent change. We will notify registered users by email or in-app notice of material changes at least 30 days before they take effect.

16. Contact

For privacy questions, requests, or complaints:

GET HAUZED, S.L.
Calle Circumval·lació, 77, 3º 3ª, 08240 Manresa, Barcelona, Spain
Email: info@hauzed.com
Phone: +34 936 07 56 78

We currently use info@hauzed.com as the privacy contact. Where we appoint a Data Protection Officer in the future, we will publish their contact details on this page.


This Privacy Policy is governed by Spanish data-protection law, including GDPR and LOPDGDD, without prejudice to the Irish DPA 2018 where it applies to Ireland-linked operations. Where a translation is provided in another language, the Spanish version prevails in case of conflict.

US
DPA + SCCs + DPF certification
MailtrapEmail testing in staging environmentsEUDPA + SCCs
IONOSDomain and DNS hostingGermany (EU)DPA
Google (Workspace)Email infrastructure for the info@hauzed.com addressEU regionsDPA + SCCs + DPF certification
Hauzed Logo
Hauzed

Making renting simple.

Get the app

Download Hauzed on the App StoreGet Hauzed on Google Play
NVIDIA Inception Program

Popular searches

  • Furnished properties in Dublin
  • Houses to rent in Ireland
  • Co-living in Dublin
  • Rent in Dublin city centre
  • Rent for Couples in Dublin

Popular districts

  • Rent in Dublin 1
  • Rent in Dublin 2
  • Rent in Dublin 3
  • Rent in Dublin 4
  • Rent in Dublin 5
  • Rent in Dublin 6
  • Rent in Dublin 7
  • Rent in Dublin 8

Support

  • Contact Us
  • Terms of Service
  • Privacy Policy
  • AI Disclosure
  • Cookies Policy

© 2026 GET HAUZED, S.L. All rights reserved.