Privacy Policy

Flatka — AI Apartment Hunting

Effective: April 10, 2026 · Last updated: July 27, 2026

This Privacy Policy explains how we collect, use, share, and protect your personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.

1. Data Controller

The data controller is ФОП Колодяжний Дмитро (Dmytro Kolodiazhnyi), registered at Kharkivska 12/7, Sumy, 40000, Ukraine.
Data Protection Officer: not appointed
Contact: contact@flatka.pl

EU Representative (GDPR Article 27): As the data controller is established outside the EU/EEA, we are in the process of appointing an EU representative in accordance with GDPR Article 27. Details will be published here once the appointment is finalized. In the meantime, you may direct any data protection inquiries to contact@flatka.pl.

2. Data We Collect

CategoryDataBasis
AccountEmail, hashed password, display name, registration date. If you sign in with Google, Apple or Microsoft we store that provider's account identifier instead of a password.Contract
UsageFavorites, hidden listings, saved searches, notes, lists, filter preferencesContract
TechnicalIP address, User-Agent, device type, access timestamps, referrer URL. Usage analytics store a one-way hash of the IP and User-Agent rather than the values themselves; the raw IP is also kept in the sign-in security log, on takedown requests, and in the daily free-view ledger that stops the listing limit being reset by clearing your browser.Legitimate interest
PaymentWhat you bought and when. Card and BLIK details, and the invoice itself, are handled by Paddle, our merchant of record; they never reach our servers.Contract
CommunicationSupport requests, feedback, complaint historyLegitimate interest

3. Purpose of Processing

  • Providing and operating the Flatka service, including AI features
  • Account authentication and access control
  • Granting the access you paid for (Paddle takes the payment and issues the invoice)
  • Detecting and preventing fraud, abuse, scraping, and unauthorized access
  • Security monitoring, incident response, and rate limiting
  • Service improvement, performance analytics, and engagement/dwell time measurement (first-party and aggregated; see section 9 for the identifier this uses)
  • Communicating service-related notifications (can be opted out of)
  • Compliance with legal obligations (tax, anti-money laundering, law enforcement)

4. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. Data is shared only with:

RecipientPurposeData shared
Paddle.com Market LtdMerchant of record: selling the Pass, taking payment, invoicing, sales tax and VAT compliance, refundsEmail, payment details, billing address, country. Paddle collects this as an independent controller under its own privacy notice.
Hetzner Online GmbHInfrastructure & storageAll data (encrypted at rest)
Brevo (Sendinblue SAS)Sending transactional and service emailEmail address, message content
Cloudflare, Inc.DNS, CDN, DDoS protection, inbound email routingIP address, request metadata, inbound email
TelegramDelivering alerts, only if you link the bot yourselfTelegram chat ID, notification content
Google (Gemini API)AI translation & summarizationListing text, which can contain an advertiser's name or phone number
OpenRouter / DeepInfraAI parsing of listing text (cost breakdown, structured fields)Listing text, which can contain an advertiser's name or phone number
Google, Apple, MicrosoftSign-in, only if you use that providerYour email and the provider's account identifier
OpenFreeMap, CARTOMap tiles, loaded by your browserIP address and the area you are looking at
Source platforms (OLX, Otodom, Gratka, Nieruchomości-online)Listing photos, loaded by your browser straight from their serversIP address and which listing you opened
Voyage AIDuplicate detection embeddings, and the free-text searches you typeListing text and your search queries — never your account details
Law enforcementLegal obligationAs required by court order or applicable law

5. International Transfers

The data controller is established in Ukraine, which does not have an EU adequacy decision. Personal data of EU/EEA residents transferred to Ukraine is protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

Most of the recipients above (Google, Apple, Microsoft, Paddle, Cloudflare, Telegram, Voyage AI, OpenRouter/DeepInfra, the map-tile providers) are established outside the EU/EEA and may further process data outside the EU/EEA. These transfers are also covered by SCCs or equivalent safeguards. You may request a copy of the relevant safeguards by contacting us.

6. Data Retention

Data typeRetention period
Account dataUntil you ask us to delete it. There is no self-service delete button yet — write to us and we do it by hand, within a month.
Usage data (favorites, notes, lists)Until the account is deleted
Free-view ledger (IP or device id, per day)Kept; no automatic purge today
Usage analytics and page sessions (hashed device identifier)180 days, then deleted automatically
Sign-in and account-security log (IP, User-Agent)Kept for as long as it is useful against fraud and unauthorized access. There is no automatic purge on this log today; you can ask us to erase yours (section 7).
Purchase and trial events (which plan, when)Kept for the life of the account — they are the record of what you paid for
Purchase recordsKept as long as tax law requires (Paddle holds the invoices; we hold which purchase granted which access)
Support and takedown correspondenceKept until you ask us to delete it

7. Your Rights (GDPR)

If you are in the EU/EEA, you have the following rights:

Access

Obtain a copy of your personal data we hold

Rectification

Correct inaccurate or incomplete data

Erasure

Request deletion of your data ("right to be forgotten")

Portability

Receive your data in a structured, machine-readable format

Objection

Object to processing based on legitimate interest

Restriction

Request that we limit how we process your data

Withdraw consent

Withdraw consent at any time (where processing is consent-based)

Complaint

Lodge a complaint with your local data protection authority

To exercise any right, email contact@flatka.pl. We will respond within one month. Identity verification may be required.

8. Automated Decision-Making

The Service uses automated systems for duplicate listing detection, deal scoring, and content analysis. These do not make decisions that produce legal effects or similarly significantly affect you as defined by GDPR Article 22. Automated checks can refuse a free trial, or temporarily limit how many listings or requests you get, without a person looking first. Suspending or terminating an account is never automatic — that always involves a person, and you can contest either outcome by writing to us.

9. Cookies & Local Storage

We use:

  • Authentication — session tokens. Required to stay signed in.
  • Device identifier (fv_id) — a random id, valid for one year, that enforces the free daily limit on opened listings. Without it the limit could be reset by clearing the page. The same id is what we count when measuring how many people use the site.
  • Preferences — language, theme, city and display density are stored in cookies for a year so the page renders correctly on the server before any JavaScript runs. Currency and filters stay in your browser's local storage and are never sent to us.

That is the complete list. We set no advertising or third-party analytics cookies, embed no tracking pixels, build no advertising profile, and share none of this with an ad network or data broker. Measurement is first-party and aggregate: we count devices and pages, not people. Because nothing here is used for advertising or shared onward, we do not show a consent banner (ePrivacy Directive Article 5(3)). If you object to the measurement use of fv_id, write to us and we will exclude your device.

10. Security Measures

  • All data in transit encrypted via TLS 1.2+
  • Passwords hashed with argon2id (never stored in plaintext)
  • Database access restricted by role-based access control
  • Regular backups with encryption at rest
  • Rate limiting and IP-based abuse detection

No system is 100% secure. If you discover a vulnerability, please report it to contact@flatka.pl.

11. Data Breach Notification

In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33. If the breach poses a high risk to your rights and freedoms, we will also notify affected individuals without undue delay (GDPR Article 34).

12. Children

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete that data promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or an in-app notice at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance.

14. Contact & Supervisory Authority

Data controller: ФОП Колодяжний Дмитро (Dmytro Kolodiazhnyi), Kharkivska 12/7, Sumy, 40000, Ukraine
Email: contact@flatka.pl

For Ukrainian data protection law: Уповноважений Верховної Ради України з прав людини (Ukrainian Parliament Commissioner for Human Rights), ombudsman.gov.ua

For EU/EEA residents (GDPR): You have the right to lodge a complaint with the data protection authority in your country of residence. For example, in Poland: Prezes Urzędu Ochrony Danych Osobowych (UODO), uodo.gov.pl. A full list of EU/EEA data protection authorities is available at edpb.europa.eu.