Privacy Policy
Flatka — AI Apartment Hunting
Effective: April 10, 2026 · Last updated: July 27, 2026
This Privacy Policy explains how we collect, use, share, and protect your personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.
1. Data Controller
The data controller is ФОП Колодяжний Дмитро (Dmytro Kolodiazhnyi), registered at Kharkivska 12/7, Sumy, 40000, Ukraine.
Data Protection Officer: not appointed
Contact: contact@flatka.pl
EU Representative (GDPR Article 27): As the data controller is established outside the EU/EEA, we are in the process of appointing an EU representative in accordance with GDPR Article 27. Details will be published here once the appointment is finalized. In the meantime, you may direct any data protection inquiries to contact@flatka.pl.
2. Data We Collect
| Category | Data | Basis |
|---|---|---|
| Account | Email, hashed password, display name, registration date. If you sign in with Google, Apple or Microsoft we store that provider's account identifier instead of a password. | Contract |
| Usage | Favorites, hidden listings, saved searches, notes, lists, filter preferences | Contract |
| Technical | IP address, User-Agent, device type, access timestamps, referrer URL. Usage analytics store a one-way hash of the IP and User-Agent rather than the values themselves; the raw IP is also kept in the sign-in security log, on takedown requests, and in the daily free-view ledger that stops the listing limit being reset by clearing your browser. | Legitimate interest |
| Payment | What you bought and when. Card and BLIK details, and the invoice itself, are handled by Paddle, our merchant of record; they never reach our servers. | Contract |
| Communication | Support requests, feedback, complaint history | Legitimate interest |
3. Purpose of Processing
- Providing and operating the Flatka service, including AI features
- Account authentication and access control
- Granting the access you paid for (Paddle takes the payment and issues the invoice)
- Detecting and preventing fraud, abuse, scraping, and unauthorized access
- Security monitoring, incident response, and rate limiting
- Service improvement, performance analytics, and engagement/dwell time measurement (first-party and aggregated; see section 9 for the identifier this uses)
- Communicating service-related notifications (can be opted out of)
- Compliance with legal obligations (tax, anti-money laundering, law enforcement)
4. Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. Data is shared only with:
| Recipient | Purpose | Data shared |
|---|---|---|
| Paddle.com Market Ltd | Merchant of record: selling the Pass, taking payment, invoicing, sales tax and VAT compliance, refunds | Email, payment details, billing address, country. Paddle collects this as an independent controller under its own privacy notice. |
| Hetzner Online GmbH | Infrastructure & storage | All data (encrypted at rest) |
| Brevo (Sendinblue SAS) | Sending transactional and service email | Email address, message content |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, inbound email routing | IP address, request metadata, inbound email |
| Telegram | Delivering alerts, only if you link the bot yourself | Telegram chat ID, notification content |
| Google (Gemini API) | AI translation & summarization | Listing text, which can contain an advertiser's name or phone number |
| OpenRouter / DeepInfra | AI parsing of listing text (cost breakdown, structured fields) | Listing text, which can contain an advertiser's name or phone number |
| Google, Apple, Microsoft | Sign-in, only if you use that provider | Your email and the provider's account identifier |
| OpenFreeMap, CARTO | Map tiles, loaded by your browser | IP address and the area you are looking at |
| Source platforms (OLX, Otodom, Gratka, Nieruchomości-online) | Listing photos, loaded by your browser straight from their servers | IP address and which listing you opened |
| Voyage AI | Duplicate detection embeddings, and the free-text searches you type | Listing text and your search queries — never your account details |
| Law enforcement | Legal obligation | As required by court order or applicable law |
5. International Transfers
The data controller is established in Ukraine, which does not have an EU adequacy decision. Personal data of EU/EEA residents transferred to Ukraine is protected by Standard Contractual Clauses (SCCs) approved by the European Commission.
Most of the recipients above (Google, Apple, Microsoft, Paddle, Cloudflare, Telegram, Voyage AI, OpenRouter/DeepInfra, the map-tile providers) are established outside the EU/EEA and may further process data outside the EU/EEA. These transfers are also covered by SCCs or equivalent safeguards. You may request a copy of the relevant safeguards by contacting us.
6. Data Retention
| Data type | Retention period |
|---|---|
| Account data | Until you ask us to delete it. There is no self-service delete button yet — write to us and we do it by hand, within a month. |
| Usage data (favorites, notes, lists) | Until the account is deleted |
| Free-view ledger (IP or device id, per day) | Kept; no automatic purge today |
| Usage analytics and page sessions (hashed device identifier) | 180 days, then deleted automatically |
| Sign-in and account-security log (IP, User-Agent) | Kept for as long as it is useful against fraud and unauthorized access. There is no automatic purge on this log today; you can ask us to erase yours (section 7). |
| Purchase and trial events (which plan, when) | Kept for the life of the account — they are the record of what you paid for |
| Purchase records | Kept as long as tax law requires (Paddle holds the invoices; we hold which purchase granted which access) |
| Support and takedown correspondence | Kept until you ask us to delete it |
7. Your Rights (GDPR)
If you are in the EU/EEA, you have the following rights:
Access
Obtain a copy of your personal data we hold
Rectification
Correct inaccurate or incomplete data
Erasure
Request deletion of your data ("right to be forgotten")
Portability
Receive your data in a structured, machine-readable format
Objection
Object to processing based on legitimate interest
Restriction
Request that we limit how we process your data
Withdraw consent
Withdraw consent at any time (where processing is consent-based)
Complaint
Lodge a complaint with your local data protection authority
To exercise any right, email contact@flatka.pl. We will respond within one month. Identity verification may be required.
8. Automated Decision-Making
The Service uses automated systems for duplicate listing detection, deal scoring, and content analysis. These do not make decisions that produce legal effects or similarly significantly affect you as defined by GDPR Article 22. Automated checks can refuse a free trial, or temporarily limit how many listings or requests you get, without a person looking first. Suspending or terminating an account is never automatic — that always involves a person, and you can contest either outcome by writing to us.
9. Cookies & Local Storage
We use:
- Authentication — session tokens. Required to stay signed in.
- Device identifier (
fv_id) — a random id, valid for one year, that enforces the free daily limit on opened listings. Without it the limit could be reset by clearing the page. The same id is what we count when measuring how many people use the site. - Preferences — language, theme, city and display density are stored in cookies for a year so the page renders correctly on the server before any JavaScript runs. Currency and filters stay in your browser's local storage and are never sent to us.
That is the complete list. We set no advertising or third-party analytics cookies, embed no tracking pixels, build no advertising profile, and share none of this with an ad network or data broker. Measurement is first-party and aggregate: we count devices and pages, not people. Because nothing here is used for advertising or shared onward, we do not show a consent banner (ePrivacy Directive Article 5(3)). If you object to the measurement use of fv_id, write to us and we will exclude your device.
10. Security Measures
- All data in transit encrypted via TLS 1.2+
- Passwords hashed with argon2id (never stored in plaintext)
- Database access restricted by role-based access control
- Regular backups with encryption at rest
- Rate limiting and IP-based abuse detection
No system is 100% secure. If you discover a vulnerability, please report it to contact@flatka.pl.
11. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33. If the breach poses a high risk to your rights and freedoms, we will also notify affected individuals without undue delay (GDPR Article 34).
12. Children
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will take steps to delete that data promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email and/or an in-app notice at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the Service after the effective date constitutes acceptance.
14. Contact & Supervisory Authority
Data controller: ФОП Колодяжний Дмитро (Dmytro Kolodiazhnyi), Kharkivska 12/7, Sumy, 40000, Ukraine
Email: contact@flatka.pl
For Ukrainian data protection law: Уповноважений Верховної Ради України з прав людини (Ukrainian Parliament Commissioner for Human Rights), ombudsman.gov.ua
For EU/EEA residents (GDPR): You have the right to lodge a complaint with the data protection authority in your country of residence. For example, in Poland: Prezes Urzędu Ochrony Danych Osobowych (UODO), uodo.gov.pl. A full list of EU/EEA data protection authorities is available at edpb.europa.eu.