Privacy
Privacy Policy
This Privacy Policy explains how OliviaFlow handles personal data on the public website and during the early-access validation stage.
Last updated: June 25, 2026
1. Who we are
OliviaFlow is an early-access product being validated for real estate teams. The public website lets visitors learn about OliviaFlow, request access, and contact the team.
Privacy questions and rights requests can be sent to [email protected].
2. What this policy covers
This policy covers the public OliviaFlow website, access-request forms, cookie preferences, analytics, security logs, and direct communications with us. It does not describe a full production customer workspace yet.
If OliviaFlow opens product access to a team, additional product, data-processing, and onboarding terms may apply before customer lead, contact, conversation, or property data is processed.
3. Data we collect
We may collect and process the following limited categories of personal data:
- Access request data, such as work email address, requested market, language preference, and optional product-update consent.
- Attribution data, such as landing page path, sanitized referrer, and UTM source, medium, or campaign values when present.
- Cookie preference data, such as whether this browser accepted or rejected Google Analytics 4.
- Technical and security data, such as IP address, browser or device information, session data, security events, service logs, and abuse-prevention signals.
- Communication data, such as emails or messages you send to us.
4. How we use data
We use personal data to:
- review and respond to access requests;
- understand which markets, messages, and campaigns are generating interest;
- send operational follow-up about access, availability, and product validation;
- send optional product updates where you have requested them or where another lawful basis applies;
- operate, secure, troubleshoot, and improve the website;
- measure public-site performance using privacy-conscious analytics; and
- detect abuse, protect the request-access form, and comply with legal obligations.
5. Legal bases
Depending on the context, we rely on one or more of the following legal bases:
- Request or pre-contract steps, where processing is needed to respond to an access request.
- Legitimate interests, including validating the product, securing the website, preventing abuse, and communicating with business users about their request.
- Consent, where required, including for optional product updates or analytics cookies in regions where consent is required.
- Legal obligation, where processing is required to comply with applicable law.
6. Analytics and cookies
We use essential cookies for site operation, security, sessions, language preference, and cookie preferences. We may also use Google Analytics 4 and Cloudflare Web Analytics to understand aggregate public-site usage.
Where required by applicable law, including for visitors in the EEA, the United Kingdom, Switzerland, and where we cannot determine the visitor's country with sufficient confidence, we ask for consent before enabling Google Analytics 4. You can review or change your Google Analytics 4 preference in our Cookie Policy.
7. Service providers
We may use service providers to host and secure the website, process access requests, deliver email, measure aggregate usage, detect abuse, and monitor service reliability. These may include infrastructure, analytics, security, email, and operational-support providers.
We do not sell access-request data. We do not intentionally use the public-site analytics setup for advertising personalization or remarketing.
8. AI and product validation
The public website describes planned or early OliviaFlow capabilities, including AI-assisted prioritization, follow-up, and property-aware workflows. Submitting an access request does not require you to provide client conversations, property databases, or sensitive business records through the public form.
If a pilot or product workspace later processes customer-provided lead, contact, conversation, media, or property data, the applicable onboarding terms should explain the customer data responsibilities, provider roles, and subprocessors before that processing begins.
9. Retention
Unless a longer period is required for legal, security, or operational reasons, we currently aim to retain data using the following criteria:
- Access request and related attribution data: up to 12 months from the last meaningful interaction.
- Security and service logs: generally 30 to 90 days, subject to operational need.
- Cookie-preference records: generally up to 6 months for browser-level analytics choices unless refreshed or replaced sooner.
- Marketing consent records: as long as needed to evidence consent and honor opt-out preferences.
10. Security
We use reasonable technical and organizational measures intended to protect the public website and access-request data. No system can be guaranteed fully secure, and we do not make absolute security claims.
11. Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or request portability of certain personal data, and to withdraw consent where consent is the legal basis.
To exercise rights, contact [email protected]. We may ask for information necessary to verify the request. If you are in Spain or the EEA, you may also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) or another competent supervisory authority.
12. Children
The website and product are intended for business and professional use and are not intended for children.
13. Changes to this policy
We may update this Privacy Policy as the product, service providers, or launch stage changes. Material updates may be communicated through the website, product, or another appropriate channel.
14. Contact
Questions about this policy can be sent to [email protected].