Privacy Policy


Last updated: August 23, 2026

Estity ("Estity", "we", "us") provides a platform that helps owners manage property in Spain — organising property information and documents, tracking finances, preparing and filing tax declarations, and related features. This policy explains, in plain terms, what personal data we process, why, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).

In short:

  • We collect only the data we need to run your account, your properties, and the features you use.
  • We use trusted providers (such as Stripe for payments) and enrich your property with data from public registries to help you meet your obligations.
  • We do not sell your personal data.
  • Optional AI features (such as document translation or summary, bank-statement import, receipt scanning, and the in-app Estity Assistant) send content you choose to submit — or messages and limited account/property context for the Assistant — to our AI provider (OpenAI). For statement import we send a redacted extract. When you import a statement format we do not yet fully support, we may also keep a copy of that file only so we can learn more formats and develop better support for users on the Platform — we do not share that file or its contents with anyone else, as described below. You can avoid this processing by not using those features.
  • You can access, correct, export, or delete your data, and object to certain processing, by emailing support@estity.com.

This policy does not cover third-party websites linked from our platform, which have their own policies.


Who we are


Estity AB (Swedish org.nr 559519-5164) is the data controller for the personal data described in this policy — including for the Platform, your account, and the tax-filing services. In this policy, "Estity", "we", and "us" refer to Estity AB.

We deliver the Spanish property and tax-related services — including submitting declarations to the Spanish Tax Agency (Agencia Tributaria, "AEAT") — together with our group company Estity Innovation SL (CIF B70939533, 29780 Nerja, Málaga, Spain), an authorised AEAT collaborator. Estity Innovation SL processes personal data on our behalf and on our instructions, as our data processor under a data-processing agreement.

We process your data in accordance with the GDPR, the Swedish Data Protection Act, applicable Spanish data protection law, and other applicable law. Our lead supervisory authority is the Swedish Authority for Privacy Protection (IMY).

Contact: support@estity.com (use the subject line "Data protection" for privacy matters).


Personal data we collect


Depending on how you use Estity, we process the following categories of data. The examples are illustrative, not exhaustive.

Data you provide

  • Account and contact data — such as name, email, optional phone number, language preference, and password (stored hashed). If you sign in with Google or Facebook, we receive basic profile information from them.
  • Property data — information about the properties you manage, such as address and characteristics, values, and other economic data, together with documents, photos, receipts, and notes you add.
  • Tax and financial data — information needed to prepare tax declarations (such as Modelo 210) and to track property finances, such as ownership shares, purchase and sale dates, property and transaction values, acquisition and financing costs (including loan interest), rental income and expenses, tax identification numbers (such as NIE/NIF), and bank details (e.g. IBAN) where you choose to pay tax by direct debit. We also store tax-filing and payment receipts.
  • Identity verification data — for certain add-on services (such as applying for a NIE number or a digital ID/certificate), identification documents you provide.
  • Onboarding and questionnaire responses — answers you give about your property and goals so we can guide you through your obligations and tailor the platform to you.
  • Communications and feedback — support messages, survey and feedback responses, and other content you send us.
  • Bank statements and AI import inputs — files or extracts you upload when using AI-assisted economy import (for example CSV/Excel statements). Before sending text to our AI provider we attempt to redact identifiers such as IBANs, account and card numbers, emails, phone numbers, and Spanish tax IDs; dates, amounts, and transaction descriptions typically remain.
  • Document AI inputs — documents (such as PDFs or images) you choose to translate or summarize. We extract text from the file (including via local OCR where needed) and send that text to our AI provider. Unlike statement import, we do not apply the same automated redaction of identifiers before transmission — the extract may include names, addresses, identifiers, and other content that appears in the document.
  • Receipt AI inputs — receipt images or files you upload when using AI-assisted receipt scanning. We may send a compressed image of the receipt and/or extracted OCR text to our AI provider so it can suggest fields such as merchant, date, amount, currency, line items, and category. Where we send OCR text, we attempt similar identifier redaction as for statement import; where we send an image, visible printed content on the receipt may be processed as shown.
  • Assistant chat inputs — messages you send to the in-app Estity Assistant, plus limited session context we attach so replies stay relevant (for example your language, current page in the Platform, property country, subscription status, ownership/filing timing signals, and selected help topics). We store conversation threads and messages so you can continue a chat. Optional thumbs-up / thumbs-down feedback on Assistant replies may also be stored to improve the product.
  • Statement learning samples — when AI import is used for a bank or file format that we do not yet fully support, a copy of the uploaded file (and related technical metadata such as header signature and internal user/property identifiers) may be stored only so Estity can learn more statement formats and develop better support for users on the Platform. We do not sell or share these files or their contents with anyone else — they are used solely by Estity for that internal product-improvement purpose.

Data about other people that you provide

To use certain features, you may give us personal data about other people, such as:

  • Property owners and co-owners named on a tax declaration (which can include identity details, date and place of birth, tax identifiers such as NIE/NIF, address, and tax-residency information) — these people may not have an Estity account
  • Tenants or guests where you use rental features (such as name and contact details)
  • Contacts and collaborators you add or invite to a property (such as name, email, and phone)

You are responsible for ensuring you are allowed to share this data with us — for example, that you have informed the person concerned or otherwise have a lawful basis. We use it only to provide the feature you are using.

Because these people usually do not have an Estity account, we normally cannot contact them directly. In line with Article 14 GDPR, we ask you to make this policy available to them, and we publish it openly on our website; where contacting them individually would be impossible or involve disproportionate effort, we rely on the exemption in Article 14(5)(b). If one of these people contacts us, we will tell them what we hold and honour their rights.


Data we collect automatically

Usage and technical data — IP address, device and browser information, activity logs, and cookie and similar technology data (see Analytics, cookies, and tracking).


Data from other sources

  • Payment providers (Stripe) — payment and subscription status
  • Analytics and advertising partners (e.g. Google, Microsoft, Meta)
  • Public registries and data providers — to enrich your property and help you understand and meet your obligations, we retrieve and store information from public and third-party sources such as the Spanish cadastre (Catastro), mapping and address providers, and tourism/rental registries
  • Referral and affiliate partners — where you registered through a partner

You do not have to provide the data we request, but without it we may be unable to provide our services.


How we use your data and our legal basis

PurposeLegal basis (GDPR)
Create and manage your account and provide the platform — including property management, document storage, tax-declaration preparation, property finance tracking, rentals, contacts, and collaborationContract (Art. 6(1)(b))
Enrich your property with data from public registries to help you understand and meet your obligationsContract and legitimate interest (Art. 6(1)(b), (f))
Process payments and subscriptionsContract (Art. 6(1)(b))
Operate referral and affiliate programs (attribution, discounts, commission, limited partner reporting)Legitimate interest (Art. 6(1)(f))
Operate, secure, and improve the service, including usage analyticsLegitimate interest (Art. 6(1)(f)); consent where required for non-essential cookies (Art. 6(1)(a))
Marketing and analytics cookies on our public websiteConsent (Art. 6(1)(a))
Newsletters and marketing emailsConsent (Art. 6(1)(a)), or legitimate interest for similar products to existing customers
Meet legal, accounting, and tax obligationsLegal obligation (Art. 6(1)(c))
Provide optional AI-assisted features you choose to use (for example translating or summarizing a document, extracting transactions from a bank statement, scanning a receipt, or chatting with the Estity Assistant), including sending relevant content and limited context to our AI providerContract (Art. 6(1)(b)); where the feature processes special categories of data only if separately justified — normally these features process document, receipt, financial, or conversational data under contract
Retain unrecognized statement uploads and related format signals (such as layout fingerprints and sample phrases) only so we can learn more formats and develop better support for users on the Platform — we do not share these files or their contents with anyone elseLegitimate interest (Art. 6(1)(f)) in improving the reliability and coverage of our import features. You can avoid this by not using AI statement import (for example use a supported bank import where available, or enter transactions manually)

Where we rely on legitimate interest, we have weighed our interests against your rights and freedoms; you can request more information about that assessment, and you can object to such processing (see Your rights).

Analytics, cookies, and tracking

We use cookies and similar technologies to keep you logged in, remember your settings, secure the service, analyse how our website and platform are used, and — on our public website — measure marketing. The main tools we use are Google Analytics, Microsoft Clarity (including heatmaps and session replay), and Meta Pixel.

  • Public website (estity.com): non-essential analytics and advertising cookies are set only with your consent, managed through Cookiebot. You can view or change your choices at any time via the Cookiebot icon on the site.
  • Logged-in platform: cookies and similar technologies that are necessary to provide the service (such as login and security) are used without consent. Non-essential analytics, marketing, and session-replay tools run only if you opt in through our in-app consent prompt, which is separate from accepting these terms and off by default. You can change or withdraw your choices at any time under Settings → Privacy, in three categories: Statistics (Google Analytics), Marketing (Meta Pixel and the Meta Conversions API), and Help us improve Estity (Microsoft Clarity session replay, with sensitive fields masked). Withdrawing a category stops the tool and clears its cookies.

For a full list of the cookies we use and how to manage them, see our Cookie Policy. Learn more about these tools at Google, Microsoft and Meta.


Payments


We provide secure payment through Stripe. Payment is handled on Stripe's secure, encrypted pages; we never store your full card details. See Stripe's privacy policy.


Who we share data with


We share data only where needed to run our services, where you have consented, where required by law, or based on a legitimate interest not overridden by your rights. Categories of recipients:

  • Estity Innovation SL (our Spanish group company) — as our processor, to deliver Spanish property and tax services and submit declarations to the AEAT
  • IT and cloud providers — hosting, infrastructure, backups
  • Stripe — payment processing
  • Email and communication providers — transactional email and support
  • Mapping, address, and registry data providers — to look up and enrich property information you ask us to process
  • Analytics and advertising partners (Google, Microsoft, Meta) — as described above
  • Referral and affiliate partners — limited per-signup and aggregate data as described below
  • Property broker partners — where you connect with one, your contact and property information for their brokerage/advisory services, with your consent (see below)
  • Spanish Tax Agency (Agencia Tributaria, AEAT) — when you instruct us to file a declaration, we submit the relevant declaration data to the AEAT on your behalf
  • Professional advisers and authorities — where necessary or legally required
  • AI service providers (OpenAI) — when you use optional AI-assisted features (such as document translation or summary, economy bank-statement import, receipt scanning, or the Estity Assistant), we send relevant content to OpenAI’s API so the model can return results. For statement import (and for receipt OCR-text paths) we send a redacted text extract where that pipeline applies; for document translation/summary we send extracted document text; for receipt vision we may send receipt images; for the Assistant we send your message, recent chat turns, and limited session/property context (see AI-assisted features below). OpenAI acts as our processor under a data-processing agreement / OpenAI’s applicable API data processing terms. We do not use the ChatGPT consumer product for this; we use the API. Sharing of API inputs and outputs for model training and improvement is disabled for our OpenAI organization, so OpenAI does not use that API traffic to train its models.

When you choose to file a tax declaration through us, you instruct us to submit your declaration data to the AEAT. Depending on the payment method you choose, we may also receive your tax payment and forward it to the AEAT on your behalf. Once a declaration has been submitted to the AEAT, it generally cannot be recalled.

We use data processors who act only on our instructions, under written data-processing agreements, mainly within the EU/EEA. We do not sell your personal data.


AI-assisted features

Optional AI features use OpenAI’s API as described above. Details differ by feature. Some Assistant flows (for example questionnaire chips or looking up your saved contacts) are handled inside Estity without calling OpenAI.

Document translation and summary

When you use AI-assisted document translation or summary:

  1. You choose a document in the Platform and start the feature.
  2. We extract text from the file (native PDF text and/or local OCR for scans and images).
  3. We send that extracted text to OpenAI over an encrypted connection (HTTPS) via their API.
  4. OpenAI returns translated or summarized text. You can review it and keep it as a document in Estity (for example a translation file linked to the original).

What may be sent: whatever text appears in or is extracted from the document, including names, addresses, amounts, identifiers, and other personal or business content. We do not apply the same automated identifier redaction used for bank-statement import.

Quality: Translations and summaries depend on the quality of the source document, the quality of the extracted text (including OCR for scans and images), the language(s) involved, and the AI model. We do not guarantee that results are complete, accurate, or suitable for legal or official use without your review. You should check important documents yourself (or with a qualified professional) before relying on them.

Legal basis: performance of the contract to provide the feature you requested (Art. 6(1)(b) GDPR).

International transfers: as under International transfers.

You can avoid this processing by not using document translation or summary.

Economy bank-statement import

When you use AI-assisted bank-statement import:

  1. You upload a statement file in the Platform.
  2. We convert it to a compact table and redact detectable IBANs, long account numbers, labeled BIC/SWIFT codes, emails, phone numbers, Spanish NIE/NIF-style identifiers, payment-card-like digit sequences, and labeled account-holder name lines where possible.
  3. We send that redacted text to OpenAI over an encrypted connection (HTTPS) via their API.
  4. OpenAI returns structured rows (date, description, amount). You review and confirm before transactions are created in Estity.
  5. Temporary upload bytes for background jobs are cleared after processing; confirmed or discarded import jobs are not kept indefinitely (see retention below). Separately, unrecognized formats may be retained for product improvement as described under Developing better bank and import support.

What may still be sent to OpenAI: transaction dates, amounts, and descriptions (often including merchant or counterparty names). Redaction is best-effort and not a guarantee of full anonymisation.

Legal basis: performance of the contract to provide the feature you requested (Art. 6(1)(b) GDPR).

International transfers: as under International transfers.

You can avoid this processing by not using AI import (e.g. use a bank-specific import where available, or enter transactions manually).

Receipt scanning

When you use AI-assisted receipt scanning:

  1. You upload a receipt (image or PDF) in the Platform.
  2. We preferably send a compressed image of the receipt to OpenAI (vision) over HTTPS, or — where vision is not used — OCR text after attempting identifier redaction similar to statement import.
  3. OpenAI returns suggested fields (such as name/merchant, date, amount, currency, line items, tags, and category). You review and confirm before the receipt or related economy data is saved.

What may be sent: printed content visible on the receipt image and/or extracted text, which may include merchant names, amounts, dates, addresses, and other details shown on the receipt.

Quality: Extracts depend on image quality, OCR, and the AI model. We do not guarantee completeness or accuracy; you must check suggestions before saving.

Legal basis: performance of the contract to provide the feature you requested (Art. 6(1)(b) GDPR).

You can avoid this processing by entering receipt details manually.

Estity Assistant (in-app chat)

When you use the Estity Assistant:

  1. You open the Assistant in the Platform and send a message (or choose a suggestion chip).
  2. For some requests we answer inside Estity without calling OpenAI (for example guiding you through property questionnaire chips that save the same settings as the normal forms, or searching contacts you already saved on the property).
  3. When a reply needs the AI model, we send your message, a short recent chat history, and limited session context to OpenAI over HTTPS — for example your language, the page you are on, property country, whether the property has a paid subscription, ownership/filing timing signals, selected help topics, and a curated catalog of in-app pages (not your full document library or tax declaration contents).
  4. OpenAI returns a structured reply (text, optional deep links into Estity, optional choices). We store the thread and messages so you can continue the conversation. You may optionally rate an Assistant reply (thumbs up / down); that rating is stored by Estity to help us improve the Assistant.

What the Assistant is for: helping you find your way around Estity and, where enabled, answering high-level questions about using Estity for property ownership — pointing to Estity features and pages first. It is not a lawyer, tax adviser, or substitute for professional advice, and it is instructed not to give DIY government filing instructions.

What we do not send for Assistant turns (examples): full contents of your tax declarations, your payment card data, or bulk document archives. Do not paste highly sensitive secrets into the chat unless needed for the question.

Unmatched topics / product interest: if you ask about something Estity does not offer yet, we may ask whether you want us to look into it and record that interest through our existing product-feedback channels.

Legal basis: performance of the contract to provide the Assistant feature (Art. 6(1)(b) GDPR); legitimate interest or consent where we process optional feedback ratings or roadmap-interest signals as described elsewhere in this policy.

International transfers: as under International transfers.

You can avoid this processing by not using the Assistant.

Developing better bank and import support

When you use AI statement import for a bank or file format that we do not yet fully support:

  • We may store a copy of the uploaded file together with related technical metadata (such as header signature, mime type, and internal user/property identifiers) in an internal learning corpus.
  • When you confirm an AI import, we may also store format signals (such as layout fingerprints, sample phrases, and amount-format hints) to help us improve recognition and import quality for similar files.
  • This data is used only by Estity to learn more formats and develop better support for users on the Platform (more banks, statement layouts, and import reliability). We do not share these files, their contents, or these format signals with anyone else — including referral or affiliate partners, brokers, or other third parties — and they are not used to train OpenAI’s models.
  • Access is limited to Estity staff (and any infrastructure processors who host our systems under our instructions) who need it for this purpose, under our security measures.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR) in improving import coverage and quality, as listed in the purpose table above.

You can avoid this retention by not using AI statement import.

Referral, affiliate, and broker partners

Affiliate and referral partners promote Estity using a unique link or landing page that contains their affiliate code. They simply drive traffic to us — they do not enter, submit, or provide your name, email, or any other personal data about you. You always create your own account yourself, and you are asked to accept this policy and our Terms of Service before completing registration. When you register after arriving through such a link, your account is linked to that partner so we can apply any discount you are eligible for, attribute your registration correctly, and calculate commission.

How much we share through our partner portal depends on the type of partner and your consent:

  • Lead and affiliate partners (who drive traffic via their link): the partner sees limited information about you — your name, your email in masked form (e.g. `j***n@example.com`), your registration date, and your referral status (e.g. registered, verified, paying) — plus aggregate totals such as number of referrals and overall commission. We share this based on our legitimate interest in operating a fair referral program, and because you are informed of it when you register through a partner link.
  • Property broker partners (real-estate broker offices that provide property brokerage and advisory services to you): where you connect with such a partner and consent, we share — for the purpose of those brokerage/advisory services — your contact details and property information, including address and location (latitude/longitude), property type, cadastral reference and value, purchase and sale price, valuations, purchase date, and the public registry data we have retrieved from the Catastro (such as build year, registered built and total area, building parts, and the municipal tax rate and its update year). These brokers act as independent controllers for their services to you, under data-sharing terms with us. We rely on your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time under Settings or by emailing support@estity.com.

For every partner type, we do not share the contents or amounts of your tax declarations, the number of declarations, your uploaded documents and receipts, your payment history, or your card data.

Where a property has co-owners, the property information shared with a broker partner may include their details; because they may not have an Estity account, we ask you to make this policy available to them (see Data about other people that you provide).

Partners must not use your data for unrelated marketing without their own lawful basis. If you do not want your account linked to a partner, register using our standard link instead.

User-to-user referrals: you can refer others either by entering their email address (we then process that email address and the referral status) or by sharing your own unique referral link yourself — in which case we collect no details about the recipient until they choose to register. If you accept a referral, we link your account to it so rewards can apply. An inviter can see only the email address they invited and its status — nothing else about your account.


International transfers


Your data is primarily processed within the EU/EEA. Where data is transferred outside the EU/EEA (for example, by some of our service providers), we apply appropriate safeguards such as the European Commission's Standard Contractual Clauses, or rely on an adequacy decision. This may include transfers to the United States when you use AI-assisted features (such as document translation/summary, statement import, receipt scanning, or the Estity Assistant) that rely on OpenAI’s API.


How long we keep your data

We keep your data only as long as necessary for the purposes above, and then delete or anonymise it. In practice:

Data typeRetention period
Account, property, and document dataWhile your account is active and for a limited period afterwards.
Accounting recordsGenerally 7 years, as required by Swedish bookkeeping law (Bokföringslagen).
Tax-related declaration recordsFor the period during which the tax authorities may review a filing (in Spain, generally at least 4 years).
Referral and commission recordsAs long as needed to run the programs and meet accounting/tax obligations.
Marketing consentsUntil you withdraw consent or unsubscribe.
Technical and analytics logsFor limited periods under our retention schedule.
Temporary AI import / receipt-scan job payloadsOnly while needed to complete or discard the job; unfinished jobs expire after a short period (product default where applicable: ready/pending jobs up to 7 days, failed jobs sooner). Confirmed results become ordinary economy / document records under normal retention.
Document AI job payloads / transient extractsOnly while needed to complete or discard the job; results you save become ordinary documents under normal document retention.
Assistant threads and messagesWhile your account/property relationship needs them for the chat history, and then deleted or anonymised when you delete the account/property data (or earlier under our retention schedule). Optional reply ratings are kept with the message or as long as needed to improve the Assistant.
Statement learning samples (unrecognized uploads kept to develop better support)Only as long as needed to analyse layouts and improve import support, then deleted or anonymised under our retention schedule.
Format artifacts (layout fingerprints, sample phrases, amount-format hints)As long as needed to improve import recognition and quality, then per our technical retention schedule.
LLM usage metering recordsAs needed for quota, security, and accounting, then per our technical retention schedule.

When you delete your account, we delete or anonymise your personal data in line with our process, keeping only what we are legally required to retain.

How we protect your data


We apply technical and organisational measures including encryption, access controls and least-privilege principles, regular review of our systems, staff training, and data-processing agreements with our suppliers. Sensitive details about property owners and rental guests — such as tax identifiers, contact details, and addresses — are encrypted. No method of transmission or storage is completely secure; if you believe your account has been compromised, contact support@estity.com.

For AI-assisted statement import (and receipt OCR-text paths) we apply automated redaction of common identifiers before transmission to OpenAI where that pipeline applies. Transmission to OpenAI uses TLS. Redaction does not remove all personal or financial data from the extract.

For document translation and summary, extracted document text is sent to OpenAI without that same redaction step. For receipt vision, receipt images may be sent as shown. For the Assistant, chat messages and limited session context are sent without bank-style redaction — treat those features accordingly and avoid pasting highly sensitive secrets into chat.

Statement learning samples and format artifacts used to develop better import support are stored with access controls, used only by Estity to learn more formats for users on the Platform, and are not shared with anyone else or with OpenAI for model training.


Automated decisions and minors


We do not carry out automated decision-making or profiling that produces legal or similarly significant effects (Art. 22 GDPR).

Estity is intended for property owners and other adults aged 18 or over. Our services are not directed at children, and we do not knowingly collect their data. If you believe a minor has provided us personal data, contact us and we will delete it.


Your rights


Under the GDPR you have the right to access, rectification, erasure, restriction, and data portability, to object to processing based on legitimate interest (including direct marketing), and to withdraw consent where processing relies on it. Withdrawing consent does not affect processing carried out before withdrawal.

Contact support@estity.com to exercise your rights; we may verify your identity first, and we aim to respond within one month.

If you are not satisfied, you can lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) — imy.se, Box 8114, 104 20 Stockholm. You may also complain to the supervisory authority in your country of residence (for example, the Spanish Data Protection Agency, AEPD, if you live in Spain).


Changes to this policy


We may update this policy from time to time. The date above shows the latest change, and material changes will be published on our website and, where required, notified by email or in the platform.


Contact


Estity AB — support@estity.com — https://estity.com