Legal
Privacy Policy
How we handle your personal data under the EU General Data Protection Regulation (GDPR / DSGVO).
Last updated: September 15, 2026
1. Controller
The controller responsible for data processing on this website is:
SNS Software Solutions GmbH
Schrötlgasse 8a, 1220 Vienna, Austria
Email: office@sns-austria.com
2. Overview
We take the protection of your personal data seriously and process it only in accordance with statutory data protection regulations (GDPR, Austrian Data Protection Act / DSG) and this privacy policy.
This policy covers two different things, and the distinction matters for your rights. Our websites (sns-austria.com and immvela.com) are informational, and we collect as little personal data as possible there — Sections 3 and 5 to 12 apply. Immvela, the platform our clients sign in to, is different: there we mostly process data on a client’s behalf rather than our own, which changes who you should address a request to. Section 4 covers it.
3. Hosting
This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA. When you visit the site, Vercel automatically processes technical connection data (see “Server log files” below) to deliver the website securely and reliably. This is based on our legitimate interest in a stable and secure online presence (Art. 6(1)(f) GDPR). We have concluded a data processing agreement (DPA) with Vercel, and transfers to the USA are safeguarded by the EU Standard Contractual Clauses.
4. Immvela (our real-estate platform)
In addition to this website, SNS operates Immvela (immvela.com, application at app.immvela.com), a modular platform for real-estate agents and brokerages in Austria, Germany and Switzerland. Immvela is a product of SNS Software Solutions GmbH and not a separate legal entity; this privacy policy covers both domains. Modules are enabled individually, so which of the processing described below actually applies depends on the modules a given brokerage uses.
4.1 Who is controller, and who is processor
For the data a brokerage puts into Immvela about its own properties, clients and prospects, the brokerage is the controller and SNS acts as processor on its instructions (Art. 28 GDPR), under a separate written agreement including a Data Processing Agreement (AVV). For the brokerage’s own account and contract data, SNS is the controller.
Each brokerage is a separate tenant and its own controller. Where a brokerage belongs to a franchise, franchise offices do not have access to each other’s operational data; a franchise can share reference material downward only by deliberate publication, never operational records about properties or people.
4.2 Data we process on behalf of clients
- Account data for the brokerage’s users: name, email address, role within the organisation, and interface-language preference.
- Property and listing records, including descriptive and technical attributes such as floor area, year of construction and energy certificate values.
- Contacts, leads and deals — that is, personal data about prospective buyers, sellers or tenants that the brokerage enters or receives.
- Documents the brokerage uploads (for example energy performance certificates) and the values read out of them. Extracted values are always shown to the brokerage for confirmation before the platform relies on them.
- Media the brokerage uploads or has generated: photographs, staged images and walkthrough footage.
- Text the platform drafts on the brokerage’s instruction (listing copy, captions, Exposé documents) and the brokerage’s edits to it.
- Access tokens issued by connected publishing platforms, used solely to publish on the brokerage’s behalf and to retrieve the resulting engagement data.
- Engagement data returned by those platforms (for example views, reactions and post statistics).
- Records of platform activity showing which module produced or used which record, used to operate the service and to make the brokerage’s own data reusable across modules.
4.3 Purpose and legal basis
This data is processed solely to provide the functions the brokerage has enabled. The legal basis is performance of the agreement with the brokerage (Art. 6(1)(b) GDPR) and our legitimate interest in providing the contracted service (Art. 6(1)(f) GDPR). Where a brokerage processes data about third parties such as prospective buyers, the brokerage is responsible for the legal basis for that processing.
4.4 AI processing, and what it does not decide
Several Immvela modules generate text or images using AI. For text generation, the relevant listing and property data is transmitted to Anthropic PBC (Claude models) acting as a sub-processor, solely to produce the output the brokerage asked for. Under Anthropic’s commercial API terms, data submitted through the API is not used to train their models. We do not sell client data, use it for advertising, or use it to train AI models of our own.
Two limits are built into the platform rather than left to policy. Factual values in generated text are taken only from data the brokerage has confirmed, so the platform does not invent property specifications. And AI-staged images carry a “virtually staged” label rendered into the image itself, so a staged photograph stays identifiable as staged wherever it is published.
No automated decision-making. Immvela does not make decisions about individuals that have legal or similarly significant effects within the meaning of Art. 22 GDPR. Where a module qualifies or routes an enquiry, it gathers and prepares information for a person to act on; it does not agree prices, appointments or contractual terms, and anything binding is confirmed by a human.
4.5 Storage and sub-processors
Immvela’s data is stored in the European Union:
- Database, authentication and file storage: Supabase, hosted in the EU (eu-central-1, Frankfurt, Germany)
- Application hosting: Vercel (see Section 3 for Vercel’s data handling)
- Background job processing: Trigger.dev
- AI text generation: Anthropic PBC (see Section 4.4)
Where a sub-processor involves a transfer outside the EU/EEA, that transfer is covered by a data processing agreement and safeguarded by the EU Standard Contractual Clauses.
4.6 Connected publishing platforms
Each connected platform (Meta/Facebook/Instagram, LinkedIn, Google/YouTube, TikTok) processes data under its own privacy policy and developer terms. Our use of data obtained through these platforms complies with each platform’s respective developer policies and terms of service.
4.7 Retention, media deletion and erasure requests
Client and account data is retained for the duration of the agreement and deleted within 30 days of account disconnection or termination, except where retention is required by law.
Media a brokerage uploads or has generated is retained until the brokerage deletes it or its account is deleted. There is currently no automatic deletion of media files. Deleting our copy does not remove anything already published to a third-party platform, which remains subject to that platform’s own retention.
If you are a buyer, seller or tenant whose data a brokerage holds in Immvela, that brokerage is your controller and is the right first point of contact for an erasure request. When a brokerage passes such a request to us, we erase that person’s records across the platform, including derived records, values extracted from documents, generated documents and stored files. We carry this out by hand, within 30 days; there is currently no automated erasure flow in the application. We may retain a record that a business event occurred where it no longer identifies the person and statutory retention applies. Brokerages may request deletion or disconnection at any time by contacting office@sns-austria.com. Step-by-step instructions for deleting the data obtained through a connected publishing platform are at immvela.com/legal/data-deletion.
4.8 Data security
We maintain technical and organisational security measures to protect the confidentiality and integrity of the data processed in Immvela. These apply equally to all data we receive from connected publishing platforms, including Google and YouTube.
- In transit. All traffic between the user’s browser and Immvela, and between Immvela and the platforms’ APIs, is encrypted with TLS (HTTPS).
- Connected-account access tokens. Access and refresh tokens for connected accounts, including those issued by Google and YouTube, are the most security-sensitive data we hold. They are encrypted with AES-256-GCM before they are stored. The key exists only in the runtime environment and never in the database, so a database dump on its own does not yield access to a connected account. If the key is absent, the system refuses to store tokens in production rather than falling back to plaintext.
- At rest. The database and file storage are operated by Supabase in the European Union (eu-central-1, Frankfurt, Germany) and are encrypted at rest there.
- Tenant separation. Every record belongs to exactly one organisation, and the application checks that separation on every access. Where a request runs under the user’s own sign-in, the database enforces it a second time at row level (row-level security). Background jobs and the server-side paths that store a platform token run with elevated database rights, and there the application check is the boundary, as it is for files in media storage.
- Media files. Photos and videos are held in non-public storage and are reachable only through short-lived signed links; no such file has a publicly retrievable address.
- Disclosure. We do not sell data and do not use it for advertising. We disclose it only to the sub-processors named in Section 4.5 and to the connected publishing platforms in Section 4.6. Data received from Google and YouTube is not sent to our AI provider and is not used to train AI models.
Immvela’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.9 Use of YouTube API Services
Immvela uses the YouTube API Services to publish to YouTube. By using those features you agree to be bound by the YouTube Terms of Service. The Google Privacy Policy applies in addition to this policy.
The permissions we request. When a YouTube account is connected we ask Google for exactly two permissions, no more than the features require:
- youtube.upload, to upload videos selected in Immvela to your channel;
- youtube.readonly, to show your channel’s name and identifier, and to retrieve the total view, like and comment counts for videos published through Immvela.
What YouTube data we store. The access token and refresh token (encrypted), your channel’s identifier and name, the identifiers of videos published through Immvela, the totals named above together with the time they were retrieved, and the token’s expiry time and the list of permissions granted. Nothing further: no comment text, no commenter names, no audience breakdowns, no watch history, no subscriber lists.
Who processes it. YouTube data is processed on our behalf by the sub-processors named in Section 4.5, and is disclosed to no one else.
What we never do with it. YouTube data is not used for advertising, is not sold or disclosed to third parties, is not sent to our AI provider, and is not used to train AI models.
Revoking access. You can withdraw Immvela’s access to your Google account at any time, independently of Immvela, through the Google security settings page. In addition, disconnecting a connected account in Immvela deletes the tokens held there.
5. Server log files
Our hosting provider automatically collects and stores information in server log files that your browser transmits to us. These may include:
- Anonymised / abbreviated IP address
- Date and time of the request
- Browser type and version
- Operating system
- Referrer URL
This data is not merged with other data sources and is used solely to ensure operation, security, and troubleshooting. The legal basis is Art. 6(1)(f) GDPR.
6. Analytics
We use Vercel Analytics, a privacy-friendly, cookieless analytics service provided by Vercel Inc. It measures aggregated, anonymous usage statistics (such as page views) without using cookies and without tracking or identifying individual visitors. No cross-site profiles are created. The legal basis is our legitimate interest in understanding and improving the use of our website (Art. 6(1)(f) GDPR).
7. Cookies
This website does not set tracking or advertising cookies. Only technically necessary storage required to display the site may be used. Because we do not use non-essential cookies, no cookie consent banner is required.
8. Contact (email & contact form)
If you contact us by email, the data you provide (your email address and the content of your message) is processed solely to handle your enquiry.
Our website also provides a contact form. When you submit it, we process the details you enter, namely your name, email address, optional phone number, the type of service you select, and your message, in order to respond to your enquiry. The legal basis is Art. 6(1)(b) GDPR (steps prior to entering a contract) or Art. 6(1)(f) GDPR (our legitimate interest in responding to enquiries).
Contact form submissions are delivered to our mailbox on our behalf by EmailJS (emailjs.com), acting as a processor. Where this involves a transfer of data outside the EU/EEA, it is safeguarded by appropriate measures such as the EU Standard Contractual Clauses.
This data is deleted once it is no longer required and no statutory retention obligations prevent deletion.
9. Data retention
We store personal data only for as long as necessary for the purposes described above or as required by statutory retention periods (e.g. under tax and commercial law). After that, the data is deleted.
10. Your rights
Under the GDPR you have the right to:
- access to your personal data (Art. 15)
- rectification of inaccurate data (Art. 16)
- erasure (Art. 17)
- restriction of processing (Art. 18)
- data portability (Art. 20)
- object to processing based on legitimate interests (Art. 21)
To exercise any of these rights, contact us at office@sns-austria.com.
11. Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority. In Austria this is the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
12. Changes to this policy
We may update this privacy policy to reflect changes to our practices or for legal reasons. The current version is always available on this page.