Privacy Policy
Last Updated: August 27, 2026
This Privacy Policy describes how EuKreate, Inc. ("Company," "we," "us," or "our") collects, uses, and shares information when you use the EuKreate platform and services (the "Service"). EuKreate is an AI-powered digital presence and buyer engagement platform for real estate professionals. The Service helps agents add AI to the digital parts of their real estate marketing by: creating EuKreate-hosted, AI- and search-optimized agent websites and listing pages; building EuKreate Intelligence — a per-agent intelligence assembled from agent-provided content, listings the agent adds, publications, public records, and third-party property and neighborhood data; and making that intelligence available to buyers through EuKreate-hosted pages, an embedded assistant on the agent's own website, lead-capture and booking workflows, and connected messaging platforms (most notably Facebook Messenger) where available.
This Privacy Policy covers the currently active EuKreate products and processing activities: EuKreate-hosted agent websites and listing pages; EuKreate Intelligence and the data ingestion and enrichment that builds it; the embedded assistant placed on an agent's own website; lead-capture forms and booking and tour workflows; demo and sales inquiry forms on our marketing site; the email relay that connects agents and buyers; the optional Facebook Messenger integration (described in Section 4.2) and other messaging-platform integrations as they are activated; and related agent dashboard features. If we activate additional products or materially different processing activities, we will update this Privacy Policy before or when those features become available.
By using the Service, you acknowledge that your information will be collected, used, and disclosed as described in this Privacy Policy. Your access to and use of the Service is governed by our Terms of Service.
We do not sell or share your personal information (as those terms are defined under applicable privacy laws), including for cross-context behavioral advertising purposes.
Geographic Availability: The Service is currently available only to users located in the United States and its territories. We do not currently market, offer, or direct the Service to individuals outside the United States. However, we include international privacy provisions (including GDPR-related disclosures in Section 15) as a protective measure for any incidental access by individuals outside the United States and to reflect our commitment to high data protection standards globally. We reserve the right to expand geographic availability in the future, at which time this Privacy Policy will be updated accordingly.
Our Role Under Data Protection Law
EuKreate acts as a data controller for personal data we collect directly from agents, including account information, business and profile information, brand assets, listing data you add, content we ingest from your existing online presence (such as your website, listing pages, public profiles, and publications), and Service usage data. EuKreate is also a controller for operating the EuKreate-hosted public pages and EuKreate Intelligence we build for you — including generating page and assistant content, platform analytics, security, abuse prevention, and improving the Service. We determine the purposes and means of this processing.
For personal data of buyers and other visitors who engage with EuKreate across its surfaces — including EuKreate-hosted agent and listing pages, the assistant embedded on an agent's own website, lead-capture forms, booking and tour workflows, and connected social messaging platforms where available — EuKreate generally acts as a data processor. The agent (or their brokerage) is the controller of the buyer engagement data collected through these surfaces, and we process such data on the agent's behalf to provide the Service. In limited circumstances — for example, fraud prevention, security, suppression-list maintenance, abuse detection, and aggregate or de-identified analytics — EuKreate processes buyer data as an independent controller, as described further in this Policy.
These roles can be nuanced for EuKreate-hosted public pages and for buyer intelligence that spans multiple surfaces. EuKreate determines the applicable controller and processor roles consistent with applicable law and our agreements with agents. Where EuKreate and an agent jointly determine the purposes and means of processing — for example, certain aggregated analytics or abuse-prevention activities — responsibilities are allocated between us as required by law.
Data Minimization
We strive to collect only the minimum personal data necessary, where appropriate for the Service, to provide the Service and fulfill the purposes described in this Privacy Policy. We regularly review our data collection practices to ensure that we are not collecting or retaining data beyond what is required. Where possible, we pseudonymize or aggregate data to reduce privacy risk.
Table of Contents
- Information We Collect
- How We Use Your Information
- How We Share Your Information
- Buyer ↔ Agent Messaging Channels (Email Relay and Connected Messaging Platforms)
- Data Retention
- Data Security
- Data Breach Notification
- International Data Transfers
- Your Rights and Choices
- Children's Privacy
- Third-Party Links and Services
- EuKreate Intelligence and AI Data Processing
- California Privacy Rights (CCPA/CPRA)
- Additional U.S. State Privacy Rights
- European Privacy Rights (GDPR)
- Do Not Track Signals
- Nevada Privacy Rights
- Changes to This Privacy Policy
- Governing Law
- Contact Us
1. Information We Collect
1.1 Information Agents Provide
Valuation Evidence and Judgment Inputs: The Service's pricing-analysis tools let you record inputs to your own valuation analysis: confirmations or rejections of property facts (including facts our AI extracts from listing text you provide, which do not affect any figure until you confirm them), reasons and notes for including or excluding comparable sales, dollar adjustments you author with your stated rationale, price recommendations you issue, and, optionally, a seller's transaction objectives (timeline, minimum and target price, and the transaction's motivation). Seller transaction objectives are stored separately with restricted access, visible only to the agent who recorded them; they are not included in generated reports, documents, exports, or any AI prompt, and are never shown on public listing pages. Free-text notes and rationales you enter in these tools are automatically screened before saving for language inconsistent with fair-housing law; rejected attempts are not saved as your note but are retained as restricted-access compliance records so that patterns of attempted misuse can be reviewed. Listing descriptions you provide may be processed by our AI Inference Providers (see Section 3.1) to surface factual claims for your confirmation; this processing creates no new data category beyond the extracted text itself.
Demo and Sales Inquiry Information: If you request a demo or otherwise contact us through a sales inquiry form on our marketing site (for example, the "Request a demo" form), we collect the details you submit, which include your first and last name, email address, phone number, brokerage or company name, and real estate license number, and may include your role, team size, primary market, website, and any message you choose to include. To submit the form you must confirm that the information you provide is true and your own and that you are a licensed real estate professional, and you must agree to this Privacy Policy and our Terms of Service; we record that you gave these confirmations, together with the placement of the form you used and basic request metadata (such as IP address and browser user agent) for security and abuse prevention. We use this information to verify that you are a genuine licensed professional, respond to your inquiry, schedule and conduct the demo, and follow up with you about the Service. You may provide this information before creating an account; if you later create an account, it may be associated with your account record.
Imported Contacts and Lead Lists: The Service lets you add leads manually and import contact lists — for example, a CSV export from another CRM, an open-house sign-in sheet, or your past-client or sphere list. Imported records may include each contact's name, email address, phone number, company, tags, and any notes you provide. You may upload only contacts you have the right to contact, and by importing them you represent that you have obtained any consent required by law to store and communicate with them. EuKreate stores and processes imported contacts on your behalf and at your direction, as your service provider / processor; you remain the party responsible for that data and its lawful use, including honoring opt-out requests. Imported contacts are treated as leads and receive the same access controls, retention, suppression, and deletion handling as other leads described in this Policy.
Account Information:
- Email address
- Password (stored in hashed form)
- First and last name
Profile and Business Information:
- Company or brokerage name
- Phone number
- Website URL
- Business address (street, city, state, zip code, country)
- License number, license state, and MLS identifier (where provided)
- Profile picture / headshot
Brand Assets:
- Company logo
- Color schemes (primary, secondary, accent, and text colors)
- Font selections and branding preferences
Content and Materials You Submit or Authorize Us to Analyze:
- Existing website content and pages, including content imported or extracted from URLs you submit or connect;
- Public professional profiles;
- Publications and articles;
- Service and process descriptions;
- Areas of local expertise;
- Testimonials and reviews, where you provide or authorize them;
- Uploaded documents and brand assets;
- Any other materials you submit, connect, upload, or authorize EuKreate to analyze to build EuKreate Intelligence and generate EuKreate-hosted pages.
EuKreate analyzes content you submit, connect, upload, or authorize. Where you provide a website or profile URL, EuKreate may follow and process pages linked from that site or reasonably associated with your professional real estate presence in order to build a complete picture of your presence and expertise. We do not intentionally crawl unrelated websites or unrelated personal content.
Listing Data:
- Property addresses, including geolocation data (latitude and longitude)
- Property descriptions, features, amenities, and disclosures
- Property details (bedrooms, bathrooms, square footage, lot size, year built, property type)
- Listing status, pricing, and listing type (sale or rental)
- URLs of the agent's existing pages on which the EuKreate assistant is embedded
- Open-house schedules and showing instructions you choose to share with the assistant
- Photo-compliance records you record for a listing — a link to the original, unmodified photos and/or your certification that the uploaded photos are not digitally modified (for example, under California AB 723), together with the date of that certification
Calendar and Availability:
- Availability rules and time windows you configure for tour bookings
- An optional scheduling or booking link (for example, to your own external calendar or scheduling page) that you choose to share
- Tour and booking details, which we use to generate calendar invitations (iCalendar/.ics files) that we email to you and the buyer
- If you choose to connect a calendar (Google Calendar or
Microsoft/Outlook — optional, and never required to use EuKreate):
- OAuth access and refresh tokens for that calendar account, which we store encrypted at rest and use only to operate the calendar-sync feature. We delete them when you disconnect the calendar or close your account.
- The email address of the connected account, so we can show you which calendar is linked
- Busy/free intervals — the start and end times when you are unavailable. We do not collect or store the titles, descriptions, locations, attendees, or any other contents of your personal calendar events
- The tour, call, and open-house events that EuKreate itself creates for you. These are written to a dedicated calendar named “EuKreate” that we create in your account. We do not modify your other calendars. Appointments you book outside EuKreate are never imported as EuKreate bookings or leads
- If a buyer opts in at booking time, their email address is added as an attendee on that event; otherwise the event contains no buyer contact details beyond what appears in your EuKreate booking record
Calendar subprocessors. When you connect a calendar, the corresponding provider processes this data on our behalf: Google LLC (Google Calendar API) or Microsoft Corporation (Microsoft Graph). If you do not connect a calendar, neither receives any data from this feature.
Google API Services User Data Policy — Limited Use. EuKreate’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically, data obtained from Google Calendar is used only to provide the calendar-sync features described above; it is not used for advertising, is not sold or transferred to third parties except as necessary to provide the feature or as required by law, and is not used to train generalized artificial-intelligence or machine-learning models. Human access to this data is limited to what is needed for security, to comply with law, or with your explicit consent.
Sensitive Personal Information: We collect limited sensitive personal information only where necessary to provide and secure the Service, such as account login credentials (passwords are stored only in hashed form), encrypted credentials for third-party accounts you connect (such as a connected Facebook Page), and — only if you opt in to the "Use Your Own Voice" feature — a voice recording or audio file of your voice (see the Voice and Biometric Data Disclosure below). We do not collect government-issued identification numbers, financial account numbers (beyond partial card details collected by a future payment processor if paid plans are introduced), racial or ethnic origin, religious beliefs, health data, sexual orientation, or citizenship/immigration status. Property geolocation data is collected solely in connection with listings you add and is not used for tracking, profiling, or any purpose beyond providing the Service. We do not use sensitive personal information to infer sensitive characteristics or for purposes that would require a right-to-limit notice under applicable privacy laws.
Voice and Biometric Data Disclosure: If you opt in to the "Use Your Own Voice" feature, you provide a sample of your voice either by recording yourself within the Service or by uploading an audio file of your voice. We send that audio to our voice-synthesis provider (ElevenLabs) to create a synthetic "voice clone" — a voice model that is used to generate spoken narration for your generated videos and, where you enable it, the buyer voice experience. This voice model is a voiceprint and, depending on your jurisdiction, may be treated as biometric information under the Illinois Biometric Information Privacy Act or similar laws. We create and use it only to provide this opt-in feature, only for your account; we do not use it to identify you and we do not sell it or share it for advertising. You can remove your cloned voice at any time, and we delete it when you remove it or close your account (subject to the retention and backup periods in Section 5).
Aside from this opt-in voice feature, we do not extract, collect, store, or use biometric identifiers or biometric information (as defined under the Illinois Biometric Information Privacy Act or similar state laws) from images, photos, or other content you upload. Headshots and brand images are used solely as visual assets within your account and the assistant UI. While we run automated face-presence detection on an uploaded profile image (to confirm it contains a face before using it as an avatar), we do not generate, store, or use a facial-recognition template, faceprint, or other persistent biometric identifier from your images. Buyer voice input, when a buyer chooses to use the assistant's voice mode, is processed solely to transcribe their speech to text; it is not used to create a voiceprint or any other biometric identifier, and the audio is not retained.
1.2 Information from Buyers and Visitors
Buyers and visitors may interact with EuKreate through EuKreate-hosted agent pages, EuKreate-hosted listing pages, embedded assistants on an agent's existing website, lead-capture forms, booking flows, QR codes and share links, and connected messaging platforms where available. When they choose to engage on any of these surfaces, we collect information from them. As described above, the agent is the controller of this data; EuKreate processes it on the agent's behalf, and also retains certain elements as an independent controller for security, fraud prevention, suppression-list maintenance, and aggregate analytics.
Buyer-Provided Information:
- Name
- Email address
- Phone number (where provided)
- Free-text questions, messages, and chat transcripts submitted to the assistant
- Optional assistant feedback — a star rating (1–5) and any free-text comment the buyer chooses to provide when prompted to rate the chat experience. This feedback is associated with the buyer's session and the listing/agent it relates to, and is surfaced to the agent (for example, in their analytics) and used by us to monitor and improve assistant quality.
- Voice input (only if the buyer uses the assistant's voice mode) — the spoken audio is captured and sent to our AI inference provider (OpenAI) to be transcribed to text (speech-to-text). We use the resulting transcript like any other typed message and do not retain the underlying audio recording.
- Tour-booking details (preferred dates/times, attendees, notes)
- Property preferences (price range, bedrooms, neighborhoods, and similar criteria volunteered by the buyer)
- Chat language preference — if the buyer tells the assistant which language they would like to chat in (for text and voice), we save that choice with their session and, once they share contact details, with their buyer profile, so the assistant uses it in future conversations until they ask to change it
- Buyer-agent referrals (if a buyer indicates they are working with a buyer agent, that agent's name and contact details)
Engagement Metadata:
- Listings viewed and time spent on each
- Assistant sessions, message counts, and timestamps
- Lead capture submissions and booking outcomes
- Buyer activity timeline events used to surface engagement to the agent
- IP address, user agent, and referring URL associated with each session (collected for security, abuse prevention, and to derive approximate location at city/region granularity)
Buyer Notice: When a buyer first engages across our buyer surfaces — the EuKreate-hosted page assistant, the embedded assistant on the agent's own website, EuKreate-hosted listing pages, lead-capture forms, and booking flows — the Service surfaces a notice informing the buyer that their information is being collected on behalf of the listing agent and shared with both the agent and EuKreate as described in this Policy. For connected messaging platforms (for example, Facebook Messenger), this notice is surfaced through the connected account's automated response or profile-linked disclosure where platform constraints allow. The notice links to this Privacy Policy, which describes the categories of personal information collected, the purposes for collection and use, how long we retain the information, and whether the information is sold or shared.
Information from connected messaging platforms (e.g., Facebook Messenger): When an agent connects a Facebook Page (additional Meta messaging integrations may be introduced in the future), buyers can interact with the connected Facebook Page, and EuKreate may relay, summarize, or respond to those messages on behalf of the agent as described in this Policy. Through the connected Page, we receive: the content of messages buyers send to the Page, the sender's platform-issued identifier (for Facebook Messenger, the Page-scoped ID or "PSID"), the Page ID, message timestamps, postback events (e.g., button taps in Messenger), and, where the platform makes it available, the sender's display name (first name and last name). We also receive copies of messages the agent types directly from the platform's native interface (for example, Pages Manager) via message-echo webhooks, so the agent's EuKreate inbox stays synchronized with the platform thread. We do not retrieve a buyer's broader profile, friends list, posts, or any data unrelated to the conversation between the buyer and the connected Page. We process this data on the agent's behalf to deliver buyer questions to the agent's EuKreate inbox, generate AI responses where appropriate (see Section 12), route escalations to the agent by email (see Section 4.1), and send the agent's replies back to the buyer on the originating platform so the buyer experience remains continuous within that platform.
1.3 Information from Third-Party Authentication
When you sign in using Google or other supported identity providers, we may receive your name, email address, profile picture, the account identifier from the provider, and email-verification status. We request only the information necessary to create and maintain your account.
1.4 Early Access and Account Information
During early access, the Service is provided free of charge and we do not require payment information to use the Service. We may collect and process information about your early access status, account limits, active-listing count, and usage of the Service for account administration, product development, service reliability, and abuse prevention.
If we introduce paid plans in the future, we may collect subscription tier, billing cycle, payment method details, and transaction history as described in an updated version of this Privacy Policy. Payment processing would be handled by a third-party payment processor such as Stripe, and we would not store full credit card numbers.
1.5 Information Collected Automatically
Usage and Activity Data:
- Features and pages you access within the agent dashboard
- Actions you take within the Service (login, listing add/remove, inbox actions, booking confirmations, settings changes)
- IP address and user agent string associated with each activity (for audit and security purposes)
Device and Technical Information:
- IP address
- Browser type and version
- Device type and operating system
- Referring URLs
Analytics Data:
- Funnel metrics (page views, assistant engagements, leads captured, tours booked, replies sent) at the listing and account level
- EuKreate-hosted page views and public-page interactions across your EuKreate-hosted website and listing pages
- QR code and share-link click and scan analytics
- Engagement with pages optimized for search engines and AI-powered search tools
- Assistant-engagement metrics across all surfaces, including EuKreate-hosted pages, the embedded assistant on your own website, and connected social messaging platforms
- Feature usage patterns
- Error logs and diagnostic data
Content Moderation Data:
- Assistant inputs and outputs may be automatically screened for abuse, prompt-injection, or content-policy violations
- Flagged content, violation types, and moderation scores may be recorded and associated with the relevant session or account
1.6 Cookies, Browser Storage, and Similar Technologies
The Service currently uses only strictly necessary cookies and service-functional browser storage to make the Service work, maintain security, remember a buyer's in-widget session, and preserve basic user preferences. We do not currently use marketing, cross-site advertising, or other non-essential tracking cookies.
Strictly Necessary Cookies (Legal basis: contract performance / legitimate interest)
- Maintain your session and authentication state
- Maintain the buyer's assistant session within a single visit
- Enable core Service functionality, including CSRF protection
Service-Functional Browser Storage (Legal basis: contract performance / legitimate interest)
- Buyer session identifiers and panel state used after a buyer opens or uses the widget to keep the assistant experience continuous across page loads or listing pages in the same browser tab session
- Buyer contact details that the buyer has entered into the widget, so the widget can avoid repeatedly asking for the same contact information and can associate follow-up activity with the same lead
- Notice acknowledgments, dashboard preferences, temporary onboarding state, and referral/source information used to operate the Service
- On our own marketing website, a browser-tab session identifier and
the campaign parameters present in the link you arrived on (for example
utm_source,utm_campaign, or an advertising click identifier such asgclidorfbclid), together with the referring website's domain. These are used to measure how many people visit our marketing pages and which of our own advertising or referral sources they came from. They are stored only for the browser-tab session, are not linked to a persistent visitor identifier, are not shared with any advertising network, and are not used to build a profile of you or to target you across other websites. - On EuKreate-hosted agent and listing pages, and on the assistant
embedded on an agent's own website, the same limited arrival
information: the share-link or QR-code identifier of the link you
followed, any campaign parameters on that link (for example
utm_sourceorutm_medium), any advertising click identifier such asgclidorfbclid, and the referring website's domain — never the full referring address and never the rest of the query string. This lets the agent see which of their own marketing efforts brought a visitor to the page — for example, that a visit came from a scanned open-house flyer rather than a social post, or from an ad they paid for rather than an organic link. It is recorded only for the browser-tab session, is not linked to a persistent visitor identifier, is not shared with or sent back to any advertising network, and is not used to build a profile of you or to target you across other websites.
Passive listing or page views may be counted server-side without
creating a persistent anonymous browser visitor ID. Browser storage may
include localStorage and sessionStorage. Some
items remain on the device until the visitor clears browser storage, uses
an available in-widget clear control, or the item is replaced;
session-only items generally expire when the browser tab or session ends.
Server-side retention of related Service records is described in Section
5.
Because these technologies are used to provide requested Service functionality and are not used for cross-site advertising, we do not currently provide a separate cookie preference center. These technologies cannot be fully disabled without impairing the Service. If we introduce non-essential cookies or tracking technologies in the future, we will update this Privacy Policy and implement an appropriate consent or opt-out mechanism before deploying them.
1.7 EuKreate-Hosted Pages and Generated Content
EuKreate creates and hosts public agent websites and listing pages on your behalf. These pages are designed to be discoverable by search engines and AI-powered search tools. In connection with creating, hosting, and operating these pages, we process:
- Agent Profile and Services: The agent profile, biography, and service and process descriptions shown on the pages.
- Brokerage and Company Information: Brokerage or company details associated with the agent.
- Listing Data: Information about listings you add and choose to display.
- Local-Expertise and Neighborhood Content: Areas of local expertise and neighborhood, school, and area information.
- Testimonials and Publications: Testimonials, reviews, publications, and articles, where ingested or authorized.
- Brand Assets: Uploaded logos, images, and other brand assets.
- Imported Website Content: Website content imported or extracted from your current site and connected URLs.
- Generated Content: EuKreate-generated page content, descriptions, and summaries derived from EuKreate Intelligence.
- Page URLs and Share Tools: Public EuKreate page URLs, QR codes, and share links.
- Buyer Interactions: Buyer interactions that occur on EuKreate-hosted pages, including assistant conversations, lead-capture submissions, and booking or tour requests.
Some of your business information is displayed publicly on EuKreate-hosted pages. Because these pages are public and intended to be discoverable, the information on them may be indexed, cached, or summarized by third-party search engines and AI systems under their own policies, which we do not control. See Section 11 for more information about third-party search and AI systems.
Information From Recipients of Shared Documents
Separately from the Service, EuKreate may share confidential business documents (such as investor materials) with a specific recipient using a private, single-purpose link. These links are not part of the Service and are not publicly listed or indexed.
These links are addressed to a named recipient. When you open one, we record:
- Name — either the name of the recipient the link was addressed to, which you confirm on the welcome screen, or a name you supply yourself if you indicate you are not that person.
- Email address — likewise either the address the link was addressed to, or one you supply yourself. The addressed email is displayed to you only in partial form (for example j***@example.com) so that a forwarded link does not disclose the recipient's full address.
- Whether the identity was confirmed or self-supplied, so we can tell an intended reader from a forwarded one.
We also automatically record the date and time of access, your IP address, and your browser user-agent string for each view.
We use this information for a single purpose: to know who has accessed a document we shared, and to secure and audit access to it. We do not use it for marketing, do not sell or share it, do not use it to build advertising profiles, and do not process it with automated decision-making or AI systems. The information is visible only to authorized EuKreate personnel and is retained as described in Section 5.
Providing this information is voluntary, but the document will not open without it. If you would prefer not to provide it, contact the person who sent you the link and request the document by another means.
1.7 Comments on EuKreate Articles
Our website publishes articles at eukreate.com/articles. Any visitor may react to an article or leave a comment; neither requires an account.
Reactions. When you react to an article we store a
one-way SHA-256 hash of a first-party cookie value
(ek_reader) together with the reaction you chose. The cookie
value itself is never stored on our servers, and the hash is not linked to
your name or email unless you separately choose to comment.
Comments. If you leave a comment we collect the name you supply, your email address, the text of your comment, a one-way hash of your IP address, and your browser user-agent string.
Your name and comment text are public once published. Your email address is never published and is never shown to other readers. We use it for one purpose only: to send you a one-time 6-digit code confirming the address is yours. We do not send notifications to commenters, do not use commenter email addresses for marketing, do not sell or share them, and do not add them to any mailing list. If we later introduce reply notifications, we will update this policy before doing so.
Automated screening. Every comment is screened before publication by an automated, rule-based system that checks for spam, abusive content, personal information, and language that would raise fair-housing concerns. This screening is deterministic pattern matching performed on our own servers — comment text is not sent to any third-party AI or language-model provider. Comments flagged by the screen, and all comments from first-time commenters, are reviewed by a person before they appear.
Retention. Published comments are retained while they remain published. The hashed IP address and browser user-agent string are retained for 90 days and then deleted from the comment; the comment itself is unaffected. Comments that are never confirmed by email are deleted after 30 days. Verification codes are stored as hashes, expire after 15 minutes, and the records holding them are deleted after 30 days. These periods are enforced by an automated job that runs daily.
Deletion. You may have your comment and the reader record behind it deleted at any time by emailing support@eukreate.com from the address you used to comment. Our full comment rules are published at eukreate.com/articles/comment-policy.
2. How We Use Your Information
We use the information we collect for the following purposes.
Provide and Improve the Service:
- Create and manage your account
- Build and maintain your EuKreate Intelligence from the content and materials you provide, the listings you add, your publications, public records, and third-party property and neighborhood data
- Ingest, extract, summarize, and structure content from your existing online presence (such as your website, listing pages, public profiles, publications, and the brand assets and materials you submit) to build and update your EuKreate Intelligence
- Generate and host your EuKreate agent website and EuKreate-hosted listing pages
- Generate listing-page summaries and buyer-Q&A responses based on the listing data, brand information, and other content you have provided
- Structure and publish content to support discoverability by search engines and AI-powered search tools — what we refer to as generative engine optimization, meaning structuring public pages so search engines and AI-powered search tools can better understand them
- Operate the AI assistant across EuKreate surfaces, including powering buyer conversations and continuity across hosted pages, the embedded assistant on your own website, and connected messaging platforms where available
- Capture buyer leads and present them in your lead inbox
- Maintain the buyer activity timeline associated with each listing and lead
- Route tour, call, callback, and showing requests to you (and to buyer agents where applicable)
- Operate the calendar / booking workflow, including writing tour events to a connected calendar at your direction
- Compute funnel analytics at the listing and account level
- Improve conversion and Service quality across EuKreate surfaces
Buyer-Agent Messaging Relay:
- Deliver messages between buyers and the listing agent (and a buyer agent where one has been identified) through our messaging-relay provider, with replies routed via per-thread reply addresses
- Maintain a suppression list for buyers who unsubscribe, are identified as undeliverable, or report messages as spam (see Section 4)
Communicate with You:
- Send transactional emails (email verification, password resets, account notifications, lead alerts, booking confirmations)
- Send notifications about items in your account that need your decision, and activity summaries or digests. You control which channels these use, how often they are batched, and the quiet hours during which non-urgent notifications are held, from Notifications in your account settings. A small number of urgent notifications — a buyer waiting on a live answer, or a failed payment — are sent regardless of quiet hours. We maintain a suppression list of agent email addresses that hard-bounce or report our mail as spam, and stop sending to them
- Provide customer support
- Send service updates and announcements
- Send marketing communications (with your consent, which you may withdraw at any time by clicking the "unsubscribe" link in any marketing email or by updating your communication preferences in your account settings)
Ensure Security and Compliance:
- Detect and prevent fraud, abuse, and unauthorized access
- Apply rate limits and bot protections to the assistant widget
- Moderate assistant inputs and outputs for policy violations
- Enforce our Terms of Service
- Maintain audit logs for security and compliance
- Comply with legal obligations
Analytics and Business Operations:
- Analyze usage patterns and trends
- Measure Service performance
- Make business decisions about features and improvements
3. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances.
3.1 Service Providers
We disclose personal information only to service providers and contractors (as defined under applicable privacy laws) who are contractually prohibited from retaining, using, or disclosing your information for any purpose other than providing services to us.
| Provider Category | Purpose | Data Shared |
|---|---|---|
| AI Inference Providers (OpenAI; Anthropic or other configured AI providers if enabled) | Generate EuKreate assistant responses to buyer questions, transcribe buyer voice input to text when voice mode is used, and produce conversation summaries | Buyer-question text, listing details, neighborhood data, agent-provided or ingested context, and relevant generated page context. When a buyer uses voice mode, their spoken audio is transmitted for speech-to-text transcription and is not retained as a recording. We use API or enterprise-tier access that contractually excludes customer data from model training. Personally-identifying details such as buyer contact details and agent contact details are minimized or removed where technically feasible before transmission; the buyer's first name may be included so the assistant can address the buyer naturally. Messaging-platform identifiers such as Messenger PSIDs are not transmitted. |
| Voice Synthesis / Voice Cloning (ElevenLabs) | Generate spoken narration for generated videos and the optional buyer voice experience; create and store a synthetic voice clone if you opt in to the "Use Your Own Voice" feature | Text to be spoken aloud (for the buyer voice experience, the assistant's written answer — not buyer contact details); for voice cloning, the voice recording or audio file you provide |
| Cloud Infrastructure (AWS) | Host application servers, store databases, store agent-uploaded brand assets and headshots | Service data hosted or stored in cloud infrastructure, protected using provider-supported security controls such as encryption at rest where available |
| Buyer ↔ Agent Messaging Relay (Postmark) | Deliver messages between buyers and agents using per-thread reply addresses, including suppression-list management for unsubscribes, hard bounces, and spam complaints | Buyer email address, agent email address, message content, threading metadata |
| Agent Notification Email (Postmark; Amazon Simple Email Service) | Send account and workspace notifications to agents — items awaiting their decision, activity summaries, and digests — and receive delivery feedback (hard bounces and spam complaints) so we stop emailing an address that no longer accepts our mail | Agent email address, notification subject and body, delivery and bounce/complaint status |
| Meta Platforms (Facebook Messenger; additional Meta messaging integrations as activated) | Receive buyer direct messages sent to a Facebook Page (or other connected messaging account) that an agent has connected to EuKreate, and deliver the agent's reply back to the buyer through Meta's Send API so the conversation remains in the originating platform; receive message-echo events for messages the agent types in Meta's native interface so the EuKreate inbox stays in sync | Buyer platform identifier (Page-scoped ID), Page or account ID, message content sent to and from the connected Page, message timestamps, postback events, sender display name (first name and last name) where the platform makes it available, and message-echo copies of agent-typed replies on the platform's native interface |
| Transactional Email (Amazon SES; Gmail SMTP for limited non-listing notifications) | Send transactional emails (verification, password resets, account notifications) and limited operational emails | Email address, name, message content |
| SMS / Phone Verification (Twilio) | Send one-time verification codes to confirm an agent's phone number | Agent phone number, verification code |
| Authentication (Google, and other supported identity providers) | User login and identity verification | Basic profile information |
| Property / Neighborhood / Public-Records Data Providers (e.g., Rentcast for property facts; Foursquare for points of interest; SchoolDigger and the U.S. Department of Education's NCES for schools; the FBI Crime Data API for crime statistics; FEMA, USGS, OpenAQ, and the FCC for flood, seismic, air-quality, and broadband data; the U.S. Census Bureau and FRED for demographic and market data; additional providers as introduced) | Property facts (including property tax, assessment, ownership, and sale-history records), market context, neighborhood insights, points of interest, schools, hazards/safety, and public-records context used to build EuKreate Intelligence and enrich pages | Property addresses and area/location queries (no buyer or agent contact information) |
| Map / Geocoding Providers (Geoapify; Google Maps Platform for geocoding and drive-time/commute estimates) | Address normalization and autocomplete, geocoding, proximity and points-of-interest data, and commute/drive-time estimates | Address queries and property addresses |
| Website Ingestion / Content-Import Infrastructure | Import and analyze the agent's existing website, profiles, publications, and submitted materials to build EuKreate Intelligence and generate pages | URLs the agent submits or connects and the public content retrieved from them |
| AI Safety / Content-Moderation Providers (where used) | Fair-housing and advertising-compliance risk screening, prompt-injection and abuse detection, and content moderation | Assistant inputs/outputs and generated content screened for policy compliance (personally identifying details minimized where feasible) |
| Social-Publishing Providers (where enabled — the Meta Graph API for Facebook and Instagram, the YouTube Data API, the TikTok Content Posting API, and the LinkedIn API) | Where you turn on optional social-publishing features and connect social accounts, post the content you approve to those platforms on your behalf. When you connect Facebook, Instagram, TikTok, or LinkedIn, an access token (and, for TikTok and LinkedIn, a refresh token) for the connected account is stored (encrypted) so posts you approve can be published; for TikTok and LinkedIn we also store your basic public profile (account/member ID, display name, and avatar) to show which account is connected. LinkedIn posts are published to your personal LinkedIn profile. You can disconnect at any time to revoke it. Certain integrations, such as TikTok, may instead upload the content to your account as a draft for you to review and post yourself | The agent-approved post content (captions, images, and videos); no buyer personal data |
| Error Monitoring | Monitor and resolve application errors | Technical logs, pseudonymized usage data |
| Analytics | Understand usage patterns and feature adoption | Pseudonymized and aggregated usage events |
We use contractual terms, Data Processing Agreements (DPAs), or comparable service-provider terms where appropriate to require providers to protect your information and use it only for the purposes we specify. These arrangements may include technical and organizational safeguards, data-breach notification obligations, and restrictions on further sub-processing. A current list of our sub-processors is available upon request by contacting privacy@eukreate.com.
3.2 Disclosure to the Listing Agent (and Buyer Agent Where Applicable)
Information that a buyer submits through an assistant, lead-capture form, or booking flow on one of our buyer surfaces is shared with the listing agent (and, where the buyer has identified one, with the buyer's agent) so that the agent can respond, schedule a tour, or otherwise follow up. This is the core purpose for which buyers engage with the Service. Once data is shared with an agent (or a buyer agent), that agent becomes responsible for its use under their own privacy practices and applicable law.
3.3 Legal Requirements
We may disclose your information if required to:
- Comply with applicable laws, regulations, or legal processes
- Respond to lawful requests from public authorities
- Protect our rights, privacy, safety, or property
- Enforce our Terms of Service
3.4 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice within the Service before your information becomes subject to a different privacy policy.
3.5 With Your Consent
We may share your information for other purposes with your explicit consent.
4. Buyer ↔ Agent Messaging Channels (Email Relay and Connected Messaging Platforms)
The Service can deliver messages between buyers and agents over more than one channel: an email relay operated by EuKreate, and optional integrations with third-party messaging platforms (most notably Facebook Messenger) when the agent connects an account from that platform.
4.1 Email Relay and Suppression
The Service routes messages between buyers and agents through our
messaging-relay provider (Postmark). We mint per-thread reply
addresses on a dedicated relay subdomain (e.g.,
reply.eukreate.com); when an agent or buyer replies to a
threaded email, the message is matched to its thread and forwarded to
the intended recipient.
To comply with anti-spam laws and platform requirements, the following events always cause a buyer's email address to be added to a suppression list and to stop receiving relayed messages from the Service:
- The buyer replies with "STOP," "UNSUBSCRIBE," or a similar opt-out keyword
- The buyer's address produces a hard bounce (permanent delivery failure)
- The buyer marks a message as spam
Once a buyer is suppressed, agent replies addressed to that buyer through the Service will not be delivered, and the agent will see a suppression indicator in their lead inbox. Suppression-list entries are retained for as long as required to honor opt-out and anti-spam obligations and cannot be removed by the agent. A buyer may request removal from a suppression list by contacting privacy@eukreate.com.
Bulk and broadcast messages. Agents may compose a single personalized message and send it to several selected leads at once. Each message is delivered individually through the same relay described above — never as a shared, group, or blind-copied mailing — with fields such as the recipient's first name or the property address substituted per recipient. Every broadcast honors the suppression list above (opted-out, hard-bounced, or spam-complaining recipients are skipped) and includes opt-out handling. EuKreate does not send marketing to your buyers on its own behalf; these messages are sent by you, as the agent, and you are responsible for their content and for compliance with applicable anti-spam and communications laws (for example, CAN-SPAM). We retain a record of each broadcast (recipient leads, subject, timestamps, and per-recipient delivery outcome) for audit and compliance.
Relay metadata (threading identifiers, send/receive timestamps, delivery status) is retained for twelve (12) months for audit and compliance, after which it is purged or aggregated.
4.2 Facebook Messenger and Other Connected Meta Messaging Integrations
When an agent connects a Facebook Page to EuKreate (additional Meta messaging integrations may be introduced in the future), the Service receives direct messages buyers send to that Page through Meta-provided webhook events, and delivers replies back to the buyer through Meta's standard messaging APIs (for example, the Messenger Send API). The data we receive through this integration is described in Section 1.2; the entities with whom we share it (including Meta itself, which both delivers and receives this data on our behalf) are described in Section 3.1.
Scope of access: EuKreate only accesses messaging data associated with Pages or business messaging accounts that an agent has explicitly connected to the Service. EuKreate does not access a buyer's Facebook timeline, friends list, photos, posts, or any other account activity unrelated to the conversation between the buyer and the connected Page. When a buyer sends a message to a connected Page, EuKreate may also call Meta's User Profile API for that sender's Page-scoped identifier to retrieve their display name (first name and last name) so that the EuKreate inbox and escalation emails can show the same buyer identity that the listing agent already sees natively in their Facebook Page inbox. EuKreate does not retrieve the sender's profile picture, locale, timezone, or any other profile fields, and does not access any other Facebook activity belonging to the buyer. EuKreate does not modify the connected Page's profile, posts, photos, category, or any other Page content; we only subscribe to message-related webhook events and send messages on the connected Page's behalf.
How the integration loop works:
- A buyer sends a direct message to the connected Page. Meta delivers that message to EuKreate through Meta-provided webhook events.
- Our AI assistant evaluates the message against the listing's data. For factual questions about the listing that we can answer with high confidence, the AI generates a response and sends it back to the buyer in the same platform thread on the agent's behalf, using Meta's messaging APIs.
- Questions involving negotiations, contracts, legal matters, financial advice, or other subjective professional judgment are escalated to the agent for manual review and response; no AI reply is sent for these.
- For escalated questions, EuKreate emails the listing agent at the address EuKreate sends notifications to. The agent's reply to that email is routed back to the buyer in the original platform thread, so the buyer experiences a continuous conversation without ever seeing the agent's email address.
- If the agent types a reply directly inside Meta's native interface (for example, Pages Manager), Meta sends EuKreate a message-echo event so the EuKreate inbox stays synchronized with the platform thread.
Meta platform permissions used: When the agent connects a Facebook Page, EuKreate requests only the Meta platform permissions necessary to operate the messaging workflows the agent has authorized:
| Permission | Purpose |
|---|---|
pages_messaging |
Receive buyer messages sent to the connected Page through Meta's webhook events, send replies back to the buyer through Meta's messaging APIs, and receive message-echo events for replies the agent types in Meta's native interface (e.g., Pages Manager). |
pages_show_list |
During onboarding, display the list of Pages the agent administers so the agent can choose which Page(s) to connect to EuKreate. |
pages_manage_metadata |
Subscribe the agent's selected Page(s) to message-related webhook
events (messages, message_echoes,
messaging_postbacks) so EuKreate can receive buyer
messages. This permission is used only for that webhook-subscription
call; EuKreate does not use it to modify the Page's name, description,
profile picture, posts, cover image, category, or any other Page
metadata. |
instagram_basic |
Read which Instagram professional account, if any, is linked to a Page the agent has connected, so the agent can see that linkage in EuKreate. This permission reads only the linked account's identifier and username. It does not grant access to Instagram direct messages, and EuKreate does not use it to read Instagram media, comments, followers, or insights. |
EuKreate does not currently request permission to receive Instagram direct messages. Instagram messaging is not active on the Service, and buyer conversations on connected Meta accounts today take place through Facebook Messenger only.
Some of the permissions above have been submitted to Meta for review and are not yet approved for general use. Until Meta approves a permission, the capability it supports is available only to accounts Meta designates as testers of our application; for all other agents the capability is simply unavailable. Where a permission that supplies a buyer's display name is unavailable, the buyer appears in EuKreate only as an opaque platform-issued identifier.
If we activate additional Meta messaging integrations in the future — including Instagram direct messaging — this Privacy Policy will be updated to describe any additional Meta platform permissions involved before that integration becomes available to agents.
How we use data received from Meta: Data received from Meta APIs is used solely to provide messaging, inbox synchronization, AI-assisted response generation for listing-related questions, booking coordination, and lead-management functionality within EuKreate. EuKreate does not sell Meta platform data, use it for advertising purposes, share it with data brokers, or use it to build unrelated user profiles.
Limits on automated messaging: Automated responses generated through connected Meta messaging platforms are limited to listing-related factual information, booking coordination, and customer-service replies within conversations the buyer has initiated with the connected Page. EuKreate does not send unsolicited outreach, bulk promotional campaigns, or unrelated marketing messages through Meta messaging platforms.
User controls: Agents may disconnect a connected Facebook Page or other Meta messaging account at any time through the EuKreate dashboard or through Meta account settings. Buyers may stop interacting with a connected Page at any time using Meta platform controls, including blocking or reporting the Page conversation. Buyers may also request deletion of data EuKreate has stored from these conversations by emailing privacy@eukreate.com or by following the steps in our Data Deletion Instructions at https://eukreate.com/data-deletion.
Retention: Connected Meta messaging-platform data is retained only for as long as necessary to provide the Service, maintain conversation continuity, comply with legal obligations, and honor suppression or deletion requests; see Section 5 for the detailed retention schedule.
SMS Communications (Agent Operational Alerts)
SMS communications. If you (an agent) opt in to SMS notifications, EuKreate may send operational messages about buyer inquiries, tour requests, listing escalations, and related account activity. Message frequency varies. Message and data rates may apply. You may opt out at any time by replying STOP. Reply HELP for assistance or contact support@eukreate.com. Mobile opt-in information and consent will not be sold, rented, or shared with third parties or affiliates for their marketing or promotional purposes. We may share information with service providers (including our SMS delivery provider, Twilio) that help us deliver messaging services, subject to contractual and confidentiality restrictions.
SMS alerts are an agent-only operational channel. EuKreate does not use this program to send marketing or promotional messages, and does not use it to contact buyers. To enable SMS alerts you provide your mobile number, affirmatively accept a separate SMS consent disclosure (presented as an unchecked checkbox, off by default), and verify possession of the number with a one-time code. We retain the resulting consent evidence — the mobile number, the disclosure version you accepted, the date and time, and limited technical context such as IP address and browser user-agent — for as long as your consent is active and thereafter as required to demonstrate compliance, as described in Section 5. A full description of the SMS alert program is available at https://eukreate.com/sms-consent.
Quiet hours and urgent alerts. You may set quiet hours during which we will not text you. Alerts arising in that window are held and delivered afterwards; your portal and email notifications are unaffected.
Consenting to receive text messages does not by itself permit us to text you during your quiet hours. That is a separate, optional consent, covering one narrow circumstance: a buyer is waiting on an answer that EuKreate Intelligence cannot answer on your behalf. Where you give it, we retain the same consent evidence as for SMS itself — the date and time, the page it was given on, limited technical context such as IP address and browser user-agent, and the exact wording displayed to you at that moment. We store the wording per consent rather than by reference, so that what you agreed to remains recoverable even after we change the text.
This consent is optional, is never a condition of using EuKreate or any paid plan, and may be withdrawn at any time in your notification settings. It ends automatically if you withdraw consent to receive text messages at all, including by replying STOP. Withdrawal takes effect on the next message; we retain the record that consent was given and withdrawn for the period described in Section 5.
Product and promotional texts (separate, optional consent). During onboarding — and later in your notification settings — EuKreate may offer you (an agent) the option to receive occasional product and promotional text messages: feature tips, offers, and onboarding reminders. This is a separate consent program from operational alerts: it is presented as its own unchecked checkbox, it is never bundled with phone verification or with the operational-alert consent described above, and it is never a condition of purchase or of using EuKreate or any paid plan. The operational alert program described above remains marketing-free; promotional texts, where we send them at all, are sent only to agents who have given this separate promotional consent. Where you give it, we retain the same consent evidence as for the other text-message consents — the date and time, the page it was given on, limited technical context such as IP address and browser user-agent, the disclosure version, and the exact wording displayed to you at that moment, stored per consent rather than by reference. You may withdraw at any time in your settings or by replying STOP to any promotional message; withdrawal is recorded and retained as described in Section 5. Replying STOP to opt out of texts entirely ends this consent as well.
5. Data Retention
We retain your information for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
Retention Periods:
- Account profile data (name, email, company, contact information): retained while your account is active. Upon account termination, profile identifiers are retained for legal compliance, financial record-keeping, dispute resolution, and internal analytics. This data is not used for marketing or to rebuild your account.
- Listing data (addresses, descriptions, prices, photos referenced by URL): retained while your account is active. When you cancel or close a paid plan, or when a plan lapses for non-payment, listings that are stood down are kept dormant for a ninety (90) day retention window and then permanently deleted; re-subscribing before the window ends restores them. On account termination, listing data is retained for thirty (30) days and then permanently deleted.
- Buyer leads, chat transcripts, and engagement timelines: retained while the agent's account is active. Upon account termination, lead and chat data are exportable for thirty (30) days and are then permanently deleted, except for data that the agent has exported and that is governed by the agent's own retention practices, and except as required to maintain the suppression list.
- Booking and calendar-event metadata: retained while the agent's account is active and for thirty (30) days after termination. Tour bookings are delivered as iCalendar (.ics) invitations by email, except to an agent who has connected a calendar — EuKreate writes that agent's events directly to the connected calendar instead, so their copy of the email carries no duplicate invitation. Any event a recipient saves to their own calendar, or that EuKreate writes to a connected calendar, remains there under that calendar provider's terms.
- Connected-account credentials (such as encrypted access tokens for a connected Facebook Page, or encrypted access and refresh tokens for a connected TikTok or LinkedIn account): retained while the connection is active. When you disconnect a connected account, or when account deletion is requested, we mark the connection disconnected, stop using it to send or respond to messages, and make commercially reasonable efforts to unsubscribe or revoke our access with the upstream provider; we may retain the stored connection record (including the encrypted token) linked to prior message history until your account is purged. On account termination, connected-account records and their stored credentials are deleted when your account is purged at the end of the retention period described above.
- Voice recordings, cloned voice models, and generated audio: retained while the "Use Your Own Voice" feature is enabled or while needed to provide agent-approved generated audio/video features. If you remove your cloned voice or close your account, we delete the source voice sample and cloned voice model from active EuKreate systems and make commercially reasonable efforts to delete or disable them with the voice-synthesis provider, subject to provider retention limits, legal obligations, and the backup retention period described in this Section.
- Buyer-agent messaging relay metadata: retained for twelve (12) months for audit and compliance.
- Connected messaging-platform conversation data (Facebook Messenger direct messages received through a connected Page, and equivalent data from any other connected messaging platforms, including message content, sender platform identifier such as Messenger PSID, Page or account ID, message timestamps, postback events, sender display name (first name and last name) where available, and message-echo records of agent-typed replies in the platform's native interface): retained while the agent's account is active and the corresponding platform connection remains in place. Upon disconnection or account termination, this data is exportable for thirty (30) days and is then permanently deleted, except for suppression-list entries and any data retained as required by applicable law.
- Suppression list entries: retained for as long as required to honor opt-out and anti-spam obligations.
- Subscription and payment transaction history: if paid plans are introduced in the future, retained as required by applicable tax and financial regulations.
- Usage and activity logs: retained for twelve (12) months for analytics, early-access administration, service reliability, abuse prevention, and security purposes.
- Backup data: may be retained for up to thirty (30) days after deletion from primary systems.
- Content moderation records: retained for the duration of your account and thereafter only as long as reasonably necessary for safety, abuse prevention, legal, and compliance purposes.
- Generated EuKreate website and listing-page content; EuKreate Intelligence and knowledge-base records (corpus, summaries, structured Q&A): retained while the agent's account is active, including while pages and generated content are in draft, review, published, unpublished, or archived states, unless deleted earlier by the agent or under applicable retention settings. Public pages are removed from active public EuKreate systems on unpublish; all such content is removed from active EuKreate systems within thirty (30) days of account termination, subject to the backup retention period and the public-cache caveat described below.
- Enriched property and neighborhood context (property facts, nearby points of interest, schools, hazards and safety data, and market data): retained while needed to keep pages and EuKreate Intelligence current, and refreshed on a recurring basis. Deleted from active systems on account termination, subject to the backup retention period.
- Public EuKreate page URLs, QR codes, and share links: deactivated when the associated page is unpublished or the account is terminated.
- Shared-document access records (recipient name, email, IP address, user-agent, and access timestamp, as described in Section 1): retained for twenty-four (24) months from the date of access, or until the associated document is deleted, whichever is earlier. Retained as an access-control and audit record; not used for marketing.
- Buyer conversation memory across surfaces (continuity carried between the hosted pages, the embedded assistant, and connected messaging): retained while the agent's account is active. Exportable for thirty (30) days after termination and then permanently deleted, except for suppression-list entries and data we are required to retain by law.
Phased Deletion Process: Upon your termination request: (1) connected third-party accounts (such as a connected Facebook Page) are disconnected and the assistant on your pages is disabled; (2) buyer leads, chat transcripts, and listing data are exportable for thirty (30) days; (3) primary-system data is permanently deleted at the end of that thirty-day window (backup copies are purged within an additional thirty (30) days). Certain data is retained beyond this period as described above for legal, financial, and compliance purposes.
Reactivation During the Retention Window: During the thirty (30) day retention window, you may sign in to the restricted account-deletion page and request reactivation. Reactivation cancels the pending deletion request, restores dashboard access to retained account data, and returns the account to active status. Buyer-facing AI assistant widgets, automated posting, and automated replies that were disabled when deletion was requested remain disabled until you turn them back on. After the final purge, the prior account data cannot be reactivated or restored, but the same email address or OAuth identity may be used to create a new account.
Deletion Methodology: When data is deleted, it is removed from our primary databases and active systems. Cached copies and backup systems are purged within thirty (30) days of primary deletion. We use both logical deletion (marking records as deleted and removing them from all queries and interfaces) and physical deletion (permanent removal from storage) depending on the data type and system architecture. After the backup retention period, deleted data is irrecoverable. Retained metadata and transaction records remain accessible only to authorized personnel for the purposes described above.
Unpublishing, deletion, and the public-cache caveat: When an agent unpublishes or deletes a EuKreate-hosted page or their account, we remove the page and its generated content from active EuKreate systems. However, copies may remain temporarily in our backups (purged on the backup schedule described in this Section), and copies may already have been cached, indexed, summarized, or archived by third-party search engines, AI systems, browsers, or other services outside EuKreate's control. We cannot control whether or for how long those third parties retain such copies; they retain or remove them under their own policies. Where technically feasible, we update our sitemaps and crawl directives (such as robots.txt) and deactivate pages so that removed or unpublished pages are no longer listed for crawling; however, we cannot control whether or when third parties recrawl, deindex, or purge previously cached copies.
You may request deletion of your data at any time (see Section 9). You may also request details about what data is retained after account termination by contacting privacy@eukreate.com.
6. Data Security
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit using TLS and encryption at rest where supported by our infrastructure providers
- Secure password hashing using industry-standard salted hashing algorithms (currently Argon2)
- Encrypted storage of OAuth tokens and other credentials
- Role-based access controls and authentication
- Rate limiting and abuse protections on public-facing endpoints, including the assistant widget
- Periodic security reviews and remediation of identified issues
- Cloud infrastructure providers that maintain their own security and compliance programs
- Audit logging of account activities
However, no method of transmission or storage is 100% secure. We cannot guarantee absolute security of your information.
Accountability: We maintain internal data protection practices, review privacy and security implications for new features and processing activities where appropriate, restrict access to personal data to authorized personnel and service providers, and maintain records of processing activities where required by applicable law. We review and update our technical and organizational measures as the Service, technology, threats, and regulatory requirements evolve.
7. Data Breach Notification
In the event of a data breach that affects your personal information, we will:
- Investigate the incident and take steps to contain and remediate the breach
- Notify relevant supervisory authorities within seventy-two (72) hours of becoming aware of the breach, as required by applicable law (including GDPR's notification requirement and applicable U.S. state breach-notification laws)
- Notify affected users via email without undue delay after becoming aware of the breach and completing an initial assessment
- Provide information about the nature of the breach, the data affected, and the steps we are taking to address it
- Offer guidance on steps you can take to protect yourself
8. International Data Transfers
Note: As the Service is currently available only to users in the United States, international data transfers as described in this section are not expected to occur in the ordinary course of operations. We include these provisions as a safeguard and to ensure readiness for future geographic expansion.
Your information may be transferred to and processed in countries other than your country of residence, including the United States, where our servers and service providers are located. These countries may have different data protection laws. Where required by applicable law, we use appropriate safeguards, which may include:
- Standard Contractual Clauses (SCCs): the European Commission's Standard Contractual Clauses (2021/914) for personal data transferred from the EEA, UK, or Switzerland to the United States or other countries without an adequacy decision.
- Transfer Impact Assessments (TIAs): where required, we evaluate relevant transfer risks and implement supplementary safeguards as appropriate.
- Data Processing Agreements (DPAs): where appropriate, we use DPAs or comparable contractual terms with service providers that process personal data.
- UK International Data Transfer Agreement (IDTA): for transfers from the United Kingdom, we use the UK IDTA or the UK Addendum to the EU SCCs, as appropriate.
9. Your Rights and Choices
Depending on your location, you may have the following rights:
Access: Request a copy of the personal information we hold about you.
Correction: Request correction of inaccurate or incomplete information.
Deletion: Request deletion of your personal information, subject to legal retention requirements.
Portability: Request a copy of your data in a structured, commonly used, machine-readable format.
Restriction: Request that we limit processing of your information.
Objection: Object to processing of your information for certain purposes, including direct marketing.
Withdraw Consent: Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing performed prior to withdrawal.
Marketing Opt-Out: Unsubscribe from marketing communications at any time using the unsubscribe link in any marketing email.
Buyer-Side Requests: Buyers seeking to exercise rights with respect to data submitted through an agent-facing buyer experience should generally direct their request to the relevant listing agent, who may be the controller of that buyer engagement data. We will assist agents in responding to such requests where required and will, on a buyer's request, identify the relevant agent so the buyer can submit their request directly. EuKreate will respond directly to buyer requests where EuKreate acts as an independent controller (for example, requests relating to suppression-list entries) or where otherwise required by law.
To exercise these rights, contact us at privacy@eukreate.com. We will respond within the timeframe required by applicable law (generally thirty (30) days; forty-five (45) days for CCPA/CPRA requests as described in Section 13). We may request verification of your identity before processing your request.
10. Children's Privacy
The Service is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If we learn that we have collected information from a child under 18, we will delete that information promptly. If you believe we have collected information from a child, please contact us at privacy@eukreate.com.
11. Third-Party Links and Services
Our Service may contain links to third-party websites or services. If you interact with the embedded assistant on an agent's own existing website, that website is hosted by the agent or their brokerage and is subject to their privacy practices, not ours. We are not responsible for the privacy practices of these third parties, and we encourage you to review the privacy policies of any third-party services you access through or in connection with our Service.
Embedded social media content. When an agent connects a social media account (for example a Facebook Page or Instagram professional account), EuKreate may use that connection's existing read permissions to retrieve the account's own recent public posts (approximately the last month) so they can be featured on the agent's EuKreate-hosted pages and kept current. This reads only content the agent's connected account itself published; it does not read messages, followers, or other accounts' content, and disconnecting the account stops the retrieval. An agent may also choose to feature their own public social media posts (for example from Instagram, Facebook, X, LinkedIn, TikTok, or YouTube) on their EuKreate-hosted pages. These posts are displayed through the platform's own embedding endpoints, loaded directly from that platform when the section comes into a visitor's view. When an embedded post loads, the hosting platform receives the visitor's IP address and request metadata and may set its own cookies or collect data under its own privacy policy — EuKreate does not control that collection. Video embeds use privacy-enhanced modes where the platform offers one (for example YouTube's no-cookie player). Visitors who do not interact with an embedded post section before navigating away may not trigger these loads at all, as embeds are loaded lazily.
EuKreate-hosted pages may be structured to improve discoverability by search engines and AI-powered search tools, including by publishing a sitemap and crawl directives (such as a robots.txt file) that permit these systems to crawl public pages. Public content on those pages may be crawled, indexed, cached, summarized, or processed by third-party search engines, AI systems, browsers, or other services according to their own policies. These third parties are not EuKreate service providers unless separately contracted. EuKreate does not control whether or how those third parties collect, retain, or use publicly available content, and once content is publicly accessible EuKreate cannot guarantee its removal from third-party caches or indexes.
12. EuKreate Intelligence and AI Data Processing
EuKreate uses third-party large-language-model and AI providers (currently OpenAI for active response generation; other configured providers, including Anthropic, may be used if enabled) across EuKreate Intelligence. For spoken audio — narration in generated videos and the optional buyer voice experience — we also use a voice-synthesis provider (ElevenLabs); see the Voice and Biometric Data Disclosure in Section 1.1 and the provider table in Section 3.1. We use these providers for purposes including:
- Generating EuKreate-hosted agent website content;
- Generating listing-page summaries and buyer Q&A;
- Answering buyer questions on EuKreate-hosted pages and through the embedded assistant on the agent's own website;
- Generating responses for connected messaging platforms (e.g., Facebook Messenger) for listing-related factual questions;
- Producing conversation summaries;
- Deriving lead-qualification signals;
- Content moderation and abuse/prompt-injection detection;
- Assisting with fair-housing and advertising-compliance risk screening; and
- Producing recommendations and draft content for agent review.
Lead-qualification signals are used to help agents understand buyer interest and prioritize follow-up. They are not used to determine a buyer's eligibility for housing, financing, pricing, or access to the Service.
Please be aware that:
- Inputs sent to AI providers: buyer question text from any surface; relevant listing details; neighborhood/enrichment data; and agent-provided context and ingested content used to build EuKreate Intelligence, with personally identifying details minimized where technically feasible. Agent contact information is removed unless required and platform identifiers such as Messenger PSIDs are not transmitted; the buyer's first name may be included so the assistant can address the buyer naturally.
- Buyer-provided personal data: we do not transmit a buyer's email address, phone number, or messaging-platform identifier (such as a Messenger PSID) to AI providers to generate responses.
- AI model training: we use commercially available API or enterprise-tier AI services under terms that restrict use of customer data for model training. We will update this Policy and, where required, provide notice if providers materially change their data-use practices.
- Human review and agent responsibility: AI outputs may contain inaccuracies, omissions, or statements that do not comply with real estate advertising or fair-housing laws. EuKreate Intelligence outputs are informational tools, not legal, financial, real-estate, or other professional advice. Agents are responsible for the content they configure and publish, including its accuracy and compliance, and certain outputs (for example, generated page content and escalated questions) are surfaced for agent review.
- Content moderation: inputs and outputs across surfaces are automatically screened for abuse, prompt-injection, potential fair-housing or advertising-compliance risks, and policy violations. Flagged content may be blocked or recorded for review.
- Third-party AI provider limitations: third-party AI providers process transmitted data under their own contractual and privacy obligations. We use commercially reasonable efforts to select providers with appropriate privacy and security commitments. For our liability with respect to third-party services, see our Terms of Service.
13. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act.
13.1 Categories of Personal Information We Collect
In the twelve (12) months preceding the Last Updated date of this Policy, we have collected the following categories of personal information (as defined under Cal. Civ. Code § 1798.140):
| CCPA Category | Examples (as Applicable to the Service) | Sources | Disclosed To |
|---|---|---|---|
| A. Identifiers | Name, email address, phone number, account identifier, IP address, third-party authentication identifier | Directly from agents and buyers; from authentication providers | Service providers (cloud, email, messaging relay, authentication); the listing agent (for buyer-submitted data) |
| B. Customer records (Cal. Civ. Code § 1798.80(e)) | Business name, business address, license number, MLS identifier | Directly from agents | Service providers (cloud, email) |
| C. Commercial information | Listings added, assistant engagement events, lead-capture submissions, booking outcomes | Automatically through use of the Service | Service providers (cloud, analytics); the listing agent |
| F. Internet or other electronic network activity | Pages and features accessed within the Service, assistant session events across surfaces, EuKreate-hosted page and public-page interactions, QR code and share-link analytics, browser/device metadata, referring URLs | Automatically through use of the Service | Service providers (cloud, analytics, error monitoring). Public content on EuKreate-hosted pages may be accessible to search engines, AI-powered search tools, browsers, or other third-party services according to their own policies, but those third parties are not EuKreate service providers unless separately contracted. |
| G. Geolocation data (general, not precise) | Approximate city/region derived from IP; property addresses you add as listings | Automatically; directly from agents | Service providers (cloud, address-data services) |
| H. Audio, electronic, visual | Logos, headshots, and brand images uploaded by agents, and — where the "Use Your Own Voice" feature is enabled — voice recordings and generated audio assets | Directly from agents; audio assets generated by the Service | Service providers (cloud; voice-synthesis provider for opt-in voice features) |
| I. Professional or employment-related information | Brokerage affiliation, license state, MLS identifier | Directly from agents | Service providers (cloud); the listing agent (where shared with a buyer agent for a referral) |
| K. Inferences | Funnel-stage and engagement-state inferences derived from buyer activity (e.g., "engaged," "booking pending"). We do not use inferences to predict sensitive characteristics. | Derived from Service usage | The listing agent; service providers (cloud, analytics) |
We do not collect protected classification characteristics, biometric information, education information, or personal information from minors under 16. We collect limited sensitive personal information only as described in Section 1.1, such as account login credentials and OAuth tokens, and we do not use sensitive personal information for purposes that would require a right-to-limit notice under Cal. Civ. Code § 1798.121.
Business or commercial purposes for collection: providing and improving the Service; account administration; building and maintaining EuKreate Intelligence; generating and hosting EuKreate agent and listing pages; supporting discoverability by search engines and AI-powered search tools; lead capture and routing; security, fraud prevention, and abuse detection; content moderation; analytics; legal compliance. These purposes are described in further detail in Section 2 of this Policy.
Sale or sharing of personal information: we have not sold or shared (as those terms are defined under the CCPA/CPRA) the personal information of any consumer in the preceding twelve (12) months, and we do not have actual knowledge of selling or sharing the personal information of consumers under sixteen (16) years of age.
Opt-Out Preference Signals: because we do not sell or share personal information or use personal information for targeted advertising, opt-out preference signals such as Global Privacy Control do not currently change how the Service processes personal information. If we later engage in activities that require honoring such signals, we will update this Policy and process them as required by applicable law.
13.2 Your CCPA/CPRA Rights
Subject to the exceptions provided by law:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes for collection, and the categories of third parties with whom we share your information.
- Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Opt-Out: Opt out of the sale or sharing of personal information. We do not sell or share personal information as defined by the CCPA/CPRA.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information for purposes beyond what is necessary to provide the Service.
- Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
Shine the Light (California Civil Code Section 1798.83): We do not disclose personal information to third parties for their own direct marketing purposes.
Authorized Agents: You may designate an authorized agent to submit a privacy rights request on your behalf. Authorized agent requests should be submitted to privacy@eukreate.com with the subject line "Authorized Agent Request."
To exercise these rights, contact us at privacy@eukreate.com or call +1-650-307-5532. We will verify your identity before processing your request and respond within forty-five (45) days.
14. Additional U.S. State Privacy Rights
If you are a resident of a state with a comprehensive consumer privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and other states with similar laws), you may have additional rights similar to those described in Section 13. To exercise any of these rights, contact us at privacy@eukreate.com.
General disclosures applicable to all state privacy laws:
- Sale of data: we do not sell your personal information as defined under any applicable state privacy law.
- Targeted advertising: we do not use your personal information for targeted advertising.
- Profiling and Automated Decision-Making: we do not engage in profiling that produces legal or similarly significant effects concerning you. While the Service uses automated systems for content moderation and AI response generation, no automated process determines your eligibility for, access to, or pricing of the Service.
- De-identified data: we may use de-identified or aggregated data that cannot reasonably be linked back to you for analytics and business improvement purposes.
- Appeals: if we deny your privacy-rights request, you may appeal by contacting privacy@eukreate.com with the subject line "Privacy Rights Appeal." We will respond within sixty (60) days.
15. European Privacy Rights (GDPR)
Note: The Service is currently available only to users in the United States and is not directed at individuals in the European Economic Area (EEA), United Kingdom, or Switzerland. We include the following provisions as a safeguard.
If you are in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation. We process your personal data on the following lawful bases:
| Data Category | Processing Activity | Lawful Basis |
|---|---|---|
| Account, profile, and business information | Account creation, authentication, Service access | Contract performance |
| Listing data and ingested agent content | Building EuKreate Intelligence, generating and hosting EuKreate pages, assistant operation, lead capture, analytics | Contract performance |
| Buyer leads and chat transcripts | Lead capture, response routing, agent inbox | Contract performance (between EuKreate and the agent); processed on behalf of the agent |
| Booking and calendar-event metadata | Tour-booking workflow at your direction (delivered as iCalendar/.ics email invitations) | Contract performance |
| Early access status and usage data | Account administration, listing-capacity enforcement, product development | Contract performance / legitimate interest |
| Usage and activity logs | Service improvement, debugging, performance monitoring | Legitimate interest |
| Device and technical information | Security, fraud prevention, abuse detection | Legitimate interest |
| Content moderation data | Policy enforcement, safety screening | Legitimate interest |
| Suppression list entries | Anti-spam compliance and honoring opt-outs | Legal obligation |
| Marketing communications | Newsletters, announcements | Consent |
| Payment records, if paid plans are introduced in the future | Tax compliance and financial regulations | Legal obligation |
Individuals in the EEA, UK, or Switzerland also have the right to lodge a complaint with their local data protection authority, withdraw consent at any time without affecting the lawfulness of prior processing, and object to automated decision-making and profiling.
For data protection inquiries in the EU, contact us at privacy@eukreate.com.
16. Do Not Track Signals
Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no universally accepted standard for how to respond to DNT signals, the Service does not currently respond to or alter its practices when it receives DNT signals from your browser. Regardless of DNT settings, we do not track you across third-party websites for advertising purposes.
17. Nevada Privacy Rights
Nevada residents may opt out of the sale of certain "covered information" as defined under Nevada SB 220. We do not sell covered information as defined by Nevada law. If you are a Nevada resident and wish to submit an opt-out request, you may contact us at privacy@eukreate.com.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated policy on our website with a new "Last Updated" date
- Sending an email notification for significant changes
- Displaying a notice within the Service
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy.
19. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Delaware, USA, without regard to conflict of law principles, except where superseded by applicable privacy and data protection laws (including the CCPA/CPRA, GDPR, and other applicable state or international privacy laws). In the event of a conflict between this Privacy Policy and our Terms of Service regarding liability, limitations, or dispute resolution, the Terms of Service shall control unless otherwise required by applicable law.
20. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
EuKreate, Inc.
- Privacy: privacy@eukreate.com
- General Inquiries: contact@eukreate.com
- Address: 2603 Camino Ramon Suite 200, San Ramon, CA 94583 USA
- Phone: +1-650-307-5532
Data Protection Inquiries: For GDPR, CCPA/CPRA, and state privacy law requests: privacy@eukreate.com
This Privacy Policy is effective as of June 15, 2026. Last reviewed: August 26, 2026 | Version 3.15

