Version 1.0 — last updated 2026. Plain-language summary first, detail below.
DeedStone («we», «us») operates DeedStone Markets. For the account and usage data described here, we are the data controller. Entity details, address and contact are in the Imprint.
The property price data we publish comes from public, official registers (see Data sources). Those registers are published at source and contain no personal identifiers — no owner, buyer or seller names. Where a register's source data could be identifying, the publisher has already removed it before publication: Estonia, for example, releases transaction statistics only as county-level aggregates covering at least five transactions. We neither receive nor store personal data from any of them.
We do not use analytics or advertising services, and we do not build behavioural profiles.
We set one strictly-necessary cookie — ds_session — which keeps you logged in.
It is HTTP-only, not accessible to scripts, and is not used for tracking or advertising. Because it
is strictly necessary to provide a service you asked for, it is not gated behind consent, and there
is no consent banner because we set no optional or third-party cookies at all.
If we ever add optional cookies or analytics, they will be off until you opt in.
We share personal data only with the providers that make the service work, and only as needed: our cloud hosting provider («HOSTING PROVIDER / REGION — to be confirmed»), the payment provider at checkout (once live), and the newsletter delivery provider used to send Signal («NEWSLETTER PROVIDER — to be confirmed»). We may disclose data where the law requires it. We never sell personal data, and we do not share it for advertising.
We keep account data while your account is open. When you delete your account it is erased immediately — the account, your export history, your plan requests and your newsletter subscription — and we show you exactly what was removed. The only records that outlive deletion are invoices already issued by our payment provider, which that provider retains for as long as tax and accounting law requires. Newsletter addresses are kept until you unsubscribe or delete your account. Server and security logs are kept for a short, bounded period («LOG RETENTION — to be confirmed»).
Safeguards: passwords are salted and hashed; the session cookie is signed and HTTP-only; access to the production server is restricted to key-based SSH. Traffic encryption (HTTPS/TLS) is a launch prerequisite — this policy will only claim encryption in transit once the site is served over HTTPS. We deliberately do not claim certifications (such as SOC 2 or ISO 27001) because we do not hold any.
If you are in the EEA, the UK or a similar jurisdiction, you have the right to: access the personal data we hold about you; correct it; delete it (erasure); port it (receive a copy in a machine-readable format); restrict or object to certain processing; and withdraw consent (for the newsletter) at any time. You also have the right to complain to your national data-protection authority.
How to exercise them: the two main ones you can do yourself, right now, from your account page — Download my data (JSON) gives you everything we hold in one machine-readable file, and Delete my account erases your account, export history, plan requests and newsletter subscription immediately, with nothing to wait for. For anything else (restriction, objection, or a correction you cannot make from the account page), email r7adco@gmail.com with the subject “Data request”. We answer within one month.
If this policy changes materially we will note the new version and date at the top of this page and, where the change is significant, tell account holders by email.
This document is a first-draft template prepared for legal review; it is not legal advice and has not been reviewed by counsel.