1. Data Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) and other national data protection laws of the member states, as well as other data protection provisions, is:
DOMIVENDOMO GmbHHeinrich-Heine-Straße 9
10179 Berlin-Mitte
Germany
Court of registration: Amtsgericht Berlin-Charlottenburg
Registration number: HRB 248917 B
VAT ID: DE 367 412 089
Phone: +49 30 549 04 219
Email: privacy@domivendomo.com
2. Data Protection Officer
You can reach our external Data Protection Officer at:
Brehme & Partner Datenschutz GbR
Kastanienallee 23, 10435 Berlin-Prenzlauer Berg
Email: dpo@domivendomo.com
PGP fingerprint: 4E2A 91B3 7D5C 8E11 0F4A 6B23 9C8D 7E51 2A4F 6B82
Please direct all requests regarding the processing of personal data, the exercise of your rights, and data protection incidents directly to our DPO. The response period is 30 days in accordance with Art. 12(3) GDPR.
3. Collection of General Data and Information
The DOMIVENDOMO GmbH website collects a range of general data and information with every access by a data subject or an automated system. This data is stored in the server's log files.
The following may be collected:
- browser types and versions used,
- the operating system used by the accessing system,
- the website from which an accessing system reaches our website (referrer),
- the sub-pages accessed on our website via an accessing system,
- the date and time of access to the website,
- an internet protocol (IP) address, truncated by the last three digits prior to storage,
- the internet service provider of the accessing system.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in operational security, error analysis, and abuse prevention). Log files are automatically deleted after 14 days unless a security incident has occurred.
5. Registration & Account
To create a user account on app.domivendomo.com, we collect the following data:
- Email address (required)
- First and last name (required)
- Phone number (optional)
- Profile picture (optional)
- Language preference & time zone
Hosts and buyers must complete identity verification through our processor Veriff OÜ (Tallinn, Estonia). This transmits an identity document, a selfie, and a liveness check. Veriff retains this data under its own data processing agreement for 7 years pursuant to § 8(1) GwG (German Anti-Money Laundering Act).
Legal basis: Art. 6(1)(b) GDPR (performance of a contract) and Art. 6(1)(c) GDPR in conjunction with § 10 GwG (statutory obligation to prevent money laundering in real-estate transactions).
6. Listings & Bookings
When creating a listing, we process all data entered by the host — description, photos, address, price, availability, documents. This data is displayed publicly on the platform while the listing is active.
A booking or inquiry opens a direct communication channel between the buyer/tenant/guest and the host. We process the messages, attachments, and booking and payment data exchanged.
Payments are processed exclusively via Stripe Payments Europe Ltd. (Dublin, Ireland). We do not store credit card data ourselves — only a transaction reference, the amount, and the payment status. Host payouts are made via Stripe Connect Express within 24 hours.
Legal basis: Art. 6(1)(b) GDPR. Invoices and transaction records are retained for 10 years pursuant to § 147 AO and § 257 HGB (German tax and commercial codes).
7. AI Property Twin
The AI Property Twin is a retrieval-augmented answer engine that answers questions based on original documents uploaded by the host. The following applies:
- Documents are indexed in a private, per-listing vector database; there is no cross-tenant access.
- Every answer includes a source citation with page number and quote.
- We use AWS Bedrock in the eu-central-1 region (Frankfurt) with guardrails enabled.
- No model training on user data. Data does not leave the EU. Requests are not used to improve external models (contractual clause with AWS).
- Sensitive data fields (social security numbers, bank statements, tax IDs) are automatically redacted before indexing.
The vector index is retained for the lifetime of the listing. Once a listing is deleted, the index is irreversibly removed within 30 days. Legal basis: Art. 6(1)(b) GDPR.
8. Live Witness
Live Witness is a voluntary, consent-based feature that connects current guests or recently verified reviewers with prospective guests. Participation is strictly opt-in.
- Messages are end-to-end encrypted (Signal protocol).
- Plaintext messages are automatically deleted after 30 days; encrypted backups within 90 days.
- Witnesses can leave the pool at any time — immediately and without giving a reason.
- Harassment, advertising, and spam are detected and blocked by an AI-powered moderation layer before delivery.
- Witnesses receive a small credit per answered inquiry (tax-relevant above €256/year pursuant to § 22 No. 3 EStG).
Legal basis: Art. 6(1)(a) GDPR (consent), revocable at any time.
9. Hosting & Service Providers
We use the following processors. Data processing agreements under Art. 28 GDPR are in place with all providers. For transfers to third countries, EU Standard Contractual Clauses (2021/914) and additional technical and organizational measures apply.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, databases, AI Property Twin (Bedrock) | Frankfurt (eu-central-1) |
| GitHub B.V. | Source code management, CI/CD | Amsterdam, Netherlands |
| Stripe Payments Europe Ltd. | Payment processing, host payouts | Dublin, Ireland |
| Veriff OÜ | Identity verification, KYC | Tallinn, Estonia |
| Mapbox EU SAS | Map rendering, What's Around | Paris, France |
| Cloudflare Germany GmbH | CDN, DDoS protection | Munich, Germany |
| Hetzner Online GmbH | Backup mirror | Falkenstein, Germany |
10. Sign in with Google
DOMIVENDOMO offers "Continue with Google" as an optional way to create and access your account, via Google's OAuth 2.0 / OpenID Connect sign-in. When you choose this option, we receive the following data from your Google account:
- Your email address
- Your name
- Your profile picture
This corresponds to the OAuth scopes openid, email, and profile. We do not request or access your Gmail, Google Drive, Google Calendar, Google Contacts, or any other Google Workspace data, and we never use this data to train AI models.
This data is used solely to create your DOMIVENDOMO account, authenticate you on sign-in, and pre-fill your profile name and picture. It is processed and stored by our authentication provider, Amazon Cognito (AWS EMEA SARL, eu-central-1, Frankfurt), and is not shared with any third party beyond what is required for authentication.
You can revoke DOMIVENDOMO's access to your Google account at any time via your Google Account permissions page. Revoking access does not delete your DOMIVENDOMO account; to delete your account, see Section 13 below or contact dpo@domivendomo.com.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).
11. Your Rights
You have the following rights regarding your personal data:
- Right of access (Art. 15 GDPR) — what data we hold about you.
- Right to rectification (Art. 16 GDPR) — correction of inaccurate data.
- Right to erasure (Art. 17 GDPR, "right to be forgotten") — unless statutory retention obligations apply.
- Right to restriction of processing (Art. 18 GDPR).
- Right to data portability (Art. 20 GDPR) — export of all listings, bookings, and messages in a machine-readable format (JSON, CSV).
- Right to object (Art. 21 GDPR) to processing based on legitimate interests.
- Right to withdraw consent (Art. 7(3) GDPR) — e.g. for Live Witness or newsletters — at any time and without detriment.
Please direct requests to dpo@domivendomo.com. We respond within 30 days pursuant to Art. 12(3) GDPR.
12. Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint at any time with a data protection supervisory authority regarding our processing of your personal data (Art. 77 GDPR). The competent authority for us is:
Berliner Beauftragte für Datenschutz und InformationsfreiheitFriedrichstr. 219
10969 Berlin
Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Web: www.datenschutz-berlin.de
13. Data Retention Period
Personal data is stored only as long as necessary for the respective purpose or as required by statutory retention obligations. Specifically:
| Data type | Retention period | Basis |
|---|---|---|
| Active user account | Until deletion by user + 30 days | Art. 6(1)(b) GDPR |
| Inactive user account | Last activity + 3 years | Art. 6(1)(f) GDPR |
| Listings (deleted) | 30-day soft delete, then irreversible | Art. 17 GDPR |
| Booking and invoice data | 10 years | § 257 HGB, § 147 AO |
| KYC data (Veriff) | 7 years after end of business relationship | § 8 GwG |
| Server log files | 14 days | Art. 6(1)(f) GDPR |
| Live Witness messages | 30 days plaintext, 90 days encrypted | Art. 6(1)(a) GDPR |
| AI Property Twin vector index | Listing lifetime + 30 days | Art. 6(1)(b) GDPR |
Last updated: 28 May 2026. In the event of material changes, we notify all registered users by email at least 30 days before they take effect.