Privacy Policy
How CODO REAL collects, uses, and protects your personal data in accordance with GDPR and Latvian law.
Last updated: 2026-08-06
Data Controller
CODO REAL (SIA CODO REAL) is the data controller responsible for the collection, processing, and protection of your personal data. We are a real estate company registered in the Republic of Latvia under commercial registration number 40103793359.
We take our responsibility for protecting your personal data seriously and are committed to full compliance with the General Data Protection Regulation (EU 2016/679) ("GDPR"), the Latvian Personal Data Protection Law, and the ePrivacy Directive.
Personal Data We Collect
We collect and process the following categories of personal data when you interact with our website, use our services, or communicate with us:
- Name and surname
- Email address
- Phone number
- Company name (for business clients)
- Property enquiry details and preferences
- Uploaded documents (identification documents, property documents, contracts)
- CRM data (client preferences, interaction history, agent notes)
- Property favourites and saved searches
- Search preferences and filters
- AI conversation history and chatbot interactions
- WhatsApp communication records
- IP address and browser information
- Cookie data and browsing behavior
- Analytics data (pages visited, time spent, actions taken)
- Location data (approximate, derived from IP address)
- Device information (device type, operating system, screen resolution)
We do not collect special categories of personal data (such as health data, racial or ethnic origin, political opinions, or religious beliefs) unless you voluntarily provide such information during the course of our services.
Purpose of Processing
We process your personal data for the following purposes:
- Customer support and communication — responding to your enquiries and providing assistance
- Property enquiries — managing your interest in specific properties and facilitating viewings
- CRM (Customer Relationship Management) — maintaining client records and managing relationships
- Client management — tracking interactions, preferences, and requirements
- Contract preparation and execution — drafting, negotiating, and executing real estate contracts
- Marketing communications — sending newsletters, property recommendations, and promotional offers
- Newsletter distribution — delivering subscribed content and updates
- Google Ads campaign management — measuring and optimizing advertising performance
- Analytics and performance tracking — understanding website usage and improving user experience
- AI-powered recommendations — providing personalized property suggestions using artificial intelligence
- Fraud prevention and security — detecting and preventing fraudulent activities
- Legal compliance — meeting obligations under Latvian law, AML regulations, and tax requirements
- Service improvement — analyzing usage patterns to enhance our services
- Communication via WhatsApp, email, and phone — maintaining contact with clients
Legal Basis for Processing
We process your personal data based on the following legal grounds under Article 6 of the GDPR:
| Legal Basis | Description | Example |
|---|---|---|
| Consent (Art. 6(1)(a)) | You have given clear consent for specific processing activities | Marketing emails, cookie usage, AI chatbot interactions |
| Contract (Art. 6(1)(b)) | Processing is necessary for the performance of a contract or pre-contractual steps | Property transactions, contract preparation, service delivery |
| Legal Obligation (Art. 6(1)(c)) | Processing is required to comply with legal obligations | AML/KYC checks, tax reporting, contract retention |
| Legitimate Interest (Art. 6(1)(f)) | Processing is necessary for our legitimate interests, balanced against your rights | Fraud prevention, security monitoring, client communication, service improvement |
We will only process your personal data if we have a valid legal basis for doing so. You have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Third-Party Services
We use the following third-party services that may process your personal data. Each service processes data according to its own privacy policy and applicable data protection laws:
| Service | Purpose | Data Processed |
|---|---|---|
| Google Analytics | Website analytics and performance tracking | IP address, browser data, pages visited, session data |
| Google Ads | Advertising campaign management and measurement | Click data, conversion data, remarketing data |
| Google Tag Manager | Tag management and deployment | Tag configuration data, trigger events |
| Google Maps | Property location display | Location data, map interaction data |
| Meta Pixel | Advertising analytics and measurement | Page views, conversion events, device data |
| OpenAI | AI-powered recommendations and chatbot | Conversation data, property preferences, enquiry text |
| WhatsApp Business | Client communication via WhatsApp | Phone number, message content, contact name |
| Supabase | Database hosting and backend services | All stored personal data in the CRM system |
| Base44 | Application platform and hosting | Application data, user session data |
| Cloud hosting providers | Server infrastructure and data storage | Server logs, IP addresses, technical data |
| Email service providers | Transactional and marketing emails | Email address, email content, open/click data |
We have entered into Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf, in accordance with Article 28 of the GDPR.
International Data Transfers
Your personal data may be transferred to, stored in, or processed in countries outside the European Economic Area (EEA), including:
- United States — Google, OpenAI, Meta, and other service providers
- Other countries where our service providers maintain data processing operations
We ensure appropriate safeguards for international data transfers through:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all service providers
- Regular review of transfer mechanisms and applicable safeguards
- Transfer Impact Assessments where required
- Compliance with the EU-US Data Privacy Framework where applicable
You may request a copy of the safeguards we have in place for international transfers by contacting us at info@codoreal.com.
AI Processing
We use artificial intelligence (AI) and machine learning technologies to provide enhanced services to our clients:
- AI-powered property recommendations — matching clients with suitable properties
- AI chatbot (Nora AI) — automated client communication and support
- AI-assisted market analysis — property valuation and market trend analysis
- AI-generated content suggestions — property descriptions and marketing copy
- AI lead scoring — prioritizing leads based on engagement and behavior
We process personal data for AI purposes with the following safeguards:
- Human oversight — all AI decisions are reviewed by qualified personnel
- No fully automated decision-making — AI assists but does not make final decisions with legal effects
- Transparency — we are open about our use of AI technologies
- Regular review — AI outputs are regularly audited for accuracy and bias
- Data minimization — we only process the personal data necessary for AI functionality
- Purpose limitation — AI is used only for the purposes described in this policy
For more information about our AI usage and its limitations, please see our AI Usage Policy.
Your GDPR Rights
Under the GDPR, you have the following rights regarding your personal data:
| Right | Description |
|---|---|
| Right of Access | Request a copy of your personal data held by us |
| Right to Rectification | Correct inaccurate or incomplete personal data |
| Right to Erasure | Request deletion of your personal data ("right to be forgotten") |
| Right to Restrict Processing | Limit how we process your personal data |
| Right to Data Portability | Receive your personal data in a structured, machine-readable format |
| Right to Object | Object to processing based on legitimate interests or for direct marketing |
| Right to Withdraw Consent | Withdraw consent for processing at any time without giving a reason |
| Right to Lodge a Complaint | File a complaint with the Latvian Data Protection Authority |
To exercise any of these rights, please contact us at info@codoreal.com. We will respond to your request within one month, as required by the GDPR. In certain circumstances, we may extend this period by two further months, in which case we will inform you of the extension and the reasons for it.
You may also lodge a complaint with the Latvian Data Protection Authority (Datu valsts inspekcija):
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of complying with legal obligations. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Active client data | Duration of client relationship + 10 years | Legitimate interest / Legal obligation |
| Property enquiry data | 3 years after last contact | Legitimate interest |
| Marketing consent data | Until consent is withdrawn | Consent |
| Contract data | 10 years after contract end | Latvian Civil Law / Tax Law |
| AML/KYC data | 5 years after relationship ends | AML Law (Latvia) |
| Website analytics data | 26 months (Google Analytics default) | Legitimate interest |
| Cookie data | As specified in Cookie Policy | Consent |
| Log data | 90 days | Security / Legitimate interest |
| AI conversation data | 12 months | Legitimate interest |
When the retention period expires, we will either delete your personal data or anonymize it so that it can no longer be associated with you.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration. Our security measures include:
- Encryption — TLS 1.2/1.3 for data in transit, AES-256 encryption for data at rest
- Role-based access control — access to personal data is limited to authorized personnel based on their role and responsibilities
- Authentication — multi-factor authentication (MFA) for all administrative and backend access
- Logging — comprehensive logging of data access, modifications, and system events
- Monitoring — continuous monitoring for security threats and anomalous activity
- Backups — regular encrypted backups with tested restoration procedures
- Audit logs — detailed audit trails for all data operations, retained for security and compliance purposes
- Network security — firewalls, intrusion detection systems, and DDoS protection
- Regular security reviews — periodic assessments and penetration testing
- Employee training — mandatory data protection and security training for all staff
- Incident response — documented procedures for handling data security incidents
- Vendor management — security assessments of all third-party service providers
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a prominent notice on our website
- Send an email notification to registered users where applicable
We encourage you to review this policy periodically to stay informed about how we collect, use, and protect your personal data.
Contact
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
You may also contact the Latvian Data Protection Authority (Datu valsts inspekcija) if you believe that our processing of your personal data violates applicable data protection laws.
