Skip to content
Privacy

Privacy Policy

Information on the processing of your personal data in accordance with GDPR.
As of: April 2026

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Der KI Flüsterer

Halil Aksit

Pickertstr. 45

24143 Kiel

Germany

kontakt@derkifluesterer.de

Brands and Platforms:

  • ImmoVision.ai – Germany and Europe
  • gayrimenkul-ai.com – Turkey

2. General Information on Data Processing

We process personal data only to the extent necessary to provide our website, our content, our platform, our services, our communication and sales processes, as well as to process inquiries, leads, contracts, credits, billing, and ongoing customer relationships.

Personal data is any information relating to an identified or identifiable natural person.

Processing is carried out in particular on the basis of Art. 6 Para. 1 lit. a, b, c, and f GDPR.

This privacy policy applies in particular to:

Insofar as we process data for customers as part of order processing, the processing is additionally carried out in accordance with the contractual agreements concluded with the respective customer.

  • our website and landing pages,
  • exposés and microsites,
  • contact and inquiry forms,
  • appointment and communication functions,
  • the customer, team, and admin dashboard,
  • AI-supported functions within ImmoVision,
  • transcription, analysis, and workflow functions,
  • media and video processing,
  • credit, billing, and wallet functions,
  • paid services and online payments.

3. Hosting and Technical Provision

Our website and platform are hosted by Hetzner Online GmbH in Germany.

As part of the hosting, technically required data is processed, in particular:

Processing is carried out for the purpose of the secure, stable, and technically error-free provision of our online offer on the basis of Art. 6 Para. 1 lit. f GDPR.

Insofar as Hetzner processes personal data on our behalf, this is done on the basis of a data processing agreement in accordance with Art. 28 GDPR.

  • IP address,
  • Date and time of access,
  • Pages and content accessed,
  • Browser type and browser version,
  • Operating system used,
  • Referrer URL,
  • Server log files,
  • Technical status and error data.

4. Server Logs, Security Protocols, and Abuse Prevention

We process server and security logs to ensure the integrity and availability of our systems, to detect attacks, abuse, and technical malfunctions, to analyze errors, to track unauthorized access, and to ensure the secure operation of our website and platform.

In particular, the following data may be processed:

Processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR.

Server and security logs are only stored for as long as necessary for operation, security, error analysis, and evidence purposes.

  • IP address,
  • Time of access,
  • Technical request data,
  • Status and error messages,
  • Security events,
  • System and protocol data.

5. Cookies, Local Storage, and Comparable Technologies

On this website and in the publicly accessible areas of our system, we currently use exclusively technically necessary cookies and comparable technologies, insofar as this is actually implemented technically.

These may include in particular:

Insofar as the storage of information in your terminal equipment or access to information already stored is strictly necessary to provide a digital service explicitly requested by you, no consent is required for this under § 25 Para. 2 TDDDG.

Further processing of personal data in this context is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR.

We do not currently use any analysis, tracking, or marketing cookies on the general website. No advertising trackers, remarketing tags, or marketing pixels for profile-based advertising are currently used.

  • Session cookies for session management,
  • Security cookies or security tokens,
  • CSRF protection mechanisms,
  • Technically necessary login storage,
  • Language settings and i18n preferences,
  • Technically necessary status storage for forms or protected areas,
  • Technically required storage in local storage or session storage.

6. Note on Payments via Stripe

If you call up a payment process, a credit top-up, a checkout, or embedded payment elements from Stripe, Stripe may use its own cookies and comparable technologies in connection with its services, insofar as this is necessary for payment processing, authentication, fraud prevention, security, and the provision of Stripe services. Stripe describes this in its Cookie Policy and its Privacy Policy.

These processing operations concern the specific payment process called up. We do not currently use any marketing or analysis cookies beyond this on our general website.

7. Language Settings / Internationalization

If our website or platform supports multiple languages, we may store the language or regional representation you have chosen in order to restore the desired display on a subsequent visit.

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR or Art. 6 Para. 1 lit. f GDPR. Insofar as a technically necessary access to your end device or a technically necessary storage is required for this, this is done within the framework of § 25 Para. 2 TDDDG.

8. Self-hosted Fonts

Locally hosted fonts are used on this website.

When the website is called up, there is therefore no automatic retrieval of fonts from external third-party providers solely for loading the fonts. This avoids a connection to external font services being established solely for the display of fonts when the page is called up.

9. Own Media Content and Self-hosted Videos

Our pages may include our own images, graphics, MP4 files, and other media content that we host ourselves or deliver via our own infrastructure.

When such content is retrieved, technically necessary connection and delivery data are processed. Processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR.

10. General Contact

If you contact us via contact form, email, telephone, or other means, we process the data you provide to process your inquiry and to contact you.

In particular, the following may be processed:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR, insofar as your inquiry is directed towards the conclusion of a contract or pre-contractual measures. In other cases, processing is carried out on the basis of Art. 6 Para. 1 lit. f GDPR.

Your data will be deleted as soon as your inquiry has been finally processed and there are no legal retention obligations or legitimate interests in providing evidence to the contrary.

  • Name,
  • Email address,
  • Telephone number,
  • Company name,
  • Content of your message,
  • Object or service reference,
  • Technical metadata in connection with the transmission.

11. Website Contact Form

If you use our website contact form, we process the data you enter to process your inquiry, answer queries, and get in touch with you.

Mandatory information in forms is marked as such. Without this information, your inquiry may not be processed.

12. Expose, Microsite, and Object Inquiries

On exposés, object pages, microsites, or comparable landing pages, you can make inquiries about specific real estate, objects, services, or offers.

In particular, the following may be processed:

Processing is carried out to process the inquiry, for contract initiation, for forwarding to responsible contact persons, and for internal organization and follow-up on the basis of Art. 6 Para. 1 lit. b GDPR.

  • Name,
  • Contact details,
  • Object or offer reference,
  • Message,
  • Appointment request,
  • Desired contact method,
  • Internal assignment and processing information.

13. Appointment Booking / Calendar Functions

If you request or book appointments via our website, exposés, microsites, or the system, we process your data for appointment scheduling, appointment confirmation, appointment postponement, and appointment organization.

In particular, the following data may be processed:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR.

  • Name,
  • Email address,
  • Telephone number,
  • Desired appointment,
  • Object or process reference,
  • Notes or details of the concern,
  • Status data for appointment management.

14. User Accounts, Login, and Dashboard

If an account is created for customers, teams, administrators, or other authorized users, we process personal data for setting up, managing, and using the account.

These may include in particular:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR and additionally Art. 6 Para. 1 lit. f GDPR to ensure IT security and system integrity.

  • Name,
  • Email address,
  • Username,
  • Role and rights settings,
  • Password hash,
  • Login and session data,
  • Usage and administration logs,
  • Organization-related assignments.

15. CRM, Lead Management, and Internal Case Processing

As part of the use of our platform, we process personal data for the management, structuring, and processing of leads, customer inquiries, processes, tasks, and communication histories.

These may include in particular:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR, insofar as this is necessary for contract initiation or contract execution, and additionally on the basis of Art. 6 Para. 1 lit. f GDPR for internal organizational and administrative purposes.

  • Master data and contact details,
  • Object reference and interest data,
  • Communication histories,
  • Internal processing notes,
  • Responsibilities, status, and tasks,
  • Notes, appointment reference, and process data.

16. Internal Lead Statistics and System-Internal Evaluations

Insofar as we create internal reach, inquiry, lead, usage, or process statistics, this is generally done for internal control, quality assurance, capacity planning, abuse prevention, billing traceability, and optimization of our processes.

Insofar as this is done purely on the server side, internally, and without tracking technologies of the public website that require consent, we base the processing on Art. 6 Para. 1 lit. f GDPR. Our legitimate interest lies in the economic, technical, and organizational control of our offer.

According to our system concept, there is currently no public website web analysis for marketing, remarketing, or profile-based advertising purposes.

17. AI Functions via Google Cloud Vertex AI / Gemini

For certain AI functions within ImmoVision, we use Google Cloud Vertex AI and Gemini models according to our system configuration. Google provides a Cloud Data Processing Addendum for this and also publishes the relevant subprocessor information for Google Cloud.

In doing so, inputs, content, and processing-related data may be transmitted to the Google Cloud / Vertex AI infrastructure to the extent technically necessary for the respective AI function. This can in particular concern:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR, insofar as the AI processing is necessary to provide requested functions or pre-contractual services, and additionally on the basis of Art. 6 Para. 1 lit. f GDPR, insofar as the processing serves the technical provision, usability, stability, and efficient provision of our services.

Insofar as we configure Vertex AI regionally, this can be done in particular via the europe-west3 region (Frankfurt, Germany). Google documents the available Vertex AI locations and regional endpoints separately.

Google also documents for Vertex AI that customer data is not used to train or fine-tune AI/ML models without the customer's prior permission or instruction. Google also points out that published Gemini models can use project-related in-memory caching with a 24-hour TTL by default, which can be deactivated at the project level.

  • Text inputs,
  • Structured content,
  • Usage data in connection with the respective function,
  • Uploaded content, insofar as the respective function requires this,
  • Outputs of the AI function.

18. Video Creation via Self-hosted AI

For video creation, we use a self-hosted AI infrastructure.

Processing takes place within our own or controlled hosting and server environment and serves the creation, processing, and output of video content based on the provided media and information.

In particular, the following may be processed:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR, insofar as processing is necessary to provide the requested service, and additionally on the basis of Art. 6 Para. 1 lit. f GDPR.

According to our system concept, a transmission to external AI providers for training purposes does not take place within the framework of this self-hosted video creation.

  • Uploaded images and media,
  • Object-related content and texts,
  • Format and render settings,
  • Technical processing data.

19. Image Processing, Virtual Staging, and Media Processing

Within ImmoVision, images, media, and object-specific content can be processed to generate, for example, image optimizations, visual preparation, virtual staging, variations, renovation previews, or presentation-related outputs.

In particular, the following may be processed:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR and additionally Art. 6 Para. 1 lit. f GDPR.

  • Uploaded image files,
  • Media metadata,
  • Descriptions and specifications,
  • Object reference,
  • Generated or edited media results,
  • Technical job and status data.

20. Transcription, Call Recording, and Workflow Processing

Insofar as corresponding functions are used, ImmoVision can process communication and voice data, in particular for:

In particular, the following may be processed:

Processing is carried out on the basis of Art. 6 Para. 1 lit. b GDPR, insofar as the use of these functions is part of the contract or was requested pre-contractually, and additionally on the basis of Art. 6 Para. 1 lit. f GDPR.

Insofar as call recordings or transcriptions are triggered by our customers, they are responsible for ensuring that the legal requirements necessary for this, in particular information or consent obligations, are complied with.

  • Transcription,
  • Summarization,
  • Workflow evaluation,
  • CRM-related structuring,
  • Task and lead derivation,
  • Conversation documentation.
  • Audio recordings,
  • Voice content,
  • Time and metadata,
  • Generated transcripts,
  • Summaries,
  • Structured evaluations,
  • Workflow and status data.

21. Payment Processing, Credits, Billing, and Online Payments

If you use paid services, credits, onboarding services, or other paid offers, we process your data for contract execution, payment processing, accounting, wallet/credit management, billing event recording, and traceability of use.

In particular, the following data may be processed:

The legal basis is Art. 6 Para. 1 lit. b GDPR and Art. 6 Para. 1 lit. c GDPR, insofar as legal retention and evidence obligations exist.

  • Name,
  • Billing address,
  • Email address,
  • Contract and service information,
  • Credit balance,
  • Top-ups,
  • Payment status,
  • Billing events,
  • Wallet movements,
  • Transaction and invoice data,
  • Tax-relevant information.

21.1 Use of Stripe

For payment processing, we may use Stripe. As part of payment processing, Stripe may in particular process payment, transaction, identification, fraud prevention, and technical device data. Stripe also points out that cookies and similar technologies may be used in connection with its services and that personal data may be processed for the execution of transactions, fraud prevention, authentication, and performance analysis of Stripe services.

Stripe may process personal data partly as a processor and partly as its own controller, in particular for fraud prevention, to avoid financial losses, for security purposes, and to provide Stripe services.

22. Recipients / Categories of Recipients

Personal data is only passed on to recipients to the extent necessary to fulfill our services, for technical provision, for payment processing, or due to legal obligations.

Recipients or categories of recipients can in particular be:

  • Hosting service providers, in particular Hetzner Online GmbH,
  • Google Cloud / Vertex AI / Gemini within the framework of the actually activated AI functions, insofar as used,
  • Stripe and affiliated Stripe companies, insofar as payment services are used,
  • Internal departments involved in processing inquiries, leads, contracts, billing, credits, or the provision of services,
  • External technical service providers for maintenance, security, or support, insofar as this is necessary,
  • Accounting, tax advice, or other bodies, insofar as this is legally or contractually required.

23. Third-Country Transfers

A transfer of personal data to states outside the European Union or the European Economic Area only takes place insofar as this is necessary for the respective processing and there is a legally permissible basis under data protection law.

In particular, in the case of international cloud, AI, or payment service providers, processing outside the EEA cannot be excluded in every case. Insofar as such transfers take place, they are carried out on the basis of suitable guarantees or other legally permissible transfer mechanisms.

This may in particular concern Stripe, insofar as personal data are processed within the framework of global payment and security infrastructures. Insofar as Google Cloud is used, the contractual data protection regulations of Google Cloud provided for this apply, including the Cloud Data Processing Addendum.

24. Storage Duration

We store personal data only as long as necessary for the respective processing purposes or as long as legal retention obligations exist.

In detail, the following regularly applies:

Audio, transcription, workflow, media, and AI data are generally processed and deleted or anonymized according to the respectively defined product, contract, and deletion concepts, unless retention obligations or legitimate reasons prevent this.

  • Server log files only as long as necessary for operation, security, and error analysis,
  • Contact inquiries until the inquiry has been finally processed and beyond that only to the extent that legal retention obligations exist or further communication is necessary,
  • Lead and object inquiries as long as this is necessary for processing, follow-up, contract initiation, or legally secure documentation,
  • Service-related data as long as this is necessary for contract execution, documentation, and legal evidence,
  • Invoice, wallet, billing, and accounting data in accordance with legal commercial and tax retention periods,
  • User accounts until the termination of the user relationship and expiry of any evidence or retention periods.

25. Legal Bases for Processing

Unless otherwise stated in this privacy policy, we process personal data on the basis of the following legal bases:

For technically necessary access to end devices or storage, § 25 Para. 2 TDDDG additionally applies.

  • Art. 6 Para. 1 lit. a GDPR – Consent,
  • Art. 6 Para. 1 lit. b GDPR – Contract / pre-contractual measures,
  • Art. 6 Para. 1 lit. c GDPR – Legal obligation,
  • Art. 6 Para. 1 lit. f GDPR – Legitimate interests.

26. Automated Decisions / Profiling

According to our system concept, exclusively automated decision-making within the meaning of Art. 22 GDPR, which has legal effect or significantly affects you in a similar way, does not currently take place.

Insofar as AI-supported functions are used for internal support, prioritization, summarization, classification, or processing, these generally serve to support internal processes and do not replace such exclusively automated decisions within the meaning of Art. 22 GDPR.

27. Your Rights

Under the GDPR, you have the following rights in particular:

  • Right to information,
  • Right to rectification,
  • Right to erasure,
  • Right to restriction of processing,
  • Right to data portability,
  • Right to object to processing based on Art. 6 Para. 1 lit. f GDPR,
  • Right to withdraw consent given at any time with effect for the future,
  • Right to lodge a complaint with a data protection supervisory authority.

28. Right to Lodge a Complaint with the Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority.

For controllers based in Schleswig-Holstein, the Independent State Center for Data Protection Schleswig-Holstein is regularly responsible.

Independent State Center for Data Protection Schleswig-Holstein

Postfach 71 16

24171 Kiel

mail@datenschutzzentrum.de

0431 988-1200

29. Obligation to Provide Data

The provision of personal data is not prescribed by law or contract in general. For certain functions, the provision of the required data is necessary so that we can process your inquiry, organize an appointment, execute a contract, provide a user account, manage credits, or provide a desired function.

Without the respectively required information, certain services may not be provided or contracts may not be concluded.

30. Data Security

We take appropriate technical and organizational measures to protect personal data against loss, unauthorized access, manipulation, disclosure, or other impermissible processing.

These may include in particular:

  • Role-based access concepts,
  • Encryption during transmission,
  • Password hashing and authentication protection,
  • Backup and recovery concepts,
  • Logging of security-relevant processes,
  • Tenant separation and rights management,
  • Restriction of administrative access.

31. Changes to this Privacy Policy

We reserve the right to adapt this privacy policy if legal requirements, technical processes, or our services change. The current version published on this website applies in each case.