Privacy policy

Last updated:

1. Who We Are

REtelligent operates a property workflow optimisation platform that includes machine learning and artificial intelligence features (the “Service”). Depending on where you are located and how you use the Service, the REtelligent entity responsible for your personal information is:

  • REtelligent Pty Ltd (ACN 694 108 613; ABN 87 694 108 613) — for Authorised Users, customers, and data subjects outside the European Union. Registered and trading address: Unit 2, 8A Judith Street, Carnegie VIC 3163, Australia.

  • REtelligent EU S.R.L. (CUI 54685957) — for Authorised Users, customers, and data subjects in the European Union. Registered Romanian address — Bucureşti Sectorul 1, Bulevardul G-ral Gheorghe Magheru, Nr. 31, Biroul 2, Etaj 5.

References to “REtelligent”, “we”, “us”, or “our” mean the applicable entity.

Contact: privacy@retelligent.co for privacy queries; legal@retelligent.co for legal matters.


2. Scope of This Policy

This Privacy Policy describes how REtelligent collects, uses, discloses, and protects personal information / personal data (collectively “Personal Information”) in connection with:

(a)         the operation of the REtelligent platform on behalf of our customers (typically property managers, real-estate agencies, asset managers, and similar business users);

(b)        the operation of our websites and marketing communications;

(c)         interactions with prospective customers, partners, vendors, and employees.

Important distinction. When REtelligent processes Personal Information on behalf of a customer (e.g., tenant data, contractor data, property occupant data input by the customer), the customer is the Controller (EU) or APP entity (AU), and REtelligent is the Processor / service provider. The customer’s own privacy notices apply to the customer’s collection and use; this Policy describes our processing as Processor. Where REtelligent processes Personal Information for its own purposes (e.g., your interaction with our website, prospective-customer communications, employees), REtelligent is the Controller / APP entity, and this Policy is the primary notice.


3. What Personal Information We Collect

3.1 Information Customers Provide About Other Individuals (Tenants, Residents, Contractors)

Information Customers Provide About Other Individuals (Tenants, Residents, Contractors)

When our customers use the Service, they input information about individuals — typically tenants, residents, prospective tenants, trade contractors, and others involved in property management workflows. We process this information on behalf of our customers, per their instructions and the applicable Data Processing Agreement. Categories may include:

  • Identification: name, contact details, identifiers

  • Property and tenancy information

  • Financial data (where input by the customer)

  • Communication content within or routed through the Service

  • Photographic and image data (including geo-stamped images)

  • Behavioural and interaction data with the Service

  • Technical identifiers (IP, device ID) collected automatically

We do not control what our customers input. Customers are responsible for the lawfulness of the input under applicable privacy law.

3.2 Information We Collect From Authorised Users

For Authorised Users (employees / contractors of our customers using the Service):

  • Account information (name, email, role)

  • Authentication data (passwords stored as hashes; MFA tokens)

  • Usage data (features used, actions taken)

  • Technical data (IP, device, browser)

3.3 Information We Collect From Website Visitors

  • Pages visited, referring URLs, technical data

  • Information submitted in contact / demo / waitlist forms

  • Cookie data (per Section 7)

3.4 Information We Collect From Prospective Customers and Partners

  • Contact details, business affiliation, role

  • Communications history

  • Information relevant to sales engagement

3.5 Special Categories

We do not knowingly collect Special Categories of personal data (GDPR Art. 9) or Sensitive Information (AU Privacy Act Section 6(1)) about individuals, and our customer Agreement prohibits customers from inputting such categories into the Service except where expressly authorised and supported by appropriate safeguards.


4. How We Use Personal Information

4.1 To Provide the Service

  • Operate the platform and AI Features as documented

  • Authenticate users and authorise access

  • Generate workflow recommendations and execute Autonomous Actions per the customer’s Delegation of Authority configuration

  • Communicate operational and security notices

4.2 To Improve the Service

  • Generate Aggregated Statistics (fully de-identified) for model training, benchmarking, and analytics, per the applicable clause. Aggregated Statistics, once fully de-identified, are no longer personal information.

  • Where the customer has opted in to the Training Contribution Program (Heavy customers only, per the AI Addendum, Section 5.3), pseudonymised data is used for model training.

  • Investigate and resolve technical issues.

4.3 To Operate Our Business

Send marketing communications (subject to lawful basis and opt-out)

  • Respond to inquiries and provide customer support

  • Manage commercial relationships

  • Comply with legal obligations

4.4 To Protect Security

  • Detect and prevent fraud, abuse, and security incidents

  • Maintain logs and audit trails (per the AI Addendum, Section 3.5)

  • Comply with security and legal investigations

5. Legal Basis for Processing (EU / GDPR)

We process Personal Information on the following legal bases:

  • Contract (GDPR Art. 6(1)(b)) — to perform the contract with the customer (Authorised Users) or with you (Controller-relationships).

  • Legitimate interests (GDPR Art. 6(1)(f)) — for service improvement (Aggregated Statistics), security, fraud prevention, and prospective-customer communications, balanced against your rights.

  • Consent (GDPR Art. 6(1)(a)) — for non-essential cookies, marketing communications where consent is required, and Training Contribution Program participation (customer-side consent).

  • Legal obligation (GDPR Art. 6(1)(c)) — to comply with regulatory requirements.

Where REtelligent is Processor on behalf of a customer (the most common case), the legal basis for the underlying processing is determined by the customer as Controller; REtelligent processes on the customer’s documented instructions.

The Digital Omnibus proposal (November 2025) may recognise AI development and operation as a “legitimate interest” under the GDPR, which would simplify the basis for some training-related processing. We will update this Policy when the proposal is finalized.


6. Disclosure of Personal Information

We disclose Personal Information to:

6.1 Our Sub-processors

Cloud hosting providers, AI infrastructure providers, communications providers, payment processors, and analytics providers that support the Service. Our current sub-processor list is published at https://www.retelligent.co/legal-pages/sub-processors and is also available at the Service’s privacy center. We impose obligations on sub-processors no less protective than the GDPR / Privacy Act and remain responsible for their handling.

6.2 Customers

We disclose Personal Information collected on behalf of customers to those customers, per the DPA. We do not disclose customer A’s data to customer B except via fully de-identified Aggregated Statistics.

6.3 Legal Disclosures

We may disclose Personal Information in response to a valid subpoena, court order, search warrant, or other lawful legal process. Where lawfully permitted, we notify the affected customer / data subject before disclosure.

6.4 Business Transfers

In the event of a merger, acquisition, financing, reorganisation, or sale of substantially all assets, Personal Information may be transferred to the acquirer, subject to continuation of obligations no less protective than this Policy.

6.5 With Consent

For purposes not described in this Policy, with consent.


7. International Transfers

7.1 Cross-Border Processing

All persistent Personal Information is stored and processed in the European Union (AWS eu-central-1, Frankfurt, Germany); there is no Australian data domicile. For AU-based data subjects, this means Personal Information is disclosed from Australia to Germany, and to other overseas sub-processors, with REtelligent Pty Ltd remaining accountable under APP 8.2 and section 16C of the Privacy Act 1988 (Cth). For EU-based data subjects, storage remains within the EEA; certain sub-processors located in the United States receive Personal Data in transit (for example messaging, email and AI inference) under the safeguards in Section 7.2. The current sub-processors and their locations are listed in the sub-processor list.

7.2 Transfer Safeguards

For transfers outside the EEA to non-adequacy jurisdictions, we apply the European Commission’s Standard Contractual Clauses (Module 2 for transfers to REtelligent as Processor; Module 3 for transfers between Processor and Sub-processor) supplemented by measures consistent with EDPB Recommendations 01/2020. See the Data Processing Agreement (European Union), Section 9 for the contractual mechanism.

7.3 APP 8 (Australia)

For Australian customers, REtelligent’s overseas disclosures of Personal Information are governed by APP 8 of the Privacy Act 1988. REtelligent remains accountable for the handling of Personal Information by overseas sub-processors.


8. AI and Automated Decision-Making — Transparency

REtelligent operates AI Features integrated into the Service. We commit to the following transparency in line with EU AI Act Article 50 and the Australian Privacy Act 1988 reforms (automated decision-making transparency, effective 10 December 2026).

8.1 What AI Features Do

The AI Features include: - Maintenance triage and classification — analysing maintenance requests and recommending workflows - Tradie / contractor dispatch — matching pre-approved tradies to in-scope, value-capped maintenance work - Lease abstraction — extracting structured data from lease documents - Tenant communications — generating templated communications (acknowledgments, status updates) - Predictive maintenance alerts — generating alerts for property manager review

Detailed feature descriptions and Foundation Model disclosure are in the AI Addendum Annex B.

8.2 General Logic of Automated Processing

The AI Features use machine learning models (including third-party Foundation Models from providers such as OpenAI, Anthropic, Google, or Mistral, as disclosed in the AI Addendum) trained on de-identified maintenance, leasing, and property-management data. The models classify, predict, and generate outputs that the property manager (the customer) uses to support decisions. We use confidence thresholds, value caps, and category filters to route lower-confidence or higher-stakes outputs to Human-in-the-Loop (HITL) review per the customer’s Delegation of Authority configuration.

8.3 What the AI Features Will Not Do Autonomously

We engineer the AI Features so that the following actions are not executed autonomously, regardless of customer configuration:

  • Decisions materially affecting a natural person’s housing access, financial standing, employment, or other legally protected interests — these require human review;

  • Communications with legal effect (e.g., notices to vacate, liability admissions, refund commitments);

  • Authorisation of payment or financial commitments above customer-set value caps;

  • Safety-sensitive maintenance work (structural, electrical, gas, plumbing, fire) — dispatch requires human review.

See the AI Addendum Annex A for the complete Delegation of Authority schema.

8.4 Your Rights Regarding Automated Decisions

Where an AI Feature has been involved in a decision materially affecting you:

(a)         you may request, through the customer (the property manager), human review of the decision;

(b)        you may request information about the AI Feature’s involvement, the general logic, and the categories of data used. We will provide this through the customer or directly upon verified request to privacy@retelligent.co.

(c)         you may, where the decision is subject to GDPR Art. 22, exercise the rights described in Section 10.4 below.

8.5 AI Generated Content

Where you interact with content generated by AI (e.g., a templated communication generated by the Service), the customer is responsible for ensuring you can identify AI-involved content per applicable law (EU AI Act Art. 50). REtelligent provides in-product disclosure mechanisms to support this.


9. Data Retention

  • Active Customer Data: retained for the duration of the customer’s Subscription Term plus the 30-day post-termination portability window, then deleted from active systems within 30 days and from archival backups within 6 months.

  • Aggregated Statistics: retained indefinitely after de-identification (per the applicable clause).

  • Audit trails and security logs: retained as required for security and legal compliance, typically 7 years.

  • Marketing data: retained while the relationship is active and for a reasonable period thereafter, subject to opt-out / erasure requests.


10. Your Rights

10.1 Rights Under the GDPR (EU Residents)

You have the right to:

  • Access the Personal Information we hold about you (APP 12);

  • Correct Personal Information that is inaccurate, out-of-date, incomplete, irrelevant, or misleading (APP 13);

  • Opt out of direct marketing (APP 7);

  • Complain to us, and (if unresolved) to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au;

  • Be informed about the use of automated decision-making affecting you (Privacy Act ADM reforms, effective 10 December 2026), per Section 8 above.

Where REtelligent processes Personal Information on behalf of a customer (e.g., tenant data), please direct requests to the customer in the first instance; we will support the customer’s response.

10.2 EU Data Subjects (GDPR Articles 15–22)

You have the right to:

  • Access (Art. 15) — request a copy of your Personal Data and information about how we process it;

  • Rectification (Art. 16) — correct inaccurate or incomplete Personal Data;

  • Erasure (Art. 17) — request deletion in defined circumstances;

  • Restriction (Art. 18) — request that we restrict processing in defined circumstances;

  • Portability (Art. 20) — receive your Personal Data in structured, commonly used, machine-readable format;

  • Object (Art. 21) — object to processing based on legitimate interests, including direct marketing;

  • Not be subject to automated decision-making producing legal effects or similarly significantly affecting you, except where permitted by Art. 22 with safeguards;

  • Withdraw consent (Art. 7) — where processing is based on consent;

  • Lodge a complaint with a Supervisory Authority — for Romanian data subjects, the Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP); other EU data subjects may complain to their national Supervisory Authority.

Where REtelligent is Processor on behalf of a customer, please direct requests to the customer in the first instance.

10.3 How to Exercise Your Rights

Contact privacy@retelligent.co. We will respond within the timeframes required by applicable law (typically 30 days, with extensions where lawful and necessary).

10.4 Article 22 GDPR — Automated Individual Decision-Making

Where a decision producing legal effects or similarly significantly affecting you has been based solely on automated processing (including profiling), you have the right to: (a) human intervention; (b) express your point of view; and (c) contest the decision. We engineer the AI Features (per the AI Addendum Annex A) so that determinative decisions of this kind are not made solely by automated processing — they require Human-in-the-Loop review. If you believe a determinative decision affecting you was made solely by automated processing, contact privacy@retelligent.co.


11. Personal Information Security

We apply technical and organisational measures appropriate to the risks of the processing, including:

  • Encryption of Personal Information at rest (AES-256) and in transit (TLS 1.3);

  • Role-based access controls and multi-factor authentication;

  • Independent third-party penetration testing annually;

  • Logging, monitoring, and incident detection;

  • Personnel confidentiality obligations and data protection training;

  • Sub-processor governance per https://www.retelligent.co/legal-pages/sub-processors.

Despite these measures, no system is completely secure. In the event of a breach, we notify affected customers and (where required) Supervisory Authorities and data subjects in accordance with applicable law and our Data Processing Agreements.


12. Cookies and Tracking

Our websites use cookies and similar technologies. Strictly necessary cookies are used without consent; analytics and marketing cookies are used with consent where required. Detailed cookie information and management options are available in our Cookie Policy at https://www.retelligent.co/legal-pages/cookie-policy.


13. Children

Our Service is not intended for individuals under the age of 16. We do not knowingly collect Personal Information from children. If we become aware that a child has provided Personal Information to us through the Service (other than via a customer’s authorised processing under applicable law), we will take steps to delete that information.


14. Changes to This Policy

We may update this Policy from time to time. Material changes will be notified to Authorised Users via email and through the Service. The “Effective date” at the top reflects the current version. Previous versions are available on request.


15. Contact and Complaints

Privacy queries: privacy@retelligent.co Legal queries: legal@retelligent.co Postal contact (AU): REtelligent Pty Ltd, Unit 2, 8A Judith Street, Carnegie VIC 3163, Australia Postal contact (EU): REtelligent EU S.R.L., Bulevardul G-ral Gheorghe Magheru, Nr. 31, Biroul 2, Etaj 5, Bucureşti Sectorul 1, Romania Data Protection Officer (EU): REtelligent has appointed a Data Protection Officer. The Data Protection Officer can be contacted at privacy@retelligent.co (please mark correspondence for the attention of the Data Protection Officer).

If we cannot resolve your concern, you may complain to:

  • AU: the Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au

  • EU (Romania): ANSPDCP — www.dataprotection.ro

  • EU (other): your national Supervisory Authority