1. Who we are
Realisio is operated by 811 GROUP s.r.o., Dunajská 39, 811 08 Bratislava, Slovak Republic, Company ID (IČO) 46070354 and Tax ID (DIČ) 2023224654 ("Realisio", "we", "us"). For processing covered by this Policy, 811 GROUP s.r.o. is the data controller unless we expressly state that we act as a processor for a business customer.
Questions and data-protection requests may be sent to info@realisio.sk or by post to our registered office above.
2. Scope and our role
This Policy applies to the Realisio website, accounts, subscriptions, support and AI-powered property-visualisation tools. It does not cover third-party websites or services that publish their own privacy notices.
We act as controller for website, account, billing, security and direct customer-relationship data. When a business customer uploads personal data and determines why it is processed, that customer is normally the controller and we act as its processor under a data processing agreement. The customer must have a lawful basis and give any required notices to the people shown in or connected with uploaded content.
3. Personal data we collect
- Account and identity data: name, email address, organisation, role, language, login identifiers and account settings.
- Transaction data: plan, credit balance, purchases, billing address, tax details, payment status and invoices. Full card details are handled by the payment provider and are not stored by us.
- User content: property photos, prompts, project names, generated images, videos and floor plans, metadata and any personal data visible in or attached to that content.
- Technical and usage data: IP address, device/browser information, timestamps, pages and features used, diagnostic events, security logs and cookie identifiers where enabled.
- Communications: support requests, feedback, survey responses and other messages you send us.
- Marketing preferences and consent records, where marketing or optional analytics are used.
4. Where data comes from
We receive data directly from you, from the organisation that provides your account, automatically from your device, and from service providers such as payment, authentication and analytics providers. A customer may also upload content containing data about property owners, tenants, buyers, agents or people visible in a photograph.
5. Why we use data and our legal bases
- Contract: to create and administer accounts, accept uploads and prompts, generate and deliver outputs, manage credits and subscriptions, process payments, provide support and communicate service information.
- Legal obligation: to keep accounting and tax records, answer lawful authority requests, handle consumer rights and comply with data-protection and electronic-communications law.
- Legitimate interests: to secure and prevent abuse of the service, troubleshoot and improve reliability, understand aggregate product use, protect legal claims and communicate with business customers. We balance these interests against your rights.
- Consent: for non-essential cookies, optional analytics and electronic marketing where consent is required. You may withdraw consent at any time without affecting earlier lawful processing.
6. Photos, prompts and AI processing
We process uploaded photographs, prompts and related content to generate the visualisation or other output you request and to operate the selected feature. We do not make uploads public unless you choose to share or publish them. Depending on the feature, content may be transmitted to AI processing providers operating within the European Union. Inputs are processed in the EU and may be used to train and improve our models (see the Terms of Service).
Do not upload special-category data, identity documents, intimate imagery, photographs of children or other sensitive personal data unless it is strictly necessary, lawful and specifically authorised. Remove or blur people, vehicle plates, documents and screens where they are not needed for the property visualisation.
We do not use personal data for solely automated decisions that produce legal or similarly significant effects. The service generates creative outputs, but the customer decides whether and how to use them.
7. Cookies and similar technologies
We may use strictly necessary storage for security, login, language and service operation. Optional analytics, preference or marketing technologies may be used only after the required consent and must be listed in the cookie interface or cookie policy with their provider, purpose and lifetime.
You can change optional choices through the “Cookie settings” link in the site footer. Browser controls can also block or delete storage, but disabling necessary technologies may prevent parts of the service from working.
8. Who receives personal data
We disclose data only where necessary to operate the service, comply with law, protect rights, or complete a corporate transaction. Recipients may include the following categories:
- Stripe or the confirmed payment provider for card payments, fraud prevention, billing and invoices.
- Vercel Inc. (hosting and application runtime), Cloudflare, Inc. (file storage – Cloudflare R2) and Stripe Payments Europe (payments).
- Professional advisers, auditors, insurers and public authorities where legally required.
- A buyer, investor or successor in a merger, financing, reorganisation or sale, subject to appropriate confidentiality and notice requirements.
9. International transfers
Our main providers (Vercel, Cloudflare, Stripe) process data within the European Union. If a specific case involves a transfer outside the European Economic Area and the destination does not benefit from an adequacy decision, we use an approved safeguard such as the European Commission's Standard Contractual Clauses, complete a transfer assessment where required, and apply supplementary security measures. You may request information about relevant safeguards.
10. How long we keep data
When a retention period ends, we delete or irreversibly anonymise the data unless preservation is required by law, a dispute or a valid legal hold.
- Account and profile data: while the account is active and for 30 days after closure, unless longer storage is needed for claims or law.
- Uploads, prompts and generated outputs: kept while the account is active and deleted within 30 days of account closure, plus encrypted backups for up to 30 days.
- Invoices and accounting records: generally 10 years following the year to which they relate, where required by Slovak accounting and VAT law.
- Security and diagnostic logs: 12 months. Support communications: 24 months.
- Consent and objection records: for as long as needed to demonstrate compliance and defend legal claims.
11. Security
We use proportionate technical and organisational measures designed to protect personal data, including access controls, transport encryption, restricted administrative access, logging, backups, supplier review and incident procedures. Files are stored in Cloudflare R2 with at-rest encryption, transferred over TLS, and administrative access is restricted and logged; we do not yet hold formal security certifications. No online service can guarantee absolute security.
If a personal-data breach is likely to create a risk to people, we notify the competent authority within the legally required period and notify affected people where the risk is high.
12. Your rights
Subject to the conditions in applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests or direct marketing. Where processing relies on consent, you may withdraw it at any time. You also have the right not to be subject to qualifying solely automated decisions.
Send a request to info@realisio.sk. We may ask for reasonable information to verify identity and authority. We normally respond within one month; complex or numerous requests may lawfully take longer. Rights may be limited where an exemption applies or where we act only on a customer's documented instructions. In the latter case, contact the relevant customer first or tell us which customer controls the data.
13. Children
The service is intended for businesses and adults and is not directed to children. Do not create an account if you lack legal capacity to enter the agreement. If you believe a child has provided personal data without proper authorisation, contact us so that we can investigate and delete it where required.
14. Complaints
Please contact us first so we can try to resolve your concern. You may also lodge a complaint with the Office for Personal Data Protection of the Slovak Republic or with the supervisory authority in the EU/EEA country where you live, work or believe an infringement occurred.
15. Changes to this Policy
We may update this Policy when the service, providers or law changes. We will publish the revised version and update the date above. If a change materially affects how we use personal data, we will provide an additional notice through the service or by email where appropriate. Earlier versions: available on request at info@realisio.sk.