Skip to main content

Privacy and Consent

Privacy and consent are critical. The platform must separate normal service processing from profiling, score sharing, marketing, and marketplace visibility.

Processing categories

CategoryMeaning
Service data processingProcessing required to provide rental management features.
ProfilingProcessing used to evaluate behavior, reputation, or risk.
MarketingProcessing used for promotional communication.

Service processing can be necessary for contract management. Profiling and score sharing require explicit opt-in consent.

Consent typePurpose
PROFILINGAllows calculation of behavioral or reputation scores.
SCORE_SHARINGAllows sharing a tenant score with other parties.
MARKETPLACE_VISIBILITYAllows tenant or property data to appear in marketplace workflows.
MARKETINGAllows marketing communication.

Proposed entity: user_consents

FieldDescription
idPrimary identifier.
user_idUser giving consent.
party_idBusiness identity affected by consent.
consent_typeConsent category.
statusGRANTED or REVOKED.
granted_atGrant timestamp.
revoked_atRevocation timestamp.
sourceUI, invitation flow, settings page, or support action.
policy_versionPrivacy policy version accepted.

Opt-in and opt-out

  • Profiling must be opt-in.
  • Score sharing must be opt-in.
  • Marketplace visibility must be opt-in.
  • Users must be able to revoke consent.
  • Revocation must stop future processing for that purpose.

Data minimization

Only process the minimum data required for the declared purpose. For example, marketplace matching does not need to expose raw bank transactions to landlords.

Explainability requirements

For any score or ranking, the platform should explain:

  • which data categories were used
  • the score version
  • the main positive and negative factors
  • the confidence level
  • how the user can correct wrong data