Skip to content
In The City

Privacy notice

This document explains what data the portal processes about you, why, for how long, and what you can do about it. It is written to match how the system actually behaves — not as a generic template.

Who processes the data

The controller is the company named in the footer of this document. You can reach us by e-mail at the address below — requests about personal data are answered at the same address.

The controller is established outside the European Union, but the portal is aimed at people in Slovakia and Czechia. The GDPR therefore applies to it in full.

What data we process

The portal deliberately asks for little. Registration asks for your first name, last name, e-mail and password (no password with Google) — not your phone number or address. Your name lets colleagues in the company and invited people see who they are dealing with; the e-mail is verified with a one-time code.

  • Account: first name, last name, e-mail address, password (stored only as an unreadable hash, never in readable form), interface language and market. Until you complete the sign-up we keep these details for at most 24 hours and then delete them. Sign-in links and e-mail codes are also stored only as a hash and are short-lived (link 15 minutes, code 30 minutes).
  • Sign-in with Google, if you use it: the identifier of your Google account and when it was connected and last used. What exactly Google sends us is described in a separate section below.
  • What interests you: the life events you choose, an optional date of the event, the municipality or district you select, and anything you have hidden from your results.
  • What you enter: bookings, company reviews, claimed coupons, content reports and appeals against moderation decisions.
  • Search: the text you type into search, together with the event we matched it to.
  • Notifications: if you turn them on, your device address at your browser vendor and a log of what we sent you.
  • Companies: if you manage a company, also data about the company, its listings and — if you use the feature — its business cases and clients.
  • Company document library: the files company members upload to it, their older versions, the text extracted from them for search, who uploaded, changed, moved or deleted a file, and each member's favourite and recently opened files.

We do not track visits at the level of a person. Views and contact clicks are counted only in aggregate per listing and day — without your account, without your IP address and without cookies. A company sees how many times its listing was viewed, not by whom.

On what basis and why

  • Performance of a contract: running your account, bookings, reviews tied to a completed booking, operational notifications about your bookings.
  • Legitimate interest: security of the portal (rate limiting, abuse protection), content moderation and improvement, aggregate listing statistics for companies.
  • Legal obligation: responding to reports of illegal content and keeping records of moderation decisions.
  • Consent: browser notifications (you turn them on yourself and can turn them off at any time) and offer suggestions, which you can switch off in settings.
  • Company document library: the company that uploaded the files is responsible for their content; the portal processes them on its behalf as part of the service for the company — it stores them, checks them with an antivirus, makes them available to its members according to their role, extracts text for search and, if switched on, lets a language model suggest a folder.

Sensitive topics

Some life events touch on health or other sensitive areas. The portal will NEVER infer such topics from what you search for — only you can enable them deliberately in your interests.

When a search lands on a sensitive topic, the record is detached from your account at the moment it is written, and sensitive topics are never sent to the language model. They do not appear in the public list of events at all.

Sign-in with Google

You can also sign in or register with the “Continue with Google” button. It is up to you — your account works the same with a password and without Google.

From Google we receive and use three things:

  • The identifier of your Google account — a number that does not change even if you change your e-mail at Google. It is how we recognise you the next time you sign in. We store it with your account together with the date it was connected and last used for signing in.
  • Your e-mail address and whether Google has verified it. We only let you in with an e-mail Google has verified. For a new account it becomes the account e-mail; an account you already have under that e-mail is connected to Google and its e-mail does not change.
  • Your first name and last name, if your Google account has them. We use them only when creating a new account — anything missing you fill in yourself. We never overwrite the name of an existing account with the one from Google.

Google’s response may also include other profile details, such as a link to your profile photo, and an access key to its interface — we do not read, store or use any of it. The portal does not receive your Google password, contacts, e-mails or files, and does not ask for access to them.

If you sign in with Google using an e-mail you already have an account under, Google is connected to that account and we send you an e-mail about it. If that account had not verified its e-mail yet, we remove its password and sign it out of all devices: Google has verified the e-mail for you, and nobody who does not own it can get into the account with a password they made up at registration.

Google learns that you are signing in to the In The City portal — that is governed by Google’s privacy policy. We send Google nothing about you. During sign-in your browser keeps a technical cookie for 10 minutes with one-time codes that protect the return from Google against forgery; it is deleted on return.

You disconnect Google in My account, in the Sign-in with Google section. An account created through Google has no password — first you set one (otherwise you could not get into the account), and you request deletion of the account with a code we send you by e-mail. After disconnecting we delete the Google account identifier; the record that Google was connected to an existing account and later disconnected is kept for 24 months as a security trail.

Who receives the data

We do not sell data and do not provide it for third-party advertising. The list below is complete — the portal loads no third-party script into your browser and uses no third-party analytics.

  • Language model provider (Anthropic, USA). What goes there: the text you type into search or to the assistant; a photo of your identity document if you have the contract party details pre-filled — including your name, national ID number, document number and your likeness; case documents the office uploads for reading (title deed, reservation form, purchase contract); the contract text when the office asks for a review; and, when a file is uploaded to the company document library and folder suggestions are switched on, the file name, the names of the folders the uploader can see and at most 2,000 characters from the beginning of the text of the file. The provider processes this data to return an answer; we send nothing else to it. The photo is sent WHOLE and exactly as you took it — we do not crop it, do not shrink it and do not strip the data the camera wrote into the file. And the contract text submitted for review usually contains the same identifiers (name, national ID number, document number), because they are filled into the contract from the party details. Note — if you type personal data into a message to the assistant yourself, it goes with the message; we have no way to filter it out. For the document library, before sending we remove e-mail addresses, phone and other long numbers (including national ID numbers and payment card numbers), IBAN account numbers and document numbers from the name, the folders and the text; names and addresses cannot be removed reliably, so they may be sent. We keep only the suggested folder, not the text that was sent.
  • SMS gateway operator: your phone number and the message text when we send you the verification code before signing a contract.
  • Maps service (Google): the address text you enter in a listing form. The call is made by our server, so the service does not see your IP address or anything about you.
  • E-mail service (Google Workspace): your e-mail address and the content of messages we send you (verification, password reset, booking confirmation).
  • Google (sign-in), if you use it: it learns that you are signing in to this portal. We send it nothing else about you — the data flows the other way, from Google to us.
  • Your browser vendor’s notification service (Google, Mozilla, Microsoft, Apple): the notification text and your device address, if you enable notifications.
  • Public company registers (RPO, ARES): a company registration number, if you ask us to pre-fill it.

We store photos and documents on our own server, not with a third-party service; the antivirus that checks files in the company document library runs on it too. With a photo of an identity document, where you attach it makes all the difference. A photo used to PRE-FILL the contract party details is not stored at all — it is used only to read the details and then discarded. A document you UPLOAD to your case in the client portal (or one the office attaches to the case) is kept, and the portal has no way to delete it yet; uploading is therefore irreversible in practice. What the language model reads from the photo must be sent to that model, and the same applies to documents and contract text submitted for review.

Transfers outside the European Union

The controller is established in the United Arab Emirates and some of the providers listed above process data outside the EU. The legal basis securing these transfers is under review and will be added here before the portal opens to the public.

How long we keep data

  • Account and its content: for as long as the account exists.
  • Documents uploaded to a business case: for as long as the case exists. The portal cannot yet delete an individual document or a whole case, so uploading is irreversible in practice. We say so plainly — we will not promise a period the system cannot keep.
  • Details read from a photo of your ID document before you confirm them: 72 hours at most, that is, for as long as your one-time link is valid (the sweep runs once an hour). The national ID number and document number are held encrypted; confirming moves them into the secure case store and unconfirmed ones are deleted.
  • National ID number and document number in the secure case store: no period is set yet — it depends on the office’s own obligations and will be added after legal review. Until then they stay stored.
  • Records of what the office did — who opened a document and when a photo was sent to the language model: kept permanently and cannot be changed or deleted. They are the trail of what happened to your data.
  • Sign-in: a session lasts 30 days from your last visit, at most 90 days.
  • Google account connection: until you disconnect it, at most for as long as the account exists. Record of connecting to an existing account and of disconnecting: 24 months.
  • Verification links: e-mail verification 48 hours, password reset 48 hours.
  • Searches: 90 days if we matched the query to an event, otherwise 30 days. Unmatched queries are detached from the account after 7 days.
  • The record of which listing was shown to you: detached from your account after 90 days, deleted after a year.
  • Rate-limiting records (these contain an IP address): 1 day.
  • Hidden listings and companies: 180 days.
  • Moderation decisions and appeals: kept even after an account is deleted, without a link to a person — they are the record of why content was removed.
  • Company document library: files and their versions until the company deletes them. A deleted file stays in the trash for 30 days and is then deleted permanently with all its versions and extracted text; the company owner or administrator can delete it permanently sooner. A file in which the antivirus finds a threat is not stored, and if the threat is found later, the file is deleted. When a member's account is deleted, their files stay with the company and show "former member" instead of their name. The list of recently opened files keeps the last 20.

The periods for searches and view records are provisional and will be confirmed by legal review.

Your rights

You can exercise most rights yourself, directly in your account, without waiting for our reply.

  • Access and portability: in My account you can download all data tied to your account in the open JSON format.
  • Erasure: request deletion in My account. The account becomes inactive immediately and is deleted after 30 days; until then you can cancel the request. The delay protects against a rash or unauthorised action.
  • Objection and restriction: you can switch off suggestions, hide individual listings, companies or whole categories, and set quiet hours for notifications.
  • Rectification: you can edit your account and interest data directly in your account.
  • Complaint: you have the right to lodge a complaint with a supervisory authority — in Slovakia the Office for Personal Data Protection of the Slovak Republic, in Czechia the Office for Personal Data Protection.

What is NOT deleted when your account is removed, but loses its link to you: company reviews (they stay published without an author, so a company rating cannot be erased by deleting the reviewer), completed bookings held by companies, and moderation records. We say this plainly, because full erasure is not the same as detaching data from a person.

Cookies

The portal uses three strictly necessary cookies: one keeps you signed in on the public site, one in the administration, and one remembers your cookie decision. We do not ask for consent to these — the portal would not work without them. The first two are created when you sign in; the third when you make a choice in the banner.

We use marketing cookies ONLY with your consent, and for one purpose: to tell whether a visit came from our advertising. Without your consent we store nothing and send no data to any advertising network. Consent lasts 6 months; you can change or withdraw it at any time in Cookie settings — withdrawing is just as easy as giving it.

We use no analytics cookies at all. We count visits in aggregate per listing and day — without cookies, without your IP address and without your account.

We keep a record of your decision: what you chose, when, in which language and under which version of this text. The record holds no IP address and no browser details — it holds a random number that says nothing about you and serves only to match a later withdrawal to the original consent.

Automated processing

The portal automatically selects which listings to show you — based on the events you chose and the location you entered. This is a recommendation, not a decision with legal effect: it denies you nothing and requires nothing of you.

For more complex queries, a language model helps classify what the question is about. The model never decides that content will be removed — permanent removal is confirmed by a person and can be appealed.

In the company document library, a language model may suggest a folder for an uploaded file. It is only a suggestion, labelled as an AI suggestion — a person moves the file with a button or leaves it where it was uploaded.

Changes

When the way the portal handles data changes, we change this document and update the date of last revision. We will notify you of significant changes.

Contacting real-estate agencies

Besides portal users, we also process the contact details of real-estate agencies and their agents to whom we offer the portal’s services. This section says where those details come from, what we do with them and how you can stop us.

  • Where the data comes from: public agency and agent profiles on real-estate portals (nehnutelnosti.sk, zoznamrealit.sk), the member list of the Association of Real Estate Agencies of Slovakia and agencies’ public websites. Some addresses are derived from an agent’s name and the agency’s domain; the footer of every e-mail names the exact page where we found the address.
  • What data: the agency’s name and registered office, company ID, website, phone, e-mail addresses, the agent’s name and position, city, number of listings and association membership. None of it is linked to portal user accounts — contacts live in a separate database of an internal tool.
  • Why: to invite the agency to join the portal — with a series of at most a few e-mails over roughly three weeks. The series stops when you reply, when you unsubscribe, or when an e-mail cannot be delivered.
  • On what basis: the controller’s legitimate interest in approaching businesses in the sector the portal serves (Article 6(1)(f) GDPR). Agencies already on the portal do not receive the invitation.
  • What we measure: whether the e-mail was opened (an image in the e-mail) and which link was clicked — per address, without cookies and without profiling. Replies are read by a designated person; automatic replies and non-delivery reports are processed automatically only to stop the series.
  • For how long: we keep a contact while it is published in the sources above. After you unsubscribe we do NOT delete the address; we mark it as unsubscribed and keep it only so that we never write to you again — otherwise the next import of public data would add your address as new.
  • Your rights: you may object to being contacted at any time — via the “No further e-mails” link in every e-mail, which stops the whole agency and its domain, or by e-mailing the address in the footer of this document. You also have the right of access, rectification, erasure and to lodge a complaint with a supervisory authority.
In The City FZ-LLC

B01G39D, Al Hulaila Industrial Free Zone, Ras Al Khaimah, Spojené arabské emiráty

Licencia č. 47022221

project@inthecity.ae

Last updated: 2026-09-25