Contents
- Who We Are
- Our Role: Controller vs. Processor
- Personal Data We Collect
- How & Why We Use Personal Data
- Cookies & Analytics
- How We Share Personal Data
- International Data Transfers
- Data Retention
- Security
- Your Rights — EEA & UK (GDPR)
- Your Rights — United States
- Your Rights — India (DPDP Act)
- Other Jurisdictions
- Children
- Changes to This Policy
- Contact & Complaints
1. Who We Are
This Privacy Policy is issued by BuyerIntentSystem ("we," "us," "our"), with its registered office at [REGISTERED ADDRESS]. We provide the Serious Buyer System™ — lead-scoring tools, setup services, and 1:1 consulting for real-estate professionals (the "Services").
For questions about this Policy or your personal data, contact: buyerintentsystem@gmail.com.
Where the GDPR or UK GDPR requires a Data Protection Officer or a local representative, requests may be directed to the address above.
For the purposes of the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 (India), our designated Grievance Officer may be reached at buyerintentsystem@gmail.com.
2. Our Role: Controller vs. Processor
- We act as a controller (or "data fiduciary" under India's DPDP Act) for personal data about our website visitors, prospects, and customers — e.g., when you fill in a form, book a call, or buy our services. This Policy covers that processing.
- We act as a processor / service provider when our customers (e.g., real-estate agents) submit their leads' personal data to our tools. In that case the customer is the controller, our Data Processing Agreement governs, and individuals should direct privacy requests to the agent or brokerage they interacted with. We will forward any request we receive to the relevant customer.
3. Personal Data We Collect
3.1 Data you provide directly
- Contact & identity data: name, email, phone, company/brokerage, role, market/region.
- Business & engagement data: information you share in intake forms, consultations, questionnaires, and support requests.
- Billing data: billing address, tax IDs, and transaction records. Card details are processed by our payment providers (Stripe and Razorpay) — we do not store full card numbers.
- Communications: emails, messages, call notes, and (with notice/consent where required) call or meeting recordings.
- Marketing preferences: subscriptions, opt-ins, and opt-outs.
3.2 Data collected automatically
- Usage & device data: IP address, browser type, device identifiers, pages viewed, referring URLs, and interaction events, collected via cookies and similar technologies (see Section 5).
3.3 Data from third parties
- Scheduling, payment, CRM, and analytics providers you interact with as part of the Services; publicly available business information; and referral partners (where lawful).
We do not intentionally collect sensitive/special-category data (e.g., health, religion, biometrics) and ask that you not submit it.
4. How & Why We Use Personal Data
| Purpose | Examples | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Providing the Services | Setting up your system, delivering consulting, providing tools and Materials, support | Performance of a contract (Art. 6(1)(b)) |
| Billing & accounting | Invoicing, payment processing, tax records | Contract; legal obligation (Art. 6(1)(c)) |
| Communications | Responding to enquiries, scheduling calls, service notices | Contract; legitimate interests (Art. 6(1)(f)) |
| Marketing | Newsletters, nurture emails, offers — with unsubscribe in every message | Consent (Art. 6(1)(a)) or legitimate interests for existing customers, per local law |
| Analytics & improvement | Understanding site usage, improving content and tools | Consent (for cookies where required); legitimate interests |
| Security & fraud prevention | Protecting our systems, preventing abuse | Legitimate interests; legal obligation |
| Legal claims & compliance | Establishing or defending claims, responding to lawful requests | Legal obligation; legitimate interests |
Under India's DPDP Act, we process personal data based on your consent or for certain legitimate uses recognized by the Act (e.g., voluntary provision for a specified purpose, compliance with law). You may withdraw consent at any time as described in Section 12.
No automated decisions with legal effect. We do not use your personal data to make automated decisions that produce legal or similarly significant effects about you. Lead scores generated by our tools relate to data our customers control and are decision-support for the customer, not automated decision-making by us about you.
5. Cookies & Analytics
Our website uses:
- Strictly necessary cookies — required for the site to function.
- Analytics — we use Google Analytics 4 to understand site usage. Where required by law (e.g., EEA/UK), analytics cookies are set only with your consent via our cookie banner, and IP data is handled per Google's data-minimization settings.
- Marketing/advertising cookies — we do not currently use advertising or retargeting cookies.
You can manage cookies via our cookie banner (where displayed), your browser settings, or Google's opt-out tools (tools.google.com/dlpage/gaoptout). We honor Global Privacy Control (GPC) signals where legally required.
6. How We Share Personal Data
We do not sell personal data, and we do not "share" it for cross-context behavioral advertising as defined by the CPRA. We disclose personal data only to:
- Service providers/processors who help us run the business — hosting, email, scheduling, payments, analytics, CRM, e-signature — under contracts restricting their use of the data. Current providers include: Google Workspace, Google Analytics, Stripe, Razorpay, Calendly, and our CRM and form tools.
- Professional advisors (lawyers, accountants, insurers) under confidentiality duties.
- Authorities where required by law, court order, or to protect rights, safety, or property.
- Business transfers — in a merger, financing, or sale of assets, subject to this Policy's protections.
7. International Data Transfers
We use service providers that may process data in other countries, including the United States. Where personal data protected by the GDPR/UK GDPR is transferred outside the EEA/UK, we rely on adequacy decisions or the European Commission's Standard Contractual Clauses (and the UK Addendum/IDTA), with supplementary measures where appropriate. For data covered by India's DPDP Act, we transfer personal data only to countries not restricted by the Central Government. You may request a copy of relevant transfer safeguards via buyerintentsystem@gmail.com.
8. Data Retention
We keep personal data only as long as needed for the purposes above, then delete or anonymize it. Typical periods:
- Customer account and engagement records: duration of the relationship + seven (7) years (contract/tax requirements).
- Prospect/marketing data: until you unsubscribe or after twenty-four (24) months of inactivity.
- Website analytics: fourteen (14) months.
- Customer Data we process as a processor: per the customer's instructions and the DPA.
9. Security
We apply technical and organizational measures appropriate to the risk — encryption in transit, access controls, least-privilege access, vendor due diligence, and staff confidentiality obligations. Details are in our Security Overview. No system is perfectly secure; if a breach affecting your data occurs, we will notify you and regulators as required by law.
10. Your Rights — EEA & UK (GDPR / UK GDPR)
If you are in the EEA or UK, you have the right to:
- Access your personal data and receive a copy;
- Rectify inaccurate or incomplete data;
- Erase data ("right to be forgotten") in certain circumstances;
- Restrict or object to processing, including objecting to direct marketing at any time;
- Data portability — receive data you provided in a machine-readable format;
- Withdraw consent at any time, without affecting prior processing;
- Complain to your supervisory authority (e.g., the ICO in the UK, or your local EU data protection authority).
To exercise these rights, email buyerintentsystem@gmail.com. We respond within one month (extendable by two months for complex requests, with notice).
11. Your Rights — United States (incl. California)
Depending on your state (e.g., California, Colorado, Connecticut, Texas, Virginia), you may have the right to:
- Know/access the categories and specific pieces of personal information we collect, use, and disclose;
- Delete personal information, subject to exceptions;
- Correct inaccurate personal information;
- Opt out of "sale" or "sharing" of personal information and certain profiling — we do not sell or share personal information as those terms are defined by the CPRA;
- Limit use of sensitive personal information — we do not use sensitive personal information for purposes requiring this right;
- Non-discrimination — we will not discriminate against you for exercising your rights.
Categories collected (last 12 months): identifiers; commercial information; internet/electronic activity; professional information; inferences (lead-fit) — as described in Section 3, from the sources in Section 3, for the purposes in Section 4, disclosed to the recipients in Section 6.
Submit requests via buyerintentsystem@gmail.com. We will verify your identity and respond within 45 days (extendable once by 45 days). You may use an authorized agent with proof of authorization. If we deny a request, you may appeal by replying to our decision; appeal outcomes include contact details for your state Attorney General.
12. Your Rights — India (DPDP Act 2023)
If you are in India, as a Data Principal you have the right to:
- Access a summary of your personal data and processing activities;
- Correction and erasure of your personal data;
- Grievance redressal — contact our Grievance Officer at buyerintentsystem@gmail.com; we respond within the timelines prescribed by law;
- Nominate another individual to exercise your rights in case of death or incapacity;
- Withdraw consent at any time, as easily as it was given.
If unsatisfied with our response, you may complain to the Data Protection Board of India.
13. Other Jurisdictions
Wherever you are located, we honor applicable local privacy rights (e.g., PIPEDA in Canada, the Australian Privacy Act, LGPD in Brazil). Contact buyerintentsystem@gmail.com and we will handle your request under the law that applies to you.
14. Children
Our Services are for business users and are not directed at children under 18. We do not knowingly collect children's personal data; if you believe a child has provided us data, contact us and we will delete it.
15. Changes to This Policy
We may update this Policy from time to time. We will post the updated version here with a new "Last updated" date and, for material changes, notify you by email or a prominent site notice before the changes take effect.
16. Contact & Complaints
BuyerIntentSystem
[REGISTERED ADDRESS]
Privacy contact: buyerintentsystem@gmail.com
Grievance Officer (India — DPDP Act, 2023): buyerintentsystem@gmail.com