Tesoro CRM
← Alle documenten

Data Subject Rights & AI Governance Tesoro CRM


Part 1 — Your rights and how to exercise them

1.1 Two roles

1.2 Which rights

Access (art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), and withdrawal of consent (7(3)).

1.3 How and within which time frame

  1. Submit your request via privacy@tesorohq.io.
  2. We verify your identity (without excessive additional data).
  3. We handle your request within one month (art. 12(3)); extendable by two months in case of complexity, communicated with reasons.

1.4 Complaint to the supervisory authority

You can lodge a complaint with the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es — or with the supervisory authority in your own EU country of residence.


Part 2 — AI governance

2.1 Scope

The only AI feature in the Service is the translation/rewriting of property descriptions. There is no AI on contacts, emails, deals, leads or scoring.

2.2 Which data the AI processes

The processing involves: the title + description of a property + (optionally) features and the company name. No contact names, email addresses, phone numbers, notes or messages. Property data is in principle not personal data. Agents are asked not to place identifiable personal data or special categories in free-text descriptions.

2.3 Location and transfer

The AI runs within our EU/Cloudflare infrastructure. No separate transfer to an external AI provider outside this framework takes place.

2.4 No automated decision-making (art. 22)

The AI provides text suggestions; no decisions with legal effect or similar effect are made solely by automated means. The agent reviews and uses the output (human intervention).

2.5 Transparency

The AI feature and its limitations are named in the Terms and Conditions and the Privacy Statement. If AI is extended to data that does constitute personal data, we carry out a new assessment in advance.