Privacy

Privacy policy

How Listed handles personal data — for property managers who use the platform, for property owners who send an enquiry through a property manager's website, and for visitors to listed.digihome.no.

Last updated 13 September 2026 Draft 0.9 · pending legal review

This text is a working draft prepared by the Listed team. It describes how the platform is built to work and is published for transparency while it is reviewed by legal counsel. Wording may change before the commercial launch; the date above shows the current version.

01Who we are and what this covers

Listed is a software platform built and operated by DigiHome Tech AS (org. no. 835 674 622), Kokstadvegen 46, 5257 Kokstad, Norway ("DigiHome", "we"). Property-management companies ("property managers") use Listed to capture owner enquiries on their own website, send proposals, sign agreements electronically and onboard properties into their property-management system (PMS).

This policy explains what personal data we process, why, on what legal basis, for how long, and what rights you have. It applies to three groups of people:

  • Property managers and their team members who hold a Listed workspace account.
  • Property owners and other people who submit an enquiry, receive a proposal, sign an agreement or complete onboarding through a property manager's Listed journey.
  • Visitors to our own marketing website and to the public support chat.

02Controller or processor — who is responsible

The role we play depends on whose data it is.

Workspace accounts, billing and our website
DigiHome is the data controller. We decide how account, billing, support and website-visitor data is used.
Owner enquiries and everything that follows
The property manager is the data controller. Owners send their details to the property manager, on the property manager's own website and under the property manager's brand. DigiHome processes that data as the property manager's data processor, on their instructions, under a data-processing agreement (DPA).

If you are a property owner and want to exercise your rights over an enquiry, proposal or agreement, please contact the property manager you dealt with. We will help them respond.

03What data we process

Account data (property managers)
Name, work e-mail, role, password hash, workspace and company details, VAT/tax profile, invoice contact, activity in the workspace and audit entries (who did what, when).
Owner enquiry data (on behalf of property managers)
Name, e-mail, phone, company details for business owners, the property's address and characteristics, links to existing listings, photos the owner uploads or imports, rental plans and notes, proposals and their status, the signed agreement (signature, name, timestamp, IP address, user agent), and onboarding answers.
Sensitive onboarding fields
Access codes, Wi‑Fi passwords and bank-account details that owners provide during onboarding are encrypted at rest, shown in full only to the owner, masked for the property manager's team by default, and every reveal is logged.
Support conversations
Messages exchanged in the public sales chat or the in-app support, the e-mail address you give us to follow up, and — for signed-in users — your workspace. Conversations may first be answered by an AI assistant and are read by Listed's team.
E-mail delivery and replies
When a property manager e-mails an owner through Listed, we record the message, delivery status and any reply sent to the lead-specific reply address, so the conversation appears in the property manager's inbox.
Website-embed telemetry
The Listed embed script reports the hostname and page path where it runs, its version and display mode, so the property manager can see that the installation works. This telemetry contains no personal data about visitors.
Usage analytics (with your consent)
Page views and interactions on our marketing website and in the application, collected through a privacy-focused analytics tool only after you accept analytics cookies.
Technical logs
IP address, timestamps, request paths and error information kept for security and reliability.

04Why we process it and on what legal basis

  • To provide the service to property managers — contract (GDPR art. 6(1)(b)).
  • To process owner data on a property manager's behalf — the property manager's instructions under the DPA (art. 28); the property manager determines the legal basis towards the owner, typically pre-contractual steps and contract.
  • To create legally valid electronic signatures and keep an evidential record (signature, time, IP address) — contract and legitimate interest in the integrity of agreements (art. 6(1)(b) and (f)).
  • To invoice property managers and comply with bookkeeping law — contract and legal obligation (art. 6(1)(b) and (c)).
  • To answer support and sales questions — legitimate interest and, where you contact us, pre-contractual steps (art. 6(1)(b) and (f)).
  • To keep the platform secure and prevent abuse — legitimate interest (art. 6(1)(f)).
  • To measure and improve our website and product with analytics cookies — consent (art. 6(1)(a)), which you can withdraw at any time.

05AI-assisted features

Listed uses large language models to draft text: summaries of new enquiries for the property manager, suggested proposal letters, and first answers in the support chat. Text you or an owner have written may be sent to an AI provider to generate these drafts. Drafts are always reviewed by a person before they are sent to an owner, and AI providers are bound by our data-processing terms and do not use the content to train their models.

06Sub-processors and third parties

We use a small number of service providers to run Listed. They only process data on our instructions:

  • Cloud hosting and database infrastructure (application servers, MongoDB, object storage).
  • Transactional e-mail delivery and inbound reply handling (Resend).
  • AI model providers for drafting and support answers (OpenAI, Google or Anthropic, via a managed gateway).
  • Product analytics (PostHog) — only with your consent.
  • Payment and invoicing services, when online payment is enabled (Stripe).
  • Address lookup and map data services for property search.

In addition, property managers connect their own systems — a PMS such as Hostaway, Guesty, Smoobu or Lodgify, their e-mail provider, webhooks or a CRM. When they do, property data is sent to those systems under the property manager's own agreements with those providers.

A current list of sub-processors with locations is available on request and will be published here before commercial launch.

07International transfers

We aim to keep data within the EU/EEA. Where a provider processes data outside the EEA (for example some AI or e-mail providers in the United States), we rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses, together with additional safeguards where needed.

08How long we keep data

  • Workspace and account data: for as long as the workspace exists, then deleted or anonymised within 90 days of termination, unless we must keep it longer by law.
  • Owner enquiries, proposals and agreements: as long as the property manager keeps them in their workspace. Signed agreements are kept for the duration of the relationship and the legal retention period that applies to contracts.
  • Invoices and bookkeeping records: five years after the end of the financial year (Norwegian Bookkeeping Act).
  • Support conversations: 24 months after the case is closed.
  • Technical logs: up to 90 days.
  • Analytics data: 12 months, or until you withdraw consent.

09How we protect data

All traffic is encrypted in transit (TLS). Sensitive onboarding fields and integration credentials are encrypted at rest with keys managed separately from the database. Access to production systems is limited to named staff with multi-factor authentication, and actions on personal data inside a workspace are logged. Property managers control who in their team has access, and at which role.

10Cookies and analytics

Listed uses two kinds of storage in your browser:

Strictly necessary
Your sign-in session, your language and layout preferences, the cookie choice itself, and a one-hour marker that stops the embed script from reporting the same page repeatedly. These are needed for the service to work and are set without consent.
Analytics (optional)
A privacy-focused analytics tool that helps us understand which pages are used and where people get stuck. It is only loaded after you choose “Accept analytics” in the cookie notice. You can change your choice at any time via “Cookie settings” in the footer.

We do not use advertising cookies and we do not sell personal data.

11Your rights

Under the GDPR and the Norwegian Personal Data Act you have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to processing, to receive it in a portable format, and to withdraw consent at any time. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or the supervisory authority where you live.

To exercise your rights, e-mail privacy@digihome.no. If your request concerns an enquiry, proposal or agreement with a property manager, we will forward it to them and assist with their response. We answer within 30 days.

12Changes to this policy

We will update this policy when the service or the law changes. Material changes are announced to workspace administrators by e-mail and inside the application before they take effect. The date at the top shows the current version.

13Contact

DigiHome Tech AS (org. no. 835 674 622) · Kokstadvegen 46, 5257 Kokstad, Norway · hello@digihome.no. Privacy questions: privacy@digihome.no.

Related

The terms that apply to property managers using Listed.

Questions about these documents? hello@digihome.no