Privacy policy

This policy explains which personal data is processed when you visit https://livelisted.app, use the application, or interact with availability pages and widgets published by our customers. It applies under the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (DSG).

Last updated 07/09/26

1. Controller

BUILDING BRANDS GmbH, Viktringer Ring 13, 9020 Klagenfurt am Wörthersee, Austria. Managing director: Georg Micheu. Privacy enquiries: privacy@livelisted.app.

2. Two roles: controller and processor

For the website, customer accounts and contract handling, BUILDING BRANDS GmbH is the controller.

For the data customers (developers, project marketers) enter into livelisted — units, prices, reservations, sales partners, prospect enquiries — the respective customer is the controller. livelisted processes that data as a processor under Art. 28 GDPR on the basis of the data processing agreement that forms part of the Terms of Service. Data subjects should contact the customer in these cases; we assist with the response.

3. Visiting the website

When you visit, our hosting provider processes technically necessary data: IP address, time, page requested, browser and device type, referring page. The purpose is delivering the page, defending against attacks and analysing errors. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation). Server logs are deleted after 30 days at the latest.

We currently use no analytics, tracking or advertising cookies. Only technically necessary cookies are set: the sign-in session (signed-in users only) and the chosen language (cookie “ll_lang”, 12 months). These cookies require no consent.

4. Registration and account

On registration we process your email address, optionally name, company name and password (hashed), and sign-in timestamps. Sign-in usually happens through a link sent by email. Purpose: providing the account and performing the contract; legal basis Art. 6(1)(b) GDPR.

If you join the interest list on the homepage, we store your email address and, if given, company name to contact you about the product (Art. 6(1)(f) or (a) GDPR). You can withdraw at any time by email.

5. Using the application

Customers enter projects, units, prices, status changes, reservations with deadlines, notes, sales partners (company name, contact email, invited users) and documents. Every status change is recorded with time and acting person (email address) in the history; this history is deliberately immutable because it documents the sales record.

Sales partners invited by a customer receive their own account with access only to released projects. Their email address is shown to the inviting organisation.

This processing is carried out on behalf of the customer (section 2).

6. Public availability pages, widget and enquiries

Customers can publish a project's availability and price list — as a page under livelisted.app/p/… or as a widget on their own website. No third-party personal data is published; notes, sales partner names and reservation details always stay internal.

Anyone who sends an enquiry about a unit through such a page or widget submits name, email address, optionally phone number and a message. This data is passed to the publishing customer, who answers it; the enquirer receives a confirmation by email. The customer is the controller for the enquiry; livelisted is the processor. Legal basis: consent given on sending (Art. 6(1)(a) GDPR) and pre-contractual steps (lit. b). To prevent abuse, time and number of enquiries per email address are evaluated briefly.

The widget loads data from livelisted.app into the customer's website; the visitor's IP address is transmitted to our hosting provider (section 3). The widget sets no cookies.

7. Emails

We send sign-in links, invitations, confirmations, reminders about expiring reservations, notices of automatic releases and enquiry notifications. Marketing emails are sent only with consent. Delivery is handled by the provider named in section 9.

8. PDF import

If a price list is uploaded as a PDF, we transmit the file's content to Anthropic PBC to extract the units automatically. Only the file content is transmitted, no account or user data. The file is not used to train models and is not stored permanently there. The result is only adopted after review by the user. Customers decide themselves whether to use this function; Excel and CSV imports are processed exclusively on our own systems.

9. Processors and recipients

We use the following providers, with whom data processing agreements under Art. 28 GDPR are in place:

Where providers are based in the USA, transfers rely on the EU-US Data Privacy Framework (adequacy decision of the European Commission) and, in addition, the Commission's standard contractual clauses. Application data is stored in the EU.

Beyond that, we disclose data only where legally required or with your consent.

10. Retention

Account data is kept until the account is deleted; contract data for the statutory retention periods (in Austria generally seven years). Customers' application data is deleted within 90 days after the contract ends unless an export is requested first. Prospect enquiries are managed by the customer and deleted with the customer's data at the latest. Server logs: 30 days. Email delivery logs at the sending provider: up to 30 days.

11. Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time with effect for the future. Contact privacy@livelisted.app. If your request concerns data a customer processes with us, we forward it and assist with the response.

You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at.

12. Security

All connections are TLS-encrypted. Access to customer data is separated per organisation at database level (row level security); sales partners see only released projects. Status histories are immutable. Credentials for third-party services are never stored in source code.

13. Changes

We update this policy when processing or providers change. The current version is always available at livelisted.app/legal/privacy; the date of the last change is shown above.