DreamHouse Legal

Privacy Policy

This Privacy Policy explains how DreamHouse UG (limited liability) (“DreamHouse”, “we”, “our”) collects, uses, discloses and protects your personal data when you interact with our websites, applications, services, products and tools (collectively, the “Services”).

Effective date: 1 June 2025

1. Scope and updating of this privacy policy

This Privacy Policy applies to your use of our Services, regardless of the device or platform you use to access them, including mobile devices and applications.

We may update this Privacy Policy at any time. If we make material changes, we will post the updated version on our website and indicate the effective date above. If you have registered with us, we will notify you of material changes via email.

2. Responsible person

The controller within the meaning of the General Data Protection Regulation (GDPR) is DreamHouse UG (limited liability), Am Brunnhölzl 17, 84106 Volkenschwand, Germany. References in this policy to “DreamHouse”, “we” or “our” always refer to this legal entity.

3. Data Protection Officer and contact person

We have appointed a Data Protection Officer (DPO) to oversee the protection of your personal data. If you have any questions about this policy or about data protection at DreamHouse, you can reach the DPO at:

Data Protection Officer support@DreamHouse.eu
DreamHouse UG (limited liability)
Am Brunnhölzl 17
84106 Volkenschwand, Germany

4. What personal data do we collect and process?

We collect personal data when you use our Services, create an account, fill out forms, update your settings, contact our support team, or otherwise interact with us. We also receive information from other sources, such as credit bureaus and data providers.

4.1 Data you provide directly

Examples include:

If you choose not to provide required information, you may be unable to register or use certain Services.

4.2 Data collected automatically

4.3 Data collected via cookies and similar technologies

We use cookies and similar technologies to collect activity and device data from the devices you use to access DreamHouse Services. This includes pages visited, session duration, links clicked, ad interactions, device information (model, OS version, browser), advertising identifiers, unique device tokens and IP address.

4.4 Data from other sources

We combine data you provide with data from these sources, ensuring that third parties are authorised to share it with us.

4.5 Data shared via social media

Social network links on our Services allow you to share content or recommend products. No personal data is transmitted to these networks unless you actively click their links. Once you do, the respective network’s privacy policy governs your data.

5. Purposes and legal bases of data processing

We process your personal data for various purposes and under different legal bases, including to provide and improve our Services, offer personalised experiences, communicate about your account, deliver customer support, provide marketing, and prevent fraud or illegal activity. The key legal bases are summarised below.

5.1 Contract performance — Article 6(1)(b) GDPR

We process data to:

Where necessary, we share data with:

5.2 Legal obligations — Article 6(1)(c) GDPR

Data may be shared with law enforcement, courts, regulatory authorities, third parties with statutory rights, tax authorities, external service providers and credit reporting agencies, in each case subject to legal review.

5.3 Vital interests — Article 6(1)(d) GDPR

We process data to detect, prevent and investigate unlawful acts that may harm your vital interests or those of others. Where required, we share data with law enforcement, courts, government bodies and service providers.

5.4 Legitimate interests — Article 6(1)(f) GDPR

We process data for our legitimate interests, provided they are not overridden by your rights. Measures include:

Possible recipients include external service providers, other DreamHouse users, authorities, courts, credit bureaus, background check services, debt collection agencies and copyright holders.

Information about your right to object to processing based on legitimate interests is provided in the section “Your rights”.

5.5 Consent — Article 6(1)(a) GDPR

With your consent, we process personal data to personalise and measure advertising, analyse user behaviour for improvements, process precise location data, and provide specific services with third-party partners. You may withdraw your consent at any time.

We do not disclose or sell your personal data to third parties for marketing purposes without your consent.

5.6 Automated decision making

We may use technologies considered automated decision-making or profiling. We do not make automated decisions that have significant effects on you unless necessary for a contract, authorised by law or based on your consent. Details about your rights in this context appear in section 8.

6. International data transfer

Some recipients of your personal data are located outside your country. When transferring data to such recipients, we implement appropriate safeguards.

6.1 Transfers from the European Economic Area

We transfer data outside the EEA only on the basis of appropriate safeguards or adequacy decisions. Countries currently considered to provide adequate protection include Andorra, Argentina, Canada (PIPEDA), Switzerland, Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, South Korea, New Zealand, Uruguay and the United Kingdom.

7. Storage period and deletion

We store personal data as permitted by law and only as long as necessary for the purposes described in this policy. Afterwards, we delete or anonymise data in accordance with our retention rules, unless legal obligations require longer storage (e.g. taxation, accounting, auditing). In Europe, retention periods typically range from 6 to 10 years for contracts and correspondence.

Where deletion is not possible, we may restrict processing (e.g. by blocking data) until statutory limitation periods expire. Our retention decisions depend on:

Specific retention periods are documented in our internal Data Retention Policy.

8. Rights of the data subject

Subject to national law restrictions, you have the right to access, rectify, erase, restrict processing and transfer your personal data. You may withdraw consent, object to processing based on legitimate interests, and lodge a complaint with a supervisory authority.

Our competent supervisory authority is:

Bavarian State Data Protection Authority Post Office Box 1349
91504 Ansbach, Germany

Exercising your rights

You can:

We generally process rights requests free of charge. For manifestly unfounded or excessive requests, we may charge a reasonable fee or refuse to act, as permitted by law.

To exercise your rights, please contact us using the details in section 3.

9. Cookies and similar technologies

We use cookies and similar technologies to provide a better, faster and more secure experience and to deliver personalised advertising. Cookies may be:

We use both session cookies (active until you close your browser) and persistent cookies (stored longer). Where possible, we implement appropriate security measures to prevent unauthorised access to cookies and similar data.

Your choices

You can manage cookie settings in your browser or device and decide whether we may use cookies for personalised advertising and analytics. Opting out of personalised advertising does not remove ads; they will simply be less tailored to you.

For details about analytics and advertising preferences, refer to the relevant controls in your account or device.

10. Data security

We protect your personal data with technical and organisational measures designed to minimise risks associated with loss, misuse, unauthorised access, disclosure and alteration. Measures include firewalls, encryption, access controls and physical safeguards at our data centres.