Privacy policy
This policy describes what Stagyo actually does with personal data — the service as it is coded, not a template. It applies to visitors of the site, to account holders and their team members, to the people whose data a customer enters in the service, and to the professionals we contact to present Stagyo.
1. Who is responsible
The controller is PropelSaaS Ltd, Office 20779, 182-184 High Street North, East Ham, London E6 2JA, United Kingdom. For any question about this policy or to exercise your rights, write to contact@stagyo.com.
We are established in the United Kingdom and process data under the UK GDPR and the Data Protection Act 2018. Because we offer the service to people in the European Union, the EU GDPR applies to that processing as well; both texts give you the same rights, described in section 8.
2. Data we process as controller
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, e-mail address, agency name, language, date of account creation and of e-mail confirmation, date of acceptance of the Terms | Create and run the account, identify the members of a team, prove that the contract was accepted | Performance of the contract | Lifetime of the account, then 3 years (limitation period for claims) |
| Password | Authentication | Performance of the contract | Lifetime of the account — stored hashed with bcrypt, never in clear, never readable by us |
| Credit ledger, Stripe customer and subscription identifiers, invoices | Billing, accounting, fraud prevention | Performance of the contract; legal obligation to keep accounting records | 6 years after the end of the financial year concerned |
| E-mails we exchange with you (support, notices) | Answer you, keep track of what was agreed | Performance of the contract; legitimate interest | 3 years after the last exchange |
| Server logs (IP address, requested page, browser, date) | Security, detection of abuse, diagnosis of failures | Legitimate interest in keeping the service secure | Rotated automatically; kept at most 30 days |
| View counter and date of last opening of a share link | Tell the agency that its client has opened the presentation | Legitimate interest | Lifetime of the link — no IP address, no browser signature, no named record of the visitor is stored by the application |
| Business contact details of real-estate professionals (name, role, agency, professional e-mail, website, city), the e-mails sent to them and whether they were opened or answered | Present Stagyo to professionals who may be interested (business-to-business prospecting) | Legitimate interest in promoting our service to businesses; you can object at any time, in one click from every e-mail or by writing to us | 12 months after the last contact, or immediately on objection; the fact that you objected is kept so that we never write to you again |
The professional contact details we use for prospecting come from public sources — agency websites, professional directories and property portals — and are limited to what identifies a person in their professional role. We never buy consumer lists and we never prospect private individuals.
3. Data we process on behalf of our customers
A customer decides what goes into its account: the photographs it uploads, the images it generates, and the property records it keeps (title, address, price, notes, viewings, offers, and possibly the names and contact details of sellers, buyers or tenants). For that data the customer is the controller and we are its processor: we process it only on the customer's instructions, to provide the service, and never for our own purposes.
As processor, we undertake to:
- process the data only to provide the service and as documented in this policy and the Terms;
- apply the security measures described in section 7 and bind everyone who has access to the data by a duty of confidentiality;
- engage only the sub-processors listed in section 5, remain responsible for them, and inform customers before adding one so that they can object;
- help the customer answer requests from the people concerned and comply with its own data-protection obligations;
- notify the customer without undue delay of any personal-data breach affecting its data;
- delete the data at the end of the contract, subject to the retention periods below, and provide a copy beforehand on request;
- sign a separate data-processing agreement on request.
Photographs and generated images are kept until the customer deletes them or closes the account. Deleting a property erases its original photo and every generated variant from disk immediately. When an account is closed, its content is erased within 30 days, and disappears from backups within a further 30 days.
If you are a seller, buyer or tenant whose data was entered by an agency, that agency is your first point of contact; we will nevertheless pass on to it any request you send us.
4. What we never do
We do not sell, rent or pass personal data to data brokers or advertisers. We do not use your photographs, images or records to train an artificial-intelligence model, ours or anyone else's. We do not profile you and take no automated decision with legal or similar effects on you.
5. Recipients and sub-processors
- Google (Gemini API) — the photographs you submit for generation, the style instructions, and the generated images. This is the only processing that takes a photograph out of our infrastructure, and it happens only at the moment you start a generation. Google processes this data as our processor under its API terms, does not use it to train its models, and may process it in data centres outside the United Kingdom and the European Union.
- fal.ai (Features and Labels, Inc.) — the same data, for the same purpose, when generation is routed through fal.ai's hosted image models instead of Google's API. fal.ai processes it as our processor under its terms, does not use it to train models, keeps the inputs and outputs only as long as needed to return the result, and processes it in the United States.
- Stripe — payments. Card details are entered on Stripe's pages and never pass through our servers; we keep only customer, subscription and transaction references. Stripe acts as an independent controller for the payment data it collects.
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Allemagne — serveurs situés à Helsinki, Finlande — hosting of the application, its database, uploaded and generated files, and encrypted backups, in the European Union.
- Our e-mail delivery provider — sends transactional e-mails (confirmation, password reset, receipts, invitations) and the prospecting e-mails described in section 2; receives the recipient's address and the content of the message.
- Umami (audience measurement) — see section 6; runs on our own infrastructure and shares nothing with third parties.
We may also disclose data when the law requires it, to a court or authority with jurisdiction, or to a successor that takes over the service, in which case you will be informed.
International transfers. Data is stored in the European Union and accessed from the United Kingdom, which the European Commission recognises as providing adequate protection. Where a sub-processor processes data in the United States (Google, fal.ai, Stripe), the transfer is covered by that provider's certification under the EU-US Data Privacy Framework and its UK extension, and by standard contractual clauses as a fallback. You can obtain a copy of the applicable safeguards by writing to us.
6. Cookies and audience measurement
Stagyo sets no advertising or cross-site tracking cookie and loads no third-party script of that kind. The only cookies set are strictly necessary to run the service and are exempt from consent:
stageo_session— keeps you signed in (14 days, signed, HttpOnly).stageo_form— anti-CSRF protection for forms (1 hour).stageo_share— remembers that a protected share link has been unlocked (8 hours, limited to that one link).stageo_lang— remembers the language you chose (1 year). It holds a language code and nothing else.
To know which pages are read and whether the sign-up form works, we use Umami, an open-source audience-measurement tool that we host ourselves. It sets no cookie, stores no IP address and builds no profile: it counts page views and a few named events (such as “sign-up submitted”) in a form that cannot be linked to a person. This is why no consent banner is shown. You can nevertheless opt out by enabling the “Do Not Track” setting of your browser, which Umami honours.
7. Security
Traffic is encrypted with HTTPS (HSTS enabled). Passwords are hashed with bcrypt. Each customer's data is partitioned: no request from one account can reach the properties, photographs or members of another. Public share links expose only the visuals selected by the customer, with no access to the rest of the account, and can be revoked at any time. Backups are encrypted and kept in the European Union. Access to production systems is restricted to the people who operate the service and protected by key-based authentication. If a breach affecting your data occurred, we would inform you and the competent authority as the law requires.
8. Your rights
You have the right to access the data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw a consent you have given. Write to the address in section 1; we may ask you to confirm your identity, and we answer within one month. Most of your data can also be seen and edited directly in the application.
You may lodge a complaint with a supervisory authority: in the United Kingdom, the Information Commissioner's Office (ico.org.uk); in France, the CNIL (cnil.fr); or the authority of the EU country where you live or work. We would rather hear from you first, and will do our best to resolve the issue.
9. Changes to this policy
We update this policy when the service or the law changes. Material changes — a new sub-processor, a new purpose — are announced by e-mail or in the application before they take effect. The date of the current version is shown below.
Last updated: Sep 1, 2026