GnextD Land Portugal
Menu

Version 1.5

Effective 23 August 2026

Privacy notice

How personal data is handled during browsing, land checks, accounts, reports and contact.

Portuguese is the controlling version. This English text is a faithful translation.

This notice is separate from the Terms of use. It explains personal-data processing; it does not turn a check acknowledgement into acceptance of general terms or use consent as a blanket basis for the service.

1. Controller

The controller is Markus Tanz, Self-employed individual, Portuguese tax number PT284143669, Aldeia do Golf, 8125-433 Vilamoura, Algarve, Portugal.

Privacy questions and data-rights requests: [email protected]. Telephone: +351 931 617 738.

2. Data processed

Depending on the feature used, the following data may be processed:

  • Address or place query, coordinates, browser-provided location, map point, parcel reference, municipality, language and check scope.
  • Email, authentication identifier, session data, display name, avatar and language preference where an account exists. If a user chooses “Continue with Google”, Google supplies the authorised basic profile data needed to create or link the account.
  • Check requests, results, reports, job state, retention dates, export/deletion requests and versioned legal acceptances where collected.
  • Content sent by email or telephone and the data needed to reply.
  • Technical data such as IP address, date and time, requested route, response status, request identifier, browser/device and security events.
  • Optional “helpful/not helpful” feedback, stored only as daily counts by content type, identifier and revision, language and answer; the table receives no IP address, browser agent, account, session, location, property or individual event.
  • For the Assistant: the current question and up to two previous user questions held only in the tab, verified guide IDs, retrieval scores and the local explanation. Without improvement permission, the question and answer are not retained as an interaction.
  • With separate improvement permission, a cleaned and generalised question, validated answer, language, a local mathematical vector, the IDs, versions and hashes of the guides used, boundaries, relations and voluntary feedback. These data are not described as anonymous while they can be linked to the guest token or account.
  • After express audience-measurement consent, language, route template and canonical address of an allowlisted public page. The technical request can also expose IP address, browser agent and measurement identifiers to the supplier; searches, parameters, fragments, coordinates, properties, accounts and private routes are not sent as event fields.

3. Purposes and legal bases

Data is used only for defined purposes under the applicable legal basis:

  • Run the requested check, manage an account and reports, provide export/deletion and answer requests — service performance or pre-contract steps, Article 6(1)(b) GDPR.
  • Operate, protect, diagnose and improve service reliability, prevent abuse and defend rights — the operator’s and users’ legitimate interests, Article 6(1)(f), balanced against the data subject’s rights.
  • Aggregate voluntary feedback to identify questions and guides that need correction or improvement — legitimate interest in content quality, Article 6(1)(f), without individual profiling.
  • Answer through the Assistant without retaining the conversation — performance of the requested service, Article 6(1)(b); apply quotas, Turnstile and abuse protection — legitimate interests in security and availability, Article 6(1)(f).
  • Keep a cleaned interaction for retrieval testing, quality improvement and creation of human-review candidates — only under the Assistant-specific consent, Article 6(1)(a). Refusal or withdrawal does not reduce answer quality or change the quota.
  • Optionally measure aggregate use of allowlisted public pages — consent, Article 6(1)(a). Without an affirmative choice, no event is sent; consent can be withdrawn in the footer.
  • Meet tax, accounting, consumer, security and other legal duties — Article 6(1)(c).
  • Use a genuinely optional feature that requires consent — Article 6(1)(a), with a right to withdraw. Browser geolocation permission is not used as blanket consent for other processing.

4. Location and shareable state

Device location is requested only after a user action. A user can instead enter an address or coordinates without browser geolocation.

A confirmed search, coordinates and scope can form part of the page address so the check can be reopened or shared. Those values may remain in browser history, a bookmark, a copied link and technical records associated with the request. Do not share that URL if the location is sensitive.

5. Guest and account use

A guest check is not stored in GnextD private history. The browser stores only a number from 0 to 2 in the sessionStorage key gnextd.land.guest-checks.v1; the key is limited to the tab/session, is not sent to the server and disappears when that tab session ends. Location can still appear in the URL and technical records for the period below.

For an authenticated account, GnextD stores the requests, results and private reports needed for history. Reports remain in private storage and download links are temporary. A user can delete items, export account data and request account deletion.

In the Assistant, guests can make three accepted questions per UTC day and authenticated users twenty. To enforce the quota and pause between questions, the server retains only a daily HMAC identifier derived from the source IP confirmed by Cloudflare; the raw IP is not stored in that quota and the identifier is deleted within 48 hours.

A guest improvement choice is associated with a necessary random token; PostgreSQL stores only its hash. After sign-in, the guest choice is not automatically linked to the account: if the account has no decision, the Assistant asks once.

6. Recipients and external services

Data may be handled by GnextD hosting and its self-hosted Supabase infrastructure, a contracted email-delivery supplier and technical providers acting under instructions and confidentiality duties.

When a remote source, map or geocoder is active, GnextD or the browser may send the query, coordinates, viewed map area, IP address, browser agent and technical data to the identified service — for example DGT and a configured mapping or geocoding supplier. The Data sources & method page identifies services and limits. Official external links are controlled by their respective operators.

When Geoapify address search is configured, the browser communicates only with the GnextD API and never receives the key. The server sends the search text, language and Portugal country filter to Geoapify’s EU endpoint. Under Geoapify’s published privacy policy and DPA, API-request data can include the text, headers, server IP address and timestamp; identifiable request details are generally retained for no more than 24 hours and, exceptionally for suspicious or fraudulent activity, for up to two months.

Cloudflare can process IP address, request, headers and security signals as reverse proxy, TLS, WAF and abuse protection. Its Zaraz CMP records the optional-purpose choice. If and only if that purpose is accepted and the integration is activated, one native Google Analytics 4 tool receives the bounded public event described above; there is no GTM, behavioural advertising, User-ID, Google Signals or event field containing a search, coordinates or account data.

For every guest question, Cloudflare Turnstile validates abuse signals before the request is accepted. GnextD also verifies the action, hostname and, where available, the confirmed remote IP; the challenge token is not used to build a user profile.

Assistant semantic retrieval and explanation run on GnextD local infrastructure with E5, PostgreSQL/pgvector and Qwen through llama.cpp. Questions are not sent to OpenAI or another LLM supplier and are not used for external training.

If a user chooses “Continue with Google”, the browser is sent to Google authentication and Google returns the authorised identifier, verified email and basic profile data to GnextD’s self-hosted Supabase infrastructure. This is used only to create, link and access the account; it neither depends on nor grants consent for analytics or advertising.

GnextD does not sell personal data and does not use the analytics choice to authorise advertising or another purpose.

7. International transfers

Production configuration should favour processing in the European Economic Area. Cloudflare and Google Ireland, when a user chooses Google access or enables optional measurement, may use group entities outside the EEA. Applicable contracts, adequacy decisions, standard contractual clauses and required supplementary measures apply. Google access is optional and measurement remains separately consent-controlled.

8. Retention

Current maximum periods are:

  • Private account checks, results, reports and jobs: up to 12 months, unless deleted earlier by the user or legal retention is required.
  • Terms-acceptance record: while the account or contractual relationship is active and for 3 years after it closes.
  • Normal access logs: 30 days.
  • Security events: 90 days; records connected with a confirmed incident: 3 years.
  • Anonymised account-deletion audit: no more than 90 days after completion.
  • Contact requests: up to 12 months after closure, unless law or the establishment, exercise or defence of claims requires longer.
  • Daily aggregate feedback counts: up to 24 months; a periodic retention sweep removes older rows, which are also removed when new feedback is recorded.
  • Cleaned Assistant interactions retained with consent: up to 90 days; withdrawal immediately excludes them from retrieval and review and starts deletion of linkable data and vectors.
  • Guest-quota HMAC identifiers: no more than 48 hours. Content-free daily topic and confidence aggregates: up to 24 months.
  • Minimal Assistant-choice evidence: for as long as necessary to demonstrate the choice and no longer than 3 years under the documented internal retention policy. Approved GnextD Answers become revisioned editorial content and no longer depend on an originating interaction that is no longer linkable.
  • Optional Google Analytics 4 audience events: no more than 2 months. Measurement cookies accessible on this domain are deleted on withdrawal or rejection; the CMP choice remains until changed or its technical expiry.

9. Data-subject rights

As applicable, a data subject may request access, correction, erasure, restriction, portability and objection, and may withdraw consent without affecting earlier processing. Optional measurement and Assistant improvement permission are separate choices that can be changed in the footer. Rejecting one does not affect the other, answer quality or the quota.

Account controls provide export and deletion requests, including the account Assistant choice and linked interactions. A guest can export or erase data reachable through the current choice token in that browser.

Send a request to the privacy contact. Proportionate identity verification may be needed. A complaint may be made to Portugal’s supervisory authority, Comissão Nacional de Proteção de Dados (CNPD).

10. Security and automated decisions

Controls include separation of public and private data, access control, private report storage, temporary download links and ordered deletion. No measure removes all risk, so incidents will be handled and notified where law requires.

Current results are produced by deterministic GIS rules. GnextD does not make a solely automated decision with legal or similarly significant effects on the user, and generative AI does not decide whether land is buildable.

Every automatic explanation is identified as local AI based on verified guides and may contain errors. The presented guides and sources remain authoritative. An Answer can be published or directly reused only after human review; a source change makes the dependent revision stale until revalidated.

11. Changes to this notice

This notice is version 1.5, effective 23 August 2026. Material changes will have a new version and date and, where required, be communicated directly. Portuguese is the controlling version.

Version 1.5 · Last reviewed: 23 August 2026

Back to Land