Scout - Legal
Privacy Policy
Effective 21.07.2026
Applies to: https://www.scoutgo.app (including the marketing site and the early-access waitlist), the Scout mobile application for iOS, and any related services (together, “Scout” or the “Service”).
This Privacy Policy explains who we are, what personal data we process, why, on what legal basis, who we share it with, where it goes, how long we keep it, and how you can exercise your rights under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums).
If anything is unclear, write to privacy@scoutgo.app.
1. Who we are (Data Controller)
Epic House SIA (SIA), registration number 40203716958, VAT number LV40203716958, with registered office at Duntes iela 6, Riga, LV-1013, Latvia, registered at Register of Enterprises of the Republic of Latvia (the “Company”, “we”, “us”), operates the Service.
The Company is established in Latvia (EU). Our lead supervisory authority under the GDPR one-stop-shop is the Datu valsts inspekcija (DVI) in Riga. Data subjects in any other EU/EEA Member State retain the right to lodge a complaint with their own local supervisory authority (e.g., the AEPD in Spain).
- General contact: hello@scoutgo.app
- Privacy / data-subject requests: privacy@scoutgo.app
- Data Protection Officer: - - privacy@scoutgo.app
For the avoidance of doubt:
- We act as data controller for personal data of our customers (real-estate agents and agencies who sign up for Scout), website visitors, waitlist sign-ups, and prospects.
- We act as a data processor for personal data of property leads / buyers that our customer agents collect through the Service. Our processing on their behalf is governed by the Data Processing Agreement at https://www.scoutgo.app/dpa.
- If you are a buyer, property-seeker or listed agent: the agent or agency you dealt with - not Scout - is the controller of your personal data and your point of contact for any privacy request. You may still write to privacy@scoutgo.app and we will route your request to the responsible agent without undue delay.
2. What personal data we process
2.1 Information you give us as a customer (agent or agency)
- Account data: name, email address, role, organisation membership.
- Authentication data: magic-link tokens, session identifiers.
- Profile data: phone numbers, optional photo, language preference.
- Channel credentials: WhatsApp connection state (via the WhatsApp Web protocol) and Google Calendar tokens. These secrets are encrypted at rest.
- Subscription and billing data: payment-provider customer ID, subscription status, invoiced address, VAT / tax identification number. Card data is held by our payment provider; we never see it.
- Support data: the content of any email, ticket or chat you send us.
2.2 Information you give us when you join the waitlist
If you request early access through our website, we collect the email address, name, and type of interest (for example, individual agent or agency) that you submit in the waitlist form. See section 3 for how we use it.
2.3 Information generated by your use of the Service
- Lead conversation data: when buyers contact you via WhatsApp, Scout stores their phone number, name (when provided), the full conversation, any voice notes (kept as audio files only - we do not transcribe them), and the search preferences they expressed (budget, location, type of property).
- Property data: properties you create, search for, share, or view, and associated viewing offers, scheduled times, and outcomes.
- Listing-agent contact data: when you ask Scout to coordinate a viewing for a property listed on a third-party portal, we may extract the listing agent’s professional contact details (name, phone, email) from publicly available property pages and use them solely to contact that agent on your behalf.
- Usage data: technical logs (request paths, response codes, timestamps, truncated IP), feature usage, error reports.
- Device data (mobile): device model, OS version, app version, push notification token.
2.4 Information we receive from third parties
- From our payment provider: subscription events, payment status.
- From our email provider: sign-in / magic-link delivery status.
- From third-party property-listing sources: property listings and the publicly-displayed contact details of listing agents.
- From WhatsApp: messages addressed to your channel and basic sender metadata.
2.5 Cookies, analytics and similar technologies
On our website we use only strictly-necessary cookies to keep you signed in and to prevent CSRF attacks. We do not use advertising cookies or cross-site trackers. See the Cookie Policy.
The Scout mobile app uses first-party product analytics (a provider hosted in the EU - Frankfurt) to understand how features are used and to find and fix bugs. Analytics events are keyed to a pseudonymous account identifier - we do not send your email or name to the analytics provider - and the data stays within the EEA. You can turn product analytics off at any time in Account → Privacy inside the app.
We do not track you across other apps or websites for advertising. The Scout mobile apps do not use Apple’s App Tracking Transparency (ATT) data, and we declare “Data Not Used to Track You” in our App Store privacy answers.
2.6 Special categories of data
We do not intentionally collect special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data, health data, sex life or sexual orientation). If a buyer volunteers such information in a free-text message, it is processed only to the extent necessary to serve the agent and is subject to the same retention rules as ordinary message content.
2.7 Children
Scout is intended for professional real-estate users only. We do not knowingly process the personal data of children under 14. If you believe a minor has contacted an agent through Scout, write to privacy@scoutgo.app and we will delete the data without undue delay.
3. Why we process your data and on what legal basis
| Purpose | Categories of data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Provide the Service to customer agents | Account, profile, channel credentials, lead data | (b) Performance of the subscription contract |
| Process payments and meet tax obligations | Billing, VAT/tax ID, invoices | (b) Performance of contract; (c) Legal obligation (Latvian tax and accounting law; EU VAT rules) |
| Operate AI-assisted lead qualification and search | Lead messages, search criteria | (b) Performance of contract; or (f) Legitimate interest in operating an effective product |
| Contact listing agents to coordinate viewings | Listing-agent professional contact details | (f) Legitimate interest of customer agents in arranging viewings; balanced against the listing agent’s reasonable expectations as a publicly-listed professional |
| Manage the early-access waitlist and send access / launch updates | Email, name, type of interest | (a) Consent - opt-in; withdraw at any time |
| Security, fraud prevention, abuse mitigation | Logs, IP, device data | (f) Legitimate interest in protecting the Service |
| Comply with legal requests | Any | (c) Legal obligation |
| Send service emails (magic links, billing, security alerts) | (b) Performance of contract | |
| Send product-update emails | (a) Consent - opt-in only; you can unsubscribe at any time | |
| Defend legal claims | Any | (f) Legitimate interest |
We carry out a written balancing test (“legitimate interest assessment”) before relying on Art. 6(1)(f) and you can request a copy by writing to privacy@scoutgo.app.
You can withdraw waitlist or marketing consent at any time via the unsubscribe link in any email or by writing to privacy@scoutgo.app; withdrawal does not affect processing carried out before you withdrew.
4. Automated decisions and AI
Scout uses third-party large-language-model (LLM) AI for exactly two purposes:
- Translating lead chat messages into the agent’s language (the lead’s message text is sent to the model).
- Generating property-listing descriptions from property data and listing photos (no client personal data is sent).
All model calls are made under contractual zero-data-retention terms, enforced on every request: prompts and outputs are not retained by the AI provider and are not used to train any model. Some AI providers are located in the United States; those transfers are covered by EU Standard Contractual Clauses. We do not use your data to train AI and we do not send lead or client personal data for description generation.
These tools support our customer agents - they do not replace human decision-making. A human agent confirms every viewing offer, every property shown to the buyer, and every action sent on the buyer’s behalf. We therefore consider that no “solely automated decision” within the meaning of GDPR Art. 22 is taken.
You can object to AI processing by writing to privacy@scoutgo.app. If you do, we will switch your account to a non-AI mode where available, or, if AI is inseparable from the Service, help you cancel your subscription.
4.1 Google user data (Limited Use)
Scout connects to the Google Calendar API (with your explicit consent, granted via Google's OAuth screen) to check availability and schedule property viewings on your behalf.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular, Google user data (raw, aggregated, or derived):
- is used only to provide and improve the user-facing scheduling features you have requested;
- is never sold, and never used or transferred for advertising purposes;
- is never used to create, train, or improve foundational or generalised AI/ML models - neither by us nor by any third party;
- where AI processing is involved in serving your request, is processed by our AI provider strictly under the contractual zero-data-retention terms described above: it is not retained by the provider and is not used for model training or any secondary purpose.
You can disconnect Google Calendar at any time from the app or via your Google account permissions; we then delete the associated tokens.
5. Who we share your data with (recipients & sub-processors)
We share data only with the categories of recipients below, all of whom are bound by written data-processing agreements:
- Cloud, hosting and storage providers
- Messaging, email and push-notification providers
- Product-analytics provider (EU-hosted)
- AI providers (under contractual zero-data-retention terms)
- Payment provider
- Property-data sources - only as sources of listings, not as recipients of your data
- Professional advisers (lawyers, auditors) under confidentiality
- Public authorities when legally required
The categories of sub-processor, and how to request the current itemised list (which names each one, with its purpose, location and transfer safeguard), are set out on our Sub-processors page.
We do not sell, rent, trade or otherwise share personal data with anyone for advertising or marketing.
6. International transfers
Most of our infrastructure is located in the European Union. Some sub-processors - for example certain AI, payment, push-notification and hosting-control-plane providers - are located in the United States or the United Kingdom and may therefore receive personal data outside the EEA.
For each such transfer we rely on the European Commission’s Standard Contractual Clauses (SCCs) (Decision 2021/914), the UK International Data Transfer Addendum where relevant, or an applicable adequacy decision, together with a transfer impact assessment.
You may request details of the safeguards for a specific transfer - including a copy of the SCCs and the assessment - by writing to privacy@scoutgo.app.
7. How long we keep your data
| Data class | Retention |
|---|---|
| Active account data | While your subscription is active |
| Inactive account data | 24 months after last login, then deleted or anonymised |
| Waitlist sign-ups | Until access is granted or you ask to be removed; reviewed at least every 12 months |
| Lead conversation data | 24 months after the lead is closed, unless the agent purges sooner |
| Soft-deleted messages | 30 days, then permanently deleted |
| Billing records, invoices, accounting documents | 10 years (Latvian Accounting Law) |
| Server / security logs | 12 months |
| Cookie-consent records | 12 months |
| Backups | 30 days rolling, encrypted |
The full schedule lives in our internal Retention Policy and is reflected in code through database TTL indexes and scheduled purge jobs.
8. Your rights
Under GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (“right to be forgotten”, Art. 17)
- Restrict processing (Art. 18)
- Portability - receive your data in a structured, machine-readable format (Art. 20)
- Object to processing based on legitimate interest, including profiling (Art. 21)
- Withdraw consent at any time, where processing is based on consent (Art. 7(3))
- Not be subject to a solely automated decision with legal or similarly significant effect (Art. 22)
- Lodge a complaint with our lead supervisory authority - Datu valsts inspekcija (DVI), Elijas iela 17, Riga LV-1050, Latvia, https://www.dvi.gov.lv - or with the supervisory authority of your habitual residence (for example, the AEPD at https://www.aepd.es if you reside in Spain)
You can delete your account at any time from your in-app Account screen, and manage analytics in Account → Privacy. To exercise any other right - including access to or a portable copy of your data - write to privacy@scoutgo.app from the email address linked to your account. We respond within one month (extendable by two further months for complex requests, with notice).
We will not charge you for exercising your rights, except where requests are manifestly unfounded or excessive.
9. Security
We protect your data with:
- TLS in transit; AES-256 (or equivalent) at rest for managed databases.
- Application-level encryption of secrets such as third-party bot tokens.
- Strict role-based access; multi-factor authentication on admin accounts.
- Daily encrypted backups with a tested restore procedure.
- Regular security reviews of code that touches personal data.
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the DVI within 72 hours and, where the risk is high, notify you without undue delay.
10. Changes to this policy
We may update this policy. When we do, we will change the version and effective date at the top, and - for material changes - notify customers by email at least 14 days in advance. The current version is always available at https://www.scoutgo.app/privacy.
Previous versions are archived and available on request.