Privacy
Privacy policy
Effective 2026-05-21 · Data controller: Opes Terra FZCO (trading as Belgrave Estates)
Draft — pending legal review
This policy explains how Opes Terra FZCO (trading as Belgrave Estates)("Belgrave", "we") collects, uses, stores and shares personal data when you use belgraveestates.com, our private-client portal, our brokers' portal, or speak to us by phone, WhatsApp, or email. It is written to satisfy the UK GDPR, the EU GDPR, the UAE Personal Data Protection Law (PDPL), the California Consumer Privacy Act (CCPA/CPRA), and equivalent frameworks in the markets we operate in.
1. Who we are
Belgrave is a luxury real-estate brokerage operating in the UK, the GCC, and selected European jurisdictions. The data controller for this website is Opes Terra FZCO (trading as Belgrave Estates). Registered address: — see footer of belgraveestates.com. Questions about this policy go to [email protected].
2. What we collect
- Account data — email, password (hashed by our identity provider, Keycloak; we never see the plaintext), name, phone, preferred language, country of residence.
- KYC data — passport / national-ID image, proof of address, source-of-funds declaration. Encrypted at rest with envelope encryption; readable only by Belgrave compliance staff.
- Transaction data — properties you viewed, saved, enquired about; offers made; viewings booked.
- Communication data — emails, WhatsApp messages, call recordings (only where you have been told the call is recorded; jurisdiction-dependent).
- Device + telemetry — IP address, browser fingerprint hash, traceparent, device cookie, page interactions. Used for fraud prevention, security, and product improvement. Never sold.
3. Why we collect it
Each purpose maps to a UK/EU GDPR lawful basis:
- Contract performance — to broker your transaction, we must know who you are and what you want.
- Legal obligation — AML / KYC record-keeping (UK MLR 2017, EU AMLD, equivalent regional rules).
- Legitimate interest — security, fraud prevention, product improvement. Balancing test on file; you may object.
- Consent — analytics + marketing cookies, marketing emails, promotional WhatsApp. You can withdraw at any time via your preferences page or by adjusting your .
4. Who we share it with
Belgrave operates as a private partnership and brokers transactions on your behalf. Your data is shared only with:
- The Belgrave advisors assigned to your account.
- External brokers (in the "belgrave-brokers" realm) when you ask us to introduce them. Each such introduction is consented to per-property.
- Conveyancing solicitors, mortgage providers, surveyors — only when you have engaged them for a transaction.
- Regulators + tax authorities, where legally compelled.
- Sub-processors who run our infrastructure (Keycloak / Postgres / OpenSearch / our cloud provider). All under written data-processing agreements; full list on request.
We never sell your data. We never share it with advertising networks. Marketing cookies (if you opt in) are first-party, on our own measurement infrastructure; we do not use third-party trackers for re-marketing.
5. How long we keep it
- Account data: while your account is active + 7 years after closure (UK MLR record-keeping).
- KYC data: 7 years after the last transaction (or longer where local regulators require it).
- Transaction data: 7 years.
- Communication data: 12 months (24 months for closed transactions).
- Telemetry / device data: 12 months by default; risk-signal time-series is held for 180 days under our TimescaleDB retention policy.
6. Your rights
Under UK / EU GDPR you have the right to access, rectify, port, delete, restrict, and object to the processing of your personal data, plus the right not to be subject to purely automated decisions. UAE PDPL and California residents have similar (not identical) rights. Exercise any of these by emailing [email protected] or through your account preferences.
We respond within 30 days. Identity verification is required — we will not act on a deletion request unless we can confirm the request comes from the data subject.
7. International transfers
Belgrave operates in multiple jurisdictions. When we move data between them (e.g. a UK-resident client engaging on a Dubai listing), we rely on the UK International Data Transfer Agreement, EU Standard Contractual Clauses, or equivalent transfer mechanisms. We never transfer KYC data to a jurisdiction with weaker statutory protection than its origin.
8. Security
- Passwords stored only as hashes inside our identity provider; multi-factor authentication available for every account.
- KYC documents and other sensitive fields are envelope-encrypted with per-category keys held in a hardware-backed secret store; no Belgrave engineer has direct access.
- All admin actions on customer accounts are logged with operator identity + step-up MFA + reasoned audit trail.
- Annual penetration tests; documented disaster-recovery procedures with monthly rehearsal.
9. AI features
We offer an AI-powered concierge (via the Model Context Protocol). To prevent leakage of personal data into AI providers, the AI is permitted to browse listings and generate links to our booking / enquiry / call-back forms — but it cannot collect your name, email, or phone in chat. All contact details are captured on belgraveestates.com under your own session, with cookie consent and CSRF protection in place.
10. Changes to this policy
Material updates trigger a banner the next time you sign in. The effective date at the top of this page is authoritative. Previous versions are kept in our document archive — request a copy at any time.
11. Complaints
If you believe we have mishandled your data, please raise it with our privacy team first: [email protected]. You also have the right to complain to the supervisory authority in your country (in the UK, the Information Commissioner's Office; in the EU, your national DPA; in the UAE, the relevant emirate's data-protection authority).