ParcelDossier

Privacy Policy

Version: v1.0 | Effective: 2026-08-30

ParcelDossier is a property assessment service provided by Cheppers Zrt. This Privacy Policy describes what data the Provider handles in connection with ParcelDossier, why it handles it, where it is processed, who it is shared with, how long it is kept, and how it is backed up. The six data-handling headings below are named and ordered so that each topic can be located without interpretation.

Who we are

Cheppers Zrt., a company incorporated in Hungary, provides ParcelDossier and is the seller of record for it in AWS Marketplace. This Policy refers to Cheppers Zrt. as “the Provider”, and to the legal entity that subscribes to ParcelDossier as “the Customer”.

The Provider acts in two different capacities, and the distinction matters throughout this Policy:

Registered address: 1137 Budapest, Szent István körút 22. 3/8., Hungary

Privacy contact: product@cheppers.com

Scope

This Policy covers the ParcelDossier commercial assessment API, the tenant console made available with it, and the buyer registration flow that AWS Marketplace directs subscribers to. It does not cover any separate Cheppers product, and it does not cover the Customer’s own handling of the Output it receives.

The service is designed to key on the parcel rather than on the person. An assessment is anchored to a property, a parcel identifier, and public records about that parcel. The Provider does not seek property-owner names, does not build profiles of individuals, does not sell personal data, and does not act as a data broker. Where personal data is present in a payload, it is present because the Customer chose to include it, and the Provider processes it only to return that Customer’s assessment.

The Provider makes no representation as to the correctness or completeness of any estimate, opinion, coverage value, or confidence value in the Output. That subject is governed by the End User License Agreement and Terms of Service at legal/EULA.md, not by this Policy.

The two classes of data we handle

Every heading below answers for both of the following classes. They are defined once here so that the six topics do not have to redefine them.

Account data is the data that identifies and administers the Customer as a subscriber. It comprises the Customer’s AWS account identifier and licence identifier obtained from AWS Marketplace, the registration email the buyer supplies on the registration page, API key metadata consisting of a non-secret key prefix and a hash of the key but never the key itself, console login and session records, support correspondence, and the usage and billing records that follow from the subscription.

Submitted property data is the property payload the Customer submits and everything derived from it. The payload is an Assessment Context shaped according to RESO Data Dictionary 2.0 field naming, and it may include Media[] photo URLs together with the images the service fetches from them. Derived data comprises the generated assessment, the evidence records the service compiles about the parcel, the per-lane processing logs for the assessment, and the coverage and confidence values reported for each assessment dimension.

Data collection

Account data. Account data is collected at subscription and during ordinary support. When a buyer subscribes in AWS Marketplace and lands on the registration page, AWS supplies a registration token which the Provider exchanges for the buyer’s AWS account identifier and licence identifier through the AWS Marketplace resolve-customer call. The buyer supplies a registration email on that page. API key metadata is generated by the Provider when a key is issued or rotated. Console login records and support correspondence are collected as they occur. The Provider does not buy account data from third parties and does not collect it from any source other than AWS Marketplace, the registration form, and the Customer’s own use of the service.

Submitted property data. Submitted property data comes only from the Customer’s own API request. The Provider does not scrape or otherwise acquire listing content from real estate portals, from MLS feeds, or from any listing syndication source, and it holds no MLS licence. A Media[] URL is fetched only when the Customer supplies it in a payload, only for the duration of the assessment that uses it, and only through server-side request forgery guards that restrict which network destinations may be reached (SEV-04). Where a photo cannot be fetched, the affected dimension reports coverage of none rather than substituting a guess. Separately from the payload, and about the parcel rather than about any person, the service retrieves public records and free federal data as described under Data usage.

Data storage

Account data. Account data is stored in Amazon Web Services in the us-east-1 region, in a managed relational database operated by the Provider for the commercial service. It is encrypted in transit using TLS and encrypted at rest by industry-standard means (INFRA-04). API keys are never stored: the Provider retains only a non-secret prefix used to identify the key and a hash used to verify it (TEN-02), so a copy of the Provider’s database does not yield a usable credential. The commercial database is separate from any other Cheppers system and holds no data from the Provider’s own non-commercial applications.

Submitted property data. Submitted property data is stored in the same AWS us-east-1 environment and under the same encryption in transit and at rest (INFRA-04). Every commercial record carries an explicit tenant identifier, and the tenant identity used to read or write a record is derived from the API key presented on the request rather than from any parameter the request supplies (CTX-03, TEN-03). One Customer’s payloads, assessments, evidence records, and logs are therefore not reachable from another Customer’s request. Images fetched from a Media[] URL are held only for the duration of the assessment that uses them.

Data usage

Account data. Account data is used to authenticate the Customer, to issue, rotate, and invalidate API keys, to enforce per-tenant rate and concurrency limits (TEN-04), to operate the tenant console, to meter and reconcile the subscription with AWS Marketplace, to send service and account communications, and to respond to support requests. It is also written into the append-only security audit log described below where an event is security-relevant. Account data is not used for advertising, is not used to build a profile of any individual beyond what administering the subscription requires, and is not sold.

Submitted property data. Submitted property data is used solely to produce the assessment for the Customer that submitted it. Every processing step that touches it is listed here so that no flow is hidden:

The Provider does not use submitted property data to train, fine-tune, or otherwise adapt any general-purpose model, and does not permit any sub-processor to do so. There is no cross-customer cache, index, or memory that is written from one Customer’s submitted property data and read while serving another Customer.

One narrow further use is permitted, and only in the form the End User License Agreement defines. Clause 10 of legal/EULA.md grants the Provider the right to use De-identified Aggregate Data to operate, evaluate, calibrate, and improve the service. In plain language, that clause permits the Provider to learn from patterns across many customers after every identifier of the Customer, of the Customer’s clients, of any natural person, and of any specific parcel or address has been removed and the remainder has been combined with data from other customers. It does not permit the Provider to publish or disclose anything that identifies a Customer or an individual transaction, to reconstruct a Customer’s confidential information, or to re-identify anyone. Because that data is irreversibly de-identified before it enters the aggregate corpus, it is no longer associated with the Customer, which is why the retention heading below treats it separately.

Data sharing

Account data. Account data is shared with Amazon Web Services in two capacities. AWS is the infrastructure provider on which the service runs. AWS Marketplace is the billing operator: it resolves the buyer at subscription, notifies the Provider of subscription lifecycle events, and receives the hourly metering calls. A metering call carries only the pricing dimension name, the quantity, the usage hour, and the customer and licence identifiers AWS itself issued. It carries no property content, no assessment output, and no personal data beyond those AWS-issued identifiers. Account data may also be disclosed to a professional adviser under a duty of confidence, or to a public authority where the Provider is legally compelled to disclose it. Account data is not sold, is not shared for advertising, and is not shared for any other purpose.

Submitted property data. Submitted property data is shared with Amazon Web Services as the infrastructure provider, and with Amazon Bedrock as the AWS inference service, in both cases in the us-east-1 region and in both cases as a sub-processor acting on the Provider’s documented instructions. It is not shared with AWS Marketplace, which receives metering quantities only.

Beyond AWS, the service queries public-record and free federal data sources about the subject parcel. These queries are outbound requests for information about a property, not disclosures of the Customer’s identity, and they are stated here rather than left to be discovered:

No query to any of these sources carries the Customer’s identity, the Customer’s account data, any API key, or any assessment output. The Provider does not sell submitted property data, does not share it for advertising, and does not disclose it to any third party other than the sub-processors named below and, where legally compelled, a public authority. Where the Provider is compelled to disclose, it will give the Customer notice where it is lawful to do so and will disclose no more than is required.

The current sub-processors are Amazon Web Services for infrastructure hosting in us-east-1, Amazon Bedrock as an AWS service for model inference in us-east-1, and AWS Marketplace for subscription, entitlement, and metering. Annex III of legal/DPA.md holds the current list in full, and that Annex, not this paragraph, is the list of record.

Data retention

Account data. Account data is deleted within 30 calendar days of the later of a written deletion request from the Customer and the termination or expiry of the Customer’s subscription. This is the same timeframe stated in clause 12.1 of legal/EULA.md. Two categories are expressly retained beyond it. Security audit records are retained for at least 1 year, and for any longer period applicable law requires, because a security log that can be erased on request is not an audit log (OBS-01). Billing and metering records required for tax, accounting, statutory bookkeeping, or AWS Marketplace reconciliation are retained for the period applicable law requires, and are not deleted before that period ends.

Submitted property data. Submitted property data is deleted within 30 calendar days of the later of a written deletion request from the Customer and the termination or expiry of the Customer’s subscription, on the same timeframe as account data and on the same timeframe as clause 12.1 of legal/EULA.md. Deletion covers the submitted Assessment Contexts, the generated Output, the evidence records, and the per-assessment processing logs. De-identified Aggregate Data as defined in clause 10.2 of legal/EULA.md is not covered: having been irreversibly de-identified before it entered the aggregate corpus, it is no longer associated with the Customer, cannot be located by reference to the Customer, and is therefore neither returned nor deleted. The procedure for making a deletion request is published separately as the customer data deletion procedure, and the 30 calendar days timeframe stated here is the timeframe that procedure operates to.

Data backup

Account data. Account data is backed up through the managed backup facility of the database service in which it is stored. Backups remain within the same AWS us-east-1 region as the primary data and are encrypted at rest by the same means. Backups are not copied to any other region and are not shared with any party beyond the sub-processors named above.

Submitted property data. Submitted property data is backed up by the same managed facility, within the same region, and under the same encryption. One consequence is stated plainly rather than left implicit: when data is deleted under the retention heading above, backup copies containing it are not individually purged. They age out of the backup set as the backup retention window elapses, and the data is not restored into the live service in the interim. The backup retention window is 30 days.

For account data, where the Provider is the controller, the legal bases are:

For submitted property data, the Provider is the processor and the Customer is the controller. The Customer determines the legal basis on which that data is processed and warrants, under clause 5.1 of legal/EULA.md, that it holds the rights, licences, consents, and permissions necessary for the submission.

International transfers

Cheppers Zrt. is established in the European Union, and processing for the commercial service occurs in the AWS us-east-1 region in the United States. Personal data therefore crosses an international transfer boundary.

The transfer mechanism is the European Union Standard Contractual Clauses, incorporated by reference through clause 6 of legal/DPA.md, with the annexes of that Addendum populating the annexes of the Standard Contractual Clauses. Module Two applies where the Customer is the controller and the Provider is the processor, and Module Three applies where an onward transfer to a sub-processor is involved.

Because all runtime processing, including model inference, occurs in us-east-1, there is a single processing location to disclose. No inference is performed in the European Union, and no separate European inference disclosure is required.

Your rights

Where the Provider is the controller of personal data about an individual, that individual has the rights that data protection law gives them, namely the rights of access, rectification, erasure, restriction of processing, data portability, and objection to processing carried out on the basis of legitimate interests.

To exercise a right, write to the privacy contact identified under Contact below. The Provider will respond within the period applicable law allows and may ask for information reasonably necessary to verify identity before acting on a request.

Where the request concerns submitted property data, the Provider is the processor rather than the controller. In that case the Provider will refer the request to the Customer that submitted the data and will assist that Customer in responding, as clause 4 of legal/DPA.md requires. The Provider will not act unilaterally on data another organization controls.

Any individual also has the right to lodge a complaint with a data protection supervisory authority. The Provider’s lead supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH). A complaint may in any event be lodged with the supervisory authority of the individual’s habitual residence or place of work.

Changes to this policy

Each published version of this Policy carries a version number and an effective date, stated on line 3 of this document. The version in force at the time data is processed governs that processing.

The Provider will notify active subscribers of a material change before it takes effect, using the contact details held for the Customer or through AWS Marketplace. The current version is published at the location identified under Contact, and it is the same text as the version held in the Provider’s repository, which is the source of record.

Contact

Provider: Cheppers Zrt.

Privacy and data protection enquiries, and requests to exercise a right described above: product@cheppers.com

Registered address: 1137 Budapest, Szent István körút 22. 3/8., Hungary

Published home of this document: https://parceldossier.com/legal/privacy