Privacy Policy

1. Controller

Controller within the meaning of the General Data Protection Regulation (GDPR) is:

Main real estate e.K.
Goethestraße 23
60313 Frankfurt am Main

Phone: +49 69 288 430
Email: info@main-real-estate.de

Owner: Carmen Agathakis-Ebeling

2. General Information on Data Processing

We process personal data exclusively within the framework of the applicable data protection provisions. Personal data is any information relating to an identified or identifiable natural person.

Personal data is processed in particular:

  • to provide, secure and technically administer our website,
  • to process contact and property inquiries,
  • to initiate, carry out and process brokerage agreements,
  • to conduct business correspondence,
  • to prepare and process invoices,
  • to fulfil legal obligations, in particular obligations under the German Anti-Money Laundering Act (Geldwäschegesetz, GwG),
  • to assert, exercise or defend legal claims.

Depending on the type and purpose of the processing, the following legal bases apply in particular:

  • Art. 6(1)(b) GDPR for pre-contractual measures as well as the performance and processing of contracts,
  • Art. 6(1)(c) GDPR for compliance with legal obligations,
  • Art. 6(1)(f) GDPR to safeguard our legitimate interests,
  • Art. 6(1)(a) GDPR, insofar as you have given us your consent.

3. Hosting and Server Log Files

Our website is hosted by:

IONOS SE
Elgendorfer Straße 57
56410 Montabaur

When you access our website, the web server automatically processes technical information. This may include in particular:

  • the page or file accessed,
  • date and time of access,
  • browser type and version,
  • operating system used,
  • device type used,
  • referrer URL,
  • technical information relating to the page request,
  • IP address in anonymised form.

This processing takes place to ensure the technically error-free provision of our website as well as the security and stability of the systems used.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, stable and functional provision of our website.

According to IONOS, the corresponding visitor data is generally stored for a period of eight weeks. IONOS also states that, as part of the web hosting, this visitor data is not transferred to third countries.

We have concluded a data processing agreement with IONOS in accordance with Art. 28 GDPR.

IONOS WebAnalytics

In connection with web hosting, IONOS may use IONOS WebAnalytics for the statistical evaluation of the use of our website. According to IONOS, this is done using log files or pixel technology and without the use of cookies. IONOS states that the IP address is processed in anonymised form.

This processing serves statistical analysis and the technical optimisation of our website.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in the analysis and optimisation of the technical quality and usability of our website.

4. SSL/TLS Encryption

For security reasons, our website uses SSL or TLS encryption. This protects data that you transmit to us via our website from unauthorised access by third parties during transmission.

You can recognise an encrypted connection in particular by the “https://” prefix in your browser’s address bar.

5. Cookies and Similar Technologies

Our website uses cookies and similar technologies. Cookies are small files that are stored on your device. Similar technologies may store information on your device or access information already stored there.

Where storage or access is strictly necessary to provide a telemedia service that you have expressly requested, this is carried out on the basis of Section 25(2) No. 2 TDDDG (German Telecommunications and Digital Services Data Protection Act).

Where this involves the processing of personal data, this is carried out – depending on the respective purpose – in particular on the basis of Art. 6(1)(f) GDPR.

Cookies that are not technically necessary, external media and other services requiring consent are generally only used after you have given your express consent. The legal bases in this respect are Section 25(1) TDDDG and Art. 6(1)(a) GDPR.

You can revoke or change any consent given at any time with effect for the future via the cookie settings available on our website.

6. Consent Management with Borlabs Cookie

We use Borlabs Cookie to manage the privacy and cookie settings you have made.

Borlabs Cookie stores in particular information about:

  • the selection you have made,
  • the cookie duration,
  • the cookie version used,
  • the domain and path of the website,
  • the consents given or refused,
  • a randomly generated identifier (UID).

According to the provider, no personal visitor data is transmitted to Borlabs in this process; the corresponding information is stored on our own server.

Storing your consent decision is necessary so that your selection can be taken into account on further visits to the site and so that the granting or refusal of consent can be documented.

The storage of, or access to, the cookie required for this purpose is based on Section 25(2) No. 2 TDDDG. Insofar as documenting your consent decision is necessary to fulfil our statutory record-keeping obligations, the processing is carried out in particular on the basis of Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.

You can change your settings at any time via the cookie settings on our website.

7. Property Listings and WP-ImmoMakler

We use the WordPress extension WP-ImmoMakler to display and manage our property listings on the website.

WP-ImmoMakler is used to display property information intended for publication on our website. In connection with the use of the property listings, the cookie “wp-immomakler” may be used.

This may serve in particular to:

  • enable navigation within the property listings,
  • store a selected sort order,
  • manage a watchlist,
  • recognise properties you have selected during the intended storage period.

Where the storage of, or access to, the cookie is necessary for a function you have expressly requested, this is based on Section 25(2) No. 2 TDDDG.

Where this involves the processing of personal data, it is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in a technically functional and user-friendly presentation of our property listings.

The respective storage period is shown in the cookie settings on our website. You can also delete stored cookies via your browser settings.

8. Language Settings and WPML

We use WPML (WordPress Multilingual Plugin) to provide different language versions of our website.

WPML may use technically necessary cookies, in particular to store the selected or current language of the website and to provide the corresponding language version.

Where this storage of, or access to, information on your device is necessary for the language function you requested, this is based on Section 25(2) No. 2 TDDDG.

Where this involves the processing of personal data, it is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in a consistent, technically functional and user-friendly multilingual presentation of our website.

The respective storage periods are shown in the cookie settings on our website.

9. Contact and Contact Form

If you contact us via the contact form provided on our website, by email, by telephone or via another means of communication, we process the personal data you provide to us.

This may include in particular:

  • name,
  • email address,
  • telephone number,
  • content of your message,
  • details of a property sought or offered,
  • date and time of contact,
  • other information you provide voluntarily.

We use the WordPress extension Contact Form 7 to provide the contact form. The data you enter via the form is processed to handle your inquiry and to conduct the related correspondence.

If your contact aims at the initiation or performance of a brokerage agreement or another contractual relationship, the processing is carried out on the basis of Art. 6(1)(b) GDPR.

In all other cases, the processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in the appropriate and efficient handling of incoming inquiries and business communication.

The information marked as required in the contact form is needed in order to process your inquiry. Further information is voluntary.

The data transmitted will be deleted once the respective inquiry has been fully processed and there are no statutory retention obligations, contractual requirements or other legitimate reasons for further storage.

Where confirmation of having read the privacy policy is required in the contact form, this serves to inform you about the data processing. This confirmation does not constitute an additional data protection consent to the processing required to handle your inquiry.

10. Email and Form Submission via Brevo

We use services provided by Brevo for the technical transmission of contact form inquiries and the associated electronic communication.

The provider is:

Brevo GmbH
Köpenicker Straße 126
10179 Berlin

The parent company is Brevo SAS, 106 boulevard Voltaire, 75011 Paris, France.

In connection with the transmission and processing, the following data may be processed in particular:

  • name,
  • email address,
  • telephone number,
  • content of your message,
  • date and time of transmission,
  • technical information relating to transmission and delivery.

This processing serves the reliable technical transmission and handling of your inquiry as well as the conduct of the related correspondence.

Where your inquiry is aimed at initiating or performing a contract, the processing is carried out on the basis of Art. 6(1)(b) GDPR. Otherwise, the processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in secure, reliable and efficient electronic communication.

We have concluded a data processing agreement with Brevo in accordance with Art. 28 GDPR.

According to Brevo, the data relevant to the provision of the service is stored within the European Union. Brevo may engage further sub-processors in the course of providing its services.

The data will be deleted as soon as it is no longer required to process the respective inquiry and there are no statutory retention obligations, contractual requirements or other legitimate reasons for further storage.

Further information: Brevo’s privacy policy

11. Cloudflare Turnstile (Spam Protection)

We use Cloudflare Turnstile to protect our contact form against spam, abusive input and automated access.

The provider is:

Cloudflare, Inc.
101 Townsend St.
San Francisco, CA 94107
USA

Cloudflare Turnstile is used to determine whether an input or form submission is made by a human or automatically by a computer program or bot.

This may involve processing technical information about the access, the browser used and the device, such as the IP address, browser and device information, and other technical data required to detect automated access and carry out the security check.

Turnstile is designed to carry out this check without classic CAPTCHA tasks wherever possible. Cloudflare states that the data collected in connection with Turnstile is not used for advertising purposes.

The processing is carried out on the basis of Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, and in particular our contact form, against automated attacks, misuse and spam, and in ensuring the security and functionality of our website.

Where information is stored on or read from your device in connection with the use of Cloudflare Turnstile and this is strictly necessary to provide the security function you expressly requested, this is based on Section 25(2) No. 2 TDDDG.

It cannot be ruled out that Cloudflare processes personal data in the USA. Cloudflare is certified under the EU-U.S. Data Privacy Framework. Where the requirements for this are met, the data transfer may therefore be based on the European Commission’s adequacy decision pursuant to Art. 45 GDPR.

Further information: Cloudflare’s privacy policy

12. Google Maps

We use Google Maps on our website to display our company location and to show the location of property listings on a map.

For users in the European Economic Area, the provider is generally:

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Google Maps is only loaded on our website after you have expressly consented to the data processing. Until you give your consent, only a placeholder is displayed.

When Google Maps is loaded, the following data may be processed and/or transmitted to Google in particular:

  • IP address,
  • date and time of access,
  • browser and device information,
  • information on the use of the map service,
  • location information, insofar as you allow it to be transmitted.

It cannot be ruled out that personal data is processed by companies affiliated with Google or on servers located outside the European Union or the European Economic Area.

The legal bases are your consent pursuant to Art. 6(1)(a) GDPR and, insofar as information is stored on or read from your device, Section 25(1) TDDDG.

You can revoke your consent at any time with effect for the future via the cookie settings on our website.

Further information: Google’s privacy policy

13. Wordfence Security

We use Wordfence Security to protect our website against malware, unauthorised access, attacks and other security-relevant activities.

The provider is:

Defiant, Inc.
800 5th Avenue, Suite 4100
Seattle, WA 98104
USA

Wordfence provides, in particular, a web application firewall, a malware scanner and other functions for detecting and defending against security-relevant access. In this context, the IP address of a website visitor may be processed in particular.

The following data may be processed in particular:

  • IP address,
  • date and time of access,
  • URL accessed or resource requested,
  • technical browser and device information,
  • information on failed or suspicious access and login attempts,
  • other security-relevant technical data.

This processing serves to detect and defend against attacks, malware and unauthorised access, and to ensure the integrity and availability of our website.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in protecting our website, our IT systems and the data processed via them from unauthorised access and other security risks.

For the processing of personal data, Defiant provides a Data Processing Addendum (DPA) which, under the provider’s terms, forms part of the underlying agreement and contains provisions on data processing and international data transfers.

Where personal data is transferred to the USA or other third countries, this is done in compliance with the requirements of Art. 44 et seq. GDPR, in particular on the basis of an applicable adequacy decision or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

Further information: Wordfence’s privacy information

14. Processing of Personal Data in Connection with Brokerage Engagements

In connection with the initiation, performance and processing of our activities as a real estate broker, we process personal data of prospective tenants/buyers, clients, owners, landlords and other parties involved, insofar as this is necessary for the respective activity.

This may include in particular:

  • title, first name and surname,
  • address,
  • email address,
  • landline and/or mobile phone number,
  • details of a property sought or offered,
  • details of rental, purchase or other contract terms,
  • details of agreed fees or commissions,
  • information on viewings and contract negotiations,
  • business correspondence,
  • other information required to broker or evidence a real estate transaction.

This processing is carried out in particular:

  • to identify and support prospective clients and clients,
  • to process property inquiries and listings,
  • to select and forward suitable property listings,
  • to conduct business correspondence,
  • to organise and conduct viewings,
  • to initiate, carry out and process brokerage agreements,
  • to document evidencing and brokerage activities,
  • to prepare and process invoices,
  • to assert, exercise or defend legal claims,
  • to fulfil statutory record-keeping, evidencing and retention obligations.

The legal bases are, in particular, Art. 6(1)(b), (c) and (f) GDPR.

Where processing is necessary to carry out pre-contractual measures or to perform a brokerage agreement, it is carried out on the basis of Art. 6(1)(b) GDPR.

Where statutory obligations exist, in particular under the German Ordinance on Brokers and Property Developers (Makler- und Bauträgerverordnung, MaBV), the German Anti-Money Laundering Act (Geldwäschegesetz, GwG), the German Commercial Code (Handelsgesetzbuch, HGB) or tax law provisions, the processing is carried out on the basis of Art. 6(1)(c) GDPR.

Where data is processed to document our activities or to assert, exercise or defend legal claims, the processing may be based on Art. 6(1)(f) GDPR. Our legitimate interest lies in particular in the proper documentation of our brokerage activities and in securing and enforcing legal claims.

Providing the data required for a brokerage engagement is necessary. Without this information, we may not be able to accept or carry out an engagement.

15. Obligations under the German Anti-Money Laundering Act

As a real estate broker, we are subject, to the extent provided by law, to the obligations of the German Anti-Money Laundering Act (Geldwäschegesetz, GwG).

The due diligence obligations under anti-money laundering law apply to real estate brokers in particular when brokering purchase agreements, as well as when brokering lease or tenancy agreements where the monthly net cold rent or net cold lease amounts to at least EUR 10,000.

Where the statutory requirements are met in the respective transaction, we are obliged to collect certain information, to establish and verify the identity of contracting parties or other parties involved, and to keep the records required by law.

This may include in particular first and last name, place and date of birth, nationality, residential address, details of the identification document, details of authorised representatives and beneficial owners, and other legally required information.

The legal basis for this processing is Art. 6(1)(c) GDPR in conjunction with the relevant provisions of the Anti-Money Laundering Act.

The records and other supporting documents required under the Anti-Money Laundering Act are generally retained for five years, unless other statutory provisions require a longer retention period. The GwG also provides that these records and supporting documents must be destroyed after ten years at the latest.

16. Provision of Property Details and PIN Code Procedure via node

We use software and/or technical services provided by our real estate software provider to manage our property listings and to provide certain property information:

node Systemlösungen e.K.
Katharinenstraße 9
10711 Berlin

In connection with the transmission and provision of property information, and any PIN code procedure used, personal data may be processed.

Depending on the function used, this may include in particular:

  • name,
  • email address,
  • information about the property requested,
  • a technical or unique identifier for the transaction,
  • date and time of access,
  • IP address,
  • information on the provision of, or access to, a property brochure,
  • information for documenting evidence or a declaration.

This processing is carried out in particular to provide requested property and brochure information, to conduct our brokerage activities, and – where necessary – to document and evidence the provision or retrieval of information.

Where processing is necessary to carry out pre-contractual measures or a brokerage agreement, it is carried out on the basis of Art. 6(1)(b) GDPR.

Where a statutory documentation obligation exists, the processing may be based on Art. 6(1)(c) GDPR.

Where the processing serves to document and provide evidence of our brokerage activities, it may be based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the traceable and legally sound documentation of our brokerage and evidencing activities.

We have concluded a data processing agreement with node Systemlösungen e.K. in accordance with Art. 28 GDPR.

17. Recipients of Personal Data

Personal data is only transferred to third parties insofar as this is legally permissible, necessary to perform an engagement or contract, required to fulfil a legal obligation, or covered by your consent.

Depending on the respective matter, the following recipients may be considered in particular:

  • owners, landlords, sellers or other principal contracting parties,
  • prospective buyers, tenants or other contracting parties, insofar as the transfer is necessary for the brokerage,
  • representatives and advisors engaged by the contracting parties,
  • notaries, lawyers, tax advisors and other professional advisors,
  • other real estate brokers in the context of a joint transaction,
  • IT, hosting, software and communications service providers,
  • providers of real estate and brokerage software,
  • authorities and other public bodies, insofar as there is a legal obligation to transfer data,
  • other recipients, insofar as there is a legal basis or you have consented to the transfer.

Where service providers process personal data on our behalf, they are engaged in accordance with Art. 28 GDPR.

18. Transfer of Personal Data to Third Countries

For certain services we use, it cannot be ruled out that personal data is transferred to, or processed by, recipients outside the European Union or the European Economic Area.

Any such transfer is carried out only in compliance with the requirements of Art. 44 et seq. GDPR.

The following may in particular serve as a basis for a data transfer:

  • an adequacy decision by the European Commission pursuant to Art. 45 GDPR,
  • a valid certification of a US company under the EU-U.S. Data Privacy Framework, insofar as the adequacy decision applies,
  • appropriate safeguards pursuant to Art. 46 GDPR, in particular the European Commission’s Standard Contractual Clauses,
  • in statutorily provided exceptional cases, one of the conditions set out in Art. 49 GDPR.

Further information on any third-country transfers can be found under the respective services described in this privacy policy.

19. Retention Period

We generally only store personal data for as long as is necessary to fulfil the respective purpose of processing, or as long as statutory retention obligations or other legally recognised reasons require further storage.

Depending on the type of documents, the following statutory retention periods may be relevant in particular:

  • Business records under the MaBV: generally 5 years; the period begins at the end of the calendar year in which the last record-relevant transaction for the respective engagement occurred. Longer statutory periods remain unaffected.
  • Records and other supporting documents under the Anti-Money Laundering Act: generally 5 years, unless another statutory provision requires a longer retention period.
  • Accounting vouchers: generally 8 years.
  • Business letters received and sent: generally 6 years.
  • Commercial books, inventories, opening balance sheets, annual financial statements and the other documents listed in Section 257(1) No. 1 of the German Commercial Code (HGB): generally 10 years.

The statutory retention periods each begin in accordance with the relevant statutory provisions.

In addition, personal data may be stored insofar as this is necessary to assert, exercise or defend legal claims. In this context, the statutory limitation periods may in particular be taken into account.

Where processing is based on your consent, the relevant data is generally processed until the consent is revoked or the purpose of processing ceases to apply, unless another legal basis or statutory retention obligation justifies further storage.

20. Data Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, we implement appropriate technical and organisational measures to protect personal data against loss, alteration, unauthorised access, unauthorised disclosure and other unlawful processing.

The security measures used are reviewed in line with technological developments and the respective risk situation and adjusted where necessary.

21. Your Rights

Subject to the statutory requirements, you have in particular the following rights with regard to the processing of your personal data:

  • the right of access pursuant to Art. 15 GDPR,
  • the right to rectification pursuant to Art. 16 GDPR,
  • the right to erasure pursuant to Art. 17 GDPR,
  • the right to restriction of processing pursuant to Art. 18 GDPR,
  • the right to data portability pursuant to Art. 20 GDPR,
  • the right to object pursuant to Art. 21 GDPR,
  • the right to withdraw consent pursuant to Art. 7(3) GDPR,
  • the right to lodge a complaint with a data protection supervisory authority pursuant to Art. 77 GDPR.

To exercise your rights, you can contact us at any time using the contact details given in Section 1.

Withdrawing consent does not affect the lawfulness of processing carried out on the basis of the consent before its withdrawal.

22. Right to Object under Art. 21 GDPR

Insofar as we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object at any time, on grounds relating to your particular situation, to this processing.

Following an objection, we will no longer process the personal data concerned unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing serves to assert, exercise or defend legal claims.

Where personal data is processed for the purpose of direct marketing, you have the right to object at any time, without giving reasons, to the processing for the purpose of such marketing.

Following your objection, the personal data concerned will no longer be used for direct marketing purposes.

23. Right to Lodge a Complaint with a Supervisory Authority

Under Art. 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority if you consider that the processing of your personal data infringes the GDPR.

The supervisory authority responsible for us is:

Der Hessische Beauftragte für Datenschutz und Informationsfreiheit
(Hessian Commissioner for Data Protection and Freedom of Information)
Gustav-Stresemann-Ring 1
65189 Wiesbaden

Phone: +49 611 1408-0
Email: poststelle@datenschutz.hessen.de

24. No Automated Decision-Making

We do not use decision-making based solely on automated processing – including profiling – within the meaning of Art. 22 GDPR that produces legal effects concerning you or similarly significantly affects you.

25. Data Protection Officer

Our company is not currently subject to a statutory obligation to appoint a data protection officer.

26. Objection to Unsolicited Advertising

We hereby object to the use of contact and communication data published as part of legally required disclosures for the purpose of sending unsolicited advertising or other unsolicited information.

We reserve the right to take legal action in the event of unsolicited advertising material being sent to us, in particular spam emails.

27. Updates to this Privacy Policy

We reserve the right to amend this privacy policy if the legal situation, the services we use, the technical design of our website, or the nature of the data processing changes.

The version published on our website at the time of your visit shall apply.

Last updated: August 2026