Contents
- Who We Are
- Scope
- Data We Collect
- How We Use Your Data
- Legal Basis for Processing (GDPR)
- Data Sharing & Third Parties
- International Transfers
- Data Retention
- Security
- AI Processing & Automated Decisions
- Your Rights
- Cookies & Tracking
- Children's Privacy
- California Residents (CCPA)
- Changes to This Policy
- Contact
01Who We Are
ELIT VIRTUAL LLC operates the My 5th Star platform — AI automation agents for real estate agencies. We are a Colorado limited liability company.
1942 Broadway Ste 314C, Boulder, CO 80302-5233, USA
Email: [email protected]
WhatsApp: +32 499 40 97 70
For EU/UK data protection law purposes we wear two hats, and which one we are wearing changes what you can ask us for:
- We are the controller for data about our own website visitors, enquirers and subscribers — the people who contact us about buying My 5th Star. We decide why and how that is processed, and this Policy governs it.
- We are a processor for personal data about an agency's leads and clients. The agency is the controller. It decides who to contact and why; we act on its instructions under our Data Processing Agreement.
02Scope
This Policy applies to visitors of my5thstar.com, subscribers to the My 5th Star platform, and anyone who contacts us directly. It does not apply to third-party services you connect to our platform — those operate under their own policies.
03Data We Collect
Account & contact data. Name, email, phone number, company name, job title, and billing information when you register or contact us.
Usage data. Pages visited, features used, session duration, device type, browser, IP address, and referring URL — collected automatically when you use the Service.
Communications data. Emails, WhatsApp messages, and support chat transcripts you send us.
Lead & client data (processed on your behalf). Personal data of your real estate leads and clients that you upload or sync into the platform — names, contact details, property preferences, conversation history. You control what you input; we process it only to deliver the Service.
AI interaction data. Prompts and conversation logs generated by our AI agents within your account, used for quality assurance and accuracy improvement.
04How We Use Your Data
- Providing the Service: operating AI agents, processing leads, sending automated messages, and delivering your subscription
- Account management: creating accounts, processing payments, and providing customer support
- Communications: transactional emails, product updates, and (where consented) marketing messages
- Security & fraud prevention: monitoring for suspicious activity and protecting our platform
- Analytics & improvement: understanding usage patterns to improve the platform — using aggregated, anonymised data where possible
- Legal compliance: meeting obligations under Colorado law, applicable US federal law, and GDPR/UK GDPR for EU/UK users
We do not use your data or your clients' data to train general-purpose AI models accessible to other customers.
05Legal Basis for Processing (GDPR)
For users in the EEA or UK, we rely on the following legal bases under GDPR:
- Contract (Art. 6(1)(b)): processing necessary to deliver the Service you subscribed to
- Legitimate interests (Art. 6(1)(f)): platform security, fraud prevention, and Service improvement — where not overridden by your rights
- Legal obligation (Art. 6(1)(c)): compliance with applicable law
- Consent (Art. 6(1)(a)): for optional marketing communications and non-essential cookies — withdrawable at any time
06Data Sharing & Third Parties
We do not sell, rent, or trade your personal data. We share data only in these circumstances:
- Sub-processors: every third party that may process personal data on our behalf is named in full on our sub-processors page — what each one does and where it is located. All are bound by data processing agreements and prohibited from using the data for their own purposes. "Trusted service providers" is not an answer a data protection officer can check; a list is.
- Integrations you authorise: when you connect third-party platforms, data flows as you configure — you control these connections
- Legal requirements: when required by law, court order, or to protect rights, property, or safety
- Business transfers: in the event of a merger or acquisition, subject to equivalent privacy protections
07International Transfers
ELIT VIRTUAL LLC is based in the United States (Colorado). Some sub-processors may be located in other countries. For transfers of EEA/UK personal data outside those regions, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission. You may request details by emailing [email protected].
08Data Retention
- Your account data (the subscriber): kept while you are a customer and for 12 months after, unless you ask us to delete it sooner — we keep it that long so a returning customer is not made to start again, not because we need it
- Your leads' and clients' data (processed for you): kept for 30 days after your subscription ends so you can still export it, then permanently deleted from active systems. This is a shorter clock than your own account data, deliberately: it is not our data to hold on to
- Analytics data: retained in anonymised form for up to 24 months
- Financial records: retained for 7 years as required by US tax law
09Security
Specific measures, rather than a claim of "industry standard":
- Encryption in transit — HTTPS only (TLS 1.2+). Unencrypted connections are refused.
- Encryption at rest — AES-256 by our database provider, and above that, the credentials you connect (WhatsApp, Meta, Telegram, Twilio, email provider tokens) are encrypted again by the application itself with a separate encryption key per agency. One agency's key cannot open another's data, and destroying an agency's key renders its stored credentials permanently unreadable.
- API keys are never stored readably — only a one-way hash is kept, so they cannot be recovered from our database by us or by anyone else.
- Tenant isolation — enforced both in the application on every request and by database row-level security.
- Separated administration — operating the platform is a different account from using it. No customer account can reach administrative functions.
- Two-factor authentication available on accounts, with hashed single-use recovery codes, and throttling of repeated failed sign-ins.
- Tamper-evident audit log — each entry cryptographically linked to the one before it, re-verified on a schedule, so an entry altered after the fact is detected.
- Automated checks before any code ships, and documented incident-response procedures.
The current, maintained version of this is published at dashboard.my5thstar.com/security. We do not publish third-party penetration-test reports; if that changes, that page will say so.
In the event of a data breach we will notify affected users and, where required, relevant authorities (including EU supervisory authorities within 72 hours under GDPR) without undue delay. No transmission method is 100% secure and we cannot guarantee absolute security.
10AI Processing & Automated Decisions
The Service is an AI system, and that has consequences for personal data that a generic privacy policy would not cover. Set out plainly:
Messages are generated and sent automatically. When a lead writes to an agency using My 5th Star, the reply is normally written and sent by the AI without a person reading it first. The content of that conversation is stored as part of the agency's CRM record.
Leads are scored automatically. Each lead is rated on a numeric scale from the content of their messages, and higher-rated leads are prioritised and escalated to a human sooner. This is automated processing that evaluates a person, so we state it rather than bury it.
Which models process the text. Message content is sent to AI model providers to generate replies. Which provider is used depends on the agency's configuration; all of them are named on our sub-processors page, with the country each operates in. Some are outside the EEA, and Standard Contractual Clauses apply to those transfers.
No training on your data. We do not use customer data, lead data or conversation content to train general-purpose AI models available to other people, and our model providers are contractually barred from doing so on data we send them.
Voice calls. Where an agency enables AI voice calling, calls may be recorded and transcribed. Recording laws vary by jurisdiction and consent for that is the agency's responsibility as controller.
11Your Rights
Depending on your location, you have the following rights over your personal data:
To exercise any right, email [email protected] with the subject "Data Rights Request". We respond within 30 days. EU/UK users may also lodge a complaint with their local supervisory authority.
12Cookies & Tracking
Our website uses cookies and similar technologies. We use:
- Essential cookies: required for the site to function — cannot be disabled
- Analytics cookies: understand how visitors use the site, anonymised where possible
- Marketing cookies: measure advertising effectiveness — only with your explicit consent
You can manage preferences via the consent banner or your browser settings.
13Children's Privacy
The Service is not directed at anyone under 16. We do not knowingly collect personal data from minors. If you believe we have done so inadvertently, contact us at [email protected] and we will delete it promptly.
14California Residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know: what personal information we collect, use, and disclose
- Right to delete: request deletion of your personal information, subject to certain exceptions
- Right to opt out of sale: we do not sell personal information — this right is automatically honoured
- Right to non-discrimination: we will not discriminate against you for exercising CCPA rights
To submit a CCPA request, email [email protected] with the subject "CCPA Request". We respond within 45 days.
15Changes to This Policy
We may update this Policy at any time. For material changes we will notify you by email or via a prominent platform notice at least 14 days before the change takes effect. The "Last updated" date above always reflects the most recent revision.
16Contact
1942 Broadway Ste 314C, Boulder, CO 80302-5233, USA
Email: [email protected]
WhatsApp: +32 499 40 97 70
Web: my5thstar.com
See also our Terms & Conditions.