Privacy Policy
of neogroup GmbH (neospaces)
Last updated: 2026-05-20
This English version is provided for convenience. In case of any inconsistency or conflict of interpretation between the German and English versions, the German version prevails.
1. Overview and scope
This Privacy Policy explains how neogroup GmbH, operating under the brand "neospaces" (hereinafter "we", "us" or "neospaces"), processes personal data. It applies to the use of our website neospaces.de, to all channels through which you contact us, to our activity as a brokerage firm for commercial real estate (in particular indication of opportunities, brokerage, advisory), and to our recruitment and candidate referral processes.
Processing is carried out in compliance with the EU General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG), the German Telecommunications-Digital-Services-Data-Protection Act (TDDDG) and the German Anti-Money Laundering Act (GwG).
2. Controller
The controller within the meaning of Art. 4 No. 7 GDPR is:
neogroup GmbH
Neue Schönhauser Str. 8, 10178 Berlin, Germany
Represented by the Managing Directors Alexander Ditzel and Moritz Adrian
Phone: +49 30 75677020
E-Mail: hello@neospaces.de
3. Data Protection Officer
We have not appointed a Data Protection Officer as the statutory thresholds (§ 38 BDSG) are not met. Please direct privacy enquiries to hello@neospaces.de.
4. Your rights as a data subject
Under the GDPR you have the following rights:
- right of access (Art. 15 GDPR);
- right to rectification (Art. 16 GDPR);
- right to erasure (Art. 17 GDPR);
- right to restriction of processing (Art. 18 GDPR);
- right to data portability (Art. 20 GDPR);
- right to withdraw any consent given (Art. 7 (3) GDPR);
- right to lodge a complaint with a supervisory authority (Art. 77 GDPR); the supervisory authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information.
To exercise your rights, an informal e-mail to hello@neospaces.de is sufficient. We may take measures to verify your identity before responding to your request.
5. Right to object under Art. 21 GDPR
Right to object on grounds relating to your particular situation. You have the right, on grounds relating to your particular situation, to object at any time to processing of personal data concerning you which is based on a legitimate interest (Art. 6 (1) lit. f GDPR). We will then no longer process your data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
Right to object to direct marketing. Where we process personal data for direct marketing purposes, you have the right to object at any time to such processing; this also applies to profiling to the extent it is related to such direct marketing. If you object to such processing for direct marketing purposes, we will no longer process your personal data for such purposes.
Objections may be made informally to: hello@neospaces.de.
6. Hosting, server log files and infrastructure
Our website is hosted by an EU-based hosting provider. When you access our website, the server automatically collects connection data ("server log files"): IP address, date and time of the request, browser, operating system, referrer URL, page accessed.
Legal basis: Art. 6 (1) lit. f GDPR (legitimate interest in stable, secure operation of the website).
Storage period: server log files are deleted or anonymised after 30 days at the latest, unless required for the investigation of a specific security incident; in that case they are stored until the investigation is closed, but no longer than 90 days.
For backend functionality (database, edge functions, file storage) we use services on EU infrastructure. We have entered into data processing agreements pursuant to Art. 28 GDPR with all hosting and infrastructure providers.
7. Cookies and similar technologies
We use cookies and similar technologies (e.g. LocalStorage, pixels) on our website. Cookies are small text files stored on your device.
Strictly necessary cookies are required for the operation of the website (e.g. session management, language settings, storing your cookie consent). Legal basis: § 25 (2) no. 2 TDDDG in conjunction with Art. 6 (1) lit. f GDPR.
Cookies requiring consent (in particular for analytics, tracking and marketing) are only set if you have given your prior consent via our cookie banner. Legal basis: § 25 (1) TDDDG in conjunction with Art. 6 (1) lit. a GDPR.
You may withdraw your consent at any time with effect for the future via the banner icon on our website or by deleting cookies in your browser. A detailed overview of the cookies we use is available in our cookie banner under "Settings".
8. Web and product analytics
On the basis of your consent (Art. 6 (1) lit. a GDPR, § 25 (1) TDDDG) we use web and product analytics services to evaluate the use of our website and continuously improve our offering. This includes, among other things, page views, click paths, dwell time, and device and browser data.
Recipients: providers of web analytics and product analytics services. Some providers are based outside the EU; in this respect Section 16 (international data transfers) applies.
Storage period: typically up to 14 months from collection, after which data is deleted or aggregated.
You may withdraw your consent at any time.
9. Contact requests
If you contact us by e-mail, telephone, contact form or messenger service, we process your contact data and the content of your message to handle your request.
Legal basis: Art. 6 (1) lit. b GDPR (pre-contractual measures), Art. 6 (1) lit. f GDPR (legitimate interest in efficient handling of enquiries).
Storage period: until your request has been dealt with, plus statutory retention periods (in particular § 257 HGB, § 147 AO – up to 10 years for tax-relevant correspondence).
10. Processing in the context of our brokerage activities
As a brokerage firm we process personal data of clients, prospects and contractual partners for the initiation, brokerage and execution of lease, sub-lease and purchase agreements relating to commercial real estate.
Data categories: identification and contact data, contract data, credit information (for tenant prospects, where necessary), correspondence, viewing records, negotiation status.
Legal bases: Art. 6 (1) lit. b GDPR (contract initiation and performance), Art. 6 (1) lit. f GDPR (legitimate interest in our brokerage activities), Art. 6 (1) lit. c GDPR (compliance with legal obligations, in particular under the GwG – see Section 11).
Recipients: owners, landlords, tenants, buyers, sellers and their advisors (lawyers, tax advisors, auditors, notaries) to the extent necessary; processors from the categories IT/hosting, CRM, e-mail and communication, cloud storage, accounting and invoicing, AI providers (see Section 13), credit reporting agencies, and authorities where legally required.
Storage period: contract data and related correspondence are stored until the end of the business relationship plus statutory retention periods (in particular 6 years under § 257 HGB, 10 years under § 147 AO). Prospect data without a contract is deleted no later than 3 years after the last contact.
11. Identification and due diligence under the Anti-Money Laundering Act
As real estate brokers we are subject to the obligations of the German Anti-Money Laundering Act (GwG). We are in particular required to identify contractual partners and beneficial owners, to continuously monitor business relationships, and to report suspicious cases to the Financial Intelligence Unit (FIU).
Data categories: name, date and place of birth, nationality, address, identification document data, information on the beneficial owner, where applicable information on the origin of funds.
Legal basis: Art. 6 (1) lit. c GDPR in conjunction with §§ 10 et seq. GwG.
Storage period: 5 years after the end of the business relationship or completion of the transaction, but no longer than 10 years (§ 8 (4) GwG).
Providing this data is required by law. Without the required information we are not permitted to enter into or continue the business relationship.
12. Job applications and candidate referrals
Job applications. If you apply to us, we process the application data you submit (name, contact data, CV, references, LinkedIn profile, further documents). Legal basis: § 26 (1) BDSG in conjunction with Art. 6 (1) lit. b GDPR (initiation of an employment relationship) and Art. 6 (1) lit. a GDPR insofar as you provide voluntary information. Storage period: if no employment relationship is established, deletion no later than 6 months after completion of the application process, unless you have consented to longer storage in our talent pool.
Referrals. Our referral feature allows you to recommend a candidate for an open role. We process (a) your contact data as referrer and (b) the data of the referred person (name, contact data, current company, LinkedIn, where applicable CV and further documents). By submitting a referral you confirm that you have informed the referred person and – where required – obtained their consent. We will inform the referred person about the collection of their data within the time limit set out in Art. 14 (3) GDPR.
Legal bases for referrals: for the referred person, Art. 6 (1) lit. b GDPR in conjunction with § 26 BDSG; for the referrer, Art. 6 (1) lit. f GDPR (legitimate interest in administering the referral and any referral bonus).
13. Use of Artificial Intelligence (AI)
We are an AI-native brokerage firm and use Artificial Intelligence – in particular Large Language Models (LLMs) and comparable models – intensively in our workflows. This includes, among other things, analysing object and market data, preparing marketing materials, structuring draft contracts, evaluating application documents, and supporting communication and research processes.
Data processing by AI providers: where we transmit personal data to AI providers, this is done exclusively on the basis of data processing agreements pursuant to Art. 28 GDPR. We have agreed with our AI providers that data entered will not be used to train publicly available models ("zero data retention" / "no training" agreements where available).
Legal basis: Art. 6 (1) lit. b GDPR, Art. 6 (1) lit. f GDPR (legitimate interest in efficient, AI-supported workflows).
No automated decision-making in individual cases: no decision based solely on automated processing within the meaning of Art. 22 GDPR takes place. All brokerage, personnel and contractual decisions are made by humans and merely supported by AI in preparation.
Third-country transfer: individual AI providers are based outside the EU/EEA. The safeguards described in Section 16 apply.
14. Direct marketing, newsletters and business contacts
Where we contact you for marketing or business development purposes (e.g. by e-mail newsletter, postal mail or LinkedIn message), this is done on the following legal bases:
- for newsletters to persons who have given consent: Art. 6 (1) lit. a GDPR in conjunction with § 7 (2) UWG (double opt-in);
- for promotional contact in the context of an existing or prospective B2B business relationship: Art. 6 (1) lit. f GDPR, in compliance with § 7 (3) UWG.
You may object to promotional contact at any time (see Section 5).
15. Recipients and processors
We disclose personal data only to the following categories of recipients, to the extent necessary:
- IT and hosting providers, cloud storage providers;
- CRM, e-mail, communication and collaboration services;
- AI providers (see Section 13);
- applicant tracking systems;
- accounting, invoicing and payment service providers;
- web and product analytics services;
- advisors (lawyers, tax advisors, auditors, notaries);
- credit reporting agencies;
- third parties involved in our brokerage services (owners, landlords, tenants, buyers, sellers and their advisors);
- authorities and public bodies, where legally required.
We have entered into contracts pursuant to Art. 28 GDPR with all processors.
16. International data transfers
Individual service providers we use, in particular in the areas of AI, web analytics and product analytics, are based outside the EU/EEA, typically in the USA. In this respect, personal data is transferred to a third country. An adequate level of data protection is ensured by adequacy decisions of the European Commission (in particular EU-US Data Privacy Framework, Art. 45 GDPR) and/or by concluding EU Standard Contractual Clauses (Art. 46 (2) lit. c GDPR) and supplementary technical and organisational measures. You may request a copy of the applicable safeguards from us.
17. Data security
We take technical and organisational measures pursuant to Art. 32 GDPR to protect your data against accidental or intentional manipulation, loss, destruction, or access by unauthorised persons. These include in particular the encryption of data transmission (TLS/HTTPS), access controls, regular security updates, and the obligation of our employees to maintain data secrecy.
18. Obligation to provide data
In the context of our business relationship, you must provide the personal data required for the initiation, performance and termination of a business relationship and for the fulfilment of the related contractual and statutory obligations (in particular under the GwG). Without this data, we will generally not be in a position to conclude, perform or continue a contract with you.
19. Changes to this Privacy Policy
We reserve the right to adapt this Privacy Policy to reflect changes in the legal framework or in our processing activities. The current version applies from the time it is published on our website. In the event of material changes we will additionally inform you in an appropriate manner where possible and reasonable.