Vestra Data Protection, GDPR, and CCPA Compliance Notice

Last Updated: January 23, 2026

Introduction

Vestra Holdings (“Vestra”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal information. This Data Protection, GDPR (General Data Protection Regulation), and CCPA (California Consumer Privacy Act) Compliance Notice (“Notice”) explains how Vestra collects, uses, discloses, stores, and protects your personal data when you access or use our website, mobile applications, peer-to-peer marketplace, investment services, or any other features provided by Vestra (collectively the “Platform”).

This Notice is designed to comply with applicable data protection laws including the European Union’s GDPR (Regulation (EU) 2016/679), the UK GDPR as incorporated into UK law under the Data Protection Act 2018, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (CCPA/CPRA), and other relevant privacy regulations.

If you have any questions about this Notice or your rights under it, please contact us at:

  • Phone: +63 946 449 8012
  • Email: support@vestraproperties.pro
  • Address: Aurora, CO, 80016, United States

Scope of this Notice

This Notice applies to all users of Vestra’s Platform worldwide. It covers:

  • What personal data we collect
  • How we use your data
  • Legal bases for processing
  • How we share/disclose data
  • International transfers
  • Your rights under GDPR/CCPA
  • Security measures
  • Retention periods
  • Children’s privacy
  • Changes to this notice

What Personal Data We Collect

Categories of Personal Information Collected

Depending on how you interact with Vestra’s Platform and services, we may collect the following categories of personal information:

  1. Identifiers: Name, address, email address, phone number, account username/passwords.
  2. Government Identifiers: Passport number, national ID number (for KYC/AML compliance).
  3. Financial Information: Bank account details; payment card numbers; transaction history.
  4. Investment Information: Details about property shares owned/traded; investment preferences.
  5. Device & Usage Information: IP address; browser type/version; device identifiers; usage logs.
  6. Geolocation Data: Approximate location derived from IP address or device settings.
  7. Professional/Employment Information: Occupation and employer (where required for regulatory purposes).
  8. Communications: Records of communications with customer support or through our Platform.
  9. Marketing Preferences: Choices regarding receiving marketing from us.

We do not knowingly collect sensitive personal information unless required by law for identity verification purposes.

Sources of Personal Data

We collect information directly from you when you register an account or interact with our Platform; automatically via cookies and similar technologies; and from third parties such as identity verification providers or financial institutions.

How We Use Your Personal Data

Vestra uses your personal data only for lawful purposes in accordance with applicable regulations:

  1. To provide services: Creating/managing accounts; facilitating investments/trades; processing payments/withdrawals.
  2. To verify identity: Conducting KYC/AML checks as required by law.
  3. To communicate: Sending service-related notifications; responding to inquiries/support requests.
  4. For compliance: Meeting legal/regulatory obligations in real estate investment and financial services.
  5. For security/fraud prevention: Monitoring activity for suspicious behavior; enforcing platform policies.
  6. For analytics/improvements: Analyzing usage trends to improve user experience and develop new features.
  7. For marketing (with consent): Sending promotional materials/offers where permitted by law.

We will not use your personal information for purposes materially different from those described without notifying you and obtaining consent where required.

Legal Bases for Processing Personal Data (GDPR)

Under the GDPR and UK GDPR, Vestra relies on one or more of the following legal bases to process your personal data:

  1. Performance of a contract: To provide requested services/investment opportunities.
  2. Legal obligation: To comply with anti-money laundering laws/tax reporting requirements.
  3. Legitimate interests: For fraud prevention/security/enhancing user experience—provided such interests are not overridden by your fundamental rights/freedoms.
  4. Consent: For sending direct marketing communications where legally required.

Where consent is relied upon as a basis for processing, you may withdraw it at any time without affecting prior processing.

How We Share/Disclose Your Personal Data

Vestra does not sell your personal information but may share it in limited circumstances:

With Service Providers:

We engage trusted third-party vendors who assist in providing technology infrastructure (e.g., cloud hosting), payment processing partners/banks/custodians, KYC/AML verification providers, analytics providers (e.g., Google Analytics), customer support tools.

These vendors are contractually obligated to protect your information consistent with this Notice.

With Other Users:

Limited profile/investment details may be visible to other users within peer-to-peer trading features as necessary for transaction execution.

For Legal Compliance:

We may disclose information if required by law/regulation/court order/subpoena/government request—including tax authorities or regulators overseeing real estate investments.

In Corporate Transactions:

In connection with mergers/acquisitions/restructuring/sale of assets—subject to confidentiality protections.

With Consent:

Otherwise only with your explicit consent.

International Transfers

Your personal data may be transferred outside your country/jurisdiction—including outside the European Economic Area (“EEA”)—to countries that may have different levels of data protection than those in your jurisdiction.

Where we transfer EEA/UK residents’ data internationally—including to the United States—we ensure appropriate safeguards are in place such as Standard Contractual Clauses approved by the European Commission or adequacy decisions where available.

You can request further details about these safeguards using our contact details above.

Your Rights Under GDPR & CCPA

If You Are Located in the EEA/UK:

You have certain rights under GDPR regarding your personal data:

  1. Right to access – Obtain a copy of your personal data held by us.
  2. Right to rectification – Request correction of inaccurate/incomplete data.
  3. Right to erasure (“right to be forgotten”) – Request deletion subject to legal exceptions.
  4. Right to restrict processing – Limit how we use your information in certain circumstances.
  5. Right to object – Object to processing based on legitimate interests/direct marketing at any time.
  6. Right to portability – Receive a copy in machine-readable format/transmit it elsewhere.
  7. Right not to be subject solely to automated decision-making producing legal effects concerning you.

To exercise these rights email support@vestraproperties.pro with “Data Subject Request” in the subject line.

If You Are a California Resident:

Under CCPA/CPRA you have these additional rights:

  1. The right to know what categories/pieces of personal info we’ve collected/disclosed/sold about you over past 12 months;
  2. The right to request deletion;
  3. The right to opt-out of sale/sharing* (*Vestra does NOT sell/share consumer info for monetary value);
  4. The right not be discriminated against for exercising privacy rights;
  5. The right to correct inaccurate info;
  6. The right to limit use/disclosure of sensitive info;

Requests can be made via email at support@vestraproperties.pro or toll-free phone at +63 946 449 8012.

We will verify requests using reasonable methods before acting on them as required by law.

Cookies & Tracking Technologies

Vestra uses cookies/web beacons/pixels/local storage/similar technologies on its website/applications for authentication/session management/security/preferences analysis/performance monitoring/marketing purposes.

You can manage cookie preferences via browser/device settings or opt-out mechanisms provided within our Platform where available.

For more detail see our Cookie Policy on our website.

Security Measures

Vestra implements industry-standard technical and organizational measures designed to protect against unauthorized access/loss/misuse/destruction/disclosure including but not limited to:

  • Encryption at rest/in transit using SSL/TLS protocols;
  • Access controls/authentication/logging;
  • Regular security assessments/vulnerability scanning;
  • Employee training/confidentiality agreements;
  • Secure development practices/code reviews;

Despite these efforts no method is completely secure—users should also take care in safeguarding their credentials/devices.

Retention Periods

Personal data is retained only so long as necessary for legitimate business/legal/compliance reasons including fulfilling contractual obligations/account management/regulatory recordkeeping/tax/reporting requirements/dispute resolution/security/fraud prevention/audit purposes.

When no longer needed it will be securely deleted/anonymized per industry standards unless longer retention is mandated by law/regulation/court order/governmental authority.

Children’s Privacy

Vestra’s Platform is intended only for adults aged 18+ years old (or age of majority). We do not knowingly collect/process children’s personal information without parental consent as defined under applicable laws such as COPPA/GDPR Article 8. If we learn that a child has provided us with their info without proper authorization we will promptly delete it upon notification/request.

Changes To This Notice

We reserve the right periodically update/amend this Notice reflecting changes in technology/laws/business practices/platform features/user feedback/etc.. Material changes will be posted prominently on our website/applications along with updated effective date above—you are encouraged review regularly.

Continued use after updates constitutes acceptance thereof.

If material changes affect previously collected info substantially/differently than stated here—we will notify affected individuals directly where feasible.

Contact Us / Complaints

If you have questions/comments/exercise rights/file complaints regarding this Notice/data practices:

Email: support@vestraproperties.pro
Phone: +63 946 449 8012
Mailing Address: Aurora CO 80016 United States

If unsatisfied response re EU/UK residents’ concerns—you have right lodge complaint supervisory authority e.g., ICO (UK), CNIL (France), DPC (Ireland) etc.