• How it works
  • Why Locari
  • WhatsApp
  • Pricing
  • FAQ
Log inStart for free
  • How it works
  • Why Locari
  • WhatsApp
  • Pricing
  • FAQ
Start for freeLog in
Help›Data Protection — Overview›Consent Management

Data Protection — Overview

Consent Management

When Locari collects consent from applicants, and how it is tracked and documented — with automatic reminders and secure withdrawal.

Locari obtains the applicant's explicit consent where your listing makes the smoker question or an ID document a mandatory requirement — these are special categories of personal data under Art. 9 GDPR. If your listing has neither of the two as a mandatory requirement, no separate consent is collected; processing then rests on the initiation of the tenancy agreement, and your listing's privacy policy is linked in every email to applicants. This page shows how the consent process works, what you can do, and what happens automatically. You find all consents in the relevant rental case, in the Consents tab.

When Locari asks for consent:

  • Smoker question as a mandatory requirement: on the first incoming applicant email — before an applicant record is created. Without consent, the applicant is neither created nor evaluated.
  • ID document as a mandatory requirement: only when the applicant moves into the Document verification phase. Until then the application runs without a separate consent.
  • If you activate either criterion later, Locari requests consent retroactively from the applicants already on file.

What Locari does automatically once consent is required: send the consent email, send reminders on day 1, 3, and 5, expire consent after 10 days without response and delete the data. What you decide: whether to send a manual reminder, whether to withdraw a granted consent, whether to delete applicant data early.

Common Tasks

  • Check an applicant's consent status
  • Send a manual reminder
  • Understand consent for chatbot or manual entry
  • Process a withdrawal
  • Understand the burden of proof
  • Understand consent email language

How To

View consent status

  1. Open the rental case and switch to the Consents tab.
  2. In the table you see the current status per applicant (Pending / Granted / Declined / Withdrawn / Expired).
  3. Clicking a row opens the detail view with all timestamps, channel, and — for granted consent — the Withdraw consent button.
  4. Example: Applicant Schmidt, status "Pending", 2 of 3 reminders sent.

Send manual reminder

  1. Open the Consents tab — the applicant must have status "Pending".
  2. Click the Send reminder button in the row.
  3. Locari sends an unscheduled reminder email; the automatic reminder schedule continues unchanged (the reminder count is not incremented by this).

What Locari does in the automatic reminder schedule: day 1, day 3, day 5 — maximum 3 reminders. If the applicant does not respond by day 10, consent is automatically marked as expired and data is deleted. What you decide: you can trigger an additional manual reminder at any time without changing the automatic schedule.

Views and Fields

"Consents" Tab in the Rental Case

The table is split into Pending and Completed and shows:

  • Applicant: email address
  • Status: Pending / Granted / Declined / Withdrawn / Expired
  • Requested: timestamp of the first consent email
  • Completed: timestamp of grant/decline/withdrawal/expiry
  • Reminders: number of reminders sent (0–3)
  • Method: email link / admin / web form / Locari
  • IP address: stored only for consent via email link (Art. 7 GDPR documentation requirement)
  • Actions: Send reminder (only when "Pending") and Delete data

Implicit Consent — Chatbot and Manual Entry

When you enter applicant data yourself via the Locari chatbot or a form, consent is treated as implicitly granted — you, as landlord, are acting as the controller and have actively entered the data. In this case no consent email is sent.

What Locari does for implicit consent: immediately create the consent record as "Granted" and generate a withdrawal token (so the right of withdrawal under Art. 7(3) GDPR is preserved). What you decide: whether to inform the applicant retrospectively about the data processing — this is recommended for the transparency obligation under Art. 13 GDPR.

Consent Email Language

The language of the consent email is determined by the country of the listing:

Country of ListingLanguage
Germany (DE), Austria (AT), Switzerland (CH)German
France (FR)French
United Kingdom (GB)English
Other or not setGerman (default)

Revocation of Consent

By the Applicant

The withdrawal link in every consent email is permanently valid and never expires. Applicants can at any time:

  1. Click the withdrawal link in the email.
  2. Or write to you — then you withdraw it yourself from the consent detail view (Withdraw consent).

After withdrawal, data deletion runs automatically:

  1. Confirmation email to the applicant
  2. Complete deletion of all applicant data (profile, documents, communication, notes)
  3. Anonymization of the consent record — proof for supervisory authorities is retained (Art. 7(1) GDPR)

Data deletion after withdrawal is irreversible. The consent record itself is anonymized (no longer personally identifiable), but remains available as an audit record for authority requests.

When Consent is Declined

If the applicant declines consent, Locari immediately deletes the applicant data and sends a confirmation email to the applicant.

When Consent Expires

If an applicant does not respond after 10 days, consent is automatically marked as expired and data is deleted — the same deletion sequence as for a decline.

Burden of Proof

Locari documents for each consent:

  • Timestamps (request, grant, decline, withdrawal, expiry)
  • Status and channel (email link / admin / web form / Locari)
  • IP address and browser identifier (for consent via email link)
  • Number of reminders sent
  • the consent text shown

You see these details per applicant in the detail view in the Consents tab. After a deletion, the anonymized record is retained as proof.

Related Pages

  • Data Protection — Overview
  • GDPR Compliance
  • Data Deletion and Periods
  • Applicant Details
  • AI Communication with Applicants
Was this helpful?

Still have questions?

Contact us

Your personal letting assistant. Locari does the work – you decide.

More info in our Privacy Policy.

Product

  • How it works
  • Artificial intelligence
  • Control via WhatsApp
  • Security
  • Pricing

Company

  • About
  • Why Locari
  • Anti-profiling
  • Changelog
  • Careers
  • Press

Legal

  • Trust Center
  • Privacy Policy
  • Cookie Policy
  • Withdrawal & cancellation
  • Report illegal content
  • Imprint

Contact

  • Get in touch
  • Support & help
  • FAQ
  • Data protection
© Locari. A service by Ametis Digital GmbH.Rathausgasse 17 · 12529 Schönefeld · Germany