Version 1.3
Data Processing Agreement
Effective from September 20, 2026
Introduction
Tenant is the controller of personal data in the workspace; Supplier is the processor thereof. For account management, billing, security and Supplier's own statutory obligations, Supplier may be an independent controller.
Subject matter, duration and hierarchy
This Data Processing Agreement forms part of the Agreement between Tenant ('Controller') and Supplier ('Processor'). It applies for as long as Processor processes personal data on behalf of Controller and thereafter for as long as data has not yet been lawfully deleted or returned.
In the event of conflict concerning the protection of personal data, this Data Processing Agreement takes precedence over the General Terms and Conditions and the Order Form, except where a specific written provision demonstrably offers greater protection to data subjects. Nothing in this Data Processing Agreement limits the rights of data subjects or the powers of a supervisory authority.
Roles and instructions
Processor processes personal data solely on documented instructions from Controller, including instructions arising from use of the Service and the Agreement, unless Union law or applicable Member State law requires processing. In that case, Processor shall inform Controller in advance, unless the law prohibits this for compelling reasons.
Processor shall inform Controller immediately if an instruction appears to infringe the GDPR or other applicable data protection legislation and may suspend execution until the instruction is confirmed, modified or withdrawn.
Controller determines purposes and means, has a valid legal basis, provides the required information to data subjects and ensures that data and instructions are lawful, proportionate and accurate. Processor decides independently on purely internal organisational and security measures insofar as these do not alter the instruction.
Confidentiality and personnel
Processor ensures that persons with access to personal data are bound to confidentiality by contract or law, have access only on a need-to-know basis and receive appropriate instructions and training. Access is reviewed periodically and withdrawn in a timely manner.
Security
Taking into account the state of the art, implementation costs, nature, scope, context and purposes and the risks to data subjects, Processor shall implement appropriate technical and organisational measures in accordance with Article 32 GDPR. The main lines are set out in Annex B and may be improved provided the level of protection does not materially decrease.
Processor does not guarantee absolute security. Controller remains responsible for secure configuration, user management, endpoints, linked accounts, data minimisation, local exports and its own procedures.
Personal data breach
Processor shall inform Controller without undue delay after a confirmed breach concerning personal data processed on behalf of Tenant becomes known. Where practicable, Processor shall aim for an initial notification within 48 hours of confirmation. A notification is not an admission of liability.
The notification shall contain, insofar as then available: nature and suspected scope, categories of data and data subjects, likely consequences, measures taken or proposed and a point of contact. Missing information shall be provided in stages. Processor shall document the incident, support reasonable assessment and preserve forensic integrity.
Controller decides on notifications to supervisory authorities and data subjects, unless Processor is independently required to do so by law. Costs of support are included insofar as the incident is attributable to Processor; otherwise reasonable professional rates apply following prior consultation.
Rights of data subjects, DPIA and supervision
Processor shall assist, taking into account the nature of processing and available information, with appropriate technical and organisational measures in response to requests from data subjects and in relation to obligations concerning security, data breaches, data protection impact assessments and prior consultation. A request received directly shall be forwarded and not handled independently on the merits, unless required by law.
Sub-processors
Controller gives general written authorisation for the sub-processors on the current Sub-processor List. Processor shall impose on each sub-processor in writing substantially the same data protection obligations and remains responsible to Controller for their performance as Article 28 GDPR provides.
A proposed new or replacement core sub-processor shall be announced where reasonable at least thirty days in advance. Controller may lodge a reasoned objection within fourteen days on concrete privacy or security grounds. The parties shall seek a reasonable solution; if none is found, Controller may terminate only the substantially affected part. This does not relieve Controller of amounts already due.
International transfers
Personal data shall only be transferred outside the EEA if Chapter V GDPR is complied with, for example on the basis of an adequacy decision, binding corporate rules or the applicable standard contractual clauses of the European Commission with supplementary measures where necessary.
If the standard contractual clauses of Implementing Decision (EU) 2021/914 are required, the appropriate module, annexes and competent supervisory authority shall form part of this Data Processing Agreement by reference. Supplementary commercial provisions shall not contradict those standard clauses or impair the rights of data subjects.
Audit and information
Processor shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. If independent assurance, certifications, penetration test summaries or standardised questionnaires are insufficient, Controller may conduct an additional audit once per twelve months, and more frequently following a relevant confirmed incident or at the direction of a supervisory authority.
Audits shall be announced at least thirty days in advance, conducted during business hours by an independent expert under confidentiality, commence remotely and shall not damage security, continuity, privacy of other customers or confidential information. Controller shall bear reasonable costs, except in the event of material breach by Processor.
Return, deletion and evidence
Following termination of the service, Processor shall delete or return personal data at the choice of Controller, within technical and contractual export capabilities, unless applicable law requires retention. The workspace shall remain in recovery retention for a minimum of sixty days following termination of operational access. Thereafter a controlled deletion review shall follow; legal holds or statutory obligations shall block deletion.
Back-ups shall be overwritten according to their secure cycle and shall not be re-used for normal business purposes. Contract acceptances, audit logs, invoices, security evidence and limited suppression or evidence data may be retained separately for statutory obligations or legal proceedings.
Liability
The mutual liability of the parties under this Data Processing Agreement is governed by the liability regime of the General Terms and Conditions. That regime does not limit the rights of data subjects under Article 82 GDPR, recourse insofar as mandatory, or the powers of supervisory authorities. Neither party is required to indemnify the other for the portion of damage caused by its own breach of the GDPR.
Annex A — processing details
| Item | Description |
|---|---|
| Subject matter | Hosting and processing of Tenant data in the REOVA real estate and CRM service. |
| Duration | The term of the Agreement plus applicable recovery, back-up, evidence and statutory retention periods. |
| Purposes | CRM, real estate management, contacts, deals, viewings, tasks, documents, communication, feeds/imports, audit, support and activated AI assistance. |
| Data subjects | Employees and representatives of Tenant; sellers, buyers, tenants, landlords, leads, contacts, service providers and other persons entered by Tenant. |
| Data | Identification and contact data, communication, real estate and transaction data, appointments, documents, media, notes, usage and audit data and data in linked services. |
| Special categories of data | Not intended as a standard category. Tenant shall enter these only if necessary, lawful, explicitly permitted and appropriately secured. |
| Frequency | Continuous during active use; occasional exports, migrations, recovery and support on instruction. |
| Deletion | According to the Service and data policy, with a minimum of 60 days recovery retention following termination of operational access and controlled review thereafter. |
Annex B — technical and organisational measures
| Domain | Measures |
|---|---|
| Access | Tenant isolation, role-based authorisation, server-side session control, separation of authentication and application identities, least privilege and periodic revocation. |
| Database | Tenant filters at application level plus PostgreSQL row-level security; controlled tenant context for writes; separate control-plane privileges for sensitive lifecycle actions. |
| Transport and storage | TLS for transport; encryption and key management by hosting and storage providers; encryption of selected integration credentials. |
| Software security | Code review, dependency management, scoped tests, input validation, secrets outside source code, webhook verification and protection against cross-tenant access. |
| Logging | Audit logs and limited security logging with tenant and actor context; sensitive payloads and free text are minimised where possible. |
| Availability | Managed cloud infrastructure, database recovery capabilities, task idempotency, monitoring and recovery procedures appropriate to the Service. |
| Incidents | Detection, triage, containment, recovery, evidence preservation, communication and evaluation following relevant incidents. |
| Continuity | Recovery retention, controlled exports, dependency monitoring and procedures for provider or infrastructure failure. |
| AI | Central AI gateway, configurable models, usage logging, authorisation prior to execution and human confirmation for decisive actions. |
| Evaluation | Risk-driven testing and adjustment of measures; substantiated improvements may be introduced without contract amendment. |
Annex C — sub-processors
The current Sub-processor List forms part of this Data Processing Agreement by reference. In the event of discrepancies, the most recently validly communicated version shall be controlling for future processing.