Skip to content
nlesen

Version 1.3

Data Processing Agreement

Effective from September 20, 2026

Introduction

Tenant is the controller of personal data in the workspace; Supplier is the processor thereof. For account management, billing, security and Supplier's own statutory obligations, Supplier may be an independent controller.

Subject matter, duration and hierarchy

This Data Processing Agreement forms part of the Agreement between Tenant ('Controller') and Supplier ('Processor'). It applies for as long as Processor processes personal data on behalf of Controller and thereafter for as long as data has not yet been lawfully deleted or returned.

In the event of conflict concerning the protection of personal data, this Data Processing Agreement takes precedence over the General Terms and Conditions and the Order Form, except where a specific written provision demonstrably offers greater protection to data subjects. Nothing in this Data Processing Agreement limits the rights of data subjects or the powers of a supervisory authority.

Roles and instructions

Processor processes personal data solely on documented instructions from Controller, including instructions arising from use of the Service and the Agreement, unless Union law or applicable Member State law requires processing. In that case, Processor shall inform Controller in advance, unless the law prohibits this for compelling reasons.

Processor shall inform Controller immediately if an instruction appears to infringe the GDPR or other applicable data protection legislation and may suspend execution until the instruction is confirmed, modified or withdrawn.

Controller determines purposes and means, has a valid legal basis, provides the required information to data subjects and ensures that data and instructions are lawful, proportionate and accurate. Processor decides independently on purely internal organisational and security measures insofar as these do not alter the instruction.

Confidentiality and personnel

Processor ensures that persons with access to personal data are bound to confidentiality by contract or law, have access only on a need-to-know basis and receive appropriate instructions and training. Access is reviewed periodically and withdrawn in a timely manner.

Security

Taking into account the state of the art, implementation costs, nature, scope, context and purposes and the risks to data subjects, Processor shall implement appropriate technical and organisational measures in accordance with Article 32 GDPR. The main lines are set out in Annex B and may be improved provided the level of protection does not materially decrease.

Processor does not guarantee absolute security. Controller remains responsible for secure configuration, user management, endpoints, linked accounts, data minimisation, local exports and its own procedures.

Personal data breach

Processor shall inform Controller without undue delay after a confirmed breach concerning personal data processed on behalf of Tenant becomes known. Where practicable, Processor shall aim for an initial notification within 48 hours of confirmation. A notification is not an admission of liability.

The notification shall contain, insofar as then available: nature and suspected scope, categories of data and data subjects, likely consequences, measures taken or proposed and a point of contact. Missing information shall be provided in stages. Processor shall document the incident, support reasonable assessment and preserve forensic integrity.

Controller decides on notifications to supervisory authorities and data subjects, unless Processor is independently required to do so by law. Costs of support are included insofar as the incident is attributable to Processor; otherwise reasonable professional rates apply following prior consultation.

Rights of data subjects, DPIA and supervision

Processor shall assist, taking into account the nature of processing and available information, with appropriate technical and organisational measures in response to requests from data subjects and in relation to obligations concerning security, data breaches, data protection impact assessments and prior consultation. A request received directly shall be forwarded and not handled independently on the merits, unless required by law.

Sub-processors

Controller gives general written authorisation for the sub-processors on the current Sub-processor List. Processor shall impose on each sub-processor in writing substantially the same data protection obligations and remains responsible to Controller for their performance as Article 28 GDPR provides.

A proposed new or replacement core sub-processor shall be announced where reasonable at least thirty days in advance. Controller may lodge a reasoned objection within fourteen days on concrete privacy or security grounds. The parties shall seek a reasonable solution; if none is found, Controller may terminate only the substantially affected part. This does not relieve Controller of amounts already due.

International transfers

Personal data shall only be transferred outside the EEA if Chapter V GDPR is complied with, for example on the basis of an adequacy decision, binding corporate rules or the applicable standard contractual clauses of the European Commission with supplementary measures where necessary.

If the standard contractual clauses of Implementing Decision (EU) 2021/914 are required, the appropriate module, annexes and competent supervisory authority shall form part of this Data Processing Agreement by reference. Supplementary commercial provisions shall not contradict those standard clauses or impair the rights of data subjects.

Audit and information

Processor shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. If independent assurance, certifications, penetration test summaries or standardised questionnaires are insufficient, Controller may conduct an additional audit once per twelve months, and more frequently following a relevant confirmed incident or at the direction of a supervisory authority.

Audits shall be announced at least thirty days in advance, conducted during business hours by an independent expert under confidentiality, commence remotely and shall not damage security, continuity, privacy of other customers or confidential information. Controller shall bear reasonable costs, except in the event of material breach by Processor.

Return, deletion and evidence

Following termination of the service, Processor shall delete or return personal data at the choice of Controller, within technical and contractual export capabilities, unless applicable law requires retention. The workspace shall remain in recovery retention for a minimum of sixty days following termination of operational access. Thereafter a controlled deletion review shall follow; legal holds or statutory obligations shall block deletion.

Back-ups shall be overwritten according to their secure cycle and shall not be re-used for normal business purposes. Contract acceptances, audit logs, invoices, security evidence and limited suppression or evidence data may be retained separately for statutory obligations or legal proceedings.

Liability

The mutual liability of the parties under this Data Processing Agreement is governed by the liability regime of the General Terms and Conditions. That regime does not limit the rights of data subjects under Article 82 GDPR, recourse insofar as mandatory, or the powers of supervisory authorities. Neither party is required to indemnify the other for the portion of damage caused by its own breach of the GDPR.

Annex A — processing details

ItemDescription
Subject matterHosting and processing of Tenant data in the REOVA real estate and CRM service.
DurationThe term of the Agreement plus applicable recovery, back-up, evidence and statutory retention periods.
PurposesCRM, real estate management, contacts, deals, viewings, tasks, documents, communication, feeds/imports, audit, support and activated AI assistance.
Data subjectsEmployees and representatives of Tenant; sellers, buyers, tenants, landlords, leads, contacts, service providers and other persons entered by Tenant.
DataIdentification and contact data, communication, real estate and transaction data, appointments, documents, media, notes, usage and audit data and data in linked services.
Special categories of dataNot intended as a standard category. Tenant shall enter these only if necessary, lawful, explicitly permitted and appropriately secured.
FrequencyContinuous during active use; occasional exports, migrations, recovery and support on instruction.
DeletionAccording to the Service and data policy, with a minimum of 60 days recovery retention following termination of operational access and controlled review thereafter.

Annex B — technical and organisational measures

DomainMeasures
AccessTenant isolation, role-based authorisation, server-side session control, separation of authentication and application identities, least privilege and periodic revocation.
DatabaseTenant filters at application level plus PostgreSQL row-level security; controlled tenant context for writes; separate control-plane privileges for sensitive lifecycle actions.
Transport and storageTLS for transport; encryption and key management by hosting and storage providers; encryption of selected integration credentials.
Software securityCode review, dependency management, scoped tests, input validation, secrets outside source code, webhook verification and protection against cross-tenant access.
LoggingAudit logs and limited security logging with tenant and actor context; sensitive payloads and free text are minimised where possible.
AvailabilityManaged cloud infrastructure, database recovery capabilities, task idempotency, monitoring and recovery procedures appropriate to the Service.
IncidentsDetection, triage, containment, recovery, evidence preservation, communication and evaluation following relevant incidents.
ContinuityRecovery retention, controlled exports, dependency monitoring and procedures for provider or infrastructure failure.
AICentral AI gateway, configurable models, usage logging, authorisation prior to execution and human confirmation for decisive actions.
EvaluationRisk-driven testing and adjustment of measures; substantiated improvements may be introduced without contract amendment.

Annex C — sub-processors

The current Sub-processor List forms part of this Data Processing Agreement by reference. In the event of discrepancies, the most recently validly communicated version shall be controlling for future processing.