Legal

Data Processing Agreement

Version 1.0

# Data Processing Agreement

## 1. Scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between

the Operator ("Processor") and the Customer ("Controller") and applies whenever

the Processor processes personal data on behalf of the Controller within the

Service.

Emails sent through an SMTP server configured and controlled by the Controller

are transmitted outside the Processor's infrastructure and are not covered by

this DPA.

## 2. Subject matter and duration

Processing under this DPA starts when the Customer creates an organisation in the

Service and ends when the organisation is deleted (including the grace period).

## 3. Nature and purpose

Hosting, storing, displaying, and computing reports over data that the Controller

or its users enter into the Service.

## 4. Categories of data and data subjects

- **Categories of data:** identification and contact details, address, tax

identifiers, banking details, and any other content the Controller chooses to

enter.

- **Data subjects:** the Controller's employees, tenants, clients, vendors, and

other natural persons whose data the Controller enters into the Service.

## 5. Processor's obligations

The Processor shall: (a) process data only on documented instructions of the

Controller, (b) ensure confidentiality commitments of authorised personnel,

(c) implement appropriate technical and organisational measures (Art. 32 GDPR),

(d) assist the Controller with data-subject requests and Art. 32–36 obligations,

(e) delete or return all data at the end of the service.

## 6. Subprocessors

The Controller grants general authorisation for the Processor to engage the

subprocessors listed on the **Subprocessors** page of the Service. Material

changes to that list will be announced in-app before they take effect, and the

Controller may object for valid data-protection reasons.

## 7. Audits

Once per calendar year, the Controller may request reasonable information to

demonstrate compliance. On-site audits may be conducted by an independent auditor

under confidentiality, at the Controller's cost.

## 8. Personal data breach

The Processor shall notify the Controller without undue delay after becoming

aware of a personal data breach, with the information required under Art. 33(3)

GDPR.

## 9. International transfers

See the Privacy Policy for the safeguards relied on for transfers outside the

EEA.