# Data Processing Agreement
## 1. Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between
the Operator ("Processor") and the Customer ("Controller") and applies whenever
the Processor processes personal data on behalf of the Controller within the
Service.
Emails sent through an SMTP server configured and controlled by the Controller
are transmitted outside the Processor's infrastructure and are not covered by
this DPA.
## 2. Subject matter and duration
Processing under this DPA starts when the Customer creates an organisation in the
Service and ends when the organisation is deleted (including the grace period).
## 3. Nature and purpose
Hosting, storing, displaying, and computing reports over data that the Controller
or its users enter into the Service.
## 4. Categories of data and data subjects
- **Categories of data:** identification and contact details, address, tax
identifiers, banking details, and any other content the Controller chooses to
enter.
- **Data subjects:** the Controller's employees, tenants, clients, vendors, and
other natural persons whose data the Controller enters into the Service.
## 5. Processor's obligations
The Processor shall: (a) process data only on documented instructions of the
Controller, (b) ensure confidentiality commitments of authorised personnel,
(c) implement appropriate technical and organisational measures (Art. 32 GDPR),
(d) assist the Controller with data-subject requests and Art. 32–36 obligations,
(e) delete or return all data at the end of the service.
## 6. Subprocessors
The Controller grants general authorisation for the Processor to engage the
subprocessors listed on the **Subprocessors** page of the Service. Material
changes to that list will be announced in-app before they take effect, and the
Controller may object for valid data-protection reasons.
## 7. Audits
Once per calendar year, the Controller may request reasonable information to
demonstrate compliance. On-site audits may be conducted by an independent auditor
under confidentiality, at the Controller's cost.
## 8. Personal data breach
The Processor shall notify the Controller without undue delay after becoming
aware of a personal data breach, with the information required under Art. 33(3)
GDPR.
## 9. International transfers
See the Privacy Policy for the safeguards relied on for transfers outside the
EEA.