Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the agency using Estate CRM (the “Customer”, as controller) and TKOCY LTD, registration number HE399700, Kiriakou Matsi 9, 4712 Limassol, Cyprus (the “Processor”). It sets out the terms required by Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Cyprus Law 125(I)/2018. Words defined in the GDPR have the same meaning here.
1. Scope and roles
- This DPA applies to personal data that the Processor processes on behalf of the Customer when providing Estate CRM (the “Customer Personal Data”).
- The Customer is the controller and the Processor is its processor. Where the Customer itself acts as a processor for another controller, the Processor is its sub-processor and the Customer is responsible for passing on the relevant instructions.
- This DPA does not cover data for which the Processor is itself controller (such as users’ account and billing data), which is described in the Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter: hosting and processing of the Customer’s real-estate business data in Estate CRM.
- Duration: for as long as the Customer uses the Service, and afterwards until deletion under section 10.
- Nature: collection (including through public enquiry forms, portal e-mails and viewing forms the Customer uses), recording, organisation, storage, retrieval, matching of client requirements with listings, consultation, sending of e-mails, SMS and alerts on the Customer’s instructions, publication of listing data the Customer chooses to publish, restriction, erasure and destruction.
- Purpose: providing the Service to the Customer under the Terms, including support, security, backups and troubleshooting.
- Annex 1 describes the data subjects and categories of data.
3. Customer’s obligations
- The Customer is responsible for the lawfulness of the processing, including having a legal basis, giving information to data subjects, and respecting marketing and consent rules for messages it sends.
- The Customer’s instructions are these Terms and this DPA, the Customer’s configuration and use of the Service, and any further written instructions agreed between the parties.
4. Processor’s obligations
- The Processor processes Customer Personal Data only on documented instructions from the Customer, including with regard to transfers outside the EEA, unless EU or Member State law requires otherwise; in that case it informs the Customer before processing, unless the law prohibits this.
- The Processor informs the Customer immediately if, in its opinion, an instruction infringes the GDPR or other data-protection law.
- The Processor does not sell Customer Personal Data, does not use it for its own purposes (including advertising or training AI models), and does not combine it with other customers’ data.
5. Confidentiality
The Processor ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality (by contract or by law), and that access is limited to those who need it to provide, support or secure the Service.
6. Security
- The Processor implements appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, costs, and the nature, scope, context and purposes of the processing. The measures in place are listed in Annex 2.
- The Processor may update the measures as technology develops, provided the overall level of security is not reduced.
- The Customer is responsible for the security measures under its control: its Users’ sign-in details, roles and access rights, the two-step sign-in policy, and the devices used.
7. Sub-processors
- The Customer gives general authorisation for the Processor to engage sub-processors. The current list is published on the sub-processors page (Annex 3).
- The Processor informs the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by e-mail to the account owners or in the Service. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service and receive a refund of fees prepaid for the period after termination.
- The Processor imposes on each sub-processor, by written contract, data-protection obligations that give at least the same level of protection as this DPA, and remains responsible to the Customer for its sub-processors’ performance.
- Optional features that a User switches on (such as AI writing, Google Calendar sync or Telegram alerts) use the sub-processors listed for them only when switched on.
8. Assistance
- Taking into account the nature of the processing, the Processor assists the Customer with appropriate measures to respond to data subjects’ requests (access, rectification, erasure, restriction, portability, objection). Most requests can be handled by the Customer directly in the Service (editing, merging and deleting contacts). If a data subject contacts the Processor directly, the Processor passes the request to the Customer without undue delay and does not answer it itself unless instructed.
- The Processor assists the Customer, taking into account the information available to it, with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation). [Lawyer: decide whether extensive assistance is chargeable.]
9. Personal data breaches
- The Processor notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with a target of within 48 hours.
- The notification describes, as far as known: the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information not yet available is provided as it becomes available.
- The Processor takes reasonable steps to contain the breach and mitigate its effects, and documents it. Notification to the supervisory authority and to data subjects is the Customer’s decision as controller; the Processor assists.
10. Deletion or return
- When the Service ends, the Customer may ask for an export of Customer Personal Data within 30 days, in a common machine-readable format.
- After those 30 days the Processor deletes Customer Personal Data from the live Service, and backups containing it expire within a further 60 days, unless EU or Member State law requires storage. On request, the Processor confirms the deletion in writing.
11. Audits
- The Processor makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, in the first place by answering reasonable written questions and providing documentation of its measures.
- If that is not sufficient, or a supervisory authority requires it, the Customer (or an independent auditor bound by confidentiality) may carry out an audit, with at least 30 days’ notice, during business hours, no more than once in 12 months (except after a breach), in a way that does not compromise other customers’ data or the Service’s security. Each party bears its own costs [— lawyer to confirm].
12. International transfers
- The Service is hosted in the EU. Customer Personal Data is transferred outside the EEA only to sub-processors listed in Annex 3, and only where the transfer is covered by an adequacy decision (including the EU-US Data Privacy Framework for certified companies) or by the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), with supplementary measures where required.
- If a transfer mechanism is invalidated, the parties will cooperate to put another valid mechanism in place, or the Processor will stop the transfer.
13. Liability and order of precedence
- Liability under this DPA is subject to the limitations in the Terms, except where the GDPR does not allow limitation [— lawyer to review].
- If this DPA and the Terms conflict on data protection, this DPA prevails. If the Standard Contractual Clauses apply and conflict with this DPA, the Clauses prevail.
14. Term
This DPA applies for as long as the Processor processes Customer Personal Data, and ends automatically once that data has been deleted or returned under section 10.
Annex 1 — Details of the processing
Data subjects
- The Customer’s clients and prospective clients: buyers, sellers, tenants, landlords;
- property owners and their representatives;
- leads: people who send enquiries through share pages, the Customer’s website, portals or e-mail;
- the Customer’s staff and partners (as recorded in deals, commission splits and activities);
- other people the Customer records, such as co-buyers or lawyers.
Categories of personal data
- Contact details: names, company, e-mail addresses, phone numbers, nationality, preferred language, address where entered;
- property interests: requirements (type, area, budget, size, features), matches and their status, listings viewed or liked;
- property and ownership details linking a person to a listing, and listing agreements;
- communications and history: enquiries and their text, notes, calls, meetings, viewings and their outcome, e-mails, SMS and messages logged, deals and commission;
- consent and marketing records (such as a GDPR consent date, alert and unsubscribe status);
- identity-document numbers (ID or passport), where the Customer enters them;
- signatures on viewing forms, with the time and IP address of signing;
- any other data the Customer puts in free-text or custom fields.
Special categories
The Service is not designed for special categories of data (Art. 9 GDPR) or criminal-offence data (Art. 10). The Customer should not enter them.
Frequency
Continuous, for the duration of the Service.
Annex 2 — Technical and organisational measures
- Separation of customers. Every customer’s data carries its agency identifier. The application filters every query by the signed-in user’s agency and fails closed (no agency, no data). As a second wall, PostgreSQL row-level security policies on every customer table allow only the current agency’s rows; the production application connects as a database role that cannot bypass these policies. Automated tests check both layers for every customer table.
- Access control in the application. Roles (owner, manager, agent, assistant) and permissions are enforced on the server. Agents can be limited to their own contacts. Identity-document numbers are left out of list views.
- Authentication. Passwords stored as one-way hashes with strength rules; sign-in throttling; optional two-step sign-in with an authenticator app (one-time recovery codes stored protected), which account owners can make mandatory; mandatory for our platform administrators. A new session is created at every sign-in.
- Encryption. All traffic over TLS (HTTPS), through Cloudflare to our server. Secrets stored encrypted at rest in the database: two-step sign-in secrets, customers’ SMS API tokens, calendar connection tokens and platform credentials. [Confirm whether server disks / R2 storage are encrypted at rest, and add it here.]
- Files. Original uploads are kept in private storage and downloaded only through the authenticated application. Resized public photos sit under unguessable paths. Public listing pages show only public fields and an approximate location.
- Logging and accountability. Changes to listings, contacts and requirements are logged with who, when and the old and new values (sensitive values redacted). “Sign in as” support sessions by our staff are logged and visibly marked in the app.
- Backups and recovery. Encrypted-in-transit nightly database backups, kept 14 days on the server and 60 days off-site in EU storage [confirm R2 region]; each backup is verified after it runs, and restoring is tested [confirm how often].
- Hosting. Servers in the EU (Germany). Application services listen only on the local interface behind the web server; the database role has no superuser rights.
- Monitoring. Health checks of database, cache, scheduler and queue with alerts; error monitoring that strips personal data (no IP addresses, cookies, request bodies or names; SQL values removed).
- Data minimisation to third parties. AI writing sends only a listing’s public facts, plus the minimum client context for message drafts; nothing is saved without the user’s review. Calendar sync never sends clients’ phone numbers or e-mail addresses.
- Development. Code changes are tested automatically before release, including tenant-isolation tests; dependencies are kept up to date.
- People. Staff with access are bound by confidentiality, and access is limited to what their role needs. [Add: staff training, device security, incident response procedure.]
Annex 3 — Sub-processors
See the current list on the sub-processors page.