Property Rooms — Data Processing Agreement
- Version
- 1.0
- Effective date
- August 20, 2026
This Data Processing Agreement ("DPA") forms part of the agreement governing the use of Property Rooms.
This English version is provided for convenience. In the event of inconsistency, the Polish version prevails unless mandatory applicable law requires otherwise.
1. Parties
Controller
The Controller is the real estate agency, independent real estate professional or other professional customer identified as the account owner in Property Rooms ("Controller").
The Controller determines which clients are invited to Property Rooms and the purposes for which their personal data is processed within client rooms.
Processor
Aliaksandr Karnilovich NIP: 9512513807 Wąwozowa 6/61 02-796 Warsaw Poland
Email: privacy@propertyrooms.pl
operating Property Rooms ("Processor").
The Controller and Processor are jointly referred to as the "Parties".
2. Scope
This DPA applies where Property Rooms processes personal data on behalf of the Controller in connection with client rooms and related collaboration functionality ("Client Room Data").
Client Room Data includes personal data entered into or generated through rooms by the Controller, its personnel, invited clients and other authorised participants.
This DPA does not apply to personal data for which Property Rooms independently determines the purposes and means of processing, including account administration, platform security, billing and invoicing, trial requests, support correspondence, legal compliance and anonymous or aggregated statistics that no longer relate to an identifiable individual.
Operational activity data necessary to provide room functionality, read/unread state, notifications or security remains subject to this DPA where it relates to identifiable room participants.
Data derived from Client Room Data will not be used by Property Rooms for its own independent product-analytics purposes unless first anonymised or aggregated so that it no longer relates to an identified or identifiable individual.
3. Roles
For Client Room Data:
the account owner acts as Controller; Property Rooms acts as Processor.
The Processor shall process Client Room Data only on documented instructions from the Controller, as necessary to provide the Service, or where required by Union or Member State law.
Where applicable law requires processing beyond the Controller's instructions, the Processor shall inform the Controller before such processing unless prohibited from doing so by law.
If the Processor believes that an instruction infringes applicable data-protection law, it shall inform the Controller without undue delay.
4. Documented instructions
Documented instructions include actions performed by authorised users through Property Rooms, including:
creating and administering client rooms; inviting and removing participants; adding, updating and deleting properties and notes; using room and property discussions; storing reactions and workflow information; sending service-related notifications; configuring account and room settings; authorised support requests; other written instructions agreed between the Parties.
The Processor is not required to carry out an unlawful or technically impossible instruction, or an instruction materially outside the agreed Service, without separate agreement.
5. Controller obligations
The Controller is responsible for:
having an appropriate lawful basis for Client Room Data; providing information required under GDPR Articles 13 or 14, as applicable; inviting only persons whose data it is entitled to process; limiting data entered into the Service to what is reasonably necessary; having the right to disclose information entered into Property Rooms; determining the purposes and lawful basis of processing; maintaining appropriate user permissions for its account.
Property Rooms is not intended for systematic processing of special-category personal data under GDPR Article 9 or criminal-conviction and offence data under Article 10.
The Controller should not intentionally enter such data unless it has an appropriate lawful basis and, where necessary, additional safeguards have been agreed.
6. Confidentiality
The Processor shall ensure that persons authorised to process Client Room Data:
are subject to appropriate confidentiality obligations; receive access only where necessary for their duties; process data in accordance with this DPA and documented instructions.
Property Rooms platform administrators do not have ordinary application-level access allowing them to freely browse client rooms.
Access by authorised personnel to production systems or underlying data shall be limited to circumstances reasonably necessary for operation, security, incident handling, maintenance or legal compliance.
7. Security
The Processor shall implement and maintain technical and organisational measures appropriate to the risks of processing in accordance with GDPR Article 32.
The current categories of measures are described in Annex II.
The Processor may modify individual safeguards as technology and risks evolve, provided that the overall level of protection is not materially reduced.
8. Subprocessors
The Controller grants the Processor general authorisation to engage subprocessors necessary to provide Property Rooms.
Current providers are identified in Annex III and may also be maintained on the current Property Rooms subprocessor page.
The Processor shall:
maintain an up-to-date list of material subprocessors; impose appropriate data-protection obligations on them; remain responsible for their performance to the extent required by applicable law.
The Controller shall receive reasonable advance notice of a material new subprocessor that will process Client Room Data, normally approximately 14 days in advance where practicable.
The Controller may object within that period on reasonable data-protection grounds.
The Parties shall make reasonable efforts to resolve the objection.
Where no reasonable solution is available, the Controller may terminate the affected part of the Service or relevant processing before the new subprocessor begins processing its Client Room Data.
9. International transfers
Any transfer of Client Room Data outside the European Economic Area shall take place in accordance with GDPR Chapter V.
Applicable safeguards may include:
an adequacy decision; European Commission Standard Contractual Clauses; another lawful transfer mechanism.
The Controller authorises the Processor to enter into appropriate transfer arrangements with approved subprocessors where necessary to provide the Service.
10. Data-subject rights
Taking into account the nature of processing, the Processor shall reasonably assist the Controller in responding to requests concerning:
access; rectification; erasure; restriction; portability; objection; other applicable data-subject rights.
Where the Processor receives a request relating primarily to Client Room Data directly from a data subject, it may direct the request to the Controller or inform the Controller and assist with the response.
The Processor shall not independently determine the Controller's lawful basis or substantive response unless required by law.
11. Personal-data breaches
The Processor shall notify the Controller without undue delay after becoming aware of a personal-data breach affecting Client Room Data.
Where available, the notification shall provide information reasonably necessary for the Controller to assess its obligations, including:
the nature of the incident; categories of affected data; categories or approximate number of affected data subjects where known; likely consequences; measures taken or proposed to contain or mitigate the incident; a contact point for further information.
Information may be provided in phases where it is not immediately available in full.
The Processor shall reasonably cooperate with the Controller in investigating and responding to the incident.
12. Compliance assistance
Taking into account the nature of processing and the information available to it, the Processor shall reasonably assist the Controller with obligations relating to:
security of processing; personal-data breaches; data-protection impact assessments; prior consultation with supervisory authorities; data-subject rights; information necessary to demonstrate compliance with GDPR Article 28.
Ordinary assistance inherent in the operation of the Service is included in Property Rooms.
Unusually extensive assistance arising solely from the Controller's specific compliance requirements may be subject to reasonable fees agreed in advance where permitted by law.
This does not apply where assistance is required because of a breach of this DPA attributable to the Processor.
13. Return and deletion
Before deletion, the Controller may request through support a return of Client Room Data in a reasonably available structured format.
Property Rooms is not required to provide a self-service export tool.
Following termination of the Service, the Controller may choose:
return of Client Room Data; or deletion of Client Room Data.
Unless the Controller instructs otherwise, deletion is the default following the applicable retention policy.
Data in the active production environment is deleted according to the published retention period, currently generally within up to 30 days following termination of the Service.
Residual copies may remain in rotating backups until the relevant backup expires under the documented retention cycle. Backup copies are maintained for resilience and disaster recovery and are not intended for ordinary active processing.
The Processor may retain personal data where retention is required by Union or Member State law.
14. Audits and compliance information
The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA and GDPR Article 28.
Where appropriate, the Parties should first use:
security documentation; written questionnaires; existing compliance materials; remote review.
The Controller may conduct an audit itself or through an authorised auditor where reasonably necessary to demonstrate compliance.
Except in urgent circumstances such as a serious security incident or supervisory-authority request, audits should be subject to reasonable notice, occur during normal business hours and avoid unreasonable disruption or disclosure of other customers' confidential information.
Each Party bears its own audit costs unless the audit identifies a material breach of this DPA attributable to the Processor or applicable law requires otherwise.
15. Duration
This DPA remains in force for as long as the Processor processes Client Room Data on behalf of the Controller.
Provisions concerning confidentiality, return and deletion, audits and liability survive termination where relevant data or obligations remain.
16. Relationship with the Terms
This DPA supplements the Property Rooms Terms of Service.
In the event of a conflict concerning Client Room Data:
mandatory applicable data-protection law prevails; this DPA prevails; the Terms otherwise continue to apply.
The governing-law and jurisdiction provisions of the Terms also apply to this DPA unless mandatory data-protection law requires otherwise.
17. Electronic acceptance
This DPA may be accepted electronically.
Property Rooms shall retain an acceptance record including at least:
the Controller account; the person accepting; DPA version; date and time of acceptance.
A person accepting this DPA on behalf of an organisation represents that they are authorised to bind that organisation.
18. Contact
Questions concerning this DPA or Client Room Data may be sent to:
privacy@propertyrooms.pl
Annex I — Description of Processing
A. Subject matter
Provision of Property Rooms as a private collaboration workspace in which real estate professionals and their clients can discuss, evaluate and compare properties and manage the associated client workflow.
B. Duration
For the duration of the Controller's use of Property Rooms and the applicable deletion and backup-retention periods following termination.
C. Nature and purposes
Processing may include:
collection of information submitted by authorised users; storage of client-room information; management of room membership and permissions; storage of messages, comments and notes; storage of property reactions and preferences; storage of manually entered property information; workflow status and next-action functionality; property comparison; read/unread state; service notifications; authentication and access control; backup and disaster recovery; troubleshooting; security and abuse prevention; support performed on the Controller's instructions.
D. Categories of data subjects
Depending on the Controller's use of the Service:
prospective buyers; prospective tenants; clients of the Controller; property owners or sellers where their information is entered; invited household members or other participants; agents and authorised personnel whose activity forms part of the client workflow.
E. Categories of personal data
Depending on use of the Service:
name; email address; room membership; property preferences; budget and preferred locations where provided; messages; comments; reactions; workflow information; notes; information voluntarily entered by users; identifiers and timestamps necessary to provide functionality, read state and notifications.
F. Special-category data
Systematic processing of GDPR Article 9 or Article 10 data is not an intended feature of Property Rooms.
Annex II — Technical and Organisational Measures
Property Rooms applies measures appropriate to the nature and risks of the Service, including:
account-, role- and room-based access controls; server-side permission enforcement; protected authentication mechanisms; appropriate protection of passwords, tokens and other authentication credentials; multi-factor authentication for privileged administrative access; HTTPS/TLS encrypted transmission; restriction of production access according to operational need; regular backups and recovery procedures; separation of demonstration and production data; logging of appropriate administrative and security events; incident-management procedures; access-revocation procedures; data deletion and retention controls; data minimisation consistent with the purpose of the Service.
Detailed safeguards may evolve as technology and risks change.
Annex III — Approved Subprocessors
OVH
- Purpose
- Application, database and infrastructure hosting for Property Rooms.
- Data
- Application and customer data necessary to provide the Service.
- Primary location
- European Economic Area according to the current Property Rooms configuration.
Brevo (Sendinblue)
- Purpose
- Transactional email delivery, including authentication, invitations and service notifications, and handling of @propertyrooms.pl mailboxes.
- Data
- Recipient email address, name or identifier where applicable, email content and other information necessary to provide email functionality.
- Primary location
- Processing locations and international transfers are governed by the DPA and subprocessor arrangements applicable to the Property Rooms Brevo account.