Data processing agreement

Last updated 11 September 2026

These are the Article 28 terms on which OPSERION processes personal data on behalf of PROVIA customers. They form part of the terms of service and apply automatically to every account — there is nothing separate to sign.

1. Roles

You are the controller. You decide what tenant data to hold, why, and for how long. OPSERION is the processor, acting only on your instructions.

“UK GDPR” means the retained EU General Data Protection Regulation as it forms part of UK law, read with the Data Protection Act 2018.

2. Scope of processing

Detail
Subject matterProviding PROVIA to you
DurationFor as long as your account is open, plus the retention periods below
Nature and purposeStoring, organising, retrieving and transmitting data so you can manage your properties and tenancies
Types of dataNames, contact details, dates of birth, identification details and documents, employment details, emergency contacts, tenancy and financial records, uploaded documents, message logs
Categories of data subjectYour tenants and applicants, your staff, and your contractors
Special category dataNot required by the service. May be present incidentally in identification documents you choose to upload

3. Our obligations

  • We process personal data only on your documented instructions, which include your use of the service and any configuration you set. Using the product is an instruction.
  • If we believe an instruction breaches data protection law, we will tell you and may decline to act on it.
  • Everyone with access is bound by confidentiality obligations that survive the end of their engagement.
  • We keep appropriate technical and organisational security measures — see section 6.
  • We assist you, so far as is reasonable, with data subject requests, impact assessments and consultations with the ICO.
  • We notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data.
  • We make available the information you need to demonstrate compliance, and allow audits as set out in section 8.

4. Sub-processors

You give general authorisation for us to use the sub-processors listed below. Each is bound by written terms no less protective than these.

SupplierWhat they doWhere
Google Ireland Ltd / Google LLCApplication hosting, database and document storageEU and US
Netlify Inc.Serving the websiteUS, with a global content network
Twilio Ireland Ltd / Twilio Inc.Sending text messages and, where configured, emailEU and US
tawk.to Inc.Live chat on our own help page, where it is switched on. It sees what the person types to us, not the records on the page.US

We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period and we will try to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund.

5. International transfers

Where a sub-processor processes data outside the UK, the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by the supplier’s certification under the UK extension to the EU–US Data Privacy Framework. We do not transfer personal data to a country without such safeguards.

6. Security measures

  • Encryption of data in transit using TLS.
  • Encryption of data at rest by the underlying storage platform.
  • Passwords stored only as salted, iterated hashes — never recoverable.
  • Signed session tokens with a fixed expiry.
  • Role-based access control within each account, with four permission levels.
  • Documents stored privately and served only through the application’s permission checks; never as a public link.
  • An append-only audit log of actions affecting money.
  • Access to production systems limited to personnel who need it.

We may update these measures, but not in a way that materially reduces the level of protection.

7. Return and deletion

You can export your data at any time from the application, and delete your entire organisation from Settings. On deletion, records are removed immediately; stored documents are moved to a recovery area and destroyed within 30 days.

On termination we delete your data within 30 days unless you ask us in writing to return it first. Backups are overwritten on a rolling 90-day cycle. We may keep data where UK law requires it, and it stays protected by these terms while we do.

8. Audit

On reasonable written notice, and no more than once in any twelve months unless a breach or a regulator requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this agreement. Where a documented review is not sufficient, we will cooperate with an audit at your cost, conducted so as not to disrupt the service or compromise other customers’ confidentiality.

9. Data subject requests

If a tenant contacts us directly, we will not respond substantively. We will tell them to contact you and let you know it happened, unless the law prevents us. You are responsible for answering — the application gives you access to everything held about them, which is what you need to do so.

10. Liability and precedence

Liability under this agreement is subject to the limits in the terms of service. Where this agreement conflicts with those terms on the processing of personal data, this agreement prevails.

11. Contact

Data protection enquiries and breach notifications: george@opserion.uk