Data processing agreement
Last updated 11 September 2026
1. Roles
You are the controller. You decide what tenant data to hold, why, and for how long. OPSERION is the processor, acting only on your instructions.
“UK GDPR” means the retained EU General Data Protection Regulation as it forms part of UK law, read with the Data Protection Act 2018.
2. Scope of processing
| Detail | |
|---|---|
| Subject matter | Providing PROVIA to you |
| Duration | For as long as your account is open, plus the retention periods below |
| Nature and purpose | Storing, organising, retrieving and transmitting data so you can manage your properties and tenancies |
| Types of data | Names, contact details, dates of birth, identification details and documents, employment details, emergency contacts, tenancy and financial records, uploaded documents, message logs |
| Categories of data subject | Your tenants and applicants, your staff, and your contractors |
| Special category data | Not required by the service. May be present incidentally in identification documents you choose to upload |
3. Our obligations
- We process personal data only on your documented instructions, which include your use of the service and any configuration you set. Using the product is an instruction.
- If we believe an instruction breaches data protection law, we will tell you and may decline to act on it.
- Everyone with access is bound by confidentiality obligations that survive the end of their engagement.
- We keep appropriate technical and organisational security measures — see section 6.
- We assist you, so far as is reasonable, with data subject requests, impact assessments and consultations with the ICO.
- We notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data.
- We make available the information you need to demonstrate compliance, and allow audits as set out in section 8.
4. Sub-processors
You give general authorisation for us to use the sub-processors listed below. Each is bound by written terms no less protective than these.
| Supplier | What they do | Where |
|---|---|---|
| Google Ireland Ltd / Google LLC | Application hosting, database and document storage | EU and US |
| Netlify Inc. | Serving the website | US, with a global content network |
| Twilio Ireland Ltd / Twilio Inc. | Sending text messages and, where configured, email | EU and US |
| tawk.to Inc. | Live chat on our own help page, where it is switched on. It sees what the person types to us, not the records on the page. | US |
We will give you at least 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within that period and we will try to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund.
5. International transfers
Where a sub-processor processes data outside the UK, the transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or by the supplier’s certification under the UK extension to the EU–US Data Privacy Framework. We do not transfer personal data to a country without such safeguards.
6. Security measures
- Encryption of data in transit using TLS.
- Encryption of data at rest by the underlying storage platform.
- Passwords stored only as salted, iterated hashes — never recoverable.
- Signed session tokens with a fixed expiry.
- Role-based access control within each account, with four permission levels.
- Documents stored privately and served only through the application’s permission checks; never as a public link.
- An append-only audit log of actions affecting money.
- Access to production systems limited to personnel who need it.
We may update these measures, but not in a way that materially reduces the level of protection.
7. Return and deletion
You can export your data at any time from the application, and delete your entire organisation from Settings. On deletion, records are removed immediately; stored documents are moved to a recovery area and destroyed within 30 days.
On termination we delete your data within 30 days unless you ask us in writing to return it first. Backups are overwritten on a rolling 90-day cycle. We may keep data where UK law requires it, and it stays protected by these terms while we do.
8. Audit
On reasonable written notice, and no more than once in any twelve months unless a breach or a regulator requires otherwise, we will provide the information reasonably needed to demonstrate compliance with this agreement. Where a documented review is not sufficient, we will cooperate with an audit at your cost, conducted so as not to disrupt the service or compromise other customers’ confidentiality.
9. Data subject requests
If a tenant contacts us directly, we will not respond substantively. We will tell them to contact you and let you know it happened, unless the law prevents us. You are responsible for answering — the application gives you access to everything held about them, which is what you need to do so.
10. Liability and precedence
Liability under this agreement is subject to the limits in the terms of service. Where this agreement conflicts with those terms on the processing of personal data, this agreement prevails.
11. Contact
Data protection enquiries and breach notifications: george@opserion.uk