Data Processing Agreement
This page sets out how we process personal data on your behalf. It supplements the Terms of Service and the Privacy Policy.
1. Roles
When you use the subscription service to manage properties and tenancies, you are the data controller for your tenants’ personal data and we are your data processor. We process that data only on your documented instructions, which are the actions you take in the product.
For the free one-off notice generator on the home page we are not a processor of tenant data at all, because none of it is stored: the details are held in memory only for as long as it takes to render your PDF.
2. What we process, and why
Categories of data subject: your tenants, and the people in your organisation who use the service.
Categories of personal data: tenant names, dwelling addresses and Eircodes, RTB registration numbers, rent amounts and dates, and the email addresses of your own users.
Purpose: producing rent review notices and telling you when a rent may lawfully be reviewed. We do not use your tenants’ data for anything else, and we never use it to train models.
3. Security measures
Tenant names, dwelling addresses, Eircodes and RTB registration numbers are encrypted with AES-256-GCM before they are written to the database, using a key held by a separate key management service. Someone who obtained a copy of the database — or of the whole disk — could not read them.
Every tenant-scoped table is protected by PostgreSQL row level security. The application connects with a role that is subject to those policies, so a bug in our code cannot return another organisation’s rows.
Access within your organisation is governed by roles (owner, manager, viewer). Every significant action is recorded in an audit trail that deliberately contains no personal data — only identifiers and counts.
4. Sub-processors
We use the sub-processors listed below. We will tell you before adding a new one that can access personal data. All of them are established in the EU.
| Sub-processor | Purpose | Location | What it can see |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the application and database | Germany / Finland (EU) | All data, at rest on encrypted volumes. Sensitive fields are additionally encrypted by us so that they are unreadable at the infrastructure layer. |
| Brevo (Sendinblue SAS) | Transactional email: sign-in links, rent review alerts, document delivery, and messages sent through the contact form | France (EU) | Recipient email addresses and the contents of the emails we send. Where you ask us to email a notice, that attachment contains tenant names and the property address. Messages sent through the contact form pass through it on the way to our inbox. |
| Central Statistics Office | Source of the Consumer Price Index used in the rent cap calculation | Ireland | Nothing. We fetch the published index on a schedule; the CSO never sees a request tied to you. |
5. Your rights and your tenants’ rights
You can export your data at any time and you can erase a tenancy’s personal data with the “Erase tenant personal data” action, which permanently removes the encrypted fields while keeping the rent amounts and dates you need for your own records. The erasure is irreversible and is recorded in the audit trail.
If a tenant contacts us directly, we will refer them to you, because you are the controller.
On termination we delete your data within 30 days, except where we are legally required to keep accounting records of payments.
6. Breach notification
If we become aware of a personal data breach affecting your data we will notify you without undue delay and in any case within 48 hours, with the information you need to meet your own 72-hour obligation to the Data Protection Commission.
7. Location of processing
All processing takes place within the European Union. We do not transfer personal data outside the EEA.