Data Processing Agreement

Version 1.0 · Issued September 2026

The Article 28 processor terms, including the processing schedule, technical and organisational measures and the sub-processor list.

Document Data Processing Agreement, version 1.0
Published at rentalize.com/legal/dpa
Status Incorporated into the Master Subscription Agreement by clause 1.3. Executed as a signed annex where the Order Form so provides
Applies from The date of the Order Form. Data protection obligations are not deferred to go-live
Governing law Ireland

This document works in two ways. It applies automatically as an incorporated policy, so that no separate signature is needed for the majority of customers. Where a customer requires an executed Article 28 agreement, the same text is signed at the end of this document and the executed version prevails over the published version. Nothing else changes.

1. Scope and status

1.1 This Data Processing Agreement sets out the terms on which Rentalize Software Limited, trading as Rentalize (the Processor), processes personal data on behalf of the customer identified in the Order Form (the Controller). It gives effect to Article 28 of Regulation (EU) 2016/679 (the GDPR) and to the Data Protection Act 2018.

1.2 It is incorporated into the Master Subscription Agreement by clause 1.3 of that agreement. Capitalised terms not defined here carry the meaning given in that agreement. Controller, processor, personal data, processing, personal data breach and data subject carry the meanings given in the GDPR.

1.3 Where the Order Form provides that this document is executed as a signed annex, the executed version prevails over the version published at rentalize.com/legal/dpa.

1.4 Where this document conflicts with the Master Subscription Agreement in relation to the processing of personal data, this document prevails. In all other respects that agreement prevails.

1.5 This document may be varied in a way that materially reduces the protection given to personal data only by written agreement signed by both parties, in accordance with clause 1.4(c) of the Master Subscription Agreement.

2. Roles

2.1 The Controller is the controller and the Processor is the processor in respect of personal data processed through the Platform.

2.2 The Processor acts as controller in respect of account administration data, billing data, support contact data and the security and audit logs it maintains for its own compliance purposes. Its processing of that data is governed by its own privacy notice and not by this document.

2.3 Each party shall comply with its own obligations under data protection law. Nothing in this document makes either party a joint controller with the other.

3. Details of the processing

The following describes the processing carried out under the Master Subscription Agreement, as required by Article 28(3).

Item Detail
Subject matter Provision of the Rentalize property management platform and the associated implementation, migration and support services.
Duration The term of the Master Subscription Agreement, together with the post-termination access period and the backup retention cycle described at clause 11.
Nature and purpose Hosting, storage, retrieval, transmission, analysis, backup and deletion of personal data for the purposes of residential property lettings and management, including tenancy administration, rent collection and arrears, compliance, maintenance, communications and reporting.
Categories of data subject Tenants and prospective tenants, guarantors, occupants, landlords and property owners, contractors and suppliers, and the Controller’s own personnel.
Categories of personal data Identity and contact details; tenancy, occupancy and allocation records; payment, arrears and transaction data; bank details where provided for collection; correspondence, notes and maintenance records; identity verification and reference documents; portal and platform usage data.
Special category data Not required by the Platform. Where the Controller uploads special category data, including data concerning health or disability recorded in connection with an allocation or a reasonable accommodation, the Controller is responsible for establishing a condition under Article 9 and for recording it in its own record of processing.
Criminal conviction data Not required by the Platform. Where the Controller records data relating to criminal convictions or offences, it is responsible for establishing a lawful basis under Article 10 and section 55 of the Data Protection Act 2018.
Location of processing The European Union. Primary hosting on Amazon Web Services in an EU region, with backups held in a second EU member state.
Transfers outside the EEA None in the ordinary course. Any transfer is subject to clause 8.

4. Processor obligations

4.1 The Processor shall process personal data only on the documented instructions of the Controller. The Master Subscription Agreement, the Order Form, this document and the Controller’s use of the Platform in accordance with the Documentation constitute those instructions. The Processor shall notify the Controller where it considers an instruction to infringe data protection law.

4.2 Where the Processor is required by European Union or member state law to process personal data otherwise than on the Controller’s instructions, it shall inform the Controller of that requirement before processing, unless the law prohibits it from doing so on important grounds of public interest.

4.3 The Processor shall ensure that persons authorised to process personal data are subject to a binding duty of confidentiality, have received data protection training appropriate to their role, and have access only to the data their role requires.

4.4 The Processor shall implement and maintain the technical and organisational measures described at Annex A, and shall not reduce the overall level of security during the term.

4.5 The Processor shall not sell personal data, use it for its own marketing, or use it to train any machine learning model other than as permitted at clause 5.

5. Use of aggregated and anonymised data

5.1 The Processor may use aggregated and anonymised data derived from use of the Platform for product improvement, benchmarking and statistical analysis, in accordance with clause 15.3 of the Master Subscription Agreement.

5.2 Data qualifies as anonymised for this purpose only where it has been irreversibly altered such that no data subject, and no landlord, tenant, contractor or the Controller itself, can be identified from it by any means reasonably likely to be used, whether alone or in combination with other information available to the Processor. Anonymisation is applied before the data is used, the Processor shall not attempt re-identification, and aggregated outputs shall be derived from a sufficient number of sources that no single customer’s position is inferable.

5.3 The Controller may opt out of this clause at any time on written notice, without charge and without effect on any other part of the service.

6. Assistance to the Controller

6.1 Data subject requests. The Platform provides the Controller with the functionality to locate, export, correct, restrict and delete personal data directly. The Processor shall additionally provide reasonable assistance with any request the Controller cannot fulfil through that functionality, taking into account the nature of the processing.

6.2 Where the Processor receives a request directly from a data subject relating to personal data processed on the Controller’s behalf, it shall not respond to the substance of the request. It shall forward the request to the Controller without undue delay and in any event within 3 Working Days.

6.3 The Processor shall provide reasonable assistance with data protection impact assessments and with prior consultation of the Data Protection Commission under Articles 35 and 36, taking into account the information available to it.

6.4 Assistance under this clause is provided at no charge where it is proportionate to the nature of the processing. Where assistance requires sustained engineering effort beyond that, it is chargeable at the day rate stated in the Order Form, and the Processor shall say so and provide an estimate before incurring the cost.

7. Personal data breach

7.1 The Processor shall notify the Controller without undue delay, and in any event within 48 hours, on becoming aware of a personal data breach affecting personal data processed on the Controller’s behalf.

7.2 An initial notification shall be given within 24 hours where the Processor has reasonable grounds to believe the breach is likely to result in a high risk to the rights and freedoms of data subjects. These periods are shorter than the 72 hours the GDPR allows a controller, so that the Controller retains time to assess and to notify.

7.3 The notification shall describe, so far as known at the time, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where the full information is not available, it shall be provided in phases without further undue delay. Notification is not deferred pending completion of the investigation.

7.4 The Processor shall provide the information the Controller reasonably requires to meet its obligations under Articles 33 and 34, shall cooperate with the Controller in responding to the breach, and shall not notify any data subject or supervisory authority on the Controller’s behalf without the Controller’s written instruction, save where required by law.

7.5 A suspected personal data breach is treated as a severity 1 incident under the Service Level Agreement and triggers the major incident process described there, including a written post incident review.

7.6 Notification under this clause is sent by email to the Controller’s data protection contact stated at section 11 of the Order Form and is logged in the Support Portal.

8. Sub-processors and transfers

8.1 The Controller gives general written authorisation to the appointment of sub-processors, subject to this clause.

8.2 The current sub-processors are listed at Annex B. The Processor maintains a sub-processor register naming each entity, which is provided to the Controller on execution and on each change.

8.3 The Processor shall give the Controller at least 30 days written notice of any intended addition or replacement of a sub-processor. Where the Controller objects on reasonable data protection grounds within that period, the objection is handled under clause 13.5 of the Master Subscription Agreement, which includes a right of termination without exit fee where the objection cannot be resolved.

8.4 The Processor shall impose on each sub-processor, by written contract, data protection obligations no less protective than those in this document, and remains fully liable to the Controller for the performance of each sub-processor’s obligations.

8.5 Personal data is hosted within the European Union. The Processor shall not transfer personal data outside the European Economic Area except on the basis of an adequacy decision or the Standard Contractual Clauses adopted by the European Commission, together with a transfer impact assessment and any supplementary measures required. The Processor shall notify the Controller in advance of any such transfer and shall identify in Annex B any sub-processor that processes outside the European Economic Area, together with the transfer mechanism relied on.

8.6 Remote access from outside the European Economic Area for support purposes is treated as a transfer and is subject to this clause.

9. Audit and evidence

9.1 The Processor shall make available to the Controller the information necessary to demonstrate compliance with Article 28 and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.

9.2 The Processor may satisfy an audit request by providing its current ISO/IEC 27001 certificate, its Statement of Applicability, its most recent independent penetration test summary and its most recent external audit report. Those documents are the Processor’s confidential information.

9.3 Where the Controller requires an on site audit in addition, it may carry out one audit in any 12 month period on 30 days written notice, at a time that does not disrupt the Processor’s operations, limited to the systems and records relevant to the processing, and subject to the auditor signing a confidentiality undertaking. The Controller bears its own costs and the Processor’s reasonable costs at the day rate stated in the Order Form. The auditor shall not be a competitor of the Processor.

9.4 A further audit may be carried out at any time following a personal data breach affecting the Controller’s data, or where a supervisory authority requires it, notwithstanding the once yearly limit at clause 9.3 and at clause 13.8 of the Master Subscription Agreement, and the cost of that audit is borne by the Processor where the breach arose from its own act or omission.

9.5 The Processor shall not be required to give access to any other customer’s data, or to information that would compromise the security of the Platform for other customers.

10. Controller obligations

10.1 The Controller warrants that it has a lawful basis for the processing it instructs, that it has provided the privacy information required by Articles 13 and 14 to the data subjects concerned, and that it maintains its own record of processing activities under Article 30.

10.2 The Controller is responsible for the accuracy, quality and legality of the personal data it uploads to the Platform, for the configuration decisions it makes, and for the access it grants to its own users and to landlords, tenants and contractors.

10.3 The Controller shall not upload special category data or criminal offence data to free text fields where a structured field is provided, and shall not use the Platform to process personal data for purposes unrelated to the management of the properties in its portfolio.

10.4 The Controller shall maintain its own retention policy and shall use the Platform’s deletion and archiving functionality to give effect to it. The Processor does not determine retention periods for the Controller’s data.

11. Return and deletion

11.1 The Controller may export personal data in open, machine readable formats at any time during the term and during the post-termination access period stated in the Order Form, at no charge.

11.2 At the end of the post-termination access period the Processor shall, at the Controller’s election, return or delete all personal data processed on the Controller’s behalf, and shall certify deletion in writing.

11.3 Copies held in encrypted backup in the ordinary course are deleted in accordance with the Processor’s retention cycle, which does not exceed 35 days from the date of deletion from the live environment. Those copies remain subject to this document and to clause 16 of the Master Subscription Agreement while they are held, are not restored to the live environment, and are not accessed except where restoration of the whole environment is required.

11.4 The Processor may retain personal data to the extent required by European Union or member state law, in which case it shall retain only what the law requires, for only as long as the law requires, and shall continue to protect it in accordance with this document.

12. Liability

12.1 Liability arising out of or in connection with this document is governed by clause 17 of the Master Subscription Agreement, including the specific cap at clause 17.7A for a personal data breach caused by the Processor.

12.2 Nothing in this document limits the rights of a data subject under the GDPR, or the liability of either party to a supervisory authority.

Annex A: Technical and organisational measures

The measures below are maintained throughout the term. They are reviewed annually and are subject to the Processor’s information security management system.

Governance and certification

  • Information security management system certified to ISO/IEC 27001, with a documented Statement of Applicability
  • Measures operated in line with the guidance in ISO/IEC 27018 on the protection of personal data in public cloud environments, and in ISO/IEC 27701 on privacy information management. The Processor is not certified to either standard and does not represent that it is
  • Named individual accountable for information security and for data protection
  • Annual review of policies, risk register and Statement of Applicability
  • Personnel screening on engagement, written confidentiality undertakings, and security awareness training on induction and annually thereafter
  • Documented offboarding process with revocation of access within one Working Day of departure

Access control

  • Role based access control applied on the principle of least privilege
  • Multi-factor authentication required for all administrative and privileged access
  • Named individual accounts with no shared credentials for administrative access
  • Quarterly review of privileged accounts and of third party access
  • Segregation of production, staging and development environments, with no live personal data in development environments

Encryption and data handling

  • Encryption in transit using TLS 1.2 or above
  • Encryption at rest for databases, object storage and backups
  • Key management through the hosting provider’s managed key service, with keys held in the European Union
  • Pseudonymisation applied where it does not defeat the purpose of the processing

Resilience and recovery

  • Encrypted daily backups retained for at least 30 days, held within the European Union
  • Point in time recovery across the preceding period stated in the Service Level Agreement
  • Recovery point and recovery time objectives as stated in the Order Form and the Service Level Agreement
  • Backup restoration tested at least quarterly, with the result recorded
  • Documented business continuity and disaster recovery plan, tested at least annually

Monitoring, testing and incident response

  • Centralised logging, monitoring and alerting, with audit trails retained for at least 12 months
  • Documented vulnerability management and patching, with severity based remediation targets
  • Independent penetration testing at least annually, with findings tracked to closure
  • Documented incident response process, tested at least annually, with breach notification in accordance with clause 7
  • Change management with peer review, automated testing and documented release approval

Supplier management

  • Due diligence on each sub-processor before appointment, and annually thereafter
  • Written contracts imposing equivalent data protection obligations
  • Sub-processor register maintained and provided to the Controller on each change

Annex B: Sub-processors

Sub-processor Location Function Transfer outside EEA
Amazon Web Services European Union Cloud hosting, storage and compute None
[Payment services provider] European Union Open banking, direct debit and card collection None
[Messaging services provider] European Union SMS and transactional email delivery None
[Monitoring services provider] European Union Application monitoring and error reporting None
[Support services provider] European Union Support ticketing and knowledge base None
[Backup services provider] European Union Encrypted offsite backup None

The named identity of each sub-processor is set out in the Processor’s current sub-processor register, provided to the Controller on execution and on each change, in accordance with clause 8.2. Any sub-processor processing personal data outside the European Economic Area is identified as such, together with the transfer mechanism relied on under clause 8.5.

Annex C: Contacts

Role Processor Controller
Data protection contact [email protected] As stated at section 11 of the Order Form
Breach notification address [email protected] As stated at section 11 of the Order Form
Audit requests [email protected] As stated at section 11 of the Order Form

Execution

This Annex is completed only where the Order Form provides that this Data Processing Agreement is executed as a signed annex. Where it does not, this document applies as incorporated by clause 1.3 of the Master Subscription Agreement and no signature is required.

SIGNED for and on behalf of

RENTALIZE SOFTWARE LIMITED (PROCESSOR)

SIGNED for and on behalf of

[CUSTOMER REGISTERED NAME] (CONTROLLER)

Signature: .............................................. Signature: ..............................................
Name: .............................................. Name: ..............................................
Position: .............................................. Position: ..............................................
Date: .............................................. Date: ..............................................

Version history

Version Date Change
1.0 September 2026 Initial issue of the standard form, replacing the customer specific data processing schedule

Questions about this document

This document is published so that it can be read before an Order Form is signed and referred to at any time afterwards. The version stated in a signed Order Form is the version that applies to that customer for its initial term, and superseded versions stay available at the same address.

Rentalize Software Limited

Email: legal@rentalize.com