Data Processing Agreement
Version 2.0
This Data Processing Agreement ("DPA") is entered into between:
The Customer (hereinafter "Controller") — the natural or legal person who has registered for and uses the Eigentum² platform, and
Ilya Baskakov (Operating as: Eigentum²) Von-Müller-Straße 15a 82467 Garmisch-Partenkirchen, Germany Email: support@dein-eigentum.de
(hereinafter "Processor")
This DPA supplements the Terms of Service and governs the processing of personal data by the Processor on behalf of the Controller in connection with the use of the Eigentum² platform, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
Where the Processor processes personal data for its own purposes — for example the Controller's own account and billing data, the Processor's website, and the Processor's own marketing — the Processor acts as controller and that processing is governed by the Privacy Policy rather than by this DPA.
§ 1 Subject Matter and Duration
-
The Processor processes personal data on behalf of the Controller in connection with the provision of the Eigentum² property management platform as described in the Terms of Service.
-
The duration of this DPA corresponds to the duration of the underlying service agreement (Terms of Service). This DPA automatically terminates upon termination of the service agreement, subject to the data deletion and return obligations in § 13.
§ 2 Nature and Purpose of Processing
The Processor processes personal data for the following purposes:
- Storage and management of tenant and contact data entered by the Controller
- Processing of rent payments, security deposits, and financial transaction records
- Management of lease contracts and associated documentation
- Management of loans and financing, including the AI-assisted reading of loan documents the Controller selects for that purpose (§ 9)
- Storage and organisation of property-related documents, images and files
- Generating AI-assisted property valuations from property data (§ 9)
- Facilitating property information sharing with third parties designated by the Controller
- Facilitating ownership transfer workflows, including the invitation and participation of third parties designated by the Controller
- Generating in-app notifications and reminders derived from the Controller's own records
- Sending transactional and service emails on behalf of the Controller (for example notifications, invitations and automated reminders derived from the Controller's own records)
- Keeping the change histories and records described in Annex 1
The Processor does not process personal data for its own purposes, does not sell it, does not use it for advertising, and does not use it to train, fine-tune or improve any machine-learning model.
§ 3 Types of Personal Data
The following types of personal data are processed:
- Identification data: First name, last name, salutation, date of birth, nationality
- Contact data: Email address, phone number, mobile number, fax number, postal address
- Financial data: IBAN, BIC, bank name, payment amounts, rent amounts, security deposit amounts, transaction records
- Contractual data: Lease contract details (start and end dates, rent model, notice period, special terms), contract numbers
- Loan and financing data: Lender and borrower details, guarantors, account and reference numbers, principal, balances, interest rates, fixed-rate periods, repayment schedules
- Property-related data: Property addresses, coordinates, unit details, area measurements, characteristics, register and legal attributes
- Communication data: Notes, correspondence records, share messages
- Document data: Uploaded documents, images and files, including their file names, metadata and — necessarily — whatever content the Controller chooses to upload
- Emergency contact data: Name, relationship, phone number of designated emergency contacts
- Identity verification data: Verification status and timestamps
- Professional credentials: Organisation name and professional licence numbers of participants acting in a professional capacity in an ownership transfer
Special categories of personal data (Article 9 GDPR). The platform is not designed for, and does not ask for, special categories of personal data. The Processor neither requires nor evaluates them. They may nevertheless reach the platform through content the Controller uploads or types — for example a death certificate or a probate order in an ownership transfer, a health declaration inside a residual-debt insurance schedule attached to a loan file, or a free-text note. Where that occurs, the Controller remains responsible for having a condition under Article 9(2) GDPR, and the Processor processes such data solely as part of the content it stores on the Controller's behalf. The Controller is advised to redact documents that contain special categories of personal data not required for the purpose.
§ 4 Categories of Data Subjects
The personal data processed concerns the following categories of data subjects:
- Tenants (Mieter) — current tenants of properties managed by the Controller
- Prospective tenants (Mietinteressenten) — individuals considered for tenancy
- Guarantors (Bürgen) — persons providing guarantees for tenants
- Co-tenants and occupants — additional persons listed on lease contracts
- Emergency contacts — persons designated as emergency contacts
- Borrowers, co-borrowers and loan guarantors — persons named in loan and financing records and documents
- Property managers and service providers — third-party contacts managing or servicing properties
- Ownership transfer participants — the persons the Controller invites to a transfer, and the persons named in the documents uploaded to it, which may include buyers, sellers, notaries, agents, spouses, heirs and deceased persons
- Recipients of a shared property — the persons to whom the Controller grants access to a property
- The Controller's own users — the members of the Controller's organisation, in respect of the data the Controller records about them
§ 5 Controller's Instructions
-
The Processor shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by European Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest.
-
The Controller's instructions are initially defined by this DPA, the Terms of Service, and the functionality of the Eigentum² platform. Each use of a function of the platform constitutes an instruction to carry out the processing that function performs. The Controller may issue additional instructions in Text Form (§ 126b BGB) via email to support@dein-eigentum.de.
-
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other European Union or Member State data protection provisions. The Processor may suspend the execution of such an instruction until it is confirmed or withdrawn.
§ 6 Controller's Own Responsibilities
-
The Controller is responsible for the lawfulness of the processing it instructs, in particular for having a legal basis under Article 6 GDPR — and, where applicable, a condition under Article 9(2) GDPR — for entering the personal data of third parties into the platform.
-
The Controller is responsible for informing its own data subjects in accordance with Articles 13 and 14 GDPR, including about the engagement of the Processor and its sub-processors.
-
The Controller determines what it uploads, whom it invites to an ownership transfer, with whom it shares a property, and which documents it selects for AI-assisted reading. The Processor performs those operations as instructed and does not assess whether they are appropriate.
-
The Controller is responsible for the administration of its own organisation within the platform: the accounts it creates, the roles and permissions it assigns, and the withdrawal of access from persons who should no longer have it.
§ 7 Processor's Obligations
The Processor shall:
-
Process personal data within the European Economic Area (EEA), except where a sub-processor authorised under § 9 processes data outside the EEA, in which case the safeguards in § 9(7) apply.
-
Ensure that processing is carried out in accordance with the GDPR, the BDSG, and all other applicable data protection laws.
-
Implement and maintain the technical and organisational measures set out in Annex 1, and keep them under review. The Processor may modify individual measures provided the level of protection is not reduced.
-
Appoint a Data Protection Officer if required by law. As of the date of this DPA, the conditions under § 38 BDSG are not met (fewer than 20 persons regularly engaged in automated processing of personal data).
-
Not use the personal data for any purpose other than performing the services described in this DPA and the Terms of Service.
§ 8 Confidentiality
-
The Processor shall ensure that all persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that they are instructed in data protection before access is granted.
-
This confidentiality obligation shall survive the termination of this DPA.
§ 9 Sub-Processors
-
The Controller grants the Processor general written authorisation to engage sub-processors for the processing of personal data, subject to the conditions in this section.
-
The current list of approved sub-processors is set out in Annex 2 of this DPA and is also available at https://dein-eigentum.de/legal/subprocessors.
-
The Processor shall inform the Controller of any intended addition or replacement of sub-processors at least 30 days before the change takes effect, giving the Controller the opportunity to object to such changes.
-
If the Controller objects to a new sub-processor on reasonable data protection grounds, the parties shall discuss the objection in good faith. If the objection cannot be resolved, the Controller may terminate the service agreement without penalty as of the date the sub-processor change was intended to take effect.
-
The Processor shall impose on each sub-processor, by way of a contract, the same data protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.
-
Where a sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of the sub-processor's obligations.
-
For sub-processors located outside the EEA, the Processor shall ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR (adequacy decision, Standard Contractual Clauses, or EU-US Data Privacy Framework certification). Annex 2 states the safeguard relied upon for each such sub-processor.
-
AI sub-processors — express notice. Two sub-processors are engaged only for the AI-assisted features of the platform and only when the Controller starts them. The Controller acknowledges and instructs the following:
a. When the Controller requests a property valuation, the property record identified in the AI Transparency Notice is transmitted to OpenAI. That record includes the property's full address and coordinates and the Controller's free-text entries about the property. It does not include tenant, contact, guarantor, loan or account data, and it does not identify the Controller.
b. When the Controller selects loan documents and starts the reading, those documents are transmitted in full and unaltered, together with their file names. The Processor does not extract, redact, crop or pre-filter them. Everything printed in a selected document is therefore transmitted, including personal data of third parties and any special categories of personal data the document happens to contain. The selection is made by the Controller and constitutes its instruction to transmit those documents.
c. Neither provider uses the data to train, fine-tune or improve its models. Requests to OpenAI are made with response storage disabled; OpenAI may retain a copy for up to 30 days for abuse detection. Google logs prompts and responses for a limited period for the same purpose.
d. Nothing is transmitted to either provider unless the Controller starts the feature concerned. A Controller that does not use these features causes no processing by these sub-processors.
§ 10 Data Subject Rights
-
The Processor shall assist the Controller, by appropriate technical and organisational measures and taking into account the nature of the processing, in fulfilling the Controller's obligation to respond to requests for exercising the data subject's rights under Chapter III of the GDPR (Articles 15-22), including:
- Right of access (Article 15)
- Right to rectification (Article 16)
- Right to erasure (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
-
The platform itself enables the Controller to satisfy most such requests directly: records can be viewed, corrected, exported and deleted from within it, and a share or a transfer invitation can be revoked at any time.
-
If a data subject contacts the Processor directly with a request, the Processor shall promptly forward the request to the Controller and shall not respond to the data subject directly unless instructed by the Controller.
§ 11 Data Breach Notification
-
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Controller's data.
-
The notification shall include, to the extent possible:
- A description of the nature of the breach, including the categories and approximate number of data subjects and personal data records concerned
- The name and contact details of the Processor's contact point for further information
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects
-
Where the information cannot be provided in full at once, it shall be provided in phases without undue further delay.
-
The Processor shall assist the Controller in fulfilling its obligations under Articles 33 and 34 of the GDPR (notification to the supervisory authority and communication to data subjects). The obligation to notify the supervisory authority remains that of the Controller.
§ 12 Audit Rights
-
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR.
-
The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Controller shall provide at least 14 days written notice prior to any audit.
-
Audits shall be limited to one audit per calendar year, unless a data breach or other specific incident requires additional audits. Audits shall generally be limited to one business day and shall be conducted during regular business hours. An auditor mandated by the Controller must not be a competitor of the Processor and must be bound to confidentiality.
-
An audit may not extend to data or systems of other customers of the Processor, and may not compromise the security of the platform.
-
The Controller shall bear the costs of audits it initiates, unless the audit reveals a material breach of this DPA by the Processor, in which case the Processor shall bear the costs.
-
The Processor may in the first instance demonstrate compliance through this DPA and Annex 1, through the current certifications of its infrastructure providers (for example SOC 2 Type II reports or ISO 27001 certificates), and through the results of independent third-party audits, provided these are current and comprehensive.
§ 13 Data Deletion and Return
-
Upon termination of the service agreement, the Processor shall, at the Controller's choice:
- Return all personal data to the Controller in a structured, commonly used, and machine-readable format, or
- Delete all personal data and all existing copies
-
Several parts of the data can be exported by the Controller directly from within the platform. For a complete export, the Controller may request one in Text Form; the Processor shall provide it within 30 days of the request.
-
When a record is deleted in the platform — including the Controller's account and organisation — it is immediately withdrawn from use and marked as deleted, and it is irreversibly erased 90 days later, together with everything that depends on it. Files are removed from object storage in the same operation. The 90 days exist so that an erroneous deletion can be reversed and so that records subject to a statutory retention obligation are identified before destruction.
-
Data subject to statutory retention obligations (for example financial records under § 147 AO, commercial correspondence under § 257 HGB) shall be retained for the legally required period and then deleted. During this period the data shall be restricted from processing and used only for the purpose of complying with the retention obligation.
-
The Processor shall confirm the completion of data deletion upon the Controller's request.
-
Backups are overwritten in the ordinary backup cycle. A record deleted under paragraph 3 may persist in a backup until that cycle completes; it is not restored into the live system and is not otherwise processed.
§ 14 Assistance with Compliance Obligations
The Processor shall assist the Controller in ensuring compliance with the following obligations, taking into account the nature of the processing and the information available to the Processor:
- Security of processing (Article 32 GDPR)
- Notification of personal data breaches to supervisory authorities (Article 33 GDPR)
- Communication of personal data breaches to data subjects (Article 34 GDPR)
- Data protection impact assessments (Article 35 GDPR)
- Prior consultation with supervisory authorities (Article 36 GDPR)
Where such assistance goes materially beyond providing information that already exists, the Processor may charge its reasonable costs, having first informed the Controller.
§ 15 Liability
The liability of the parties under this DPA is governed by Article 82 of the GDPR and the liability provisions of the Terms of Service. Each party is liable for damages caused by processing that infringes the GDPR, in accordance with its respective role as Controller or Processor. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR.
§ 16 Final Provisions
-
This DPA is governed by the laws of the Federal Republic of Germany, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
-
In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.
-
Amendments and supplements to this DPA must be made in Text Form (§ 126b BGB).
-
If any provision of this DPA is or becomes invalid, the remaining provisions shall remain in force. The invalid provision shall be replaced by a valid provision that most closely reflects the original intent.
Annex 1: Technical and Organisational Measures
The Processor implements the following measures pursuant to Article 32 GDPR. They describe the platform as it is actually built; where a measure is provided by an infrastructure provider rather than by the Processor's own code, that is stated.
I. Confidentiality
Physical access control (Zutrittskontrolle):
- The Processor operates no data centre of its own. All processing takes place on the infrastructure of the providers named in Annex 2, whose physical security is covered by their SOC 2 Type II and ISO 27001 certifications.
System access control (Zugangskontrolle):
- Authentication by email address and password, with the password stored only as a scrypt hash with a per-password salt. Passwords are never stored in plain text and never in a recoverable form.
- Optional sign-in with Google (OAuth 2.0), where no password reaches the Processor at all.
- Email address verification is required before an account can be used.
- Optional two-factor authentication with a time-based one-time code and single-use backup codes. The shared secret and the backup codes are stored encrypted with a key held by the application.
- Sessions are carried in cookies marked HttpOnly, Secure and SameSite=Lax, expire automatically after at most seven days, and can be revoked; because the cached copy of a session lives for 30 seconds, a revocation takes effect within seconds.
- Rate limiting on the authentication endpoints and on the endpoints that can be called without signing in.
Data access control (Zugriffskontrolle):
- Role-based access control (RBAC) with granular permissions, enforced on the server for every operation rather than in the interface alone.
- Every query is scoped to the organisation of the requesting user, so that data of one organisation is not reachable from another.
- Principle of least privilege for all roles.
- Access to production data by the Processor's personnel is limited to those who need it to operate the platform, and each such person is bound to confidentiality and instructed in data protection beforehand.
Separation control (Trennbarkeit):
- Logical separation of the data of each organisation, enforced in the data access layer of the application.
- Separation of production, staging and development environments. Non-production environments are not connected to the production database, and the staging environment is closed to the public behind an access wall.
II. Integrity
Transfer control (Übertragungskontrolle):
- All data in transit is encrypted with TLS 1.2 or higher.
- HTTP security headers, including a Content Security Policy restricting the hosts from which content may be loaded.
- Authenticated API endpoints. Documents — the category that carries contracts, statements and identity papers — are served only through short-lived signed links, issued after the server has checked the requester's permission, which expire and cannot be reused. Property photographs are served from the storage host under paths derived from account and property identifiers; those paths are not guessable and are not published, and each fetch is not separately permission-checked, which is the ordinary way photographs are delivered on property platforms.
Input control (Eingabekontrolle):
- A change history for loans, recording the loan, the user, the time, the kind of change, the field affected, and the value before and after.
- An event history for ownership transfers, recording the event, the person and role that caused it, and the state before and after.
- Records of the acceptance of legal documents, of cookie decisions, of billing consents, and of tax identification number changes, each with the time and — for these four cases only — the IP address and browser user agent at the moment of the decision.
- Server-side validation of all input against declared schemas, so that data that does not conform is rejected before it is stored.
III. Availability and Resilience
Availability control (Verfügbarkeitskontrolle):
- Application hosting on Vercel in the EU (Frankfurt) region, on infrastructure certified to SOC 2 Type II and ISO 27001.
- Database hosting on Neon in the EU (Frankfurt) region: managed PostgreSQL with automatic backups and point-in-time recovery.
- File and document storage on Google Cloud Storage, encrypted at rest.
Recoverability (Wiederherstellbarkeit):
- Automated database backups with point-in-time recovery, provided by the database host.
- Infrastructure and configuration defined as code, so that an environment can be rebuilt.
- Deleted records are recoverable for 90 days before irreversible erasure (§ 13(3)).
IV. Regular Review
Processor control (Auftragskontrolle):
- Processing governed by this DPA and by written agreements with each sub-processor.
- Review of sub-processor compliance, and of the safeguards for transfers outside the EEA, on engagement and periodically thereafter.
- Documented incident response procedure for personal data breaches.
- The measures in this Annex are reviewed when the platform changes materially and at least annually.
Annex 2: Approved Sub-Processors
| Sub-Processor | Location | Processing Purpose | Transfer Mechanism |
|---|---|---|---|
| Vercel Inc. | EU (Frankfurt) | Application hosting, content delivery, serverless compute, and the short-lived server log files this produces | EU processing; no third-country transfer |
| Neon Inc. | EU (Frankfurt) | Managed PostgreSQL database hosting with automatic backups | EU processing; no third-country transfer |
| Google Cloud Platform (Google LLC) | EU (Frankfurt) / USA | File, document and image storage (Firebase Cloud Storage), and the authentication endpoints that issue short-lived file access credentials | EU-US Data Privacy Framework; Standard Contractual Clauses |
| Stripe, Inc. / Stripe Payments Europe Ltd. | Ireland / USA | Subscription billing and payment processing | Stripe Ireland as EU establishment; EU-US Data Privacy Framework |
| Resend (Plus Five Five, Inc.) | USA (EU sending region) | Transactional and service email delivery on the Controller's behalf | EU-US Data Privacy Framework; Standard Contractual Clauses |
| Google Ireland Ltd. / Google LLC (Gemini API) | Ireland / USA | AI-assisted reading of loan and financing documents the Controller selects (§ 9(8)); not used for model training | Standard Contractual Clauses; EU-US Data Privacy Framework |
| OpenAI (EEA data processed by OpenAI Ireland Ltd.) | Ireland / USA | AI-assisted property valuation, and AI-assisted reading of loan documents as a substitute or a second reading (§ 9(8)); not used for model training | Standard Contractual Clauses incorporated in OpenAI's data processing addendum |
| Google Ireland Ltd. | Ireland / USA | OAuth authentication (Google Sign-In), where a user chooses to sign in with Google | EU-US Data Privacy Framework |
Not sub-processors. The following parties receive data in connection with the platform but do not process personal data on the Processor's behalf, and are named here for completeness:
- Google Ireland Ltd. / Google LLC (Google Maps Platform) acts as a separate and independent controller under Google's Maps Platform terms. It is used for server-side address lookup while an address is being typed, and for the map frame displayed to a recipient of a shared property. Section 6.2 of the Privacy Policy describes both.
- Meta Platforms Ireland Ltd. is a joint controller with the Processor under Article 26 GDPR for the measurement of the Processor's own advertising on its public marketing pages, and only with the visitor's consent. It receives no Controller data and no customer content whatsoever.
Changes to the sub-processor list will be notified to the Controller at least 30 days before the change takes effect. The current version is available at https://dein-eigentum.de/legal/subprocessors.
The effective date of this version is displayed above this document.