Data processing agreement

When you store personal data about tenants, guarantors or contacts in StoffRent, you decide what is stored and why. In the words of the GDPR you are the controller and we are your processor.

This agreement sets out what we do with that data on your behalf. It is concluded automatically with every customer, forms part of the terms of service, and needs no signature. If your organisation requires a signed copy, write to us and we will provide one.

1. Parties and roles

The controller is the customer: the holder of the portfolio. The processor is StoffWare, Belgium, VAT BE 1040.174.154.

This agreement covers only the personal data of third parties that the customer processes through StoffRent. The customer's own account data is covered by the privacy policy, where we are the controller.

2. Subject, duration, nature and purpose

  • Subject: hosting and processing personal data within the StoffRent application.
  • Duration: as long as the customer has an account, plus the deletion period in section 8.
  • Nature: storage, organisation, consultation, calculation, generation of documents, sending of emails and, where the customer publishes a listing, publication of the data the customer selects.
  • Purpose: enabling the customer to manage their rental properties.

3. Data and people concerned

  • People: tenants and their co-tenants, guarantors, landlords and co-owners, service providers and other contacts the customer records.
  • Data: identity and contact details, address, lease and payment information, indexation history, reminders, notes written by the customer, photographs of the property, and the content of documents the customer uploads.
  • Special categories of data are not asked for by the service and should not be entered. Documents such as leases may contain identifiers like a national register number; the customer decides whether to upload them and remains responsible for that choice.

4. What we undertake

  • Process the data only on the customer's documented instructions. Using the functions of the application constitutes those instructions; anything else has to be agreed in writing. If a law obliges us to process data otherwise, we will tell the customer unless that law forbids it.
  • Ensure that anyone with access is bound by confidentiality.
  • Apply the technical and organisational measures listed in Annex 3, and keep them up to date.
  • Help the customer answer requests from data subjects, including through the export and deletion functions of the application.
  • Help the customer with security, breach notification and impact assessments, given the nature of the processing and the information available to us.
  • Notify the customer without undue delay after becoming aware of a personal data breach affecting their data, with what we know and what we are doing about it.
  • Make available the information needed to demonstrate that these obligations are met.

5. Sub-processors

The customer gives general authorisation for the sub-processors listed in Annex 2. Each one is bound by a written agreement imposing the same obligations, and we remain fully liable to the customer for their performance.

Before adding or replacing a sub-processor we give at least 30 days' notice by email. A customer who objects on reasonable data protection grounds may terminate the subscription before the change takes effect, and is refunded for the period paid but not used.

6. Transfers outside the European Union

The application and the data are hosted in the European Union. Transfers to the sub-processors established outside it rest on the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. Annex 2 says which ones are concerned.

7. Audits

On request, we provide the information needed to show that we comply with this agreement, including the relevant certifications of our sub-processors.

A customer may audit us, or have a third party bound by confidentiality do so, once per calendar year, with 30 days' notice, at their own cost and without disrupting the service. An audit following a personal data breach is not subject to that frequency limit.

8. Return and deletion

The customer can export everything at any moment from the application, in open formats, including once the portfolio has become read-only.

When the account is closed, we delete the data within 90 days, and from the backups as they rotate, except what a law requires us to keep.

9. Liability

Liability under this agreement is governed by the terms of service, and by Article 82 GDPR for anything that provision covers.

Annex 1 — Summary of the processing

Sections 2 and 3 above describe the subject matter, duration, nature and purpose of the processing, the categories of personal data and the categories of data subjects, as Article 28(3) GDPR requires.

Annex 2 — Sub-processors

  • Microsoft (Azure) — hosting of the application, database and files — European Union.
  • Vercel — delivery of the web interface, technical connection data — United States, with standard contractual clauses.
  • Stripe Payments Europe, Ltd. — subscriptions and payments; processes the customer's billing data, not tenant data — Ireland.
  • Postmark (ActiveCampaign, LLC) — sending service emails; processes recipient addresses and message content — United States, with standard contractual clauses.
  • Plausible Analytics — cookieless measurement on the public pages; no data from a portfolio — European Union.

Annex 3 — Technical and organisational measures

  • Encryption of traffic in transit, and of stored secrets such as two-factor keys, with keys kept separately from the database.
  • Passwords stored only as salted hashes.
  • Two-factor authentication available to every user, and imposable on a whole portfolio by its owner.
  • Strict separation between portfolios, enforced in the data layer on reads and writes, and verified by automated tests on every change.
  • Role-based access inside a portfolio, and access on our side limited to what operating the service requires.
  • Regular backups, held in the European Union.
  • Logging of security-relevant events, including who exported a portfolio and when.
  • Validation of uploaded files, and removal of the metadata of photographs, which can contain the place a picture was taken.
  • Dependencies kept current, and changes reviewed before they are deployed.