Skip to content

Data processing agreement

1. Subject matter and relationship to the Terms

The Agreement governs the processing of personal data the Processor carries out on the Customer's behalf in delivering the Paco service. It forms an integral part of the terms of use and applies to every account the Customer opens. Where the Agreement and the Terms conflict on a personal-data matter, the Agreement prevails.

2. Description of the processing

ElementDescription
Nature and purposeHosting, automated reading and indexing of the inspection reports and mail the Customer uploads or has collected; keeping the property's register of duties; reminders and briefs to the Customer's users; support.
DurationThe life of the Customer's account, then the retention period in article 8.
Categories of data subjectsThe Customer's users (owners, managers, staff); third parties named in the documents processed (engineers, inspectors, contractors); the Customer's employees whose residence or work permit is tracked; senders and recipients of collected mail if the Customer connects a mailbox.
Categories of dataIdentity and professional contact details; role and assignment; the content of professional reports, certificates and mail and their metadata; work permit dates and numbers; phone number and messages if a user links WhatsApp; proof photos and their metadata (capture time, coordinates, device); questions asked of the assistant; technical identifiers (logs, IP address). The Customer undertakes not to entrust data falling under Article 9 GDPR.

3. Customer obligations

The Customer warrants that it has a legal basis for the processing entrusted, that it has informed the data subjects, and that it uploads only data necessary for its property's regulatory tracking. It remains solely responsible for the lawfulness of its instructions.

4. Processor obligations

  • Instructions. The Processor processes data only on the Customer's documented instructions, including for any transfer outside the European Union. Use of the service, the settings the Customer chooses and this Agreement constitute those instructions. If the Processor considers an instruction infringes the GDPR, it informs the Customer.
  • Confidentiality. Persons authorised to process the data are bound by confidentiality and access the Customer's data only so far as is necessary to deliver the service, keep it secure, and provide support.
  • Security. The Processor implements the measures described in article 7 of the privacy policy: encryption in transit, password hashing, encryption of mailbox credentials, strict separation between organisations, restricted access, hosting within the European Union and encrypted backups.
  • Assistance. The Processor assists the Customer, by appropriate technical and organisational measures, in responding to data subjects' requests, and in meeting its security, breach-notification and impact-assessment obligations, taking into account the nature of the processing and the information available to it.
  • Data breaches. The Processor notifies the Customer of any personal data breach affecting it without undue delay after becoming aware of it, with the information needed for notification to the supervisory authority.
  • Records. The Processor keeps the record of categories of processing activities carried out on the Customer's behalf required by Article 30(2) GDPR.

5. Sub-processors

The Customer gives general authorisation for the following sub-processors, which are the same as those listed in the privacy policy:

Sub-processorRoleLocation and safeguards
Hetzner Online GmbHServer hosting (database, documents, mail)Germany (EU)
Backblaze, Inc.Nightly backup copy, encrypted before it leaves the server, deleted after 30 daysUnited States — standard contractual clauses; storage region being confirmed
Resend, Inc.Sending the service's emails (acknowledgements, invitations, resets, briefs)United States — standard contractual clauses
Mistral AIAutomated reading of uploaded documents; conversational assistant for organisations subject to the GDPRFrance (EU)
Anthropic, PBCConversational assistant, only for organisations outside the EU or that expressly asked for this provider (option closed by default); receives the question, the recent conversation memory and a register snapshot; never a whole document nor the person's identity)United States — standard contractual clauses
Twilio Inc.WhatsApp channel (sending and receiving messages), only if the Customer switches the channel onUnited States — European Commission standard contractual clauses
Telegram Messenger Inc.Receiving the brief over Telegram, only if one of the Customer's users chooses that channelOutside the EU — on the user's explicit choice (art. 49.1.a)
Sentry (Functional Software, Inc.)Technical error monitoringEU data region; no personal data is sent (sending of identifying data disabled)
Komoot GmbH (Photon service)Address completion while entering the propertyGermany (EU)
ipwho.isMay be used, only if the operator switches it on, to resolve a sign-up IP address to an approximate city (abuse check); off by defaultUnited States — the IP address alone is sent, no result kept
Google LLC / Microsoft CorporationOnly if the Customer connects a Gmail / Outlook mailbox (access to its own mail via OAuth)EU / United States — standard contractual clauses
Mews SystemsProperty management system, only if the Customer connects itCzechia (EU)
Cloudbeds, Inc.Property management system, only if the Customer connects itUnited States — standard contractual clauses

The Processor informs the Customer of any addition or replacement of a sub-processor, by email or by updating this page (dated at the top), at least 30 days before the new sub-processor processes any of the Customer's data. The Customer may object in writing within that period; failing agreement on a solution, the Customer may close its account at no cost. The Processor imposes on each sub-processor data-protection obligations equivalent to those of this Agreement and remains fully liable to the Customer for their performance.

6. Transfers outside the European Union

Hosting, documents and the automated reading of documents take place in the European Union. Transfers outside the EU are those listed in section 5: the encrypted backup copy, the sending of the service's emails, the conversational assistant for organisations outside the EU or that expressly asked for it only, and the channels or connections the Customer or its users switch on (WhatsApp, Telegram, Google/Microsoft mailbox, Cloudbeds PMS). Each is covered by the safeguards of Chapter V GDPR, in particular the European Commission's standard contractual clauses, or by the user's explicit choice of a channel.

7. Audits

The Processor makes available to the Customer the information necessary to demonstrate compliance with this Agreement. The Customer may, at most once a year unless there is an incident or a supervisory authority requests it, have an audit carried out by itself or by an independent auditor bound by confidentiality, on 30 days' written notice, during business hours and without disrupting the service. Written answers to a reasonable questionnaire serve as the audit in the first instance.

8. Data at the end of the service

On closure of the account, the Customer can export its register and supporting documents from the service. The data is then deleted or anonymised within 12 months of closure, including from backups as they expire, subject to legal retention obligations. On the Customer's written request before that date, the Processor returns a copy of its data in a common format.

9. Liability and term

The Agreement takes effect when the account is opened and remains in force for as long as the Processor processes data on the Customer's behalf. The limitations of liability in the Terms apply to the Agreement to the extent the GDPR permits.

10. Contact

For any question about this Agreement or about data subjects' rights: contact@pacoapp.io.