Not legal advice. This page describes the platform's technical and organizational measures. For legally binding statements about your business's GDPR compliance, consult a certified data protection officer or a lawyer.
What is processing on behalf?
When you process personal data of your clients (names, email addresses, phone numbers) through the platform, you as the agent are the controller in the sense of the GDPR. The platform is the processor.
This constellation requires a data processing agreement (DPA) between you and the platform operator. You find the DPA inside the product under Settings > Datenschutz (privacy), where it is available as a document.
What the platform covers
Storage location: EU
All data is stored exclusively in the EU (data center in Frankfurt). No data is transferred to third countries outside the EU/EEA, unless you connect a BYOK key of a non-EU provider.
Technical and organizational measures (TOMs)
- Encryption of all data at rest (AES-256) and in transit (TLS 1.3).
- End-to-end encryption in the credentials vault.
- Role-based access control: no team member sees more than necessary.
- Audit log of all data access and changes, retained for 90 days.
- Automatic session termination after inactivity (configurable).
Deletion workflows
You can delete personal data at any time. Under Settings > Privacy > Data deletion you find options for:
- Deleting individual entries (immediately, without recovery).
- Full account deletion (all data is irreversibly removed within 30 days).
What you have to handle yourself
Your business's privacy policy
As the controller you must state in your own privacy policy that you use processors for handling client data. The platform operator must be named there as a processor.
Your clients' consent
When you enter personal client data into the platform (for example names in notes, or access data for client apartments), you need a suitable legal basis under Art. 6 GDPR, typically performance of a contract (para. 1 lit. b) or documented consent.
Access and deletion requests
If a client requests information about their stored data or demands deletion (Art. 15-17 GDPR), you as the controller are obliged to handle the request. The platform provides the technical tools. The decision and the communication with the client are yours.
Record of processing activities
Agents with more than 20 employees are obliged under Art. 30 GDPR to keep a record of processing activities. The use of this platform must be listed there as a processing activity.
Frequently asked questions
May I process photos of properties through the platform?
Photos of buildings are usually not personal data. Photos in which people are recognizable, however, are subject to data protection. Make sure you have a legal basis for the processing (for example the consent of the person shown).
What happens to my data when I cancel?
After termination of the contract all data is deleted within 30 days. Before cancelling you can request a complete data export (Settings > Privacy > Export data).
Does the platform operator have a data protection officer?
The contact details of the platform operator's data protection officer are listed in the DPA and in the legal notice at docs.reosa.de/legal/impressum.