# GDPR for agents: what the platform covers

> **Not legal advice.** This page describes the platform's technical and organizational measures. For legally binding statements about your business's GDPR compliance, consult a certified data protection officer or a lawyer.

---

## What is processing on behalf?

When you process personal data of your clients (names, email addresses, phone numbers) through the platform, you as the agent are the **controller** in the sense of the GDPR. The platform is the **processor**.

This constellation requires a **data processing agreement (DPA)** between you and the platform operator. You find the DPA inside the product under *Settings > Datenschutz* (privacy), where it is available as a document.

---

## What the platform covers

**Storage location: EU**

All data is stored exclusively in the EU (data center in Frankfurt). No data is transferred to third countries outside the EU/EEA, unless you connect a BYOK key of a non-EU provider.

**Technical and organizational measures (TOMs)**

- Encryption of all data at rest (AES-256) and in transit (TLS 1.3).
- End-to-end encryption in the credentials vault.
- Role-based access control: no team member sees more than necessary.
- Audit log of all data access and changes, retained for 90 days.
- Automatic session termination after inactivity (configurable).

**Deletion workflows**

You can delete personal data at any time. Under *Settings > Privacy > Data deletion* you find options for:

- Deleting individual entries (immediately, without recovery).
- Full account deletion (all data is irreversibly removed within 30 days).

---

## What you have to handle yourself

**Your business's privacy policy**

As the controller you must state in your own privacy policy that you use processors for handling client data. The platform operator must be named there as a processor.

**Your clients' consent**

When you enter personal client data into the platform (for example names in notes, or access data for client apartments), you need a suitable legal basis under Art. 6 GDPR, typically performance of a contract (para. 1 lit. b) or documented consent.

**Access and deletion requests**

If a client requests information about their stored data or demands deletion (Art. 15-17 GDPR), you as the controller are obliged to handle the request. The platform provides the technical tools. The decision and the communication with the client are yours.

**Record of processing activities**

Agents with more than 20 employees are obliged under Art. 30 GDPR to keep a record of processing activities. The use of this platform must be listed there as a processing activity.

---

## Frequently asked questions

**May I process photos of properties through the platform?**

Photos of buildings are usually not personal data. Photos in which people are recognizable, however, are subject to data protection. Make sure you have a legal basis for the processing (for example the consent of the person shown).

**What happens to my data when I cancel?**

After termination of the contract all data is deleted within 30 days. Before cancelling you can request a complete data export (*Settings > Privacy > Export data*).

**Does the platform operator have a data protection officer?**

The contact details of the platform operator's data protection officer are listed in the DPA and in the legal notice at `docs.reosa.de/legal/impressum`.
