Data Processing Agreement

Pursuant to Art. 28 GDPR · Last updated: July 2026

1. Subject matter, roles and duration

This agreement specifies the data protection obligations of the parties for the processing of personal data carried out in connection with the use of “Torch Real Estate”. It becomes part of the Terms and Conditions upon conclusion of the service contract.

The controller within the meaning of Art. 4(7) GDPR is the customer (“the controller”). The processor within the meaning of Art. 4(8) GDPR is TORCHTECHNOLOGY LTD, 25 Martiou, 27, D. MICHAEL TOWER, Office 105A, Egkomi, 2408 Nicosia, Republic of Cyprus.

The duration of this agreement corresponds to the term of the service contract.

2. Nature and purpose of processing

The processor processes personal data solely to provide the contractually agreed software functions — in particular managing properties, units, tenancies and settlements, communicating with tenants, generating documents, and reminder and reporting features.

3. Categories of data subjects and data

Data subjects: tenants, rental applicants, property owners, the controller’s staff, contractors and other service providers, caretakers.

Categories of data: master data (name, address, date of birth), contact data (email, phone, messenger identifiers), contract data (tenancy, terms, rent, deposit), payment data (account information, incoming payments, arrears), settlement and consumption data, communication content, damage reports including photos, uploaded documents and application materials.

The controller decides on their own responsibility which data they enter into the Software. Processing of special categories of personal data under Art. 9 GDPR is not the subject of this agreement; the controller does not enter such data.

4. Processing on documented instructions

The processor processes the data solely on documented instructions from the controller. Use of the Software by the controller constitutes an instruction. If the processor considers an instruction to infringe data protection law, it shall inform the controller and may suspend execution.

5. Confidentiality

The processor obliges persons involved in the processing to maintain confidentiality and ensures they are informed of the applicable data protection obligations.

6. Technical and organisational measures (Art. 32 GDPR)

The processor maintains in particular the following measures:

  • Tenant isolation: strict separation of data per organisation via PostgreSQL row-level security on every table containing personal data.
  • Encryption: transport encryption (TLS) for all connections; encryption of sensitive secrets and tokens at rest (AES-256).
  • Access control: role- and organisation-based permissions, session-cookie authentication, separate access paths for the tenant portal and management.
  • Storage location: database and file storage in a data centre in Frankfurt am Main, Germany.
  • Resilience: regular database backups by the hosting provider.
  • Logging: traceability of security-relevant operations.

The processor may develop these measures further as long as the level of protection is not reduced.

7. Subprocessors

The controller grants general authorisation for the engagement of the subprocessors listed in Annex 1. The processor will inform the controller of intended changes at least four weeks in advance in text form. The controller may object to a change on important data protection grounds; in that case either party may terminate the contract.

The processor obliges subprocessors to a level of protection equivalent to this agreement.

8. Assistance to the controller

The processor assists the controller, to the extent reasonable, in fulfilling data subject rights (Art. 12–23 GDPR), in data protection impact assessments (Art. 35 GDPR) and in notifications to supervisory authorities. If a data subject contacts the processor directly, the processor forwards the request to the controller without undue delay.

9. Personal data breaches

The processor notifies the controller of personal data breaches without undue delay after becoming aware of them — as a rule within 48 hours — and provides the information required to fulfil the notification obligations under Art. 33 and 34 GDPR.

10. Deletion and return

During the term of the contract, the controller may export their data at any time using the available export functions. After the contract ends, the processor makes the data available for export for 30 days and deletes it thereafter, unless a statutory retention obligation prevents this.

11. Evidence and audits

On request, the processor provides the controller with the information necessary to demonstrate compliance with this agreement. On-site audits are permitted after reasonable notice, during normal business hours and without disrupting operations; the controller bears the resulting costs.

12. Final provisions

In the event of conflicts between this agreement and the Terms, the provisions of this agreement prevail for the processing of personal data. Otherwise the provisions of the Terms and Conditions apply.

For questions about data processing, contact hello@torchtechnology.de.

Annex 1 — Subprocessors

ProviderPurposeLocation
Supabase Inc.Database, file storage, authenticationEU (Frankfurt)
Railway Corp.Application hostingEU
ResendTransactional email (notifications, dunning, documents)EU / USA
Stripe Payments Europe, Ltd.Payment processing (customer data only, no tenant data)EU (Dublin)
Telegram FZ-LLCTelegram bot for tenant communication (only if used)Drittland / third country
OpenRouter / OpenAIAI-assisted extraction from uploaded documents and payment matchingUSA
Google LLCGoogle Calendar integration for viewings (optional, per user)USA

Transfers to third countries are based on the EU standard contractual clauses pursuant to Art. 46(2)(c) GDPR.