Valevia — Data Processing Agreement (DPA)
Last updated: 29 May 2026
This DPA forms an integral part of the SaaS Subscription Agreement ("Agreement") between Valevia and the Client.
1. Parties and Roles
| Party | GDPR Role | Description |
|---|---|---|
| Client (the real estate agency) | Controller | Determines the purposes and means of processing the personal data of its prospects, buyers, sellers and agents |
| Valevia Consulting UG (haftungsbeschränkt), Germany | Processor | Processes personal data on behalf of the Client to provide the Service |
2. Subject Matter and Duration
2.1 Subject Matter
Valevia processes personal data on behalf of the Client to provide the Valevia platform (Property Content Generation and, where subscribed, Inbox). The categories of data and data subjects are detailed in Schedule A (Property Content Generation) and Schedule B (Inbox).
2.2 Duration
This DPA applies for the duration of the Agreement. Processing ceases on termination, subject to the retention and deletion provisions in §8.
3. Instructions
3.1 Processing Instructions
Valevia processes personal data only on documented instructions from the Client, namely:
- The Agreement and this DPA (the initial instructions), and
- Any subsequent written instructions from the Client (by email or Platform configuration).
3.2 Notification of Unlawful Instructions
If Valevia considers that an instruction infringes the GDPR or other applicable EU/member-state data-protection law, Valevia will inform the Client without undue delay. Valevia may suspend the relevant processing until the Client confirms or modifies the instruction.
3.3 No Independent Use
Valevia will not process personal data for any purpose other than providing the Service, and will not sell, rent or otherwise share personal data except with sub-processors as permitted under this DPA.
4. Confidentiality
4.1 Personnel
Valevia ensures that persons authorised to process personal data are bound by appropriate confidentiality obligations and process personal data only as instructed.
4.2 Access Controls
- Platform access requires authenticated sessions (hashed passwords and JWT-based sessions).
- Service-to-service communication uses shared secrets (API keys / HMAC signatures).
- No Valevia personnel access Client personal data except where necessary for support or incident response, or as directed by the Client.
4.3 Support Access
To provide support, troubleshoot issues, and maintain the Service, authorised Valevia personnel may access the Client's workspace, including a "view as" mode that renders the Client's account as the Client sees it. Such access is limited to what is necessary for the stated purpose, performed only by authorised personnel bound by the confidentiality obligations in Section 4.1, and recorded in an access log capturing the acting person, the Client account accessed, and the time. Valevia does not use this access to read Client communications except where necessary to resolve a specific support or security matter.
5. Sub-Processors
5.1 Authorised Sub-Processors
The Client provides general written authorisation for Valevia to engage sub-processors. The current list is maintained in our Sub-Processor Register, available to the Client on request.
5.2 Obligations on Sub-Processors
Valevia ensures that each sub-processor is bound by data-protection obligations no less protective than this DPA, provides sufficient guarantees of appropriate technical and organisational measures, and processes data within the EEA or under an adequate transfer mechanism (§6).
5.3 Notification of Changes
Valevia will notify the Client at least 30 days in advance of any intended addition or replacement of a sub-processor, stating its identity, location, the nature of the processing and the categories of data. The Client may object within the notice period; if Valevia cannot reasonably accommodate the objection, either party may terminate the affected Service component.
5.4 Liability
Valevia remains liable for the acts and omissions of its sub-processors as for its own.
6. International Transfers
6.1 EEA Processing
Personal data is hosted and processed within the European Economic Area (EEA), primarily in Microsoft Azure's EU regions. Azure OpenAI processing takes place within Microsoft's EU Data Boundary.
6.2 Transfers Outside the EEA
Certain sub-processors are established outside the EEA (for example, in the United States). Where they process personal data, Valevia relies on:
- the EU-US Data Privacy Framework, where the sub-processor is certified;
- Standard Contractual Clauses (Commission Decision 2021/914); and
- supplementary measures as appropriate (e.g. encryption in transit, redaction of personal identifiers).
6.3 Current Transfer Status
| Sub-Processor | Location | Transfer Mechanism |
|---|---|---|
| Microsoft Azure (incl. Azure OpenAI) | EU (EEA) | No transfer (EU Data Boundary) |
| Stripe | EU (Ireland) | No transfer (EEA); SCCs/DPF for US backup |
| Resend | US | EU-US DPF / SCCs |
| Twilio | US | EU-US DPF / SCCs |
| Zernio | US | SCCs |
| Sentry | EU data region | No transfer (EEA); SCCs for any US support access |
| HubSpot | US | EU-US DPF / SCCs |
The Sub-Processor Register is the authoritative, current source for this information.
7. Security Measures
7.1 Technical Measures (GDPR Article 32)
Encryption
- In transit: TLS 1.2+ on all endpoints (HTTPS-only).
- At rest: AES-256 (Azure Storage and Azure Database for PostgreSQL).
- Secrets: Azure Key Vault.
Access control
- Role-based access (admin / member) with multi-tenant isolation.
- Service-to-service authentication via API keys (HMAC-signed).
- User authentication with industry-standard password hashing.
- Rate limiting and usage quotas on authentication and AI endpoints (e.g. 5 failed logins / 15 minutes).
Network
- Private endpoints for the database (not exposed to the public internet) and virtual-network isolation in production.
- Egress allow-listing on the metering gateway to prevent open-proxy abuse.
Monitoring & audit
- Audit logging of key user actions (login, data access, approvals, modifications).
- Audit log written append-only at the application level, retained in Azure Blob Storage, plus a PostgreSQL audit log.
- Application Insights telemetry for operational monitoring.
7.2 Organisational Measures
- Data minimisation — only data necessary for the Service is processed.
- Purpose limitation — data is processed solely for the contracted Service functions.
- Redaction — common personal identifiers (e.g. phone numbers, account numbers) are redacted from email content before AI classification and from analytics events.
- Pseudonymisation — conversation threads are referenced by a one-way hash in analytics rather than by email address or subject line.
- Environment separation — production, staging and test environments are isolated (separate Azure resource groups, databases and key vaults).
No method of transmission or storage is completely secure; Valevia maintains measures appropriate to the risk but cannot guarantee absolute security.
8. Data Retention and Deletion
8.1 During the Agreement
Valevia retains personal data only as long as necessary to provide the Service, or as required by law:
| Data Category | Retention |
|---|---|
| Client content (listings, descriptions, marketing assets, property images) | For the duration of the Agreement; once archived, automatically deleted 5 years after its last activity |
| Inbox email content and generated drafts | Retained for up to 12 months, then automatically deleted |
| Security and audit logs | Up to 7 years, then automatically deleted |
| Invoicing records | Up to 10 years (German law — §257 HGB / §147 AO) |
8.2 Upon Termination
At the Client's choice, Valevia will return or delete the Client's personal data on termination, as follows:
- Export window — for a limited period after termination (typically 30 days), the Client may request an export ("return") of its content (property data, listings, marketing assets) by emailing contact@valevia.eu.
- Deletion — Valevia then deletes the Client's personal data from Azure Blob Storage and the PostgreSQL databases within a reasonable period, and revokes associated access tokens and sessions.
- Confirmation — Valevia provides written confirmation of deletion on the Client's request.
- Exceptions — data Valevia must retain by law (e.g. invoicing records, above) and limited security/audit logs are retained for their applicable period in access-restricted storage.
8.3 Deletion Mechanism
Deletion is performed by removing records from PostgreSQL (hard delete), deleting the associated blobs from Azure Storage, and revoking access tokens and sessions.
9. Data Subject Rights
9.1 Assistance
Taking into account the nature of the processing, Valevia assists the Client in responding to data-subject requests (access, rectification, erasure, portability, restriction, objection) by providing technical means to export data, acting on the Client's instructions to delete specific records without undue delay, and providing relevant information about the processing.
9.2 Direct Requests
If Valevia receives a data-subject request directly, it will, without undue delay, redirect the data subject to the Client and notify the Client, and will not otherwise respond without the Client's instructions (save to acknowledge receipt and redirect).
10. Personal Data Breach
10.1 Notification to Client
Valevia will notify the Client without undue delay after becoming aware of a personal data breach affecting Client personal data, and will provide (as available): the nature of the breach and the categories and approximate number of data subjects affected; a contact point; the likely consequences; and the measures taken or proposed to address and mitigate it.
10.2 Ongoing Communication
Valevia will provide updates as its investigation progresses, cooperate with the Client's own notification obligations (GDPR Articles 33 and 34), and document the breach (facts, effects, remedial action).
10.3 Client Obligations
The Client acknowledges that, as controller, it must notify its supervisory authority within 72 hours where required (GDPR Article 33). Valevia's prompt notification is intended to give the Client sufficient time to meet that obligation.
11. Audit Rights
11.1 Right to Audit
The Client (or an independent auditor it appoints, bound by confidentiality) may audit Valevia's compliance with this DPA on 30 days' written notice, no more than once per year (unless a breach has occurred or a supervisory authority requires it), and of reasonable scope and duration. Valevia may charge reasonable costs where audit support exceeds one business day.
11.2 Documentation First
Valevia may satisfy an audit request, in the first instance, by providing its documentation of technical and organisational measures, sub-processor due-diligence records, and summaries of any independent security assessments, where available.
12. Data Protection Impact Assessment
Where the Client must carry out a DPIA under GDPR Article 35, Valevia provides reasonable assistance, including a description of the processing operations, the technical and organisational measures in place, and relevant risk information.
Recommendation: a DPIA is likely appropriate for Inbox, given the systematic processing of communications and the AI-assisted classification of correspondence that may contain financial and other personal data. See Schedule B.
13. Governing Law
This DPA is governed by the laws of the Federal Republic of Germany and the GDPR. The competent supervisory authority for Valevia is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (LfDI RLP), Hintere Bleiche 34, 55116 Mainz — datenschutz.rlp.de. Data subjects may also lodge complaints with their own national authority (e.g. CNPD in Luxembourg, APD/GBA in Belgium, CNIL in France, ICO in the United Kingdom).
Schedule A — Property Content Generation Processing Details
Categories of Data Subjects
- Property sellers (whose properties are marketed)
- Real estate agents (whose names/contact details appear in marketing materials)
- Buyers/prospects (where their names appear in property notes provided by the Client)
Categories of Personal Data
| Data Category | Examples | Source |
|---|---|---|
| Agent contact details | Name, email, phone, photo | Client submission |
| Property address | Street, city, postal code | Client submission |
| Property images | Photos (may contain faces, street views) | Client submission |
| Property descriptions | AI-generated text based on property data | Generated by the Service |
| Marketing assets | Branded images and videos | Generated by the Service |
| Review actions | Who approved/rejected, when, edit history | Platform usage |
Purpose of Processing
- Generate multilingual property descriptions.
- Generate visual marketing assets (hero, carousel, reel, story).
- Present content for human review and approval.
- Publish approved content to the Client's connected social media accounts (and, if the Client enables it, a CRM).
- Track ROI and pipeline metrics (aggregated/anonymised).
Sensitive Data
Property Content Generation does not intentionally process special-category data. Property images may incidentally contain faces or, in area photos, places of worship; these are processed solely for visual marketing and are not used for profiling or identification.
Schedule B — Inbox Processing Details
Inbox carries a higher data-protection risk than Property Content Generation. It processes correspondence between the Client's agency and third parties (prospects, buyers, sellers, tenants, other professionals).
Categories of Data Subjects
- Prospects and leads, buyers and sellers, tenants
- Professional contacts (notaries, mortgage brokers, other agents)
- The Client's own employees (whose inboxes are processed)
Categories of Personal Data
| Data Category | Examples | Sensitivity |
|---|---|---|
| Names and contact details | First/last name, email, phone | Standard |
| Financial data | Budget, offer prices, mortgage details | High |
| Property preferences | Location, size, type | Standard |
| Transaction details | Offer amounts, negotiation positions | High |
| Personal circumstances | Family situation, relocation reasons | Elevated |
| Communication content | Email body, subject lines, attachments | High |
| Behavioural data | Timestamps, response patterns, thread depth | Standard |
| Property interest (derived) | Link between an email and the Client's own property listing it concerns | Standard |
Processing Operations
- Ingestion — email content is received from the Client's email provider (Gmail, Outlook, IMAP).
- Redaction — common contact and identity identifiers (phone numbers, email addresses, account, ID and payment numbers) are automatically redacted from the email text. Personal names and addresses are retained, as they are needed for the AI to produce coherent output.
- AI classification — Azure OpenAI processes the (partially redacted) text to determine category, priority and intent.
- Property attribution — an email may be linked to the Client's own property listing it concerns (by matching the listing reference in the email text, or as part of AI classification), to organise the inbox and power the Client's per-property activity reporting. Reports derived from this linkage contain aggregate counts only, never correspondence content.
- Draft generation — a suggested reply is generated in the Client's configured tone/language.
- CRM enrichment (optional, off by default) — if the Client enables it, the sender may be cross-referenced with the Client's CRM for context.
- Agent review — the classification and draft are presented to the Client's agent for approval/editing. Valevia does not send replies automatically.
- Analytics — aggregated/anonymised classification data (category, priority, thread hash) is logged for ROI metrics.
- Aggregate market demand (anonymised, cross-Client) — the count of buyer inquiries, grouped by area (INSEE commune), property type and price band, is combined with the equivalent counts derived from other Clients to produce an anonymous, aggregated indicator of buyer demand in a market. The output is a count of distinct buyers per segment; it carries no correspondence content, no buyer identity, and is not attributable to any individual, property or Client. Segments below a minimum threshold are suppressed so no buyer can be re-identified.
Privacy-Preserving Measures
- Partial redaction before AI — contact and identity identifiers (phone numbers, email addresses, account, ID and payment numbers) are redacted from email content before classification and from analytics events. Personal names and addresses are not redacted, as they are required for the AI to produce relevant classifications and draft replies.
- Thread hashing — conversation threads are referenced by a one-way hash in analytics, not by email address or subject line.
- Limited retention — email content and generated drafts are stored to provide the Service and are retained for up to 12 months, then automatically deleted.
- Configurable scope — the Client controls which inboxes are processed and can disable Inbox at any time.
Additional Safeguards
- Inbox data is isolated from Property Content Generation data at the database level.
- The Client must obtain appropriate authorisation from its employees before enabling Inbox on their email accounts, and should inform its contacts that incoming email may be processed by AI for classification.
Anonymised, Aggregated Data
Valevia may create anonymous, aggregated statistics from data processed under this Agreement — for example, counts of buyer inquiries by area, property type and price band. Such statistics are irreversibly anonymised: they contain no personal data, no correspondence content, and cannot be linked to any individual, buyer, property or Client, and small groups are suppressed to prevent re-identification. Because anonymised data is not personal data, Valevia may use it to operate, secure and improve the Service, including to provide market-intelligence features to Clients. No Client's correspondence content, contacts, or identifiable data is ever shared with, or made visible to, any other Client — only the anonymous combined totals are.
DPIA Recommendation
We recommend the Client conduct a DPIA for Inbox, considering the systematic processing of communications, AI-assisted classification, the presence of financial data in correspondence, and the processing of third-party personal data. Valevia provides the information needed to support it.
Schedule C — Technical and Organizational Measures Summary
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ (HTTPS-only endpoints) |
| Encryption at rest | AES-256 (Azure Storage, PostgreSQL) |
| Secret management | Azure Key Vault |
| Access control | Role-based (admin/member), multi-tenant isolation |
| Authentication | Authenticated sessions with industry-standard password hashing; API keys (HMAC) for services |
| Rate limiting / quotas | Authentication and AI endpoints (e.g. 5 failed logins / 15 min) |
| Network | Private database endpoint, virtual-network isolation, egress allow-listing |
| Audit | Application-level append-only audit log (Azure Blob) + PostgreSQL audit log |
| Backup | Azure-managed automated database backups |
| Incident response | Notification without undue delay; documented playbook |
| Environment separation | Prod / staging / test isolated (separate resource groups, DBs, key vaults) |
| Data minimisation | Redaction of identifiers, purpose-limited retention |
| Deletion | Automated lifecycle policies; hard delete on termination |
Schedule D — Australia (Australian Privacy Principles)
This Schedule supplements the DPA where the Client is an Australian entity subject to the Privacy Act 1988 (Cth). It does not restate the DPA; it maps the Australian Privacy Principles (APPs) onto the existing clauses.
D.1 Roles. The Client is the "APP entity" accountable under the Privacy Act; Valevia (Processor) acts on the Client's documented instructions per §1 (Parties and Roles) and §3 (Instructions).
D.2 Cross-border disclosure (APP 8). Valevia stores and processes personal information in the EU (Microsoft Azure, West Europe) via the sub-processors authorised under §5 (Sub-Processors). Valevia will handle that information consistently with the APPs and take reasonable steps to ensure its sub-processors do likewise, supporting the Client's APP 8 accountability. This Schedule does not, by itself, discharge the Client's own APP 8 obligations.
D.3 Notifiable Data Breaches (Part IIIC). In addition to §10 (Personal Data Breach), Valevia will assist the Client to meet its NDB obligations: notify the Client without undue delay on becoming aware of a suspected or actual eligible data breach, and provide the information the Client reasonably needs to assess it and to notify the OAIC and affected individuals. See the Breach Response Runbook (../compliance/BREACH_RESPONSE.md, §4.6a).
D.4 APP flow-down. Security (APP 11) is met through the measures in Schedule C; access and correction assistance (APP 12/13) through §9 (Data Subject Requests); sub-processor obligations through §5.
D.5 Precedence. For AU-specific matters where this Schedule conflicts with the body of the DPA, this Schedule prevails; otherwise the DPA governs.