valevia
Products
PricingSecurityAbout

Valevia — Data Processing Agreement (DPA)

Last updated: 29 May 2026

This DPA forms an integral part of the SaaS Subscription Agreement ("Agreement") between Valevia and the Client.


1. Parties and Roles

PartyGDPR RoleDescription
Client (the real estate agency)ControllerDetermines the purposes and means of processing the personal data of its prospects, buyers, sellers and agents
Valevia Consulting UG (haftungsbeschränkt), GermanyProcessorProcesses personal data on behalf of the Client to provide the Service

2. Subject Matter and Duration

2.1 Subject Matter

Valevia processes personal data on behalf of the Client to provide the Valevia platform (Property Content Generation and, where subscribed, Inbox). The categories of data and data subjects are detailed in Schedule A (Property Content Generation) and Schedule B (Inbox).

2.2 Duration

This DPA applies for the duration of the Agreement. Processing ceases on termination, subject to the retention and deletion provisions in §8.


3. Instructions

3.1 Processing Instructions

Valevia processes personal data only on documented instructions from the Client, namely:

  • The Agreement and this DPA (the initial instructions), and
  • Any subsequent written instructions from the Client (by email or Platform configuration).

3.2 Notification of Unlawful Instructions

If Valevia considers that an instruction infringes the GDPR or other applicable EU/member-state data-protection law, Valevia will inform the Client without undue delay. Valevia may suspend the relevant processing until the Client confirms or modifies the instruction.

3.3 No Independent Use

Valevia will not process personal data for any purpose other than providing the Service, and will not sell, rent or otherwise share personal data except with sub-processors as permitted under this DPA.


4. Confidentiality

4.1 Personnel

Valevia ensures that persons authorised to process personal data are bound by appropriate confidentiality obligations and process personal data only as instructed.

4.2 Access Controls

  • Platform access requires authenticated sessions (hashed passwords and JWT-based sessions).
  • Service-to-service communication uses shared secrets (API keys / HMAC signatures).
  • No Valevia personnel access Client personal data except where necessary for support or incident response, or as directed by the Client.

4.3 Support Access

To provide support, troubleshoot issues, and maintain the Service, authorised Valevia personnel may access the Client's workspace, including a "view as" mode that renders the Client's account as the Client sees it. Such access is limited to what is necessary for the stated purpose, performed only by authorised personnel bound by the confidentiality obligations in Section 4.1, and recorded in an access log capturing the acting person, the Client account accessed, and the time. Valevia does not use this access to read Client communications except where necessary to resolve a specific support or security matter.


5. Sub-Processors

5.1 Authorised Sub-Processors

The Client provides general written authorisation for Valevia to engage sub-processors. The current list is maintained in our Sub-Processor Register, available to the Client on request.

5.2 Obligations on Sub-Processors

Valevia ensures that each sub-processor is bound by data-protection obligations no less protective than this DPA, provides sufficient guarantees of appropriate technical and organisational measures, and processes data within the EEA or under an adequate transfer mechanism (§6).

5.3 Notification of Changes

Valevia will notify the Client at least 30 days in advance of any intended addition or replacement of a sub-processor, stating its identity, location, the nature of the processing and the categories of data. The Client may object within the notice period; if Valevia cannot reasonably accommodate the objection, either party may terminate the affected Service component.

5.4 Liability

Valevia remains liable for the acts and omissions of its sub-processors as for its own.


6. International Transfers

6.1 EEA Processing

Personal data is hosted and processed within the European Economic Area (EEA), primarily in Microsoft Azure's EU regions. Azure OpenAI processing takes place within Microsoft's EU Data Boundary.

6.2 Transfers Outside the EEA

Certain sub-processors are established outside the EEA (for example, in the United States). Where they process personal data, Valevia relies on:

  • the EU-US Data Privacy Framework, where the sub-processor is certified;
  • Standard Contractual Clauses (Commission Decision 2021/914); and
  • supplementary measures as appropriate (e.g. encryption in transit, redaction of personal identifiers).

6.3 Current Transfer Status

Sub-ProcessorLocationTransfer Mechanism
Microsoft Azure (incl. Azure OpenAI)EU (EEA)No transfer (EU Data Boundary)
StripeEU (Ireland)No transfer (EEA); SCCs/DPF for US backup
ResendUSEU-US DPF / SCCs
TwilioUSEU-US DPF / SCCs
ZernioUSSCCs
SentryEU data regionNo transfer (EEA); SCCs for any US support access
HubSpotUSEU-US DPF / SCCs

The Sub-Processor Register is the authoritative, current source for this information.


7. Security Measures

7.1 Technical Measures (GDPR Article 32)

Encryption

  • In transit: TLS 1.2+ on all endpoints (HTTPS-only).
  • At rest: AES-256 (Azure Storage and Azure Database for PostgreSQL).
  • Secrets: Azure Key Vault.

Access control

  • Role-based access (admin / member) with multi-tenant isolation.
  • Service-to-service authentication via API keys (HMAC-signed).
  • User authentication with industry-standard password hashing.
  • Rate limiting and usage quotas on authentication and AI endpoints (e.g. 5 failed logins / 15 minutes).

Network

  • Private endpoints for the database (not exposed to the public internet) and virtual-network isolation in production.
  • Egress allow-listing on the metering gateway to prevent open-proxy abuse.

Monitoring & audit

  • Audit logging of key user actions (login, data access, approvals, modifications).
  • Audit log written append-only at the application level, retained in Azure Blob Storage, plus a PostgreSQL audit log.
  • Application Insights telemetry for operational monitoring.

7.2 Organisational Measures

  • Data minimisation — only data necessary for the Service is processed.
  • Purpose limitation — data is processed solely for the contracted Service functions.
  • Redaction — common personal identifiers (e.g. phone numbers, account numbers) are redacted from email content before AI classification and from analytics events.
  • Pseudonymisation — conversation threads are referenced by a one-way hash in analytics rather than by email address or subject line.
  • Environment separation — production, staging and test environments are isolated (separate Azure resource groups, databases and key vaults).

No method of transmission or storage is completely secure; Valevia maintains measures appropriate to the risk but cannot guarantee absolute security.


8. Data Retention and Deletion

8.1 During the Agreement

Valevia retains personal data only as long as necessary to provide the Service, or as required by law:

Data CategoryRetention
Client content (listings, descriptions, marketing assets, property images)For the duration of the Agreement; once archived, automatically deleted 5 years after its last activity
Inbox email content and generated draftsRetained for up to 12 months, then automatically deleted
Security and audit logsUp to 7 years, then automatically deleted
Invoicing recordsUp to 10 years (German law — §257 HGB / §147 AO)

8.2 Upon Termination

At the Client's choice, Valevia will return or delete the Client's personal data on termination, as follows:

  1. Export window — for a limited period after termination (typically 30 days), the Client may request an export ("return") of its content (property data, listings, marketing assets) by emailing contact@valevia.eu.
  2. Deletion — Valevia then deletes the Client's personal data from Azure Blob Storage and the PostgreSQL databases within a reasonable period, and revokes associated access tokens and sessions.
  3. Confirmation — Valevia provides written confirmation of deletion on the Client's request.
  4. Exceptions — data Valevia must retain by law (e.g. invoicing records, above) and limited security/audit logs are retained for their applicable period in access-restricted storage.

8.3 Deletion Mechanism

Deletion is performed by removing records from PostgreSQL (hard delete), deleting the associated blobs from Azure Storage, and revoking access tokens and sessions.


9. Data Subject Rights

9.1 Assistance

Taking into account the nature of the processing, Valevia assists the Client in responding to data-subject requests (access, rectification, erasure, portability, restriction, objection) by providing technical means to export data, acting on the Client's instructions to delete specific records without undue delay, and providing relevant information about the processing.

9.2 Direct Requests

If Valevia receives a data-subject request directly, it will, without undue delay, redirect the data subject to the Client and notify the Client, and will not otherwise respond without the Client's instructions (save to acknowledge receipt and redirect).


10. Personal Data Breach

10.1 Notification to Client

Valevia will notify the Client without undue delay after becoming aware of a personal data breach affecting Client personal data, and will provide (as available): the nature of the breach and the categories and approximate number of data subjects affected; a contact point; the likely consequences; and the measures taken or proposed to address and mitigate it.

10.2 Ongoing Communication

Valevia will provide updates as its investigation progresses, cooperate with the Client's own notification obligations (GDPR Articles 33 and 34), and document the breach (facts, effects, remedial action).

10.3 Client Obligations

The Client acknowledges that, as controller, it must notify its supervisory authority within 72 hours where required (GDPR Article 33). Valevia's prompt notification is intended to give the Client sufficient time to meet that obligation.


11. Audit Rights

11.1 Right to Audit

The Client (or an independent auditor it appoints, bound by confidentiality) may audit Valevia's compliance with this DPA on 30 days' written notice, no more than once per year (unless a breach has occurred or a supervisory authority requires it), and of reasonable scope and duration. Valevia may charge reasonable costs where audit support exceeds one business day.

11.2 Documentation First

Valevia may satisfy an audit request, in the first instance, by providing its documentation of technical and organisational measures, sub-processor due-diligence records, and summaries of any independent security assessments, where available.


12. Data Protection Impact Assessment

Where the Client must carry out a DPIA under GDPR Article 35, Valevia provides reasonable assistance, including a description of the processing operations, the technical and organisational measures in place, and relevant risk information.

Recommendation: a DPIA is likely appropriate for Inbox, given the systematic processing of communications and the AI-assisted classification of correspondence that may contain financial and other personal data. See Schedule B.


13. Governing Law

This DPA is governed by the laws of the Federal Republic of Germany and the GDPR. The competent supervisory authority for Valevia is the Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz (LfDI RLP), Hintere Bleiche 34, 55116 Mainz — datenschutz.rlp.de. Data subjects may also lodge complaints with their own national authority (e.g. CNPD in Luxembourg, APD/GBA in Belgium, CNIL in France, ICO in the United Kingdom).


Schedule A — Property Content Generation Processing Details

Categories of Data Subjects

  • Property sellers (whose properties are marketed)
  • Real estate agents (whose names/contact details appear in marketing materials)
  • Buyers/prospects (where their names appear in property notes provided by the Client)

Categories of Personal Data

Data CategoryExamplesSource
Agent contact detailsName, email, phone, photoClient submission
Property addressStreet, city, postal codeClient submission
Property imagesPhotos (may contain faces, street views)Client submission
Property descriptionsAI-generated text based on property dataGenerated by the Service
Marketing assetsBranded images and videosGenerated by the Service
Review actionsWho approved/rejected, when, edit historyPlatform usage

Purpose of Processing

  • Generate multilingual property descriptions.
  • Generate visual marketing assets (hero, carousel, reel, story).
  • Present content for human review and approval.
  • Publish approved content to the Client's connected social media accounts (and, if the Client enables it, a CRM).
  • Track ROI and pipeline metrics (aggregated/anonymised).

Sensitive Data

Property Content Generation does not intentionally process special-category data. Property images may incidentally contain faces or, in area photos, places of worship; these are processed solely for visual marketing and are not used for profiling or identification.


Schedule B — Inbox Processing Details

Inbox carries a higher data-protection risk than Property Content Generation. It processes correspondence between the Client's agency and third parties (prospects, buyers, sellers, tenants, other professionals).

Categories of Data Subjects

  • Prospects and leads, buyers and sellers, tenants
  • Professional contacts (notaries, mortgage brokers, other agents)
  • The Client's own employees (whose inboxes are processed)

Categories of Personal Data

Data CategoryExamplesSensitivity
Names and contact detailsFirst/last name, email, phoneStandard
Financial dataBudget, offer prices, mortgage detailsHigh
Property preferencesLocation, size, typeStandard
Transaction detailsOffer amounts, negotiation positionsHigh
Personal circumstancesFamily situation, relocation reasonsElevated
Communication contentEmail body, subject lines, attachmentsHigh
Behavioural dataTimestamps, response patterns, thread depthStandard
Property interest (derived)Link between an email and the Client's own property listing it concernsStandard

Processing Operations

  1. Ingestion — email content is received from the Client's email provider (Gmail, Outlook, IMAP).
  2. Redaction — common contact and identity identifiers (phone numbers, email addresses, account, ID and payment numbers) are automatically redacted from the email text. Personal names and addresses are retained, as they are needed for the AI to produce coherent output.
  3. AI classification — Azure OpenAI processes the (partially redacted) text to determine category, priority and intent.
  4. Property attribution — an email may be linked to the Client's own property listing it concerns (by matching the listing reference in the email text, or as part of AI classification), to organise the inbox and power the Client's per-property activity reporting. Reports derived from this linkage contain aggregate counts only, never correspondence content.
  5. Draft generation — a suggested reply is generated in the Client's configured tone/language.
  6. CRM enrichment (optional, off by default) — if the Client enables it, the sender may be cross-referenced with the Client's CRM for context.
  7. Agent review — the classification and draft are presented to the Client's agent for approval/editing. Valevia does not send replies automatically.
  8. Analytics — aggregated/anonymised classification data (category, priority, thread hash) is logged for ROI metrics.
  9. Aggregate market demand (anonymised, cross-Client) — the count of buyer inquiries, grouped by area (INSEE commune), property type and price band, is combined with the equivalent counts derived from other Clients to produce an anonymous, aggregated indicator of buyer demand in a market. The output is a count of distinct buyers per segment; it carries no correspondence content, no buyer identity, and is not attributable to any individual, property or Client. Segments below a minimum threshold are suppressed so no buyer can be re-identified.

Privacy-Preserving Measures

  • Partial redaction before AI — contact and identity identifiers (phone numbers, email addresses, account, ID and payment numbers) are redacted from email content before classification and from analytics events. Personal names and addresses are not redacted, as they are required for the AI to produce relevant classifications and draft replies.
  • Thread hashing — conversation threads are referenced by a one-way hash in analytics, not by email address or subject line.
  • Limited retention — email content and generated drafts are stored to provide the Service and are retained for up to 12 months, then automatically deleted.
  • Configurable scope — the Client controls which inboxes are processed and can disable Inbox at any time.

Additional Safeguards

  • Inbox data is isolated from Property Content Generation data at the database level.
  • The Client must obtain appropriate authorisation from its employees before enabling Inbox on their email accounts, and should inform its contacts that incoming email may be processed by AI for classification.

Anonymised, Aggregated Data

Valevia may create anonymous, aggregated statistics from data processed under this Agreement — for example, counts of buyer inquiries by area, property type and price band. Such statistics are irreversibly anonymised: they contain no personal data, no correspondence content, and cannot be linked to any individual, buyer, property or Client, and small groups are suppressed to prevent re-identification. Because anonymised data is not personal data, Valevia may use it to operate, secure and improve the Service, including to provide market-intelligence features to Clients. No Client's correspondence content, contacts, or identifiable data is ever shared with, or made visible to, any other Client — only the anonymous combined totals are.

DPIA Recommendation

We recommend the Client conduct a DPIA for Inbox, considering the systematic processing of communications, AI-assisted classification, the presence of financial data in correspondence, and the processing of third-party personal data. Valevia provides the information needed to support it.


Schedule C — Technical and Organizational Measures Summary

MeasureImplementation
Encryption in transitTLS 1.2+ (HTTPS-only endpoints)
Encryption at restAES-256 (Azure Storage, PostgreSQL)
Secret managementAzure Key Vault
Access controlRole-based (admin/member), multi-tenant isolation
AuthenticationAuthenticated sessions with industry-standard password hashing; API keys (HMAC) for services
Rate limiting / quotasAuthentication and AI endpoints (e.g. 5 failed logins / 15 min)
NetworkPrivate database endpoint, virtual-network isolation, egress allow-listing
AuditApplication-level append-only audit log (Azure Blob) + PostgreSQL audit log
BackupAzure-managed automated database backups
Incident responseNotification without undue delay; documented playbook
Environment separationProd / staging / test isolated (separate resource groups, DBs, key vaults)
Data minimisationRedaction of identifiers, purpose-limited retention
DeletionAutomated lifecycle policies; hard delete on termination

Schedule D — Australia (Australian Privacy Principles)

This Schedule supplements the DPA where the Client is an Australian entity subject to the Privacy Act 1988 (Cth). It does not restate the DPA; it maps the Australian Privacy Principles (APPs) onto the existing clauses.

D.1 Roles. The Client is the "APP entity" accountable under the Privacy Act; Valevia (Processor) acts on the Client's documented instructions per §1 (Parties and Roles) and §3 (Instructions).

D.2 Cross-border disclosure (APP 8). Valevia stores and processes personal information in the EU (Microsoft Azure, West Europe) via the sub-processors authorised under §5 (Sub-Processors). Valevia will handle that information consistently with the APPs and take reasonable steps to ensure its sub-processors do likewise, supporting the Client's APP 8 accountability. This Schedule does not, by itself, discharge the Client's own APP 8 obligations.

D.3 Notifiable Data Breaches (Part IIIC). In addition to §10 (Personal Data Breach), Valevia will assist the Client to meet its NDB obligations: notify the Client without undue delay on becoming aware of a suspected or actual eligible data breach, and provide the information the Client reasonably needs to assess it and to notify the OAIC and affected individuals. See the Breach Response Runbook (../compliance/BREACH_RESPONSE.md, §4.6a).

D.4 APP flow-down. Security (APP 11) is met through the measures in Schedule C; access and correction assistance (APP 12/13) through §9 (Data Subject Requests); sub-processor obligations through §5.

D.5 Precedence. For AU-specific matters where this Schedule conflicts with the body of the DPA, this Schedule prevails; otherwise the DPA governs.

Questions? Contact us at contact@valevia.eu

valevia

Operational intelligence for real estate agencies. Listings, marketing, inbox — automated.

GDPR compliant by design
Encrypted at rest & in transit
EU-hosted · Azure West Europe
Never used for AI training

Product

  • Listings
  • Marketing
  • Inbox
  • Pricing
  • FAQ
  • Try it free
  • Security

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Data Processing Agreement
  • Legal Notice

Connect

  • Start free trial
  • contact@valevia.eu

Operated by Valevia Consulting UG (haftungsbeschränkt) — a registered company in Germany.

© 2026 Valevia. All rights reserved.