Data Processing Agreement — annex to the ImoInspect Terms of Service
This annex forms part of the Terms of Service and applies whenever we process personal data on your behalf. Where this annex and the terms disagree about personal data, this annex wins.
Words like controller, processor, personal data and processing mean what they mean in the GDPR (Regulation (EU) 2016/679).
1. Who is what
| Controller | you — the estate agency, property manager or other business using ImoInspect |
| Processor | Awake Design, trading as ImoInspect, Buizerdlaan 57, 2496 HG Den Haag, the Netherlands, KvK 42044426 |
You decide which personal data goes into an inspection, about whom, and why. We store it, produce a report from it and deliver that report where you tell us to. That is the whole of our role and it is why we are your processor and not a controller.
One exception, stated so it is not a surprise later. For the accounts of your own staff — name, email address, phone number, role, sign-in records — we are the controller, because we decide what an account is and why it exists. That data is covered by our privacy policy, not by this annex.
2. What we process, and for whom
| Subject matter | recording property inspections and delivering the resulting report |
| Duration | for as long as your agreement runs, plus the retention periods in section 8 |
| Nature and purpose | storing inspection data, generating a PDF report, emailing a link to it, making it available in the admin panel |
| Categories of data subject | tenants, landlords, property owners, and other people named in an inspection |
| Categories of personal data | name, address, email address, phone number, NIF (tax number), date of birth, signature, photographs of the property and its contents, and free text an inspector types about a property or its condition |
| Special categories | none are asked for. The app has no field for health, ethnicity, religion or any other special category, and you should not put one in a free-text field |
Photographs deserve a line of their own: a photo of a room can incidentally contain a person, or a document lying on a table. That is a reason to point the camera carefully, and it is why the photos are treated as personal data throughout.
3. We only do what you tell us to
We process personal data only on your documented instructions. Using ImoInspect — creating an inspection, finalising it, sending a report — is the instruction; nothing else needs to be signed for the everyday case.
We do not use your inspection data for our own purposes. Specifically, and because these are the three things people are right to ask about:
- we do not sell it, rent it or share it with anyone other than the sub-processors in section 6;
- we do not use it to train machine-learning models, ours or anyone else's;
- we do not read it to build statistics about your business.
If the law ever obliges us to process data in a way you have not instructed, we will tell you before we do it, unless the law forbids us from telling you.
If we believe an instruction of yours breaks data-protection law, we will say so.
4. Confidentiality
The only people with access to your inspection data are those who need it to run and support the service. Today that is one person: Jason van Berg, the owner of Awake Design. Everyone with access is bound to confidentiality, and that obligation outlives this agreement.
We will tell you if that changes in a way that matters — if support is delegated to another person or a company, they become a sub-processor and section 6 applies.
5. Security
The measures below are the ones that actually exist, not a wish list.
In transit. Everything between the app, the admin panel and our servers travels over HTTPS/TLS. The app refuses unencrypted connections in the shipped build.
At rest. The database and the report storage are encrypted with keys managed by AWS. The database is not reachable from the internet: only the application can reach it, from inside its own private network.
On the phone. Inspection data lives in a database inside the app's private storage, which the operating system keeps away from other apps. Sign-in tokens are held in the Android Keystore. Signing out does not erase local data — deliberately, because on an offline-first app the phone may hold the only copy of a day's work — but signing in as a different organisation erases it, after warning the person doing so. That is what keeps a shared work phone from showing the previous agency's tenants.
Access control. Every request is authenticated, and every query is scoped to one organisation, so one agency cannot read another's data. Sign-in attempts are rate limited. Passwords are stored as bcrypt hashes and are not recoverable by us — we can only reset them.
Error reports. Crash reports go to Sentry and contain a stack trace, the app version and the device model. They do not contain a screenshot of the screen, and they are not designed to carry inspection content.
What we do not have. No penetration test has been commissioned yet, there is no ISO 27001 or SOC 2 certification, and the service runs in a single AWS region without a standby environment. If your procurement process requires any of those, ImoInspect does not meet it today, and we would rather you learn that here than in month three.
6. Sub-processors
You give us general authorisation to use the sub-processors below. Each is bound by a data processing agreement, and none may use the data for its own purposes.
| Sub-processor | What it does | Where |
|---|---|---|
| Amazon Web Services | servers, database, report storage | Frankfurt, Germany (eu-central-1) — inside the EU |
| Sentry | error reports | EU region (ingest.de.sentry.io) |
| Postmark (ActiveCampaign) | sending email | United States |
Postmark and the United States. Postmark has no European servers. When a report is delivered, what reaches Postmark is the recipient's email address, the subject line, the name of your agency and a link — the PDF itself is not attached and does not leave Frankfurt. Postmark retains that email content for 45 days by its own policy and then deletes it. The transfer relies on the European Commission's Standard Contractual Clauses. If your organisation cannot accept a US sub-processor, tell us: this is a supplier choice, not something the product depends on.
Adding or changing one. We will tell you at least 30 days before a new sub-processor starts processing inspection data. If you object on reasonable data-protection grounds within those 30 days, you may end your agreement for that reason, without penalty, before the change takes effect.
7. Helping you meet your own obligations
Requests from data subjects. A tenant, landlord or owner asking for access, correction or deletion is your request to answer — you decide, we do not. If one reaches us we will point them to your agency rather than act on it, and tell you it happened. If you need our help to answer, we will give it, at no charge for the kind of request that takes minutes rather than days.
Breach notification. If we discover a personal data breach affecting your data we will tell you without undue delay and in any event within 48 hours of becoming aware, by email to your administrator. We will describe what happened, which data and roughly how many people are affected, what we are doing about it, and what we advise you to do. Reporting to the supervisory authority is your decision, because you are the controller — but we will not leave you guessing while the clock runs.
Impact assessments and prior consultation. If you need to carry out a DPIA about your use of ImoInspect, we will give you the information about our processing that only we can provide.
8. Deleting and returning data
During the agreement. Deleting an inspection in the app deletes it from the phone. Reports that were delivered follow the periods below.
Retention we enforce automatically:
| The download link in a report email | 30 days |
| The stored report PDF | 12 months from the day it was sent, then deleted by a rule on the storage itself |
| Email content at Postmark | 45 days (their retention) |
| Error reports at Sentry | 90 days |
| Server logs | 30 days |
| Encrypted database backups | 7 days |
When the agreement ends. Tell us and we will delete your organisation's data, including reports still inside the 12-month window, and confirm in writing when it is done. If you would rather have it first, ask and we will export what we hold in a machine-readable form. If you tell us nothing, the periods above run their course and the data leaves on that schedule.
Two limits, stated plainly. We cannot delete data from a phone we do not control — that is your device and your inspector's. And backups are not instant: a copy may survive in an encrypted database backup for up to 7 days after deletion, after which it is rotated out. Nothing is restored from those backups except to recover the service itself.
9. Audits
You may ask us, once a year, to demonstrate that we comply with this annex. In practice that means we answer your questions in writing and send you what we have — the current version of this annex, the privacy policy, and our suppliers' own compliance documents, which for AWS, Sentry and Postmark are published and thorough.
If you need an on-site audit or a completed security questionnaire beyond that, we will cooperate, and we may charge for time reasonably spent. We would rather agree a scope first than turn down the request.
10. Liability, law and court
The liability cap in section 12 of the terms applies to this annex too.
Two things it cannot limit, and does not try to: your own liability as controller towards the people whose data you record, and a data subject's right to claim directly against a processor under Article 82 GDPR. Neither of those is ours to sign away, so no clause here pretends otherwise.
This annex is governed by Portuguese law, and disputes go to the courts of Lisbon — the same choice as the terms, for the same reasons.