← Caeiro by RealUtil

Data Processing Agreement

Caeiro by RealUtil · Effective [EFFECTIVE DATE] · This agreement is being prepared and is not yet in force.

This Data Processing Agreement ("DPA") forms part of the agreement between Yuval Kleinfeld (NIF 314122370), Portugal ("Caeiro", "Processor") and the estate agent who uses Caeiro for Business ("you", "Controller"). It governs Caeiro's processing of personal data on your behalf — that is, the data of your buyers, leads, and contacts. It does not cover your own account data, which is governed by the Privacy Policy (where Caeiro is the controller).

Where this DPA and the Terms of Service conflict on the processing of personal data, this DPA prevails.

1. Roles

You are the controller and Caeiro is the processor of the personal data described in Section 2, as those terms are defined in the GDPR (Regulation (EU) 2016/679). Caeiro processes that data only to provide the service to you.

2. Scope of processing (GDPR Art 28(3))

3. Caeiro's obligations as processor

  1. Instructions only. Caeiro processes the data only on your documented instructions, including for transfers, unless required by law (in which case it informs you first, where lawful).
  2. Confidentiality. Persons authorised to process the data are bound by confidentiality.
  3. Security (Art 32). Caeiro maintains appropriate technical and organisational measures, including: encryption in transit (TLS); encryption at rest for backups; per-user data isolation in the storage layer; access limited to the operator; session authentication via HttpOnly, Secure, SameSite cookies; and processing under sub-processor API terms that do not train on customer content and retain it only briefly for safety. These measures are reviewed and updated as appropriate to the risk.
  4. Sub-processors. You give general written authorisation for Caeiro to use sub-processors. The current list is in the Privacy Policy. Caeiro imposes data-protection obligations on each that are no less protective than this DPA, and gives at least 30 days' notice before adding or replacing one, during which you may object on reasonable data-protection grounds.
  5. Data-subject requests. Caeiro assists you, by appropriate measures, to respond to requests from data subjects exercising their rights (access, rectification, erasure, etc.).
  6. Assistance. Caeiro assists you with security, breach notification, data protection impact assessments, and prior consultation (Arts 32-36), taking into account the nature of processing and the information available to it.
  7. Deletion or return. At the end of the service, Caeiro deletes or returns all the personal data and deletes existing copies, within the period in Section 9, unless law requires retention.
  8. Audit and information. Caeiro makes available the information needed to demonstrate compliance with Art 28 and allows for and contributes to reasonable audits, including inspections, conducted by you or an auditor you mandate.

4. International transfers

Where Caeiro or a sub-processor transfers the data outside the EEA, the transfer is covered by an adequacy mechanism: the EU-US Data Privacy Framework where the importer is certified, and otherwise the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), which are incorporated into this DPA by reference.

5. Personal data breach

Caeiro notifies you of a personal data breach affecting your data without undue delay after becoming aware of it, and in any event within 48 hours, with the information you need to meet your own Art 33 obligation.

6. Liability

Liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law. [Confirm with a lawyer; some processor liabilities cannot be capped.]

7. Term

This DPA takes effect when you start using the service and continues for as long as Caeiro processes personal data on your behalf.

8. Governing law

This DPA is governed by the law of Portugal, without prejudice to the GDPR and the Standard Contractual Clauses.

9. Deletion period

On termination, Caeiro deletes or returns the data within 30 days, except where law requires longer retention. Backups are purged on their rotation cycle.

10. Acceptance

By using Caeiro for Business you accept this DPA on behalf of your business. [For clients who require a counter-signed copy, provide a signature block / e-sign route.]