Data processing agreement
In force from 1 September 2026. This agreement comes into being between the parties through the use of the Service, without a separate signature.
This English text is a translation provided for convenience. The binding version is the Hungarian one, available at Adatfeldolgozói szerződés. Where the two differ, the Hungarian text prevails.
1. Subject of the agreement
Under Article 28 of the General Data Protection Regulation (EU 2016/679, GDPR), this agreement governs the relationship between the parties to the extent that the Processor processes personal data on behalf of the Controller while providing the RentIQ service.
2. Nature, purpose and duration of the processing
Nature and purpose: keeping letting records, preparing the monthly settlement, producing and delivering the settlement document, and providing the tenant features.
Duration: for as long as the Controller's account exists, or until the data is deleted or returned in accordance with this agreement.
3. Categories of data subjects and of data
Data subjects: the Controller's tenants and other natural persons connected to the lease.
Data: identification and contact data, the details of the lease, the address of the rental unit, meter readings and the photographs belonging to them, settlement data and documents, payment data, and the content of documents uploaded by the Controller.
The Processor neither asks for nor expects special category data under Article 9 of the GDPR. If the Controller records such data, they do so at their own responsibility.
4. Obligations of the Processor
- It processes personal data solely on the documented instructions of the Controller. Using the Service as intended, together with this agreement, constitutes such an instruction.
- It informs the Controller without delay if, in its view, an instruction infringes the law.
- It ensures that persons with access to the data undertake a duty of confidentiality.
- It applies the technical and organisational measures required by Article 32 of the GDPR, including encrypted communication, hashed storage of passwords, role-based access, encryption of backups and logging.
- It does not use the data for its own purposes, does not analyse it, does not sell it and does not transfer it to third parties, apart from the sub-processors identified in this agreement and cases of statutory obligation.
5. Sub-processors
The Controller gives the Processor general authorisation to engage sub-processors. The current list is available in the Privacy policy.
The Processor informs the Controller in advance of changes to the list, and the Controller may object to a change. In the event of an objection, the Controller may terminate the contract.
The Processor imposes the same obligations on its sub-processors, and is liable for their activity as if it had acted itself.
6. Assistance
The Processor assists the Controller in meeting data subject requests through the features provided by the Service, covering access, rectification, erasure and data portability. Where a request cannot be met using the features of the Service, the Processor co-operates to a reasonable extent.
The Processor assists the Controller in meeting its data security obligations, in handling incidents and, where necessary, in carrying out a data protection impact assessment.
7. Personal data breach
The Processor informs the Controller of any personal data breach it becomes aware of without undue delay, and within 48 hours at the latest. The notification covers the nature of the breach, the categories of data likely to be affected, the possible consequences and the measures taken.
Notifying the authority and informing the data subjects are obligations of the Controller.
8. Erasure and return
After the relationship ends, the Processor either deletes or returns the personal data, at the Controller's choice, unless the law requires the data to be kept.
The handling of uploaded files is governed by the Terms of service. Before files are deleted, the Processor sends a notice and provides an opportunity to download them.
Data held in backups is deleted when the backup cycle expires.
9. Audit
The Processor makes available to the Controller all information needed to demonstrate compliance with the obligations under Article 28. The Controller may initiate an audit once a year, on prior written notice. The audit may not involve access to the data of other controllers, and may not endanger the security of the Service.
10. Liability
The liability of the parties is governed by Article 82 of the GDPR. The Processor's liability exists within the limits set out in the Terms of service of the Service, except where the law excludes such a limitation.