This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in an applicable order, subscription or account (“Customer”) and Maksymilian Mielczarek, trading as ResiSuite (“ResiSuite”).
It applies where ResiSuite processes personal data on behalf of Customer in connection with the service.
1. Roles
For personal data contained in Customer Content:
- Customer is the controller or processor acting for another controller;
- ResiSuite is the processor or subprocessor, as applicable.
Each party remains independently responsible for personal data it processes for its own purposes, such as account administration, billing, security and legal compliance.
2. Customer instructions
ResiSuite will process personal data only:
- to provide, secure, support and maintain the service;
- according to Customer’s documented instructions in the agreement and use of the service;
- as required by applicable law.
If ResiSuite believes an instruction violates applicable data-protection law, it may inform Customer and suspend affected processing where appropriate.
3. Processing details
Subject matter
Hosting and processing property-related Customer Content and account data to provide AI-assisted video creation, image editing, description generation, storage, collaboration and related services.
Duration
For the term of the service and applicable deletion, backup and legal-retention periods.
Nature and purpose
Collection, storage, organisation, retrieval, hosting, transmission, transformation, editing, generation, deletion, support, security and troubleshooting.
Categories of data subjects
- Customer users and personnel;
- agents, photographers and agency representatives;
- property owners, tenants, occupants and visitors;
- people incidentally visible in photographs or property materials;
- other individuals whose data Customer submits.
Types of personal data
- names and contact details;
- account and workspace data;
- property addresses and listing information;
- photographs, videos, descriptions and metadata;
- images of people, number plates, documents and private possessions;
- technical, security and audit data;
- support information.
Customer must not submit special-category or highly sensitive data unless strictly necessary, lawful and expressly supported by the service.
4. Confidentiality
ResiSuite will ensure that persons authorised to process Customer personal data are subject to confidentiality obligations.
5. Security
ResiSuite will implement reasonable technical and organisational measures appropriate to the risk, which may include:
- authentication and access controls;
- least-privilege permissions;
- encrypted transport;
- storage access policies;
- logging and monitoring;
- backup and recovery controls;
- vulnerability and dependency management;
- incident response procedures;
- service-provider due diligence.
No system can guarantee absolute security.
6. Subprocessors
Customer authorises the subprocessors listed at:
https://www.getresisuite.com/legal/subprocessors
ResiSuite remains responsible for requiring subprocessors to protect personal data consistently with applicable obligations.
Where required, ResiSuite will provide reasonable notice of a new subprocessor. Customer may object on reasonable data-protection grounds. If the parties cannot resolve a valid objection, either party may terminate the affected service.
7. International transfers
Where personal data is transferred from the EEA to a country without an adequacy decision, the parties will use an appropriate transfer mechanism, which may include the European Commission’s Standard Contractual Clauses.
Where the Standard Contractual Clauses are required, the applicable controller-to-processor or processor-to-processor module is incorporated by reference to the extent legally permitted, with this DPA providing relevant processing details.
8. Data-subject requests
Taking into account the nature of processing, ResiSuite will provide reasonable assistance to Customer with requests to access, correct, delete, restrict, object to or port personal data.
Customer is responsible for responding to requests and verifying the requester’s entitlement.
9. Security incidents
ResiSuite will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data.
The notice will include available information reasonably required for Customer’s compliance. Notification is not an admission of fault or liability.
10. Compliance assistance
Taking into account the nature of processing and information available, ResiSuite will provide reasonable assistance with security obligations, breach notifications, data-protection impact assessments and regulator consultations.
Additional assistance beyond normal support may be subject to reasonable fees.
11. Deletion and return
During the service, Customer may access or download supported data.
After termination or deletion, ResiSuite will delete or anonymise Customer personal data according to the Privacy Policy, unless retention is required by law. Temporary residual copies may remain in backups until expiry.
12. Information and audits
ResiSuite will make available information reasonably necessary to demonstrate compliance with this DPA.
Audits should first use documentation, questionnaires or independent reports. On-site or intrusive audits require reasonable notice, must protect other customers and confidential systems, and may be limited to once per year unless a regulator or material incident reasonably requires otherwise. Customer bears reasonable audit costs unless the audit identifies a material breach by ResiSuite.
13. Customer obligations
Customer represents that:
- it has a lawful basis for all processing instructions and Customer Content;
- it has provided required privacy notices;
- it has obtained required permissions and consents;
- its instructions comply with applicable law;
- it will limit submitted data to what is necessary;
- it will configure access and workspaces securely.
14. Liability and priority
Liability under this DPA is subject to the limitations in the Terms of Service to the maximum extent permitted by law.
If this DPA conflicts with the Terms on data-processing matters, this DPA controls. Mandatory law and applicable Standard Contractual Clauses take priority.