EasyTenant

Data Processing Agreement (DPA)

1. Preamble and subject matter

The controller within the meaning of the General Data Protection Regulation (GDPR) is the customer (property manager or landlord). The processors are jointly ONSTUDIO (Louis Maurice Dietl, Am Schoolkamp 104, 46238 Bottrop, Germany) and Services Cologne (Mehmet Ayan, Vogelsanger Straße 197c, 50825 Köln, Germany). This data processing agreement (DPA) sets out the parties' data protection obligations regarding the processing of personal data by the processor in connection with the use of EasyTenant and takes precedence over any conflicting data protection provisions of the terms and conditions.

2. Term

The term of this DPA corresponds to the term of the terms and conditions between the parties and ends automatically upon their termination, without the need for separate notice.

3. Nature, scope and purpose of processing

The processor processes personal data solely to provide the EasyTenant services agreed in the terms and conditions (receiving and categorising tenant requests, commissioning service providers, sending welcome letters, providing the dashboard) and only on documented instructions from the controller. The processor does not process the data for its own purposes.

4. Type of data and categories of data subjects

The data processed includes in particular master data and the content of tenant requests (name, address of the residential or commercial unit, contact details, personal customer number, content of messages transmitted via WhatsApp, SMS or email) as well as master data of the service providers commissioned by the controller. Data subjects are the tenants and the controller's service providers.

5. Obligations of the processor

The processor shall process personal data only on documented instructions from the controller, unless required to do otherwise by European Union or member state law. It shall bind all persons authorised to process the data to confidentiality or ensure they are subject to an appropriate statutory duty of confidentiality. If the processor considers that an instruction infringes data protection law, it shall inform the controller thereof without delay.

6. Technical and organisational measures

The processor shall take the technical and organisational measures required under Art. 32 GDPR to ensure a level of security appropriate to the risk. The measures are described in Annex 1 and are adapted to the state of the art as necessary.

7. Sub-processors

The controller grants the processor a general authorisation to engage the sub-processors listed in Annex 2. The processor shall inform the controller in good time of any intended changes concerning the addition or replacement of sub-processors; the controller may object to such a change for good cause. The processor shall impose the same data protection obligations set out in this DPA on all sub-processors by way of contract.

8. Assisting the controller

The processor shall, to the extent reasonable, assist the controller with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under Art. 12 to 23 GDPR and in complying with the obligations under Art. 32 to 36 GDPR, in particular the reporting and documentation of personal data breaches and, where required, data protection impact assessments.

9. Reporting of personal data breaches

The processor shall notify the controller without undue delay, and no later than 48 hours after becoming aware of it, of any breach of the security of personal data affecting the data processed under this DPA, and shall assist the controller in fulfilling any notification obligations towards supervisory authorities and data subjects.

10. Deletion and return

After the provision of the contractually agreed services ends, the processor shall, at the controller's discretion, delete or return all personal data processed on the controller's behalf, unless a statutory obligation requires further retention.

11. Evidence and audits

The processor shall make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the controller or an auditor mandated by the controller. Such audits shall be announced with reasonable advance notice during normal business hours and carried out with due regard to the processor's trade secrets and business confidentiality.

12. Liability and miscellaneous

The liability of the parties is governed by Art. 82 GDPR. Amendments and additions to this DPA must be made in text form; this also applies to any waiver of this requirement. The law of the Federal Republic of Germany applies. Last updated: July 2026.

Annex 1 — Technical and organisational measures (TOM)

The processor takes, in particular, the following technical and organisational measures within the meaning of Art. 32 GDPR: • Confidentiality: encrypted data transmission via TLS/HTTPS and encryption of data at rest. • Physical, system and data access control: access to systems and data is restricted to authorised persons through individual access permissions. • Separation control: multi-tenant data segregation by organisation (orgId), so that customers can only access their own data. • Pseudonymisation, where possible given the nature and purpose of the processing and where the purpose of processing is not thereby compromised. • Availability and resilience: the application is hosted with providers that perform regular backups and maintain disaster-recovery procedures. • Resilience of the systems and services used, including under increased load. • Processes for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures. • All staff and personnel involved in processing are bound to confidentiality and data protection.

Annex 2 — Sub-processors

The processor engages the following sub-processors to provide the contractually agreed services: • Vercel Inc. (USA) — hosting of the website and application; transfer to the USA based on the EU standard contractual clauses. • Neon Inc. (USA) — database (serverless PostgreSQL); data is hosted in the EU region Frankfurt am Main. • SendSeven GmbH (Augsburg, Germany) — messaging provider for WhatsApp and SMS; in turn engages: Meta Platforms Ireland Ltd. (WhatsApp), seven communications GmbH & Co. KG, Kiel (SMS gateway, EU) and Google Vertex AI (AI-assisted categorisation, EU region europe-west4, Netherlands). • Resend, Inc. (USA) — sending of emails; transfer to the USA based on the EU standard contractual clauses. • Stripe Payments Europe, Ltd. (Ireland) — payment processing. • A&O Fischer GmbH & Co. KG (Winsen/Luhe, Germany) — printing and dispatch of welcome letters.