Legal

Data Processing Agreement

Last updated: September 30, 2026

1. Parties & scope

This Data Processing Agreement ("DPA") forms part of the agreement for the use of the Proptonomy platform ("Main Agreement") between Proptonomy AS, org. no. 836 984 242, Strandgata 52, 6905 Florø, Norway ("Proptonomy", the processor) and the customer identified in the Main Agreement ("Customer", the controller).

Proptonomy provides an AI-assisted operations platform for property management (the "Service") and, in doing so, processes personal data on behalf of the Customer. This DPA governs that processing and is entered into pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR") as incorporated into Norwegian law. In case of conflict between this DPA and the Main Agreement regarding the processing of personal data, this DPA prevails.

This is Proptonomy's standard DPA. It is executed as part of each customer agreement; the signed copy references this document together with the customer-specific details (Annex I). Questions: hello@proptonomy.ai.

2. Details of the processing

  • Subject matter and nature. Hosting, storage, synchronization, display, analysis, and AI-assisted handling (classification, drafting, sending of communications, task creation and updates) of the Customer's operational data.
  • Purpose. Provision of the Service as described in the Main Agreement.
  • Duration. The term of the Main Agreement, plus the deletion/return period in section 10.
  • Categories of data subjects. Guests and prospective guests of properties managed by the Customer; property owners and their representatives; the Customer's employees, contractors, and service partners (e.g. cleaners); other individuals appearing in communications connected to the Service.
  • Categories of personal data. Identification and contact data (name, email address, phone number, messaging identifiers); reservation and stay data (dates, property, party size, booking references, payment status as synced from the Customer's PMS — the Service does not process card payment data); communication content and metadata (messages, email, attachments, photos, video, voice messages); property access information supplied by owners (e.g. codes and instructions), to the extent it relates to identifiable persons; usage and log data related to the Customer's users.
  • Special categories of data. The Service is not designed for special-category data. Incidental special-category data may occur in free-text communications from data subjects; the Customer remains responsible for instructing deletion where required.

3. Instructions

Proptonomy processes personal data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required by EU/EEA or Norwegian law. The Main Agreement, this DPA, and the Customer's configuration of the Service (including integration connections, AI autonomy settings, and read-only modes) constitute the documented instructions. Proptonomy shall inform the Customer if, in its opinion, an instruction infringes the GDPR.

4. Confidentiality

Proptonomy ensures that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security (Article 32)

Proptonomy implements the technical and organizational measures described in Annex II, taking into account the state of the art, costs, and the nature, scope, context, and purposes of the processing.

6. Subprocessors

The Customer grants a general authorization for the engagement of subprocessors. The current list is set out in Annex III. Proptonomy will notify the Customer of intended additions or replacements at least 14 days in advance, giving the Customer the opportunity to object on reasonable, data-protection-related grounds. If the objection cannot be resolved, the Customer may terminate the affected part of the Service. Proptonomy imposes data protection obligations on subprocessors that are materially equivalent to this DPA and remains liable for their performance.

7. Transfers outside the EEA

The Service, its database, and file storage are hosted within the EEA (Annex III). Certain subprocessors process personal data outside the EEA — in particular the AI gateway used for the Service's AI features. Where personal data is transferred outside the EEA, Proptonomy ensures appropriate safeguards under GDPR Chapter V (EU Standard Contractual Clauses, or an adequacy decision where applicable), as indicated per subprocessor in Annex III.

8. Assistance to the controller

Taking into account the nature of the processing, Proptonomy assists the Customer with appropriate technical and organizational measures in fulfilling the Customer's obligations to respond to data subject requests (Articles 12–23), including access, rectification, erasure, restriction, and portability. Proptonomy also assists the Customer in ensuring compliance with Articles 32–36 (security, breach notification, data protection impact assessments, and prior consultation), taking into account the information available to Proptonomy.

9. Personal data breach

Proptonomy notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and in any event within 72 hours, providing the information reasonably required for the Customer's own notification obligations, supplemented as further information becomes available.

10. Deletion and return

Upon termination of the Main Agreement, Proptonomy will, at the Customer's choice, delete or return all personal data processed on the Customer's behalf, and delete existing copies, unless EU/EEA or Norwegian law requires storage. Absent an election within 30 days of termination, Proptonomy deletes the data. Residual copies in encrypted backups are deleted as backups rotate, within 35 days.

11. Audits

Proptonomy makes available to the Customer all information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice (30 days), at most once per year unless a breach or supervisory authority requires otherwise, during business hours, and without unreasonable disruption to Proptonomy's operations.

The Service additionally provides self-service transparency features, including an audit log of write operations performed by Proptonomy in the Customer's connected property management system, and activity logs of AI-performed actions.

12. Liability & governing law

Liability under this DPA follows the liability provisions of the Main Agreement, subject to mandatory law. This DPA is governed by Norwegian law; venue as per the Main Agreement. Annex I (details of processing) is as set out in section 2 of this DPA, supplemented by customer-specific details in the signed copy.

Annex II — Technical & organizational measures

  • Hosting. Production systems and object storage hosted with Hetzner (EEA data centers). Containerized deployment; production access restricted to authorized personnel via key-based SSH.
  • Encryption. TLS for all data in transit. Encryption at rest of sensitive credentials and secrets — the API keys and client secrets used to connect the Customer's integrations, and platform secrets. Secrets are managed outside source control.
  • Access control. Role-based access (staff/owner separation), organization-scoped data isolation enforced at the application layer, per-organization API credentials for PMS integrations.
  • Integration write controls. Outbound writes to connected PMS systems pass through a central guard supporting per-integration read-only mode, with a per-operation audit log reviewable by the Customer. Switching a connection between read-only and two-way is restricted to the Customer's administrators and is itself recorded. The exceptions (webhook maintenance, and guest or tenant messages on integrations where read-only mode does not yet apply) are listed per integration in the Privacy Policy.
  • AI processing controls. AI actions are logged with their context and outputs; AI-generated messages and notes are visible to the Customer in the platform, and detailed logs are made available on request. Every AI request carries a data-collection restriction so that content is only routed to model providers that do not retain it and do not train on it. AI autonomy is configurable per organization (from read-only to auto-reply).
  • Monitoring and logging. Application logging and distributed tracing (self-hosted); no third-party analytics on the web application.
  • Backups and resilience. Continuous streaming replication of the database to a standby server in a second EEA data centre, with write-ahead-log archiving enabling point-in-time recovery, plus rotating encrypted host-level snapshots retained up to 35 days.
  • Personnel. Confidentiality undertakings; access on a need-to-know basis.
  • Incident response. Breach notification process per section 9.

Annex III — Subprocessors

SubprocessorPurposeLocation / hostingTransfer mechanism
Hetzner Online GmbHServer hosting, database, object storageGermany / Finland (EEA)n/a (EEA)
OpenRouter, Inc.AI gateway routing content to LLM providers for AI features — current downstream model vendors: Xiaomi (MiMo), Alibaba (Qwen), Google (Gemini)USA gateway; model inference may run in the USA or other third countries depending on provider routing. Every request carries a data-collection restriction so content is only routed to model providers that do not retain it or train on it.EU SCCs
Mailgun (Sinch)Transactional email deliveryUSAEU SCCs (Mailgun/Sinch DPA)

Services connected at the Customer's instruction

The following services are connected (and can be disconnected) by the Customer through the platform. They act as the Customer's own processors or as independent controllers under the Customer's direct relationship with them, not as Proptonomy subprocessors; they are listed for transparency.

  • Microsoft Ireland Operations Ltd. — Microsoft 365 email/calendar integration (EEA / global, Microsoft DPA).
  • Google Ireland Ltd. — Gmail/Google integration (EEA / global, Google DPA).
  • Meta Platforms (WhatsApp) — WhatsApp messaging channel (global, Meta terms).
  • Telegram / LINE / Slack — messaging channels (global, per provider terms).
  • PMS platforms (Guesty, Hostaway, Uplisting, Resly, Lodgify, Hybel, KrossBooking, AndHamlet) — property management system sync (per provider).
  • Operations and pricing tools (Breezeway, Enso Connect, PriceLabs, Wheelhouse) — task, guest-portal and pricing sync, when the Customer connects them (per provider).
PrivacyTermsDPA