1. Parties
This Data Processing Agreement (“DPA”) is entered into between:
- Data Controller:the managing agent organisation using the agentOS Block Manager platform (“you”, “the Controller”)
- Data Processor: {{COMPANY_NAME}}, the operator of agentOS Block Manager (“we”, “the Processor”)
This DPA forms part of the Terms of Service and is incorporated by reference. By using the platform, you agree to the terms of this DPA.
2. Scope and Purpose of Processing
The Processor processes personal data on behalf of the Controller for the purpose of providing the agentOS Block Manager software-as-a-service platform, which enables residential block management activities including:
- Managing leaseholder records, unit allocations, and service charge accounts
- Processing service charge demands, collecting payments, and managing arrears
- Maintaining compliance certificate registers and inspection records
- Facilitating communications between managing agents and leaseholders
- Storing and managing block-related documents and records
- Supporting GDPR data subject rights requests (Subject Access, Erasure, etc.)
The full Register of Processing Activities is available at /ropa.
3. Categories of Personal Data and Data Subjects
The personal data processed under this DPA relates to the following categories of data subjects:
- Leaseholders: name, email, phone, correspondence address, lease details, service charge history
- Freeholders / Owners: name, company details, contact information, portfolio ownership records
- Contractors: company name, contact person name, email, phone, address, accreditation details
- Platform users (managing agent staff): name, email address, organisational role, access log
4. Obligations of the Processor
The Processor ({{COMPANY_NAME}}) agrees to:
- Process personal data only on documented instructions from the Controller and solely for the purposes described in this DPA.
- Ensure that all persons authorised to process the personal data are subject to appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organisational security measures including AES-256-GCM encryption at rest for financial data, TLS 1.3 encryption in transit, row-level security for multi-tenant isolation, and role-based access controls.
- Not engage any sub-processor without prior written authorisation from the Controller. Current approved sub-processors are listed in Section 8 of this DPA.
- Assist the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under UK GDPR (access, erasure, rectification, portability, restriction, objection).
- Assist the Controller in ensuring compliance with Articles 32–36 UK GDPR (security, breach notification, DPIAs, prior consultation).
- At the Controller's choice, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless storage is required by law.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections.
5. UK Data Residency — Hard Requirement
The Processor commits to maintaining UK data residency as a hard technical and contractual requirement:
- All personal data is stored exclusively in UK-based data centres (primary database: Neon PostgreSQL, UK region)
- Database backups are stored in the same UK region as the primary database
- System logs containing personal data are retained within UK infrastructure
- Application hosting is deployed to UK/EU edge nodes via Vercel; no personal data leaves the UK without appropriate UK GDPR Chapter V safeguards
- Any change to data residency commitments requires 90 days' notice to Controllers and their express written consent
International transfers are only permitted where subject to appropriate safeguards under UK GDPR Chapter V, such as UK adequacy decisions, standard contractual clauses, or binding corporate rules.
6. Security Measures (Article 32 UK GDPR)
The Processor implements the following technical and organisational measures appropriate to the risk:
- Encryption at rest: Financial data (bank sort codes, account numbers) encrypted using AES-256-GCM
- Encryption in transit: All data transmitted using TLS 1.3 minimum
- Multi-tenant isolation: Row-level security (RLS) policies enforced at the database layer
- Access control: Role-based access control (RBAC) with five defined platform roles (Principal, Property Manager, Read-Only, Leaseholder, Freeholder)
- Audit trails: Immutable audit logs for all state-changing operations
- Client money protection: FCA CASS-aligned ring-fenced client money accounts per block
- Vulnerability monitoring: Continuous monitoring via platform observability tooling
7. Personal Data Breach Notification
In the event of a personal data breach, the Processor will:
- Notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach
- Provide the Controller with sufficient information to enable the Controller to notify the ICO within 72 hours as required by UK GDPR Article 33
- Cooperate fully with the Controller in investigating and remediating the breach
- Document the breach, its effects, and remedial actions taken
8. Approved Sub-Processors
The Controller authorises use of the following sub-processors. The Processor will inform the Controller of any intended changes at least 30 days in advance:
| Sub-Processor | Purpose | Location | Data Residency |
|---|
| Neon | PostgreSQL database hosting | UK | 🇬🇧 UK region |
| Vercel | Application hosting and deployment | UK/EU edge | 🇬🇧 UK primary |
| Calmony Pay | Platform subscription billing | UK | 🇬🇧 UK |
| Resend | Transactional email delivery | US (SCCs in place) | UK processing, US delivery |
9. Data Subject Rights Assistance
The Processor will assist the Controller in responding to data subject rights requests under UK GDPR. The platform provides tooling to:
- Log and track Subject Access Requests (SAR), erasure, and other data subject rights requests with 30-day deadline tracking
- Generate structured data exports for SAR responses
- Pseudonymise non-financial personal data for erasure requests
- Flag financial records that cannot be erased under legal retention obligations, with notification to the data subject
The GDPR management dashboard is available at /dashboard/gdpr.
10. Data Retention and Deletion
The Processor applies the following retention periods:
- Account data: deleted within 30 days of account closure request
- Financial records: retained for 7 years minimum (Companies Act 2006 / HMRC)
- Client money records: retained for 7 years (FCA CASS)
- Audit logs: retained for 90 days
- Leaseholder ownership history: retained indefinitely (conveyancing / Land Registry legal requirement)
Upon termination of the Controller's account, the Processor will make data available for export for 30 days, then delete all data (subject to mandatory retention obligations) within a further 30 days.
11. Liability and Indemnification
Each party shall be liable to the other for any direct losses, liabilities, costs and expenses arising from a breach of this DPA, subject to the limitations set out in the Terms of Service.
Where a party is held liable by a supervisory authority (ICO) or data subject due to a breach caused by the other party, the responsible party shall indemnify and hold harmless the other party.
12. Governing Law
This DPA is governed by and construed in accordance with the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.
13. Contact and DPO
For any queries relating to this DPA or data protection matters:
Data Protection Officer: {{DPO_EMAIL}}
Supervisory Authority: Information Commissioner's Office (ICO) — ico.org.uk