Data processing agreement
When you use Protiva we process personal data on behalf of the Customer. The Customer is the controller, Protiva is the processor. This data processing agreement records those arrangements in accordance with Article 28 GDPR and forms part of the agreement.
Parties and roles
The Customer determines the purposes and means of the processing and is the controller. Protiva B.V. (Goudstraat 2, 2718 RC Zoetermeer, the Netherlands, Chamber of Commerce 42132675) processes the personal data solely for the Customer and is the processor. This agreement prevails over the other documents in so far as the processing of personal data is concerned.
Subject matter, nature and purpose of the processing
The processing concerns the management of property and tenant data on behalf of the Customer. Its nature includes storing, displaying, organising and processing data for property management, leases, invoicing and collection, document management and AI analysis. Its purpose is to deliver the service described in the agreement.
Duration
The processing lasts as long as the agreement is in force. After termination, the arrangements on return and deletion below apply.
Types of personal data and categories of data subjects
Depending on the Customer's use, the following are processed among others:
- Types of data: name, address and contact details, lease and payment data, correspondence, and — where the Customer uses it — identity data such as ID scans.
- Categories of data subjects: the Customer's tenants, co-owners, contact persons and suppliers/interested parties.
Processing on instruction
Protiva processes personal data solely on the basis of the Customer's documented instructions, as recorded in the agreement and in the use of the platform, unless a legal obligation requires otherwise. In that case Protiva informs the Customer beforehand, in so far as that is permitted.
Confidentiality
Protiva ensures that persons processing the personal data are bound by confidentiality and have access only in so far as their work requires.
Security measures (art. 32 GDPR)
Protiva takes appropriate technical and organisational measures, including:
- Encryption of data at rest and in transit.
- Access management based on roles and the principle of least privilege.
- Strict separation of customer environments (multi-tenant isolation).
- Logging of sensitive actions and periodic review of security.
- Backups and measures for recovery after incidents.
Sub-processors
The Customer gives Protiva general authorisation to engage sub-processors for the performance of the service, such as hosting (AWS, eu-central-1), the AI processing of documents and text (Amazon Web Services through Amazon Bedrock, eu-central-1) and services for email, SMS and analytics. Protiva imposes the same obligations on sub-processors as in this agreement, and informs the Customer of intended changes so the Customer can object to them.
International transfers
All processing takes place within the European Economic Area. Protiva does not transfer personal data to countries outside the EEA. Should this become necessary in future, it will happen only with appropriate safeguards (such as the European Commission's standard contractual clauses) and after notification.
Assistance to the controller
Taking into account the nature of the processing, Protiva assists the Customer in responding to data subject requests (such as access, rectification and erasure) and with obligations relating to security, data protection impact assessments (DPIAs) and prior consultation.
Data breaches
In the event of a personal data breach, Protiva informs the Customer without undue delay after becoming aware of it, with the information the Customer needs to meet its notification obligation, and cooperates in limiting the consequences.
Monitoring and audits
Protiva makes available to the Customer the information needed to demonstrate compliance with this agreement, and allows for reviews — through reports and, where reasonable, audits — with due regard for confidentiality and the continuity of the service.
Return and deletion on termination
After termination of the agreement, Protiva deletes or returns the personal data at the Customer's choice, and deletes existing copies, unless a statutory retention obligation requires otherwise. Documents have a seven-year lifecycle; identity data (ID scans) is kept for considerably less time (a maximum of around 30 days).
Last updated: August 2026.