Handover
Menu

Data Processing Agreement

Last updated: January 2025

Introduction

This Data Processing Agreement (DPA) forms part of the Terms of Service between Handover ("Data Processor") and the agency or individual ("Data Controller") using the Handover platform.

This DPA is required under Article 28 of the General Data Protection Regulation (GDPR) and applies where the Data Controller uses Handover to process personal data of third parties, including tenants.

Definitions

  • Data Controller: The agency or individual who determines the purposes and means of processing personal data through the Handover platform
  • Data Processor: Handover, which processes personal data on behalf of the Data Controller
  • Data Subject: The tenant or other individual whose personal data is processed through the platform
  • Personal Data: Any information relating to an identified or identifiable natural person

Role Clarification

When you use Handover to document property inspections involving tenants:

  • You are the Data Controller. You determine what data is collected, why it is collected, and what inspections are created. You are responsible for having a lawful basis to process tenant data and for informing tenants about how their data will be used.
  • Handover is the Data Processor. We process tenant data solely on your instructions and for the purpose of providing the inspection documentation service.

Your Responsibilities as Data Controller

As Data Controller you are responsible for:

  1. Having a lawful basis under GDPR Article 6 to collect and process tenant personal data (typically contract performance or legitimate interests)
  2. Informing tenants that their name, email address, and digital signature will be processed through Handover for the purpose of documenting the property inspection
  3. Ensuring tenant data entered into the platform is accurate and limited to what is necessary
  4. Responding to data subject requests from tenants regarding their personal data
  5. Notifying Handover immediately if you become aware of a data breach involving data processed through the platform

Our Obligations as Data Processor

Handover commits to:

  1. Processing personal data only on your documented instructions and for no other purpose
  2. Ensuring all Handover personnel with access to personal data are bound by confidentiality obligations
  3. Implementing appropriate technical and organizational security measures including encryption, access controls, and regular security reviews
  4. Not engaging sub-processors without your general authorization. Current authorized sub-processors: Supabase (database and storage, EU), Vercel (hosting, EU), Resend (email delivery, EU), Stripe (payment processing, EU)
  5. Assisting you in responding to data subject requests from tenants
  6. Notifying you within 72 hours of becoming aware of a personal data breach
  7. Deleting or returning all personal data upon termination of the service
  8. Providing all information necessary to demonstrate compliance with this DPA

Data Transfers

All personal data processed through Handover is stored and processed within the European Economic Area. No transfers to third countries are made.

Audit Rights

You have the right to audit Handover's data processing activities to verify compliance with this DPA. Audit requests must be submitted in writing to legal@handoverpro.co with reasonable notice.

Duration

This DPA is effective for the duration of your Handover subscription and terminates automatically upon account deletion.

Governing Law

This DPA is governed by Spanish law and EU data protection legislation.

Contact

For DPA-related enquiries: legal@handoverpro.co