Data Processing Agreement (DPA)
Last updated: July 2026 · Effective on Order acceptance
Data Processing Agreement (DPA)
Last updated: July 2026 · Effective on Order acceptance
1. Parties & Scope
This Data Processing Agreement ("DPA") is entered into between the Customer ("Controller") and GARAAGRISAFE Ltd. ("Processor"), and governs the processing of personal data by the Processor on behalf of the Controller in connection with the GARAASSETS platform (the "Service").
This DPA forms an integral part of the Master Subscription Agreement and applies whenever the Processor processes Personal Data on the Controller's behalf.
2. Definitions
"Personal Data", "Controller", "Processor", "Processing", "Data Subject" and "Supervisory Authority" have the meanings given in the GDPR (Regulation (EU) 2016/679) and, where applicable, in the UK GDPR and Data Protection Act 2018.
"Sub-processor" means any third party engaged by the Processor to process Personal Data on the Controller's behalf.
3. Subject Matter, Duration & Nature
Subject matter: provision of the GARAASSETS valuation, inspection and reporting platform.
Duration: for as long as the Controller uses the Service, plus any post-termination retention period (§10).
Nature and purpose: hosting, storage, indexing, backup, AI-assisted drafting, e-signature, PDF/DOCX export, and audit logging.
Categories of data subjects: Controller's employees, clients, appraisal subjects, court parties, and end-customers.
Categories of Personal Data: name, email, phone, national ID (where uploaded), property/asset details, photos, geolocation, financial data, case documents.
4. Processor Obligations
Process Personal Data only on documented instructions from the Controller, including with regard to international transfers.
Ensure that personnel authorised to process Personal Data are bound by confidentiality obligations.
Implement appropriate technical and organisational measures per Art. 32 GDPR (see Annex II).
Assist the Controller in responding to Data Subject requests (Arts. 12–23 GDPR).
Notify the Controller without undue delay and no later than 48 hours after becoming aware of a Personal Data Breach.
Delete or return all Personal Data upon termination (see §10).
Make available to the Controller all information necessary to demonstrate compliance and allow for audits (§8).
5. Sub-processors
The Controller grants the Processor general authorisation to engage sub-processors listed in Annex III (Sub-processor list, published at /trust).
The Processor will notify the Controller of any intended addition or replacement of sub-processors with 30 days' notice via email or product notification, giving the Controller the opportunity to object.
The Processor imposes data protection obligations no less protective than this DPA on all sub-processors.
6. International Data Transfers
Primary data storage is located in the European Union (Frankfurt, Germany). Where personal data is transferred outside the EEA/UK, the Processor relies on: (a) an EU Commission adequacy decision; or (b) the EU Standard Contractual Clauses (2021/914) with appropriate supplementary measures; or (c) UK IDTA / EU-US Data Privacy Framework where applicable.
For GCC customers: personal data may, at Controller's option and subject to additional charges, be mirrored to an EU-hosted tenant with residency guarantees.
7. Security Measures (Annex II)
Encryption in transit (TLS 1.2+) and at rest (AES-256).
Row-Level Security enforcing per-tenant isolation.
Role-based access control with least-privilege principle and MFA for admin access.
Audit logging of every read/write to sensitive data.
Daily encrypted backups with 35-day retention; quarterly restore drills.
Vulnerability scanning, dependency monitoring and annual third-party penetration testing.
Incident response plan with 48-hour Controller notification SLA.
8. Audits
The Controller may audit compliance with this DPA once per calendar year, on 30 days' written notice, during business hours, at the Controller's expense and subject to reasonable confidentiality obligations.
The Processor may satisfy audit obligations by providing a current ISO 27001 / SOC 2 Type II report or equivalent independent attestation.
9. Data Subject Requests
The Processor will, insofar as possible, assist the Controller by appropriate technical and organisational measures to respond to requests from Data Subjects exercising their rights under Chapter III GDPR.
Self-service export (JSON/CSV/PDF) and per-case deletion tools are available in the platform.
10. Termination, Return & Deletion
Upon termination of the Service, the Controller may export all Personal Data in machine-readable format within 30 days.
After the 30-day export window, all Personal Data (including backups) is securely deleted within a further 90 days, unless retention is required by applicable law.
A written certificate of deletion is available on request.
11. Liability & Governing Law
Liability under this DPA is subject to the limitations set out in the Master Subscription Agreement.
This DPA is governed by the laws applicable to the Master Subscription Agreement. For EEA Controllers: Irish law and the courts of Dublin. For UK Controllers: English law. In all other regions the governing law of the Master Subscription Agreement applies; local mandatory data-protection laws may apply where legally required.
12. Signature
This DPA is deemed executed on the effective date of the Order Form or upon acceptance of the Service by the Controller, whichever is earlier. Enterprise customers may request a countersigned copy from legal@garaagrisafe.com.
legal@garaagrisafe.com · GARAAGRISAFE Ltd.