Data Processing Agreement
Last updated: August 2026
1. Framework
This Data Processing Agreement (the “DPA”) implements Article 28 of Regulation (EU) 2016/679 (GDPR) and forms part of the Service terms. It governs the processing of personal data that ALIVIO Asset Management, S.L. (“ALIVIO”, processor) carries out on behalf of the Customer (controller) when providing the Platform.
2. Subject matter, duration, nature and purpose
- Subject matter: processing of personal data needed to provide the building and asset management service.
- Duration: the term of the service relationship, plus the return or deletion periods set out in this DPA.
- Nature and purpose: hosting, storage, retrieval, organisation, communication and other operations needed to run the Platform, following the Customer’s instructions.
- Types of data: identification and contact data, professional data, data on buildings/assets, incidents, visits, reports, images and documents provided by the Customer and its users.
- Categories of data subjects: owners, providers, tenants, contact persons and the Customer’s users.
3. ALIVIO’s obligations as processor
ALIVIO undertakes to:
- process data only on the Customer’s documented instructions, including for international transfers, unless legally required otherwise;
- ensure that authorised persons commit to confidentiality;
- implement the security measures of Art. 32 GDPR (see section 6);
- respect the conditions for engaging sub-processors (section 5);
- assist the Customer in handling data subjects’ rights requests;
- help the Customer meet its obligations on security, breach notification and impact assessments (Arts. 32–36);
- at the Customer’s choice, delete or return the data at the end of the service and delete copies, save for legal retention obligations;
- make available the information needed to demonstrate compliance and allow reasonable audits.
4. Customer’s obligations as controller
- have a valid legal basis and provide information to data subjects for the data it enters;
- give lawful instructions and be responsible for their content;
- properly manage the users and permissions of its accounts.
5. Sub-processors
The Customer authorises ALIVIO to engage the sub-processors needed to provide the service, imposing the same data protection obligations on them by contract. ALIVIO will inform the Customer of any intended change to its sub-processors, giving it the opportunity to object on reasonable grounds. Main intended sub-processors:
| Sub-processor | Service | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, CDN and security | EU / USA (with safeguards) |
| Expo / EAS [verify] | Mobile app build and direct distribution (no stores) | USA (with safeguards) |
| Transactional email provider [to be designated] | Email notifications | [complete] |
6. Security measures
ALIVIO applies technical and organisational measures appropriate to the risk, including as applicable: encryption in transit, role-based access control, authentication, activity logging, backups, and restoration and incident-management procedures. Technical detail may be provided to the Customer under confidentiality.
7. Personal data breaches
ALIVIO will notify the Customer without undue delay after becoming aware of a breach affecting data processed on its behalf, providing the information reasonably available so the Customer can comply, where applicable, with Arts. 33 and 34 GDPR.
8. International transfers
Any transfer outside the European Economic Area will rely on an adequacy decision or the European Commission’s Standard Contractual Clauses, with any necessary supplementary measures.
9. Return or deletion
At the end of the service, ALIVIO will make the Customer’s data available for export for a reasonable period and, at the Customer’s choice, delete or return it, removing existing copies save for legal retention obligations.
10. Liability
Liability arising from processing is governed by Art. 82 GDPR and by the Service terms.