1. Roles
For some data your organisation is the controller and we are the processor; for other data we are the controller in our own right. The split is not a formality — it decides who answers to whom. We act as your PROCESSOR for: content and personal data you publish or collect through your microsite, and all Tagoror house data (residents' pseudonymous profiles, chores, the shared-expense ledger, bookings, reports, inventory, events) including the encrypted identity vault. We act as CONTROLLER, on our own account, for: your organisation's own account with us, the accounts of the people who sign in (including residents' guest accounts, email addresses and magic-link authentication), billing, security logs and platform telemetry. This agreement governs only the first category. The second is described in our Privacy Policy.
2. Subject matter, duration, nature and purpose
Subject matter: the personal data described in section 3, processed solely to provide the platform features you have chosen to use. Nature and purpose: hosting, storage, display, transmission, backup, and the automated processing you switch on (AI-assisted content review, translation, and search indexing). Duration: for as long as your organisation holds an active account with us, and thereafter only as section 10 permits. We do not process your data for our own purposes, we do not sell it, and we do not use it to train artificial-intelligence models.
3. Categories of data subjects and personal data
Data subjects: your customers and visitors, your staff and members, and — where you use Tagoror — your residents and guests. Personal data: identification and contact details; content, images and descriptions you publish; messages exchanged through the platform; and for Tagoror, pseudonymous handles, household activity records, shared-expense entries, bookings and house reports. Special-category data is not requested by any platform feature and must not be entered into free-text fields. Identity-document data (passport or DNI number, date of birth, nationality, address) is processed only in the segregated encrypted vault described in section 6.
4. Processing on documented instructions
We process personal data only on your documented instructions, including as regards transfers, unless required otherwise by Union or Member State law — in which case we will inform you before processing, unless that law prohibits it on important grounds of public interest. Your use of the platform's features, and the settings you choose in it, constitute your documented instructions; this agreement and the product documentation record them. If we consider an instruction to infringe data-protection law, we will tell you.
5. Confidentiality
Every person authorised to process personal data under this agreement is bound by an obligation of confidentiality, whether by contract or by statutory duty, and that obligation survives the end of their engagement. Access is limited to the personnel who need it to operate and support the service.
6. Security measures (Article 32)
We implement appropriate technical and organisational measures, including: encryption of data in transit; encryption at rest of identity-document data and other secrets, held in a segregated vault that is never joined into an ordinary read path and whose access is role-gated and audited; least-privilege database roles; multi-factor authentication for administrative access; tenant isolation enforced at the query layer and verified automatically on every build; audit logging of privileged actions; daily encrypted backups with a documented restore procedure; and monitoring with alerting. Measures are reviewed as the service changes; we may vary them provided the level of protection is not reduced.
7. Sub-processors
You give general authorisation for us to engage sub-processors. The current list is published and kept up to date; we will give you reasonable prior notice of any intended addition or replacement so that you can object on reasonable data-protection grounds. If you object and we cannot accommodate it, you may terminate the affected service. Every sub-processor is bound by written terms imposing the same obligations as this agreement, and we remain fully liable to you for their performance.
8. Assisting with data-subject rights
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures in fulfilling your obligation to respond to requests for access, rectification, erasure, restriction, portability and objection. The platform provides self-service export and erasure tools for exactly this purpose. If a data subject contacts us directly about data we process on your behalf, we will not respond substantively — we will refer them to you and tell you promptly.
9. Breach notification and prior consultation
We notify you without undue delay after becoming aware of a personal-data breach affecting data processed on your behalf, with the information reasonably available to us, so that you can meet your own 72-hour obligation. Taking into account the nature of processing and the information available to us, we assist you with data-protection impact assessments and prior consultation under Articles 35 and 36.
10. Return or deletion at the end of processing
At your choice, we delete or return all personal data to you at the end of the provision of services, and delete existing copies, unless Union or Member State law requires storage. In practice the return is the export: complete, self-service, free, and available for as long as your account is open. If we ever wind the platform down, section 11 of the Terms sets a minimum notice period of 90 days during which that export remains available, and the same export is generated and emailed to you before the closing date. Data you delete may persist in rotating backups for a short period before those backups are overwritten; we do not use backups to reinstate data you asked us to delete.
11. Audit and information
We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. We may satisfy this by providing our documentation, security descriptions and any third-party attestations we hold. On-site inspections require reasonable prior notice, must not compromise other customers' data, and are limited to what is proportionate.
12. International transfers
Personal data is processed within the European Economic Area except where a sub-processor identified in the published list operates elsewhere, in which case the transfer is covered by an adequacy decision or by Standard Contractual Clauses together with the supplementary measures we have assessed as necessary. We will not transfer data outside the EEA on any other basis without informing you.
13. Term, precedence and liability
This agreement takes effect when you accept it and lasts as long as we process personal data on your behalf. It forms part of the Terms; where it conflicts with them on the processing of personal data, this agreement prevails. The liability provisions of the Terms apply to this agreement. Nothing here limits either party's obligations or liability under the GDPR itself. For any question about this agreement, contact privacy@canarionet.com.