Handled Property Management

Data Processing Agreement

Last updated — to be confirmed

This agreement is a draft and is not yet in force

Handled is in private testing. Some details below are marked as to be confirmed, including the legal entity that would be party to this agreement. Questions are welcome at privacy@handledproperty.co.uk.

This Data Processing Agreement (DPA) forms part of the Terms of Service between you and Legal entity — to be confirmed, trading as Handled (we, us). It governs personal information that we process on your behalf. It does not need to be signed separately: it applies automatically whenever you use Handled to record information about other people.

It is required by Article 28(3) of the UK GDPR, which obliges a controller and a processor to have a contract containing the terms below. That obligation falls on both of us: you are not permitted to give personal information to a processor without one.

1. Which information this covers

Our Privacy Policy explains that there are two different roles in Handled, and this DPA covers only one of them.

InformationWho is the controllerCovered by this DPA?
Your own account — your name, email, role, firm details, tax references, audit and security recordsWe are. We decide how and why it is used.No. The Privacy Policy governs it.
What you record about other people — tenants, contacts, property ownership, financial records, uploaded documentsYou are. We act only on your instructions.Yes. This is the subject of this DPA.

If you are an accountancy firm

Where you use Handled to manage records for your own clients, you may be acting as a processor for those clients rather than as a controller in your own right. In that case we act as your sub-processor, this DPA applies between us as though references to “controller” were references to you in that capacity, and you confirm that you have the authority from your clients to appoint us. We deal only with you, not with your clients, in respect of those records.

2. Definitions

Data Protection Law means the UK GDPR and the Data Protection Act 2018, and any legislation that replaces or amends them. Controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meanings given to them in that law. Customer Personal Data means personal data within the second row of the table in clause 1. Terms defined in the Terms of Service — including Account, Plan and Service — have the same meaning here.

3. Subject matter, duration, nature and purpose

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1. Processing continues for as long as your Account is open, and then for the deletion window described in clause 10.

4. Our obligations: processing only on your instructions

We process Customer Personal Data only on your documented instructions, including in relation to transfers outside the UK, unless we are required to process it by law — in which case we will tell you before doing so, unless the law prohibits us from telling you.

Your instructions are:

We do not use Customer Personal Data for our own purposes. We do not sell it, do not use it for advertising, do not use it to train machine-learning models, and do not use it to build profiles of tenants or any other data subject.

If we consider an instruction to infringe Data Protection Law, we will tell you without undue delay. We are not obliged to give you legal advice, and telling you does not make us responsible for the lawfulness of your instructions.

5. Confidentiality

We ensure that anyone authorised to process Customer Personal Data is under an appropriate duty of confidentiality — whether a contractual obligation or a statutory one — and that the duty survives the end of their engagement. Access is limited to those who need it to provide, secure or support the Service.

6. Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR. Those measures are described in Annex 2.

We may update the measures in Annex 2 as the Service develops, provided that we do not materially reduce the overall level of security. The measures in Annex 2 are the ones actually in place; they are not aspirations.

7. Sub-processors

You give us general written authorisation to appoint sub-processors. Those currently appointed are listed in Annex 3.

8. Helping you respond to data subjects

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures — insofar as this is possible — in fulfilling your obligation to respond to requests to exercise data subject rights.

In practice the Service is built so that you can do this yourself, immediately and without asking us: you can search, view, correct, export and delete any record in your Account at any time, and export your records to CSV. For most access, rectification, erasure and portability requests this is faster than any process we could operate on your behalf.

If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request. We will tell them to contact you, and pass the request to you without undue delay, unless you have instructed us otherwise.

9. Personal data breaches, and helping you with your other duties

We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Our notification will describe, so far as we know it at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in phases as it becomes available.

Notifying you is not an admission of fault by either of us. Reporting a breach to the ICO is your decision, because you are the controller — and the 72-hour clock in Article 33 runs from when you become aware.

Taking into account the nature of the processing and the information available to us, we also assist you with your obligations under Articles 32 to 36 — security, breach notification to the ICO and to data subjects, data protection impact assessments, and prior consultation with the ICO.

10. Deletion and return

At the end of the provision of the Service, we delete or return Customer Personal Data at your choice, and delete existing copies unless Data Protection Law requires us to keep them. Specifically:

One case where we cannot delete straight away
Where a property is shared between co-owners with separate Accounts, closing one Account does not delete records the other co-owner still relies on. We will tell you if this affects your Account, and delete your Account’s own data as far as we can without destroying someone else’s records.

11. Information and audits

We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In practice:

Audit rights extend to our own systems and records. They do not extend to the systems of our sub-processors, or to any information about other customers.

12. International transfers

Customer Personal Data is stored in the United Kingdom — the database, file storage and the application itself. We will not transfer Customer Personal Data outside the UK without ensuring an appropriate safeguard under Data Protection Law is in place, such as UK adequacy regulations or the International Data Transfer Addendum to the EU standard contractual clauses.

Annex 3 records where each sub-processor holds data and where its parent company is incorporated. The distinction matters: a US-incorporated company hosting your data in London may still be capable of accessing it from the US, which counts as a transfer.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in section 15 of the Terms of Service. Nothing in this DPA limits either party’s liability to a data subject, or relieves either party of any liability imposed directly by Data Protection Law.

14. Changes to this DPA

We may update this DPA where Data Protection Law changes, where our processing changes, or to add or replace a sub-processor under clause 7. If a change materially affects your rights we will give you at least 30 days’ notice by email before it takes effect. This DPA is governed by the law of England and Wales.

Where this DPA and the Terms of Service conflict on the processing of Customer Personal Data, this DPA takes precedence.

Annex 1 — Details of the processing

Subject matterProvision of the Handled property record-keeping service.
DurationFor as long as your Account is open, and then for the deletion window in clause 10 — 60 days after closure or after a cancelled subscription ends.
Nature of the processingCollection, storage, organisation, structuring, retrieval, aggregation, export and erasure, by automated means.
PurposeKeeping records of properties, tenancies, rent, expenses and compliance dates; producing quarterly and annual tax figures; generating reminders; allowing you to share records with an accountancy firm or a co-owner; and exporting records at your request.
Types of personal dataTenant names, email addresses, phone numbers, tenancy dates, rent and deposit amounts, deposit scheme and reference, and notes you add. Contact details for contractors, agents and suppliers — name, company, phone, email, website, postal address, trade, notes. Property addresses, purchase and sale details, and ownership shares, which can identify individual owners. Financial transaction records, references and descriptions. The contents of documents you upload — tenancy agreements, safety certificates, EPCs, receipts and invoices — which are chosen by you and may contain personal data beyond the categories listed here.
Categories of data subjectTenants and prospective tenants; your contractors, agents, suppliers and other contacts; co-owners of properties you record; and, where you are an accountancy firm, your clients and the individuals in their records.
Special category dataNot required by the Service, and not requested by any field in it. If you choose to upload documents containing special category data or criminal offence data, you do so as controller and must have a condition under Article 9 or 10 for it. We do not process it for any purpose other than storing and returning the document you uploaded.

Annex 2 — Technical and organisational measures

These are the measures actually in place, not a general description of good practice.

Access control

Storage and transmission

Application security

Logging and accountability

Resilience

Annex 3 — Sub-processors

Sub-processorWhat they doWhere data is heldIncorporated
SupabaseDatabase, authentication and file storageLondon, United Kingdom (AWS eu-west-2)United States
VercelHosting and delivery of the application, and anonymous page-speed and page-view measurementServed from London, United Kingdom (lhr1); measurements are aggregated by Vercel's analytics infrastructureUnited States
ResendSending service emails — confirmation, password reset, invitationsSent via Ireland (eu-west-1); delivery logs, which include recipient email addresses, are held in the United StatesUnited States

Service emails are sent to account holders, and to people you invite to Handled. We do not send email to tenants, and no tenant record is transmitted to our email provider.

Contact

Questions about this agreement, or a request to exercise the audit rights in clause 11, go to privacy@handledproperty.co.uk, or by post to Postal address — to be confirmed.

We are registered with the Information Commissioner’s Office under registration number ICO registration number — to be confirmed.