Privacy, security & AI
Data Processing Agreement and subprocessors
When Propvora acts as your processor, where to find the Data Processing Agreement and how to see which subprocessors we use.
- Updated
- Reading time
- 2 min read
On this page
If your organisation stores information about tenants, landlords, contractors or staff in Propvora, you will want to know the legal basis on which we handle it. This article explains our role, the Data Processing Agreement and the subprocessors we use.
Controller and processor
UK data protection law distinguishes between a controller, who decides why and how personal data is used, and a processor, who handles it on the controller's instructions.
- For information your organisation puts into its workspace or portals, your organisation is the controller and Blackwellen Limited acts as your processor.
- For account, billing, website, marketing, security and partner data, Blackwellen Limited is the controller.
Our Privacy Policy explains this in full, including a small number of purposes for which we act as a controller in our own right, such as preventing fraud and keeping security logs.
The Data Processing Agreement
Where we act as your processor, our Data Processing Agreement (DPA) sets out the terms that apply, as UK data protection law requires. It forms part of your agreement with us under the Terms of Service. It covers matters such as:
- processing only on your documented instructions
- confidentiality and security measures
- the use of subprocessors
- helping you respond to data rights requests
- notifying you of personal data breaches
- what happens to your data at the end of your subscription
Read the DPA itself for the governing terms, including any timescales. If you need a signed copy for your records or have questions about its terms, email info@blackwellen.com.
Subprocessors
We use carefully chosen third-party providers for services such as hosting, storage, email, payments, error monitoring and AI. Each one works under a written contract that requires it to protect data and use it only on our instructions.
The current list, with the purpose and location for each provider, is in our Subprocessor register. Check it whenever you need an up-to-date view for your own records or risk assessments.
International transfers
Some providers are based outside the UK or may access data from other countries. The Privacy Policy explains the safeguards we rely on when personal data leaves the UK.