Propvora
Legal Centre

Privacy & data

Data Processing Agreement

The terms under which Blackwellen Limited processes personal data on behalf of Propvora customers, as required by Article 28 of the UK GDPR.

Effective:
3 October 2026
Version:
1.0
Status:
Current
Reading time:
19 min
Download

Key points

  • This agreement forms part of the Propvora Terms of Service and applies automatically to every customer. You do not need to sign anything separately.
  • You (the customer) decide how personal data in your workspace is used and are the controller. Blackwellen is your processor and acts only on your instructions.
  • We keep your data confidential and secure, use only the subprocessors on our public list, and give you notice and a right to object before adding a new one.
  • We help you respond to tenants' and others' data rights requests and with risk assessments, and we tell you about a personal data breach without undue delay.
  • When your subscription ends, you can export your data, and we then delete it, except where the law requires us to keep it.
  • Transfers outside the UK are protected by the UK–US Data Bridge, the IDTA or the UK Addendum, or adequacy regulations.

This summary is for convenience only. The full text below is what governs.

1.Introduction and incorporation

This Data Processing Agreement (DPA) is made between Blackwellen Limited, a company registered in England and Wales under number 16482166, whose registered office is at 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom (Blackwellen, the Processor), and the customer that has agreed to the Propvora Terms of Service (the Customer, the Controller).

This DPA is incorporated into, and forms part of, the Terms. It takes effect when the Customer first accepts the Terms (including at the start of a free trial) and continues for as long as the Processor processes Customer Personal Data. By accepting the Terms, the Customer accepts this DPA on its own behalf and, where applicable, on behalf of any affiliate that is a controller of Customer Personal Data processed through its Workspace.

This DPA sets out the terms required by Article 28(3) of the UK GDPR. Where the EU GDPR also applies to the Customer's processing, this DPA is intended to meet Article 28(3) of the EU GDPR too, and references to the UK GDPR are read as including the corresponding provisions of the EU GDPR.

2.Definitions and interpretation

In this DPA, the following words have the following meanings. Words defined in the Terms have the same meaning here unless defined below.

  • Customer Personal Data means personal data contained in Customer Data that the Processor processes on behalf of the Customer in providing the Service, as described in Annex 1 (section 15).
  • Authorised User means an individual the Customer permits to use the Service under its account who occupies a Seat (as defined in the Terms).
  • Customer Data means all data, content and files (including personal data) that the Customer, its Authorised Users or its Portal Users upload to, create in or transmit through the Service.
  • Data Protection Law means the UK GDPR; the Data Protection Act 2018; the Privacy and Electronic Communications (EC Directive) Regulations 2003; each as amended, including by the Data (Use and Access) Act 2025; and, where applicable to the Customer, the EU GDPR; together with any guidance and codes of practice issued by the ICO.
  • Data Subject Request means a request from a data subject to exercise a right under Chapter III of the UK GDPR.
  • ICO means the Information Commissioner's Office or its successor.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data transmitted, stored or otherwise processed by the Processor or a Subprocessor.
  • Restricted Transfer means a transfer of Customer Personal Data to a country outside the UK that is not covered by UK adequacy regulations.
  • Portal User means a third party the Customer invites to a portal connected to its Workspace, such as a tenant, landlord, owner or investor, applicant, guarantor, contractor or leaseholder.
  • Service means the Propvora platform described in the Terms, including its web application, portals and the Propvora Agent.
  • Subprocessor means any third party engaged by the Processor that processes Customer Personal Data on the Processor's behalf.
  • Transfer Mechanism means the International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU Standard Contractual Clauses (the UK Addendum), each issued by the ICO under section 119A of the Data Protection Act 2018, or the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge).
  • User means an Authorised User or a Portal User.
  • Workspace means a logically separated area of the Service in which the Customer's Customer Data is held.
  • controller, processor, data subject, personal data, processing, special category data and supervisory authority have the meanings given in Data Protection Law.

Headings are for convenience only. "Including" means including without limitation. A reference to a law includes that law as amended or re-enacted.

3.Roles of the parties

3.1 For Customer Personal Data, the Customer is the controller and the Processor is a processor. Where the Customer is itself a processor acting for a third-party controller (for example a managing agent acting for a landlord client who is the controller), the Processor is the Customer's subprocessor, and the Customer warrants that its instructions, including the appointment of the Processor, have been authorised by that controller.

3.2 The Processor is a controller, not a processor, of personal data it processes for its own purposes as described in the Privacy Policy, including Account Data, billing records, security and audit logs, and aggregated de-identified statistics. Those purposes are limited to what is necessary to provide, secure and improve the Service and to meet legal obligations, and the Processor will not use Customer Personal Data for any other purpose of its own, including marketing. This DPA does not apply to that processing.

3.3 Each party will comply with its obligations under Data Protection Law.

4.Customer obligations

4.1 The Customer is responsible for the lawfulness of its processing and of its instructions. In particular, the Customer will:

  • have, and maintain, a lawful basis under Article 6 of the UK GDPR, and where relevant a condition under Article 9 or 10 and Schedule 1 to the Data Protection Act 2018, for all Customer Personal Data it submits;
  • give data subjects all privacy information required by Articles 13 and 14 of the UK GDPR, including that the Processor and its Subprocessors process their data;
  • ensure the accuracy of Customer Personal Data and that it is adequate, relevant and limited to what is necessary;
  • configure the Service appropriately, including User roles, permissions, Portal access, AI settings and retention, and keep its Users' credentials secure;
  • decide whether the Service's security measures (Annex 2, section 16) are appropriate for the Customer Personal Data it chooses to store, especially any special category or criminal offence data; and
  • remain responsible for its own legal and regulatory duties, including those as a landlord or agent under housing and safety legislation. The Service is a tool to help with those duties; they do not discharge them.

4.2 The Customer will not instruct the Processor to process Customer Personal Data in a way that would breach Data Protection Law.

5.Processing on documented instructions

5.1 The Processor will process Customer Personal Data only on the Customer's documented instructions, including with regard to Restricted Transfers, unless required to do otherwise by UK law (or, where the EU GDPR applies, EU or member-state law) to which the Processor is subject. In that case the Processor will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

5.2 The Customer's documented instructions are: (a) the Terms and this DPA; (b) processing initiated by the Customer and its Users through the Service, including through settings, automations, Portal invitations, exports, deletions and AI features; and (c) any other reasonable written instruction from the Customer that is consistent with the Terms. Additional instructions outside the scope of the Terms require prior written agreement, and may be subject to reasonable charges.

5.3 The Processor will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law. The Processor is not obliged to carry out a detailed legal review of the Customer's instructions, and may suspend the affected processing until the Customer confirms or changes the instruction.

5.4 The Processor will not sell Customer Personal Data and will not use it to build profiles for its own purposes. The Processor does not use Customer Data to train generally available AI models, and does not permit any AI Subprocessor to use Customer Data to train its general models.

6.Confidentiality

6.1 The Processor will ensure that every person it authorises to process Customer Personal Data (including employees, officers and contractors) is subject to a contractual or statutory duty of confidentiality, receives appropriate data protection training, and has access only to the Customer Personal Data needed for their role.

6.2 The Processor will not disclose Customer Personal Data to any third party except: to Subprocessors under section 8; as the Customer instructs; or as required by law under section 5.1. If a public authority requests Customer Personal Data, the Processor will (unless legally prohibited) redirect it to the Customer, notify the Customer promptly, and disclose only the minimum required after considering whether the request is lawful and can be challenged.

7.Security

7.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of individuals, the Processor will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the UK GDPR. The measures in place at the date of this DPA are summarised in Annex 2 (section 16).

7.2 The Processor may update its security measures over time, provided that the update does not materially reduce the overall level of protection of Customer Personal Data.

7.3 Security is a shared responsibility. The Customer is responsible for the matters in section 4.1, including User management and safeguarding credentials, and for any data it exports from the Service.

8.Subprocessors

8.1 General authorisation. The Customer gives the Processor general written authorisation to engage Subprocessors. The Subprocessors in use at the date the Customer accepts this DPA are listed in the Subprocessor register, and the Customer authorises them.

8.2 Notice of changes. The Processor will give the Customer at least [Blackwellen to confirm: 14] days' notice before adding or replacing a Subprocessor, by updating the Subprocessor register and notifying the Customer's account owner by email or in the Service. The notice will identify the Subprocessor, its processing activity and its location. Where the Processor must change a Subprocessor urgently to protect the security or continuity of the Service (for example because a Subprocessor has failed or suffered a breach), it may give shorter notice, giving as much notice as it reasonably can and explaining the reason.

8.3 Right to object. The Customer may object to a new Subprocessor on reasonable grounds relating to data protection by writing to the Processor within the notice period. The parties will discuss the objection in good faith. The Processor may, at its option, offer a reasonable alternative, such as a configuration that avoids the Subprocessor (for example disabling AI features). If no alternative is reasonably available within 30 days of the objection, the Customer may terminate the affected part of the Service by written notice, and the Processor will refund any prepaid fees for the period after termination. This is the Customer's sole remedy for an objection, without affecting its rights for a breach of this DPA.

8.4 Flow-down and responsibility. The Processor will engage each Subprocessor under a written contract that imposes data protection obligations giving at least the same protection as this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. The Processor carries out appropriate due diligence before engaging a Subprocessor. The Processor remains liable to the Customer for the performance of each Subprocessor's obligations, as Article 28(4) of the UK GDPR requires, subject to section 14 (Liability, precedence and term).

8.5 Where a Subprocessor's terms are standard terms offered by a large provider and cannot be negotiated, the Processor will satisfy itself that those terms meet the requirements of Article 28(4).

9.Assistance with data subject rights

9.1 Taking into account the nature of the processing, the Processor will assist the Customer by appropriate technical and organisational measures, so far as possible, to fulfil the Customer's obligation to respond to Data Subject Requests. The Service includes functions that allow the Customer to find, view, correct, export and delete Customer Personal Data, and the Customer will use these functions first.

9.2 If the Processor receives a Data Subject Request relating to Customer Personal Data, it will not respond to it itself (other than to tell the data subject that it has passed the request to the relevant Customer, or to ask the data subject to contact the Customer) and will forward it to the Customer without undue delay, where the Processor can identify the Customer from the request.

9.3 Where the Customer cannot fulfil a Data Subject Request using the Service's functions, the Processor will give reasonable further assistance on request. The Processor may charge reasonable fees for assistance beyond what the Service's standard functions provide, except where the need for assistance results from the Processor's breach of this DPA.

10.Personal Data Breaches, DPIAs and other assistance

10.1 Breach notification. The Processor will notify the Customer without undue delay, and in any event within [Blackwellen to confirm: 48] hours, after becoming aware of a Personal Data Breach. Notice will go to the Customer's account owner by email (and, if the Customer has given one, its nominated privacy contact).

10.2 The notice will, so far as the information is available, describe: the nature of the Personal Data Breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its possible adverse effects; and a contact point for more information. Where not all information is available at once, the Processor will provide it in phases without undue further delay.

10.3 The Processor will take reasonable steps to contain, investigate and remedy the Personal Data Breach, will cooperate with the Customer, and will keep a record of it. The Customer is responsible for deciding whether to notify the ICO and data subjects, and for doing so within the 72-hour period in Article 33 of the UK GDPR where it applies. The Processor will not notify the ICO or data subjects about a breach of Customer Personal Data on the Customer's behalf unless the Customer asks it to or the law requires it.

10.4 Notification of, or response to, a Personal Data Breach is not an acknowledgement by the Processor of any fault or liability.

10.5 DPIAs and prior consultation. Taking into account the nature of the processing and the information available to it, the Processor will give the Customer reasonable assistance with data protection impact assessments under Article 35 of the UK GDPR and with any prior consultation with the ICO under Article 36, where they relate to the Customer's use of the Service. The Processor will normally meet this obligation by providing documentation, including this DPA, the Subprocessor register and the Security overview, and by answering reasonable written questions.

10.6 Security and compliance. The Processor will assist the Customer in ensuring compliance with Article 32 of the UK GDPR by meeting its obligations under section 7.

11.Deletion or return at the end of the subscription

11.1 During the subscription, the Customer can export Customer Data, and can delete records, at any time using the Service.

11.2 For 30 days after the Customer's subscription ends for any reason (the Exit Period, as defined in the Terms), the Processor will keep the Customer's Workspace in a restricted state so that the Customer can export Customer Data. At the Customer's choice, made by exporting its data during the Exit Period or by not doing so, the Processor will return the Customer Personal Data in a commonly used, machine-readable format through the export function, or delete it.

11.3 The Processor will delete Customer Data (including Customer Personal Data) from its live systems within [Blackwellen to confirm: 30] days after the end of the Exit Period, and backups containing it will be overwritten within [Blackwellen to confirm: 35] days after that deletion, on their normal rolling cycle. Until deletion, this DPA continues to apply and the data will not be actively processed except for storage and security.

11.4 The Processor may keep Customer Personal Data only to the extent and for as long as UK law requires, in which case it will keep it confidential, protect it under this DPA, and process it only for the purpose for which the law requires it to be kept.

11.5 On written request, the Processor will confirm in writing that deletion has taken place.

12.Information and audit

12.1 The Processor will make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, subject to this section 12.

12.2 The Customer will first request information in writing. The Processor will respond to reasonable written questionnaires and provide relevant documentation (such as its security policies summary, Subprocessor terms where shareable, and any available third-party reports of its Subprocessors). The parties agree that this will normally be sufficient to demonstrate compliance.

12.3 If the Customer reasonably considers that the information provided is insufficient, or if an audit is required by the ICO or another competent authority, or following a Personal Data Breach, the Customer may carry out an audit, provided that:

  • the Customer gives at least 30 days' written notice (or shorter notice where required by a supervisory authority or following a Personal Data Breach) and a proposed scope;
  • the audit takes place during normal business hours, no more than once in any 12-month period (except as required by a supervisory authority or following a Personal Data Breach), and is conducted so as to minimise disruption to the Processor's business and the Service;
  • any auditor is independent, not a competitor of the Processor, and bound by confidentiality obligations acceptable to the Processor, acting reasonably;
  • the audit does not give access to other customers' data, to information subject to legal privilege, or to the Processor's Subprocessors' facilities (audits of Subprocessors are carried out by relying on their own reports and certifications); and
  • each party bears its own costs, except that the Customer will reimburse the Processor's reasonable, documented costs of supporting an on-site or live audit, unless the audit reveals a material breach of this DPA by the Processor.

12.4 The Processor will promptly remedy any material non-compliance with this DPA identified by an audit.

13.International transfers

13.1 The Processor's default is to host Customer Data in the UK or the EEA where its Subprocessors offer that option. The Processing location of each Subprocessor is shown in the Subprocessor register.

13.2 The Customer authorises the Processor and its Subprocessors to transfer Customer Personal Data outside the UK as necessary to provide the Service, provided that each transfer is either to a country covered by UK adequacy regulations or is a Restricted Transfer covered by a Transfer Mechanism.

13.3 For a Restricted Transfer to a Subprocessor, the Processor will ensure that: (a) the Subprocessor is certified under the UK–US Data Bridge, where the transfer is to the United States and the Processor relies on that certification; or (b) the Processor (or the Subprocessor, as data exporter on the Processor's behalf) has entered into the IDTA or the EU Standard Contractual Clauses together with the UK Addendum, and has completed a transfer risk assessment, putting in place supplementary measures such as encryption where appropriate.

13.4 If a Transfer Mechanism relied on is invalidated or ceases to be available, the parties will cooperate to put an alternative lawful mechanism in place, and the Processor may suspend the affected transfer in the meantime.

13.5 Where the Customer is in the EEA and the EU GDPR applies, the UK is covered by an EU adequacy decision. If that decision ceases to apply, the parties agree that the EU Standard Contractual Clauses (Module 2 or 3, as applicable) will be incorporated by reference on the terms then published by the Processor.

14.Liability, precedence and term

14.1 Liability. Each party's liability arising out of or in connection with this DPA, whether in contract, tort (including negligence) or otherwise, is subject to the limitations and exclusions of liability in the Terms, and any reference there to a party's liability under the Terms includes its liability under this DPA. Nothing in this DPA limits or excludes: (a) any liability that cannot be limited or excluded by law; (b) either party's liability to data subjects under Article 82 of the UK GDPR, or to the ICO for fines or other sanctions imposed directly on that party; or (c) the rights of any consumer.

14.2 Where both parties are responsible for the same damage to a data subject under Article 82, each will be liable to the other for the part of any compensation corresponding to its own share of responsibility.

14.3 Precedence. If there is a conflict between this DPA and the Terms in relation to the processing of Customer Personal Data, this DPA takes precedence. If there is a conflict between this DPA and a Transfer Mechanism, the Transfer Mechanism takes precedence.

14.4 Changes. The Processor may update this DPA to reflect changes in Data Protection Law, guidance from the ICO, or changes to the Service, provided that an update does not materially reduce the protection given to Customer Personal Data. The Processor will give the Customer at least 30 days' notice of any material change. Changes required by law may take effect sooner.

14.5 Term and survival. This DPA continues until the Processor no longer processes any Customer Personal Data. Sections 6, 11, 12 and 14 survive termination for as long as needed.

14.6 Governing law and jurisdiction. This DPA and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except that a consumer living in Scotland or Northern Ireland may also bring proceedings in their local courts, and except as a Transfer Mechanism provides otherwise.

14.7 Contact. Notices under this DPA should be sent to info@blackwellen.com or to Blackwellen Limited, 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom, for the attention of the Data Protection Lead.

15.Annex 1: Details of processing

Subject matter

The provision of the Propvora property operations platform and related support to the Customer under the Terms.

Duration

The term of the Customer's subscription (including any free trial) plus the Exit Period and deletion periods in section 11.

Nature of processing

Collection through Customer and User input, Portal submissions and integrations the Customer enables; recording, organisation, structuring and storage; retrieval, consultation and search; generation of documents, reports and summaries; transmission by email and notifications; geocoding and display of property locations on maps; submission of selected content to AI providers to generate suggestions on request; backup; restriction; and erasure or destruction.

Purpose of processing

To provide the Service to the Customer, including managing properties, units, tenancies, works orders, planned maintenance, suppliers, compliance records, finance records, communications, documents, automations, reports, Portals and the Propvora Agent; to provide support requested by the Customer; and to keep the Service secure.

Categories of data subjects

  • Tenants, licensees, occupiers and household members (which may include children)
  • Prospective tenants and applicants
  • Guarantors and referees
  • Landlords, property owners and investors
  • Leaseholders and residents of managed blocks
  • Contractors, suppliers and their staff
  • The Customer's employees, agents and other Users
  • Emergency contacts and other individuals named in records

Categories of personal data

  • Identity and contact data: names, titles, addresses, email addresses and phone numbers
  • Property and tenancy data: tenancy and lease details, dates, occupancy, rent, deposits and service charges
  • Financial data: rent and payment records, arrears, invoices and bank details for payments (but not payment card data, which the Service does not store)
  • Referencing and compliance data: references, identity and right-to-rent check outcomes, compliance certificates and inspection records
  • Maintenance data: repair requests, access arrangements, photographs, videos, notes and job records
  • Communications: messages, emails, notes and call records
  • Documents uploaded by the Customer and Users
  • User account and activity data within the Workspace, including audit-trail entries
  • AI inputs and outputs generated at the Customer's request

Special category and criminal offence data

The Service is not designed to require special category or criminal offence data. The Customer may choose to record it (for example vulnerability or health information relevant to a repair, adaptations, or the result of a contractor's criminal record check). If it does, section 4.1 applies and the same security measures protect it.

Frequency

Continuous, for the duration above.

Subprocessors

As listed in the Subprocessor register.

16.Annex 2: Technical and organisational security measures

The Processor maintains at least the following measures, which may be improved over time under section 7.2:

  • Encryption: data in transit is encrypted using TLS 1.2 or higher; data at rest in the database and object storage is encrypted using AES-256 through the hosting and storage Subprocessors.
  • Tenant isolation: every Workspace's data is separated by row-level security policies enforced in the database, so that queries return only records belonging to Workspaces of which the requesting User is a member, and are further limited by that User's role.
  • Access control: authentication through the authentication Subprocessor with hashed passwords and expiring session tokens; role-based permissions within each Workspace; limited, scoped access for Portal Users; additional verification for administrative access to the platform.
  • Least privilege: Processor personnel access production data only where needed for a specific task, such as support requested by the Customer or incident response; administrative credentials and secret keys are kept server-side and are not exposed to browsers.
  • Network and application security: web application firewall, DDoS mitigation and rate-limiting through the content delivery Subprocessor; secure development practices, including keeping dependencies up to date and validating user input and uploads.
  • Logging and monitoring: application error monitoring configured to minimise personal data; audit-trail entries for significant actions within Workspaces; security logging for authentication events.
  • Resilience and recovery: managed database backups by the hosting Subprocessor; the ability to restore availability and access to data in a timely manner after an incident.
  • Supplier management: due diligence and written data processing terms with every Subprocessor; a public Subprocessor register.
  • Personnel: confidentiality obligations and data protection training for all personnel with access to Customer Personal Data.
  • Incident management: a documented process for detecting, assessing, containing, notifying and learning from Personal Data Breaches, in line with section 10.
  • Testing: regular review of the effectiveness of these measures, and updates when risks or technology change.

Further information is available in the Security overview.

Propvora is a product of Blackwellen Limited, a company registered in England and Wales (company no. 16482166), registered office 61 Bridge Street, Kington, Herefordshire, HR5 3DJ, United Kingdom. Registered with the Information Commissioner's Office under ZB905402.

info@blackwellen.com