Data Processing Agreement
Last updated: May 30, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and inbilit ("Processor") for the use of our property management platform.
GDPR Article 28 Compliance
This DPA is designed to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR). It governs the processing of personal data by inbilit on behalf of our customers.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Processing" means any operation performed on Personal Data
- "Controller" means you, the Customer, who determines the purposes and means of processing
- "Processor" means inbilit, who processes Personal Data on behalf of the Controller
- "Sub-processor" means any third party engaged by the Processor to process Personal Data
2. Scope of Processing
Subject Matter
inbilit processes Personal Data as necessary to provide the property management platform services as described in our Terms of Service.
Categories of Data Subjects
- Customer employees and authorized users
- Tenants of properties managed through the platform
- Vendors and service providers associated with managed properties
Types of Personal Data
- Contact information (name, email, phone)
- Business information (company name, address)
- Property-related data (lease information, billing records)
- Communication records (messages, support tickets)
3. Processor Obligations
inbilit shall:
- Process Personal Data only on documented instructions from the Controller
- Ensure persons authorized to process Personal Data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to data subject requests
- Delete or return all Personal Data upon termination of services
- Make available information necessary to demonstrate compliance
4. Security Measures
Encryption
TLS 1.3 for data in transit, AES-256 for data at rest
Access Control
Role-based access, multi-factor authentication, audit logging
Data Isolation
Multi-tenant architecture with strict account isolation
Backup & Recovery
Daily encrypted backups with point-in-time recovery
5. Sub-processors
We use the following sub-processors to provide our services:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database & Authentication | EU (Germany) |
| Amazon Web Services (AWS) | File Storage | EU (Netherlands) |
You may object to new sub-processors by contacting us within 30 days of notification.
6. Data Subject Rights
inbilit provides tools and assistance to help you respond to data subject requests including:
- Data access requests
- Data correction requests
- Data deletion requests ("Right to be Forgotten")
- Data portability requests
- Processing restriction requests
7. Data Breach Notification
In the event of a personal data breach, inbilit will:
- Notify you without undue delay (within 72 hours of becoming aware)
- Provide details of the nature of the breach
- Describe likely consequences and mitigation measures
- Cooperate with any investigation or regulatory inquiry
8. International Transfers
All Personal Data is stored within the European Union. We do not transfer Personal Data outside the EU/EEA unless required to provide the services and appropriate safeguards are in place (such as Standard Contractual Clauses).
9. Audit Rights
Upon reasonable notice, you may audit our compliance with this DPA. We also make available:
- Security certifications and audit reports
- Documentation of technical and organizational measures
- Responses to security questionnaires
10. Term & Termination
This DPA remains in effect for the duration of our service agreement. Upon termination, we will delete or return all Personal Data within 30 days, unless legal retention requirements apply.
11. Liability
As Controller, you are responsible for ensuring that you have a lawful basis for the processing you instruct us to carry out, for the accuracy and lawfulness of the Personal Data you provide, and for your own compliance with applicable data-protection law in respect of the data subjects (including your tenants and their occupants).
Each party's liability arising out of or related to this DPA is subject to, and counts toward, the exclusions and the aggregate limitation of liability set out in the Terms of Service (Section 12), to the maximum extent permitted by applicable mandatory data-protection law. You agree to indemnify the Processor against claims by data subjects or third parties to the extent they arise from your instructions, your configuration of the Service, or your breach of your obligations as Controller.
Nothing in this DPA limits any liability that cannot be limited under the GDPR or other applicable mandatory law.
12. Governing Law
This DPA is governed by the laws of Norway and is subject to the governing-law and exclusive-jurisdiction provisions of the Terms of Service (Section 16), without prejudice to any mandatory rights of data subjects under applicable data-protection law.