Data Processing Agreement

Last updated: May 30, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and inbilit ("Processor") for the use of our property management platform.

GDPR Article 28 Compliance

This DPA is designed to meet the requirements of Article 28 of the General Data Protection Regulation (GDPR). It governs the processing of personal data by inbilit on behalf of our customers.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person
  • "Processing" means any operation performed on Personal Data
  • "Controller" means you, the Customer, who determines the purposes and means of processing
  • "Processor" means inbilit, who processes Personal Data on behalf of the Controller
  • "Sub-processor" means any third party engaged by the Processor to process Personal Data

2. Scope of Processing

Subject Matter

inbilit processes Personal Data as necessary to provide the property management platform services as described in our Terms of Service.

Categories of Data Subjects

  • Customer employees and authorized users
  • Tenants of properties managed through the platform
  • Vendors and service providers associated with managed properties

Types of Personal Data

  • Contact information (name, email, phone)
  • Business information (company name, address)
  • Property-related data (lease information, billing records)
  • Communication records (messages, support tickets)

3. Processor Obligations

inbilit shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure persons authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in responding to data subject requests
  • Delete or return all Personal Data upon termination of services
  • Make available information necessary to demonstrate compliance

4. Security Measures

Encryption

TLS 1.3 for data in transit, AES-256 for data at rest

Access Control

Role-based access, multi-factor authentication, audit logging

Data Isolation

Multi-tenant architecture with strict account isolation

Backup & Recovery

Daily encrypted backups with point-in-time recovery

5. Sub-processors

We use the following sub-processors to provide our services:

Sub-processorPurposeLocation
SupabaseDatabase & AuthenticationEU (Germany)
Amazon Web Services (AWS)File StorageEU (Netherlands)

You may object to new sub-processors by contacting us within 30 days of notification.

6. Data Subject Rights

inbilit provides tools and assistance to help you respond to data subject requests including:

  • Data access requests
  • Data correction requests
  • Data deletion requests ("Right to be Forgotten")
  • Data portability requests
  • Processing restriction requests

7. Data Breach Notification

In the event of a personal data breach, inbilit will:

  • Notify you without undue delay (within 72 hours of becoming aware)
  • Provide details of the nature of the breach
  • Describe likely consequences and mitigation measures
  • Cooperate with any investigation or regulatory inquiry

8. International Transfers

All Personal Data is stored within the European Union. We do not transfer Personal Data outside the EU/EEA unless required to provide the services and appropriate safeguards are in place (such as Standard Contractual Clauses).

9. Audit Rights

Upon reasonable notice, you may audit our compliance with this DPA. We also make available:

  • Security certifications and audit reports
  • Documentation of technical and organizational measures
  • Responses to security questionnaires

10. Term & Termination

This DPA remains in effect for the duration of our service agreement. Upon termination, we will delete or return all Personal Data within 30 days, unless legal retention requirements apply.

11. Liability

As Controller, you are responsible for ensuring that you have a lawful basis for the processing you instruct us to carry out, for the accuracy and lawfulness of the Personal Data you provide, and for your own compliance with applicable data-protection law in respect of the data subjects (including your tenants and their occupants).

Each party's liability arising out of or related to this DPA is subject to, and counts toward, the exclusions and the aggregate limitation of liability set out in the Terms of Service (Section 12), to the maximum extent permitted by applicable mandatory data-protection law. You agree to indemnify the Processor against claims by data subjects or third parties to the extent they arise from your instructions, your configuration of the Service, or your breach of your obligations as Controller.

Nothing in this DPA limits any liability that cannot be limited under the GDPR or other applicable mandatory law.

12. Governing Law

This DPA is governed by the laws of Norway and is subject to the governing-law and exclusive-jurisdiction provisions of the Terms of Service (Section 16), without prejudice to any mandatory rights of data subjects under applicable data-protection law.

inbilit — Property Management