Data Processing Agreement

This agreement governs the relationship between the controller and the processor under Article 28 of the EU General Data Protection Regulation (GDPR). The controller is the property that uses Flatmine: an owners' association, a building or estate management, a management company or a cooperative. The processor is Kaira Digital Arts S.R.L. (Braşov, Romania), which provides the service. This text is an integral part of the Terms of Use and applies for as long as the service is used.

The subject of the processing is the provision of property management: service charge accruals, the income and expense book, collection and bank reconciliation, document storage, meeting and resolution records, and notifications. Processing lasts for as long as the account exists. Data is processed for this purpose only; it is not used for marketing and is not sold to third parties.

The processor processes personal data only on the documented instructions of the controller. The property's use of the product and its settings count as those instructions. If the processor believes an instruction infringes data protection law, it informs the controller without delay.

Categories of data: identity and contact details (name, email, phone), unit and land registry or cadastral data, type of occupancy right, service charge and debt records, payments and bank movements, documents, meeting attendance and voting records, notification records and technical security logs. Data subjects: owners, tenants, residents, managers, auditors and supplier contacts. Flatmine takes no part in the payment flow; card data is never processed.

Everyone with access to the data is bound by confidentiality, and that duty continues after the service ends.

Technical and organisational measures (GDPR Art. 32): encryption in transit (TLS), role based authorisation enforced on the server, two factor authentication, bot protection, a security log kept for 365 days for money and deletion events, debt figures shown to residents only in aggregate, regular backups, and archiving instead of permanent deletion for records that carry history.

Hosting runs on Google Cloud inside the European Union: the database and files are in Germany (Frankfurt, europe-west3) and the application servers are in Belgium (europe-west1).

Sub-processors: Google (hosting, authentication, file storage, notification delivery) and Brevo (email delivery, France). When the AI assisted functions are used, namely reading bank receipts and statements and the in-app assistant, the relevant content is sent to Google Gemini; that call is not pinned to a European Union region. A management can define its own key and use that service under its own contract. Any change to the list of sub-processors is announced in advance and the controller may object.

The processor gives the controller reasonable assistance in handling requests from data subjects for access, rectification, erasure, restriction, objection and portability. The product itself provides tools to export and delete data.

In the event of a personal data breach, the processor informs the controller without undue delay after becoming aware of it and provides the information needed to meet notification duties.

When the service ends, data is returned or deleted at the controller's choice; records subject to a statutory retention period are kept for that period.

The processor provides the information needed to demonstrate compliance with this agreement and supports audits to a reasonable extent.

This agreement is governed by Romanian law. Questions and notices: info@kairadigitalarts.com