HouseID
ENCZDEES
← All legal documents

HouseID legal centre · E

DATA PROCESSING AGREEMENT (DPA)

GDPR Article 28 processing terms where HouseID processes personal data on a Client’s behalf.

Effective: 2026-08-26Version: houseid-legal-2026-08-26.1
The Czech text is legally controlling. This translation is provided for understanding.
E.1

This DPA forms part of the Client Agreement where HouseID processes personal data on the Client's behalf. The Client is controller and HouseID processor; for its account administration, billing, security, legal obligations and own B2B contact HouseID may be an independent controller under Part C.

E.2

Subject: portal operation, document storage and classification, project implementation, user/access management, reporting, support, security, backup, approved analytics and integrations. Duration: Client Agreement plus limited exit, backup and legal-retention periods. Purpose and scope may not expand without documented instruction and any required change request.

E.3

Data subjects may include employees, contractors, administrators, suppliers, contacts, property visitors and others entered by the Client. Data may include identity, contact, role, permissions, project/operational communications, contract metadata, training, access, audit logs and document content. Special categories, criminal data, biometrics and children's data are excluded unless expressly described in the Order with legal basis and risk assessment.

E.4

HouseID processes only on documented Client instructions, including for transfers, unless law requires otherwise; it then informs the Client beforehand unless prohibited. HouseID alerts the Client if an instruction appears to infringe GDPR or other law and may suspend the affected operation pending clarification.

E.5

Authorised persons are bound by confidentiality, trained and limited by role and need. HouseID maintains joiner-mover-leaver controls, periodic access recertification and privileged-access records. Shared accounts are prohibited except managed technical accounts with separate secret controls and audit trail.

E.6

HouseID implements Article 32 measures and Part G, including identity/role controls, MFA, tenant separation, encrypted transit, encryption of managed storage, secret management, logging, monitoring, backups, recovery, vulnerability management, secure development, supplier controls and regular effectiveness testing. Parameters are evidenced in a customer security sheet; no unsupported certification is claimed.

E.7

The Client grants general written authorisation for Part H subprocessors. HouseID gives at least 30 days' notice of intended change and information for a reasoned objection. The Parties resolve objections in good faith; absent an acceptable safeguard the Client may terminate the affected service. HouseID imposes substantially the same duties and remains responsible.

E.8

Taking account of processing nature, HouseID assists with data-subject rights. It forwards requests promptly and does not answer for the Client without authority. It assists with security, incidents, DPIAs and prior consultation. Reasonable routine assistance is included; extraordinary Client-instruction work may be charged after estimate but cannot obstruct legal duties.

E.9

HouseID notifies the Client of a confirmed personal-data breach without undue delay after awareness, targeting 24 hours after confirmation, with available information on nature, categories and approximate numbers, contact, likely consequences, measures and updates. The target is neither admission nor substitute for the Client's own 72-hour duty. HouseID preserves evidence and coordinates communications.

E.10

HouseID provides information necessary to demonstrate compliance and once annually permits a documentation or independent-report audit with reasonable notice, scope and confidentiality. On-site inspection is reserved for substantiated serious risk or authority request, during business hours and without access to other clients' data. Each Party bears ordinary costs; HouseID remedies material non-compliance at its cost.

E.11

A transfer outside the EEA occurs only on documented instruction or as an approved service element and under GDPR Chapter V. HouseID documents the mechanism, assesses destination risk, applies supplementary measures and provides material information on request. Commission Decision 2021/915 for controller-processor terms is not itself an international-transfer mechanism; where needed, clauses 2021/914 or another valid tool apply.

E.12

At the end HouseID returns or deletes personal data at the Client's choice unless law requires storage. Active data follow the exit period and backups the confirmed rotation cycle. Retained data remain protected and unused for other purposes. HouseID evidences completion and exceptions on request.

Questions about privacy, security or these terms: info@houseid.cz

This public edition excludes HouseID internal compliance controls and publication gates.

Back to HouseIDAll legal documents
DATA PROCESSING AGREEMENT (DPA) · HouseID