Data protection
Updated
Legal Documents
This Data Processing Agreement (this "DPA") forms part of, and is incorporated by reference into, the agreement between Unloc AS ("Unloc", "Processor") and the customer identified in the applicable Master Services Agreement or other services agreement that references this DPA (the "Agreement").
The current version of this DPA, as published at this URL, applies to all processing of Personal Data carried out under the Agreement. See "Updates to this DPA" below for how changes are made and notified.
1. Introduction
This DPA sets out the main principles for processing of Personal Data under, and constitutes an integral part of, the Agreement.
References to this "DPA" include the following appendices, which are hosted separately and referenced below:
Appendix A – Services, Processing, Personal Data and Data Subjects (below)
Appendix B – Approved Sub-processors, published at the the Sub-Processors page and updated on an ongoing basis
Appendix C – Technical and Organisational Measures (below)
2. Purpose of the DPA
The purpose of this DPA is to regulate rights and obligations pursuant to applicable Data Protection Legislation relating to the Processor's processing of Personal Data (as data processor) on behalf of the Controller.
"Data Protection Legislation" means (i) the EU General Data Protection Regulation 2016/679; (ii) the UK General Data Protection Regulation and the UK Data Protection Act 2018 (together "GDPR"); and (iii) national privacy laws in the country where the Controller is established, each as amended or replaced from time to time. "Personal Data" means any information relating to an identified or identifiable natural person (the "Data Subject").
This DPA ensures that Personal Data is processed in accordance with Data Protection Legislation and is not used unlawfully or comes into the possession of any unauthorised party.
3. Scope of Processing
3.1 General
The Controller determines the purposes and means of the processing of Personal Data.
Processor, its Sub-processors, and other persons acting under the authority of Processor who have access to the Personal Data shall process the Personal Data only on behalf of the Controller and in compliance with the Agreement and the Controller's documented instructions, and in accordance with this DPA, unless otherwise stipulated in applicable statutory laws.
Processor shall immediately inform the Controller if, in Processor's opinion, an instruction infringes the Data Protection Legislation.
3.2 The purpose and scope of the processing
This DPA concerns the Processor's processing of Personal Data on behalf of the Controller in connection with the Services described in Appendix A. The nature and purpose of the processing are also specified in Appendix A.
4. Obligations of the Controller
The Controller warrants that the Personal Data is processed for legitimate and objective purposes and that the Processor is not processing more Personal Data than required for fulfilling such purposes.
The Controller is responsible for ensuring that a valid legal basis for processing exists at the time of transferring the Personal Data to Processor, including that any consent is given explicitly, voluntarily, unambiguously and on an informed basis. Upon Processor's request, the Controller undertakes, in writing, to account for and/or provide documentation of the basis for processing.
In addition, the Controller warrants that the Data Subjects to which the Personal Data pertains have been provided with sufficient information on the processing of their Personal Data.
Any instructions regarding the processing of Personal Data carried out under this DPA shall primarily be submitted to the Processor. If the Controller instructs a Sub-processor appointed in accordance with Section 11 directly, the Controller shall immediately inform Processor hereof. Processor shall not be liable for any processing carried out by the Sub-processor as a result of instructions received directly from the Controller, if such instructions result in a breach of this DPA, the Agreement, or Data Protection Legislation.
5. Confidentiality
Processor, its Sub-processors, and other persons acting under the authority of Processor who have access to the Personal Data are subject to a duty of confidentiality and shall observe professional secrecy in regard to the processing of Personal Data and security documentation pursuant to applicable Data Protection Legislation. The Processor is responsible for ensuring that any Sub-processor, or other persons acting under its authority, is subject to such duty of confidentiality.
The Controller is subject to a duty of confidentiality regarding any documentation and information, received from Processor, related to Processor's and its Sub-processors' implemented technical and organisational security measures, or information which Processor otherwise wants to keep confidential. However, the Controller may always share such information with supervisory authorities if necessary to act in compliance with the Controller's obligations under Data Protection Legislation or other statutory obligations.
The confidentiality obligations also apply after the termination of this DPA.
6. Technical and Organisational Measures
Processor shall implement appropriate technical and organisational measures as stipulated in Data Protection Legislation and/or measures imposed by the relevant supervisory authority pursuant to Data Protection Legislation or other applicable statutory law, to ensure an appropriate level of security.
Processor shall assess the appropriate level of security and take into account the risks related to the processing in relation to the Services under the Agreement, including risk of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data transmitted, stored, or otherwise processed.
All transmissions of Personal Data between Processor and the Controller, or between Processor and any third party, shall be done at a sufficient security level using encryption or similar means of protection, or otherwise as agreed between the Parties.
Further detail on Processor's implemented technical and organisational measures is set out in Appendix C below.
7. Access to Personal Data and Fulfilment of Data Subjects' Rights
If the Processor, or a Sub-processor, receives a request from a Data Subject relating to processing of Personal Data, Processor shall send such request to the Controller for the Controller's further handling, unless otherwise stipulated in statutory law or the Controller's instructions.
The Processor shall assist the Controller in fulfilling the Controller's obligation to respond to requests for exercising the Data Subject's rights under Data Protection Legislation, including the right to (i) access their Personal Data; (ii) rectification of inaccurate Personal Data; (iii) erasure of Personal Data; (iv) restriction of, or objection to, processing; and (v) data portability.
The Processor shall assist the Controller in fulfilling Data Subject rights at no additional cost for routine requests. For requests that are manifestly unfounded, excessive, or that require disproportionate effort, Processor may charge reasonable fees based on time spent, agreed in advance.
8. Other Assistance to the Controller
If the Processor, or a Sub-processor, receives a request for access or information from a supervisory authority relating to processing under this DPA, the Processor shall notify the Controller without undue delay, unless prohibited by law.
The Processor shall provide reasonable assistance to the Controller in connection with data protection impact assessments and consultations with supervisory authorities, at no additional cost up to a reasonable level. The Processor may charge reasonable fees for assistance requiring substantial effort, agreed in writing in advance.
9. Notification of Personal Data Breach
Processor shall notify the Controller without undue delay after becoming aware of a breach related to the processing of Personal Data ("Personal Data Breach"). The Controller is responsible for notifying the Personal Data Breach to the relevant supervisory authority.
The notification to the Controller shall as a minimum describe (i) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned; (ii) the likely consequences of the breach; and (iii) the measures taken or proposed by Processor to address it, including mitigation of adverse effects.
Where the Controller is obliged to communicate a Personal Data Breach to Data Subjects, the Processor shall assist the Controller, including providing available contact information for affected Data Subjects. The Controller bears any costs of such communication, except where the breach is caused by circumstances for which the Processor is directly responsible, in which case the Processor bears those costs.
10. Transfer
Where the Processor or a Sub-processor transfers Personal Data outside the EU/EEA or, where applicable, the United Kingdom, such transfer shall be subject to an appropriate transfer mechanism under Data Protection Legislation, including the EU Standard Contractual Clauses, the UK Addendum, or the UK International Data Transfer Agreement, or any successor mechanism. The Controller authorises Processor to enter into such mechanisms on the Controller's behalf for Sub-processors approved under Section 11. The current list of Sub-processors and their location is published at the Sub-Processors page.
11. Use of Sub-processors
The Controller agrees that Processor may appoint another processor ("Sub-processor") to assist in providing the Services and processing Personal Data under the Agreement, provided that Processor ensures that:
i. the data protection obligations set out in this DPA and in Data Protection Legislation are imposed on any Sub-processor by a written agreement; and
ii. any Sub-processor provides sufficient guarantees to implement appropriate technical and organisational measures to comply with Data Protection Legislation and this DPA, and provides the Controller and relevant supervisory authorities with access and information necessary to verify such compliance.
Processor's liability for the acts and omissions of any Sub-processor it appoints is subject to the limitation of liability provisions of the Agreement. The Processor is not liable for Sub-processors appointed directly by the Controller.
The Controller approves the Sub-processors listed at the Sub-Processors page as of the effective date of the Agreement, and hereby grants Processor general written authorisation to engage further Sub-processors. Processor maintains that list on an ongoing basis and will note the date each Sub-processor was added or replaced. The Controller may object to the addition or replacement of a Sub-processor within 2 weeks of the change being published. In case of such an objection, the Controller may terminate the Agreement and this DPA with 1 month's notice.
12. Audits
The Processor shall, on reasonable request and no more than once per year, provide the Controller with documentation to demonstrate compliance with this DPA, including a description of its technical and organisational measures, the current Sub-processor list, summaries of external security reviews, and any relevant certifications.
On-site audits are permitted only where (i) the documentation provided is materially insufficient, or (ii) there are reasonable grounds to suspect a breach of this DPA. On-site audits require 30 days' written notice, are conducted during normal office hours, must not unreasonably disrupt Processor's business, and must respect the confidentiality of other customers' data.
If the Controller appoints an external auditor, the auditor must be bound by confidentiality and must not be a competitor of the Processor. The Controller bears the cost of audits, except where an audit reveals material non-compliance by the Processor.
13. Term and Termination
This DPA is valid for as long as the Processor processes Personal Data on behalf of the Controller.
In the event of Processor's material breach of this DPA or non-compliance with Data Protection Legislation, the Controller may, after giving Processor 30 days' written notice and a reasonable opportunity to cure: (i) instruct Processor to stop further processing of Personal Data; (ii) terminate this DPA; and/or (iii) claim damages for direct economic loss caused by the breach, subject to the limitation of liability provisions of the Agreement. The cure period does not apply where the breach is incapable of cure or where immediate action is required to prevent serious harm to Data Subjects.
14. Effects of Termination
Upon termination of this DPA, the Processor shall, at the Controller's choice, delete or return all Personal Data to the Controller within 30 days, unless otherwise required by applicable statutory law. Personal Data held in routine system backups will be deleted in line with Processor's standard backup cycle. The Processor shall confirm deletion to the Controller in writing.
15. Updates to this DPA
Unloc may update this DPA from time to time — for example, to reflect changes in Data Protection Legislation, its security practices, or its Sub-processor list. Updated versions take effect once published, with the version number and effective date shown at the top of this page, and apply without requiring a separate signature from the Controller.
Where an update materially reduces the level of protection afforded to Personal Data, Unloc will give the Controller at least 30 days' prior written notice before the change takes effect. Sub-processor additions or replacements follow the notice and objection process in Section 11, not this 30-day period.
All other notices relating to this DPA shall be submitted in writing to the email address stated in the Agreement.
16. Governing Law and Legal Venue
The governing law and venue of the Agreement apply to this DPA.
Appendix A – Services, Processing, Personal Data and Data Subjects
Services
The services include the development and provision of software for creating and managing digital keys according to the Agreement.
Processing
Personal Data is processed for the purpose of delivering the Services, as set out in the Agreement.
Personal data
The Service processes the following categories of Personal Data:
i. Identity and contact data – name, phone number, email address, and user ID.
ii. Authentication data – tokens used to authenticate the end-user in the Service.
iii. Access data – lock identifiers and locations to which the end-user has access.
iv. Usage data – events related to digital key usage, including which user used which key at what time to operate which lock.
v. Technical data – device identifier, IP address, and log data required for security and operation of the Service.
Retention: Identity, contact, authentication, and access data are retained until the user profile is deleted, on instruction from the Controller or end-user. Usage data is retained for 60 days. Technical and security logs are retained for up to 12 months.
Data subjects
The Personal Data processed concerns the following categories of Data Subjects:
i. the Controller's employees, contractors, and service providers;
ii. residents, tenants, and prospective tenants;
iii. visitors and guests;
iv. other end-users authorised by the Controller to access locations via the Service.
Appendix B – Approved Sub-processors
The current, always-up-to-date list of approved Sub-processors is published on the sub-processors page.
Appendix C – Technical and Organisational Measures
Access control
Role-based access control limits employee access to Personal Data on a need-to-know basis. All administrative access to production systems and Sub-processor consoles requires two-factor authentication. Access rights are reviewed regularly and revoked promptly when no longer required.
Encryption
Customer Data is encrypted in transit (TLS) and at rest. Encryption keys are managed in Google Cloud.
Tech team and devices
Unloc's tech team resides in the EU. No Personal Data leaves the EU during development or debugging. All employee devices use full-disk encryption and run up-to-date operating systems and software.
Data locality
Sub-processors are located in the EU, or comply with frameworks providing equivalent data protection.
Cyber security
External security reviews of the Unloc app and platform are performed regularly. Identified vulnerabilities are triaged and remediated according to severity.
Backup and recovery
Customer Data is backed up via Google Cloud's managed backup services. Recovery procedures are tested periodically.
Incident response
Unloc maintains an incident response process covering detection, containment, notification, and remediation of security incidents, including Personal Data Breaches.
Personnel
Employees receive security and data protection training on hire and at regular intervals, and are bound by written confidentiality obligations.