Databehandleravtale
Sist oppdatert: October 3, 2026
1. Scope & Roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Landager and the customer ("you"). It applies to personal data that you enter into Landager about your tenants, applicants, vendors and other people ("Customer Personal Data"). For that data, you are the controller and Landager is your processor, as described in Article 28 of the GDPR and the UK GDPR. You accept this DPA by using Landager to process Customer Personal Data.
2. Details of Processing
- Subject matter and purpose: providing the Landager service: storing, organizing and displaying your records, sending the emails you set up or that the service sends on your behalf (such as rent reminders and receipts), and answering your AI assistant questions.
- Duration: for as long as you use the service, and then until deletion under section 9.
- Data subjects: your tenants, applicants, emergency contacts, vendors and any other people whose data you enter.
- Categories of data: names and contact details; lease, payment and deposit records; maintenance records; documents and photos you upload; and, for tenant applications, identity documents, employment and income information and references.
- Special categories: Landager is not designed for special category data. Do not enter it unless you have a lawful basis to do so.
3. Instructions & Confidentiality
We process Customer Personal Data only on your documented instructions, which are given by your use of the service and by this DPA, unless the law requires otherwise (in which case we will tell you, unless the law forbids it). People authorized to process Customer Personal Data are bound by confidentiality.
4. Security Measures
We implement the technical and organizational measures described on our security page, including encryption in transit, private file storage with signed links, ownership checks on every record, encrypted off-site backups, and two-factor authentication for our administrators. We may update these measures as long as the overall level of protection does not decrease.
5. Subprocessors
You authorize us to use the subprocessors listed in our Privacy Policy (currently Hetzner, Cloudflare, Resend, Google and Lemon Squeezy). We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible for them. We will announce a new subprocessor on that page at least 30 days before it starts processing Customer Personal Data; you may object by emailing us, and if we cannot address the objection you may end your subscription.
6. Assistance & Data Subject Requests
Taking into account the nature of the processing, we will help you respond to requests from people exercising their rights (access, correction, deletion and others). Most records can be viewed, corrected or deleted directly in your dashboard. If a person contacts us directly about Customer Personal Data, we will forward the request to you and will not respond ourselves unless you ask us to. We will also give you reasonable help with security, breach notifications and data protection impact assessments.
7. Personal Data Breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and give you the information we have to help you meet your own obligations.
8. International Transfers
Customer Personal Data is stored in Germany. Where a subprocessor processes it outside the EEA or the UK, the transfer relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another approved mechanism.
9. Deletion or Return
When your account ends, you can download your reports before leaving, and you can ask us for a copy of your data. On request, or when the account is closed, we delete Customer Personal Data from our live systems within 30 days, unless the law requires us to keep it. Encrypted backups are deleted on their normal rotation schedule.
10. Information & Audits
We will make available the information reasonably needed to demonstrate compliance with this DPA, and answer reasonable security questionnaires. Requests: [email protected].
