DPA
Data Processing Agreement
Last updated: 28 August 2026
The agreement governing the processing of personal data carried out by Hussteer on behalf of its clients.
This Data Processing Agreement (the “DPA”) supplements the general terms applying to Hussteer services. It governs the processing of personal data carried out by Hussteer on behalf of its clients when using the platform, in accordance in particular with Regulation (EU) 2016/679 of 27 April 2016, the General Data Protection Regulation (GDPR).
1. Parties and roles
In the context of professional use of Hussteer:
- the Client — the estate agency, agent, network or organisation that subscribed to the service — acts as data controller for the personal data they enter, import, collect or process through Hussteer;
- Hussteer acts as processor when it processes that data on the Client's behalf and on their instructions.
The Client determines the purposes and essential means of the processing they carry out using Hussteer. Hussteer processes data only to the extent necessary to provide the services subscribed to.
2. Subject of the processing
Hussteer provides a platform for real-estate professionals allowing the management of properties, contacts, prospects, sellers, buyers, mandates, viewings, appointments, transactions, documents and professional communications. In that context, Hussteer may host, organise, display, transmit, back up or technically process personal data on the Client's behalf. These operations are carried out solely in order to provide the features requested by the Client.
3. Duration of the processing
Processing carried out by Hussteer on the Client's behalf takes place throughout the contractual relationship. At the end of the contract, data is returned, exported, deleted or anonymised in accordance with the conditions provided by the service, the Client's instructions and applicable legal obligations. Any copies temporarily kept in backup systems are deleted according to the applicable technical retention cycles.
4. Nature of the operations
Depending on the features used, the operations carried out may include:
- collection;
- recording;
- organisation;
- structuring;
- storage;
- consultation;
- alteration;
- retrieval;
- export;
- transmission to authorised services;
- backup;
- and deletion of data.
5. Categories of data subjects
Data processed through Hussteer may concern:
- sellers and owners;
- buyers;
- prospects;
- tenants and rental applicants;
- landlords;
- professional contacts;
- partners and providers;
- agency staff;
- and more generally people whose information is lawfully processed by the Client in the course of their real-estate activity.
6. Categories of data
Depending on how the platform is used, the data processed may include:
- Identification data
- Surname, first name and information allowing a person to be identified.
- Contact details
- Postal address, email address, phone number and other professional or personal contact details.
- Property projects
- Property search, criteria, preferences, properties owned or offered, history of exchanges and information needed to follow up a commercial relationship.
- Property information
- Address, property characteristics, photographs, documents and information relating to its marketing.
- Contractual information
- Mandates, appointments, viewings, transactions and associated documents.
- Communications
- Notes, messages and history of exchanges recorded by users.
- Documents
- Documents uploaded to or generated in Hussteer in the course of the Client's activity.
The Client undertakes to process through Hussteer only data that is necessary and lawful in respect of their activity.
7. Client instructions
Hussteer processes personal data solely on the Client's documented instructions, in particular through normal use of the platform's features. Hussteer may not use the data entrusted by the Client for its own independent purposes, save any applicable legal obligation. If Hussteer considers that an instruction from the Client breaches the GDPR or another applicable data-protection provision, Hussteer informs the Client as soon as possible.
8. Confidentiality
Hussteer ensures that persons authorised to process personal data are bound by an appropriate duty of confidentiality. Access to data is limited to the people and providers who need it to run, maintain, secure or support the service.
9. Security
Hussteer implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, and accidental or unlawful destruction. Depending on the features and infrastructure used, those measures include:
- encryption of communications;
- encryption of stored data where the infrastructure allows it;
- logical partitioning of data between organisations;
- named access;
- authentication and access-control mechanisms;
- logging of sensitive operations;
- backups and restore mechanisms;
- and security incident management procedures.
Security measures are regularly adapted in line with developments in the platform, available technologies and identified risks.
10. Partitioning between organisations
Hussteer is designed to ensure logical separation between data belonging to the different organisations using the platform. A user must only be able to access the information their organisation and their permissions allow. Access-control mechanisms are applied at application level and, where relevant, at the data layer.
11. Sub-processors
To provide its services, Hussteer may use sub-processors. As at the date of this version, they may include:
- Vercel
- Infrastructure and application hosting.
- Supabase
- Database, authentication and storage.
- Resend
- Transactional email delivery.
- Stripe
- Payments and billing management.
- Anthropic
- Certain features relying on artificial-intelligence models.
- Certain features relying on artificial-intelligence models.
- Vercel AI Gateway
- Technical routing of certain requests to the model providers used by Hussteer.
Hussteer ensures its sub-processors are bound by data-protection obligations compatible with applicable requirements. The list of sub-processors may change over the course of the service.
12. Notice of a change of sub-processor
Hussteer informs the Client of any significant change concerning the addition or replacement of a sub-processor likely to process the personal data entrusted to Hussteer. Where regulations require it, the Client may raise a reasoned objection to that change. If no reasonable solution can be found, the parties may consider the contractual consequences applicable to the service concerned.
13. International transfers
Hussteer favours, where technically and commercially possible, infrastructure allowing data to be processed within the European Economic Area. However, some providers or features may involve processing or transferring data outside the European Economic Area. Where necessary, Hussteer ensures those transfers rely on a mechanism recognised by applicable regulations, in particular:
- an adequacy decision of the European Commission;
- the European Commission's standard contractual clauses;
- or any other legally recognised mechanism.
14. Artificial intelligence
When the Client uses a feature relying on artificial intelligence, certain data required to carry out the request may be sent to the relevant model provider. Hussteer limits the data sent to what the feature requires to work. Where possible, Hussteer applies mechanisms to reduce or avoid sending unnecessary personal information. The conditions applying to processing and retention by model providers depend on the professional services and APIs actually used by Hussteer.
15. Assisting with data subject rights
Where Hussteer receives a request directly from an individual concerning data processed on a Client's behalf, Hussteer forwards that request to the Client concerned where they can be identified. Hussteer assists the Client, as reasonably necessary and taking account of the nature of the processing, so that they can respond to requests to exercise rights under the GDPR. Those rights may include access, rectification, erasure, restriction, objection and portability.
16. Personal data breach
In the event of a personal data breach likely to affect data processed on the Client's behalf, Hussteer informs the Client as soon as possible after becoming aware of it. That notification contains, insofar as the information is available:
- the nature of the incident;
- the categories of data concerned;
- the potential consequences;
- the measures taken or planned;
- and the information allowing the Client to assess its own regulatory obligations.
17. Assisting the Client
Taking account of the nature of the processing and the information available to it, Hussteer reasonably assists the Client in meeting its obligations relating to:
- the security of processing;
- personal data breaches;
- data protection impact assessments;
- and, where applicable, consultations with a supervisory authority.
18. Deletion and return of data
At the end of the contractual relationship, the Client may retrieve the data made available to them using the export features offered by Hussteer. At the end of the applicable retention period, data is deleted or anonymised, unless a legal obligation requires it to be kept. Data held in technical backups may remain temporarily until deleted in the normal backup rotation cycle.
19. Documentation and audits
Hussteer makes available to the Client the information reasonably necessary to demonstrate compliance with the obligations set out in this DPA. Where required by regulations, and subject to reasonable conditions of confidentiality, security and organisation, Hussteer may contribute to the audits needed to verify compliance with its obligations as a processor. Audits must not compromise the security, confidentiality or availability of Hussteer services, nor expose data belonging to other clients.
20. Client obligations
The Client is responsible in particular for:
- the lawfulness of the data they collect and process;
- informing the data subjects;
- determining the purposes of the processing;
- setting appropriate retention periods;
- handling data subject rights;
- configuring users and their permissions;
- and complying with the obligations applicable to their activity.
The Client undertakes not to ask Hussteer to carry out processing contrary to applicable regulations.
21. Records and cooperation
Hussteer keeps the information and documents required to comply with its obligations as a processor. Hussteer cooperates, to the extent required by regulations, with the competent supervisory authorities.
22. Order of precedence
This DPA supplements the Terms of use, the Terms of sale and, where applicable, the contract or quote agreed between Hussteer and the Client. In the event of a conflict specifically concerning the processing of personal data, this DPA prevails over the general provisions of the contract, to the extent necessary to comply with applicable regulations.
23. Contact
For any question about data protection or this Data Processing Agreement:
- Contact
- fabrice@hussteer.com