Where a customer uses IRES AI to process personal data on behalf of third parties (typically a property-management company acting as controller for the co-owners of a community), a written Data Processing Agreement pursuant to Article 28 GDPR is required.
Availability
A template Data Processing Addendum ("DPA") is available on request. It covers subject-matter and duration of processing, categories of data subjects and personal data, obligations of the processor, sub-processors, security measures (TOMs), international transfers via Standard Contractual Clauses and audit rights.
How to obtain the DPA
Send an email to legal@iresai.app [TBD] with your legal entity name, address and the name and email of your signatory. We will send back a countersigned copy.
Subprocessors
The current list of subprocessors is documented in our Privacy Policy. Material changes are announced at least 30 days in advance via email to the DPA signatory.
Security measures (summary)
- TLS 1.2+ in transit; encryption at rest via hosting providers.
- Row-level security in the database, scoped per community and per role.
- Role-based access control and audit logging of privileged actions.
- Least-privilege access for maintainers; secrets stored in a managed vault.
- Backups and point-in-time recovery through the managed database provider.
Anonymisation and controller change
The Controller hereby instructs and authorises the Processor to anonymise Personal Data in accordance with EDPB Opinion 05/2014 (Anonymisation Techniques). With respect to the resulting Anonymous Data, the Processor acts as an independent Controller and may process, aggregate, publish, share and commercially license such Anonymous Data for statistical, research and commercial purposes — in particular to public authorities, academic and research institutions and commercial partners — without further instruction from or consent of the Controller.
The Processor shall implement technical and organisational measures ensuring that Anonymous Data cannot, by reasonable means, be re-identified, including minimum aggregation thresholds, suppression of rare attributes, removal of free-text fields and identifiers, and a prohibition on releasing combinations of attributes that could reasonably re-identify a household, a specific community or an individual. No Personal Data is transferred to the recipients of Anonymous Data.
For the avoidance of doubt, this clause does not authorise the Processor to disclose Personal Data to third parties beyond the subprocessors listed in the Privacy Policy.
