Data Processing Agreement (DPA)
This data processing agreement according to Art. 28 GDPR automatically becomes part of the main contract (subscription) as soon as a customer uses HouseControl.at for managing personal data of third parties — such as residents, owners, or service providers — and acts as the data controller. The provider (Ing. Stephan Rudolf Landsteiner, Online-Agentur Landsteiner) processes this data as a data processor within the meaning of Art. 4 No. 8 GDPR.
As of: August 2026
1. Subject Matter and Duration of Processing
The subject of this agreement is the processing of personal data by the provider on behalf of the customer in connection with the use of the HouseControl.at software-as-a-service platform for the digital management of residential properties.
The duration of this agreement corresponds to the term of the main contract existing between the parties.
2. Nature and Purpose of Processing
The provider processes personal data for the purpose of providing the HouseControl.at platform, especially for:
- the management of residential complexes, units, and resident assignments,
- the processing of damage reports and communication between property management, owners, tenants, and service providers,
- the conducting of digital votes and surveys,
- the creation and provision of documents and operating cost statements,
- Calendar functions and appointment management,
- technically necessary security, support, and administration processes.
3. Type of Personal Data
Specifically: Name, contact details (email, phone, address), access data, role and assignment data to residential units, communication content (messages, comments), voting and signature data, documents, technical usage data (IP address, log data).
Special categories of personal data (Art. 9 GDPR) are not intended for use with the platform and should not be entered into the platform by the customer.
4. Categories of Data Subjects
Residents (tenants, owners), administrative staff, service providers/contractors, as well as other persons whose data is entered into the platform by the customer in the context of property management.
5. Provider's Obligations
The provider processes personal data exclusively on documented instructions from the customer, unless required to do so by Union or Member State law to which the provider is subject; in such a case, the provider shall inform the customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The provider ensures that persons authorized to process data have committed to confidentiality or are subject to an appropriate statutory duty of secrecy.
The provider implements the technical and organizational measures described in Annex 1 in accordance with Art. 32 GDPR.
6. Customer's Right of Instruction
The customer is entitled to issue instructions to the provider at any time regarding the nature, scope, and procedure of processing. Instructions must generally be given in writing (also by email). The provider shall inform the customer without undue delay if they are of the opinion that an instruction violates data protection law.
7. Confidentiality
The provider ensures that all persons involved in the processing are obliged to confidentiality and perform their duties only within the scope of the respective required authorizations.
8. Sub-processors
The customer hereby grants their general authorization for the use of the following sub-processors (as of: August 2026):
| Sub-processor | Purpose | Registered Office / Place of Processing |
|---|---|---|
| IONOS SE | Platform hosting (server) | Germany (EU) |
| Contabo GmbH | Windows server for development, automation, and administrative access | Germany (EU) |
| ALL-INKL.COM — Neue Medien Münnich | Sending transactional emails | Germany (EU) |
| Stripe Payments Europe, Ltd. | Payment processing | Ireland (EU); data processing partly by affiliated companies in the USA |
| Google Ireland Ltd. | Login (Google sign-in), translation, AI text functions | Ireland (EU); data processing partly by affiliated companies in the USA |
| Cloudflare, Inc. | Bot and abuse protection | USA, with EU data processing via Cloudflare Germany GmbH |
| UptimeRobot | Availability monitoring of the public health check endpoint — retrieves no personal data | International |
The provider informs the customer about the intended engagement or replacement of further sub-processors. The customer may object to the change within 14 days for a legitimate reason.
9. Customer Support
The provider supports the customer, as far as possible, with appropriate technical and organizational measures in fulfilling their obligation to respond to requests for exercising the rights of data subjects mentioned in Chapter III of the GDPR.
The provider shall notify the customer without undue delay, and at the latest within 48 hours after becoming aware of it, of a personal data breach, so that the customer can comply with their reporting obligation under Art. 33 GDPR in due time.
10. Deletion and Return after Contract Termination
Upon termination of the provision of processing services, the provider deletes all personal data processed on behalf of the client or returns them at the client’s discretion, unless there is an obligation under Union law or the law of the Member States to store the personal data (e.g., tax and commercial law retention obligations).
11. Customer's Control Rights
Upon request, the provider shall make available to the customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and allow for and contribute to audits, including inspections, conducted by the customer or another auditor mandated by the customer.
12. Liability
For damages resulting from the breach of obligations under this agreement, the provider is liable without limitation according to statutory provisions for intent and gross negligence. For slight negligence, the provider is liable only for the breach of essential obligations under this agreement and, in terms of amount, limited to the contract-typical, foreseeable damage, insofar as legally permissible.
Liability for damages arising from circumstances for which the customer is solely responsible — in particular due to inadmissible instructions, incorrect or incomplete information, or the entry of data for which no sufficient legal basis for processing exists — is excluded, insofar as legally permissible.
Obligations under Art. 82 GDPR and any compensation between the parties internally remain unaffected by this provision.
13. Term and Termination
This agreement is valid for the duration of the main contract. A separate termination is not required; it ends automatically upon termination of the main contract, subject to the deletion and return obligations mentioned in point 10.
14. Final Provisions
Austrian law applies. Should individual provisions of this agreement be invalid, the validity of the remaining provisions remains unaffected. In the event of contradictions between this agreement and the main contract, the provisions of this agreement regarding the processing of personal data shall take precedence.
Appendix 1: Technical and Organizational Measures (Art. 32 GDPR)
- Confidentiality: Access control via role-based permissions, encrypted password storage, optional two-factor authentication (TOTP), encrypted transmission (TLS/HTTPS).
- Integrity: Logging of security-relevant events (audit log), CSRF protection, server-side validation of file uploads.
- Availability and resilience: Daily automated backups of database and file storage, regularly tested recovery, uptime monitoring, error monitoring.
- Verification procedures: Automated test suite and CI pipeline before each deployment, documented deploy and rollback processes.
Contact
Questions regarding this agreement can be directed to stephan@landsteiner.info be directed.